Electromagnetic compatibility and Radio spectrum Matters :
Part 1 : General requirements
EN301489-7
Electromagnetic compatibility and Radio spectrum Matters :
Part 7 : Specific conditions for mobile and portable radio and ancillary
equipment of digital cellular radio
Remote maintenance of machines using the M2Me_Connect service
The RAS family allows to connect easily and safely a machine to a remote PC, through the M2Me_Connect
Internet cloud service, for operation like remote maintenance.
When the remote PC is connected, the remote user can exchange any kind of data with each device of the
machine network as if his PC was directly connected to the machine network.
Ethernet or serial devices
The machine can consist of one or several devices connected through an Ethernet machine network or
connected through a serial RS232-RS485 interface.
The router RAS can be connected to the Internet through a cellular network, a Wi-Fi network or a factory
network
An Up-to-date IP router for particular situations
When using the Expert mode set-up, the router RAS becomes a powerful IP router-RAS-firewall for industrial
IP networks applications.
The router RAS connects to the devices network (called machine) and on the other hand to the Internet
The router RAS provides two IP interfaces : The WAN interface to reach the Internet and the LAN interface to
connect the machine.
WAN interface :
Depending on the model, the router RAS provides the following interfaces to reach the Internet :
The network connected to the WAN interface is called the WAN network or factory network.
LAN interface :
Depending on the model, the router RAS provides 1 to 4 switched Ethernet ports to connect the devices of
the machine.
That network is called the machine network.
1 serial RS232 and 1 serial RS485 interfaces are provided optionally.
Firewall
The firewall filters data between the WAN interface or any VPN interface on one hand, and the LAN interface
on the other hand.
The firewall filters source and destination IP addresses, but also remote users according to their identity.
Connecting a remote PC to a machine in any situation
M2Me Connect service is an ideal solution when a « machine », made of a set of devices connected to the
same LAN, is located in a private network (such as a Factory network).
Let’s take the example of a « machine » made of a set of connected devices and connected to the Factory
Network via a RAS-E.
Assuming that an expert is willing to remotely have access to the machine for breakdown diagnosis,
technical data acquisition, Web page display, file or program refreshment, M2Me Connect service enables
the remote operator to have access to the machine even if the machine does not have any public IP address.
Operation
When it is powered on or if the digital input is enabled, the router RAS settles a secured VPN connection
onto the M2Me Connect cloud service.
The remote PC is authenticated by the M2Me Cloud service.
Assuming that the router RAS provides two WAN connections (Cellular and Ethernet as an example), it
settles the best connection (Through the Ethernet network if possible) to the M2Me cloud service.
On the other hand, the remote user launches its M2Me secure software and settles a secured VPN
connection to the M2Me Cloud.
The directory offered by M2Me_Secure is helping the user to point the remote machine onto which he wants
to be connected.
The router RAS verifies thenafter that the remote user is allowed to be connected by checking its login &
password and as an option the certificate of the remote PC.
The router RAS grants to the remote user access rights according to its identity.
In order to warrant the level of security requested by industrial application, connection from PC to RAS is
fully encrypted and cannot be recovered even in case of intrusion onto the M2Me Connect cloud service.
M2Me connection onto the Internet is powered from the RAS. This non intrusive solution is better admitted
than an ingoing connection from the Internet onto the Machine.
Private & dynamic IP address
The machine connected into a factory network or connected to the Internet via a cellular network does not
have a public IP address. M2Me solution does not require a public IP address to settle a connection onto the
machine.
Access to each device of the machine
M2Me teleport your PC onto the machine network enabling you to have access to each device of the
machine as if you were in front of the machine.
Machine with Ethernet or serial connection
The family of RAS enables you to set up a connection to any type of PLC offering an Ethernet or a serial
connectivity.
Simple configuration of router RAS
Html configuration Server is delivered with a Wizard which gives an intuitive way of configuring the device.
Simple Operation
M2Me Secure software offers e set of directories for the remote machines. One click is enough to be
connected.
Security of customer network (Factory or WAN network)
Router RAS enables the remote operator to have access only to the machine network protecting the factory
network from any intrusion.
Machine & Device Access protection
A remote user can access to the machine if and only if its identification (login & password) has been
preregistered in the RAS router
An extra security option is offered. RAS can also demand the certificate installed in the PC of the remote
user.
The RAS can also give restricted access to the machine network giving access only to certain devices of the
machine and not to all.
Internet & Security
The flow of information passing through the M2Me connection is fully encrypted and requires authentication
to the M2Me server of both the PC of the remote user and the RAS router. A third party cannot consequently
have access to the machine preserving the integrity of the industrial process to be remote maintained.
There are different ways to connect the router RAS to the Internet and to the machine depending on the
situation which is encountered and also on the router RAS model.
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
5.1 Use case 1 : The machine is connected to the factory network
Description
The machine is separated from the factory network by the router RAS. The Internet is reached through the
factory network.
Machine IP address
Rule 1 : The IP domain of the machine network and the IP domain of the factory network must be different.
If both domains are identical, the IP domain of the machine must be modified or he RAS must be used
according to the Use case Nr 2 described below.
Rule 2 : The IP domain of the machine network and the IP domain of the remote PC must be different.
If both IP domains are identical, the IP domain of the machine must be modified or the machine network
translation option must be selected.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Communication initiated by devices belonging to the machine network towards
devices belonging to the factory network
Communication initiated by devices belonging to the factory network towards
devices belonging to the machine network
Enabled by creating
a firewall rule
Setting an additional VPN towards a server
Sending an email (all models) or a SMS (RAS-EC or RAS-ECW)
Security
The factory network and the machine network are separated by the router RAS. This is why the firewall can
operate to filter exchanges between these two networks; the machine is protected from unexpected
exchanges initiated by any device connected to the factory network. The firewall can be configured to
authorise particular exchanges.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Not filtered communication between the devices of the machine and devices of
the factory network
Setting an additional VPN towards a server
Sending an email (all models) or a SMS (RAS-EC or RAS-ECW)
5.2 Use case 2 : The machine belongs to the factory network
Description
The devices of the machine belong to the factory network.
The Internet is reached through the existing access.
In that case, the router RAS has to be connected to the factory network with its LAN Ethernet port.
Machine IP addresses
Rule : The IP domain of the machine network and the IP domain of the remote PC network must be
different.
If both IP domains are identical, it is possible to select the machine network translation option (see the
wizard configuration menu for detailed information); the IP domain of the devices of the machine is virtually
modified for the remote PC.
Security
The remote users can access only to the authorized devices of the unique machine and factory network.
But, because all the devices are connected to the same network, exchanges cannot be filtered on the local
network.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Setting an additional VPN towards a server
Sending an email (all models) or a SMS (RAS-EC or RAS-ECW)
5.3 Use case 3 : The machine is connected through a cellular network
Description
The Internet is reached through a cellular network.
Machine IP address
Rule : The IP domain of the machine network and the IP domain of the remote PC must be different.
If both IP domains are identical, the IP domain of the machine must be modified or the machine network
translation option must be selected (see the wizard configuration menu for detailed information).
Security
The remote user can only communicate with the authorised devices.
The availability and the quality of a cellular network is sometimes lower than a company network internet
access. It is important to check this situation will not provoke any kind of danger for people on the machine
site or of any other kind.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Setting an additional VPN towards a server
Sending an email (RAS-EW) or a SMS (RAS-ECW)
5.4 Use case 4 : The machine is connected through a Wi-Fi network
Description
The Internet is reached through a Wi-Fi network.
Machine IP address
Rule : The IP domain of the machine network and the IP domain of the remote PC must be different.
If both IP domains are identical, the IP domain of the machine must be modified or the machine network
translation option must be selected (see the wizard configuration menu for detailed information).
Security
The remote user can only communicate with the authorized devices.
The availability and the quality of a Wi-Fi network is sometimes lower than a company network. It is
important to check this situation will not provoke any kind of danger.
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
5.5 Use case 5 : The machine is connected through the factory & a cellular ntwk
Description
Reaching the Internet through the factory network may not be immediately authorized or available at the
moment of the machine installation; it is the reason why, the router RAS (RAS-EC or RAS-ECW) is able to
select the available way to the Internet; the factory network access to the Internet is selected as a priority
and the cellular network is used as a backup solution. The router RAS switches automatically between that
both ways.
Machine IP address
Rule 1 : The IP domain of the machine network and the IP domain of the factory network must be different.
If both domains are identical, the IP domain of the machine must be modified or he RAS must be used
according to the use case Nr 2 described above.
Rule 2 : The IP domain of the machine network and the IP domain of the remote PC must be different.
If both IP domains are identical, the IP domain of the machine must be modified or the machine network
translation option must be selected.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Communication initiated by devices belonging to the machine network towards
devices belonging to the factory network
Communication initiated by devices belonging to the factory network towards
devices belonging to the machine network
Enabled by creating
a firewall rule
Setting an additional VPN towards a server
Sending an email or a SMS
Security
The remote user can only communicate with the authorized devices.
The availability and the quality of a cellular network is sometimes lower than a company network. It is
important to check this situation will not provoke any kind of danger.
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
5.6 Use case 6 : The machine is connected through a Wi-Fi & a cellular ntwk
Description
Machine IP address
Rule 1 : The IP domain of the machine network and the IP domain of the factory network must be different.
If both domains are identical, the IP domain of the machine must be modified or he RAS must be used
according to the use case Nr 2 described below.
Rule 2 : The IP domain of the machine network and the IP domain of the remote PC must be different.
If both IP domains are identical, the IP domain of the machine must be modified or the machine network
translation option must be selected.
Connecting the remote PC to each device of the machine network through M2Me
Individual rights for each the remote user
Communication initiated by devices belonging to the machine network towards
devices belonging to the factory network
Communication initiated by devices belonging to the factory network towards
devices belonging to the machine network
Enabled by creating
a firewall rule
Setting an additional VPN towards a server
Sending an email or a SMS
Security
The remote user can only communicate with the authorized devices.
The availability and the quality of a cellular network is sometimes lower than a company network. It is
important to check this situation will not provoke any kind of danger.
Red Power-up
The SIM card is not present
Hardware failure
Cellular
Connection
Cel
Off SIM card not present – cellular interface disabled
Flashing slowly Connection in progress (1st step)
Flashing fast Connection in progress (2nd step)
Green Connected to the cellular ntwk
Cellular
signal level
Cel
Off Cellular interface disabled
1 flash Faint not sufficient signal
2 flashes Sufficient signal
3 flashes Strong signal
See detail below
Ethernet
WAN
M2Me
Off Not connected to M2Me_Connect
Flashing Connection in progress
Green Connected
Ethernet
WAN
Voyant inférieur
Off Ethernet interface not connected
Green Ethernet interface connected
Wi-Fi
Connection
Wi-Fi
Off Wi-Fi Interface not enabled
Green Wi-Fi Interface enabled
Wi-Fi
signal level
Wi-Fi
Off Wi-Fi not enabled or enabled as an access point
1 flash Faint not sufficient signal
2 flashes Sufficient signal
3 flashes Strong signal
Ethernet LAN
1 to 4
Off Ethernet interface not connected
Green Ethernet interface connected
RAS-EC-220 RAS—ECW-220
RS232
RS485
Rx
Characters received from the serial interface (to the router RAS)
Tx
Characters transmitted to the serial interface (from the router RAS)
To connect a device providing a specific connector
The RS485 serial interface is provided on the front
panel 2 positions screw-block.
It is not isolated.
Long RS485 line or high data rate
if the RS485 line is longer than10 meters or if the
data rate is greater than 19200 b/s, it is necessary
to connect one 120 Ohm matching resistor at each
end of the line and two 390 Ohm polarisation
resistors at one of the two extremities of the line.
To check that the input and the output are
correctly wired, select
Diagnostic > Hardware > Input / Output
The status of the input is displayed and
the output can be switched ON or OF.
RS232
The RS232 cable must be shorter than 10 meters.
Cables can be provided to connect the product to DTE and DCE as follows :
Check the cellular connection is authorised at the location where the router RAS is supposed to be installed.
Control of the reception level before installing the machine
Before installing the router, refer to a cell map over the Internet to check that the cellular reception signal is
strong enough at the location where the machine is supposed to be installed.
Select the right mobile service provider.
Reception level confirmation
If the reception seems possible, confirm with a control on site.
The reception level can be measured with a smartphone.
Most smartphones provide the reception level information (parameters or diagnostic menu).
To carry-out that control, use mandatorily a SIM card subscribed with the mobile service provider selected
for the router RAS.
Remark :
The router RAS itself provides the reception level information in two ways :
A reception level led indicator
The diagnostic menu of the administration web server of the router
8.2 Cellular antenna
We provide a complete catalog of cellular antennas :
If necessary, the antenna can be connected to the router RAS through a coaxial cable.
The signal attenuation in a usual coaxial cable is 0,2 to 0.4 dB / m diameter , mm), that is to say 2 to 4 dB for
a 10 meter long cable.
If a coaxial cable must be used to connect the antenna to the router, the attenuation in the cable has to be
taken into account to calculate the effective RF signal received by the router RAS.
The router provides two SIM card holders. If you use only
one SIM card, use the SIM card holder Nr 1.
Power off the router.
Remove the anti-steal lid at the top of the product
Insert the SIM card according to the drawing
8.4 Cellular service subscription
The router RAS is designed to connect to the LTE-UMTS-GPRS data transmission service like the one used
by the tablets.
The subscription should also provide the SMS service if SMS alarms are required.
A telephone service subscription is not needed.
One will take care to subscribe to a service authorizing the right volume of data per month (MB/month) and
to check the price of the MB exceeding the limit of the subscription plan, if it exists.
The subscription must be preferably signed in the country where the machine is supposed to be installed to
avoid roaming costs.
After installing and setting up the router, control the conformance of the connection :
Reception level
The reception level must be better than -90 dBm (two flashes of the reception level led indicator).
See the table below.
PING error rate
Each PING request must receive an answer.
Network response delay to a PING request
The response delay must be better than 500 ms.
If the delay is longer than one second, it means the network is overloaded or that the signal level is weak.
If the connection is not conform, change the position of the antenna or select an alternative service like
UMTS instead of LTE for instance.
(*) See the web server menu Diagnostic > Network > Interface.
The first configuration is carried-out with an HTML browser and a PC to the Ethernet LAN port 1 to 4 of the
router RAS .
Coming from factory, the IP address of the router is 192.168.0.128.
Step 1 : Create or modify the PC IP connection.
Assign to the PC an IP @ in accordance with the router RAS IP address.
For the first configuration, assign for instance 192.168.0.127 to the PC.
Step 2 : Connect the PC directly to the LAN interface of the router RAS.
Step 3 : Launch the HTML browser : http://192.168.0.128
Protecting the access to the administration web server
Select Set-up > Security > Administration rights.
Enter an administration identifier and password.
Set-up modifications with HTTPS or through the WAN interface
The administration web server is located at the LAN IP address.
Coming from factory, access to the administration web server is not allowed through the WAN interface
To use HTTPS instead of HTTP to setup the product or to authorise access to the administration web server
through the WAN interface,
Select Configuration > Security > Administration rights.
Enter an administration identifier and password.
Check the “HTTPS configuration” box.
Check the “WAN access“ box if you wish to access to the administration web server through the WAN
interface.
Remark : the port Nr used to access to the administration web server with HTTPS is 4433.
Exemple : https://192.168.38.191:4433.
Recovering the factory LAN IP address
Press the front panel push-button ;
The OPERATION led indicator will flash.
The factory IP address 192.168.0.128 will be restored but the current configuration remains active.
Retour à la configuration Usine
If firewall rules have been created finally preventing from reaching any IP address on the LAN interface
including the router itself, it may be necessary to restore the factory configuration of the router.
To restore the RAS-3G factory configuration,
Switch OFF the power supply of the router RAS.
Press the rera panel push button and, switch-on the power supply.
Keep the push button pressed until the operation led turns red.
Remark : The curent configuration is cleared and the factory IP address 192.168.0.128 is restored.
The Wizard simplifies the Internet connection set-up.
6 use cases can be selected (that 6 use cases have been described in the Overview chapter).
Once the Internet connection has been setup with the Wizard, the advanced setup mode makes possible to
setup other functions like SMS or email alarm and the firewall.
To set-up the product using the Wizard, launch the administration web server and click the Wizard button.
Use case 1 set-up
Le routeur RAS est connecté à un réseau d’usine ou d’entreprise par son interface Ethernet WAN.
STEP 1 : USE CASE SELECTION
Select the use case 1.
STEP 2 : M2Me CONNECTION
The « Ethernet WAN » page is displayed.
“Obtain an IP address automatically” checkbox :
Set that checkbox if the IP address is assigned automatically to the router RAS by a DHCP server.
Otherwise, unselect the check box and enter
The IP address assigned to the WAN interface of the router RAS,
The IP address of the default gateway on that IP network.
“Obtain DNS IP addresses automatically” checkbox :
Set that checkbox if the Domain name servers IP addresses are provided ent.
Otherwise enter the IP addresses of the DNS primary and secondary servers.
Click « Next «
The proxy server page is displayed.
« Direct access to the Internet (no proxy) » check box :
Leave that box not selected if no Proxy server exists on the WAN network.
Otherwise, select that checkbox and enter
the type of the proxy server (HTTP, SOCKS5)
the proxy IP address and port number
the type of required authentication (None, basic, NTLM) if the proxy is http
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
STEP 3 : MACHINE NETWORK
The “machine network” page is displayed.
Remark :
The IP domain of the machine network must mandatorily be different from the IP domain of the factory
network. Otherwise the IP addresses of each device of the machine must be modified.
The IP domain of the machine network must also be different form the IP domain of the remote PC.
Otherwise, the translation option described hereafter must be selected.
“IP address” & ”Netmask” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
«Are machine IP network (LAN) and remote maintenance PC IP network overlapping? Question :
If the answer is Yes, enter the translated IP domain assigned to the machine.
All the devices of machine belong to the factory network. The router RAS is also connected to the factory
network through its LAN interface.
Attention :
In that situation, a remote user can access remotely to all the devices connected to the network and not only
to the machine devices like in the Use case 1. it is why it is important to define strictly the authorised
devices and the access rights.
STEP 1 : SELECT THE USE CASE
Select the use case 2.
STEP 2 : M2Me CONNECTION
The « Ethernet LAN » page is displayed.
« IP address», « network mask », Default gateway», “Primary DNS server”, “Primary DNS server” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
Enter the DNS servers IP addresses and the defaukt gateway IP address (gateway to the Internet).
«Are machine IP network (LAN) and remote maintenance PC IP network overlapping? question :
If the answer is Yes, enter the translated IP domain assigned to the machine.
Click « Next»
The proxy server page is displayed.
« Direct access to the Internet (no proxy) » check box :
Leave that checkbox not selected if no Proxy server exists on the WAN network.
Otherwise, select that checkbox and enter
the type of the proxy server (HTTP, SOCKS5)
the proxy IP address and port number
the type of required authentication (None, basic, NTLM) if the proxy is http
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected
192.168.10.0
192.168.10.0
Use case 3 set-up
The machine is connected to the Internet through a cellular network
STEP 1 : SELECT THE USE CASE
Select the use case 3
STEP 2 : M2Me CONNECTION
The « cellular network » page is displayed.
« APN » parameter :
Enter the label of the Internet access point.
« PIN code » parameter :
Enter the SIM card PIN code.
Click « Next »
STEP 3 : MACHINE NETWORK
The “machine network” page is displayed.
Remark :
The IP domain of the machine network must also be different form the IP domain of the remote PC.
Otherwise, the translation option described hereafter must be selected.
“IP address” & ”Netmask” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected
192.168.10.0
192.168.10.0
Use case 4 set-up
The machine is connected to the Internet through a Wi-Fi network.
The Wi-Fi interface of the router RAS is used as a Wi-Fi client ; it cannot be used at the same time as an
access point.
STEP 1 : USE CASE SELECTION
Select the use case Nr 6
STEP 2 : M2Me CONNECTION
The “Wi-Fi connection” page is displayed.
«SSID» Parameter :
Enter the label of the access point.
« Shared key » parameter :
Enter the WEP or WPA key of the access point.
Click « Next »
STEP 3 : MACHINE NETWORK
The “machine network” page is displayed.
Remark :
The IP domain of the machine network must also be different form the IP domain of the remote PC.
Otherwise, the translation option described hereafter must be selected.
“IP address” & ”Netmask” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
The machine is connected to the Internet through the factory network as a priority and also through the
cellular network as a backup path. The router RAS switches automatically.
STEP 1 : USE CASE SELECTION
Select the use case 5.
STEP 2 : M2Me CONNECTION
The «Main WAN » page is displayed.
“Obtain an IP address automatically” checkbox :
Set that checkbox if the IP address is assigned automatically to the router RAS by a DHCP server.
Otherwise, unselect the check box and enter
The IP address assigned to the WAN interface of the router RAS,
The IP address of the default gateway on that IP network.
“Obtain DNS IP addresses automatically” checkbox :
Set that checkbox if the Domain name servers IP addresses are provided ent.
Otherwise enter the IP addresses of the DNS primary and secondary servers.
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
STEP 3 : MACHINE NETWORK
The “machine network” page is displayed.
Remark :
The IP domain of the machine network must mandatorily be different from the IP domain of the factory
network. Otherwise the IP addresses of each device of the machine must be modified.
The IP domain of the machine network must also be different form the IP domain of the remote PC.
Otherwise, the translation option described hereafter must be selected.
“IP address” & ”Netmask” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
«Are machine IP network (LAN) and remote maintenance PC IP network overlapping? Question :
If the answer is Yes, enter the translated IP domain assigned to the machine.
Click « Next«
The “Device list” page is displayed.
That page enables to store the devices list of the machine network.
The access right to each of these devices can be then assigned to each remote user.
To add a device to the devices list, click the “add » button and enter the name and the IP address of the
device.
If remote users are allowed to access to all the devices of the machine network, it is not useful to complete
the devices list.
The machine is connected to the Internet through the Wi-Fi network as a priority and also through the
cellular network as a backup path. The router RAS switches automatically.
STEP 1 : USE CASE SELECTION
Select the use case 6.
STEP 2 : M2Me CONNECTION
The “Wi-Fi connection (Main WAN)” page is displayed.
«SSID» Parameter :
Enter the label of the access point.
« Shared key » parameter :
Enter the WEP or WPA key of the access point.
Click « Next »
The « cellular network (Backup WAN)» page is displayed.
The IP domain of the machine ntwk and of the
factory ntwk are the same.
The machine IP domain must be modified or the
RAS must be used according to the use case 2
192.168.10.0
192.168.1.0
192.168.1.0
The IP domain of the machine ntwk and of the
remote PC ntwk are the same.
The machine IP domain must be modified or the
address translation option must be selected (see
the wizard menu).
192.168.10.0
192.168.1.0
192.168.10.0
STEP 3 : MACHINE NETWORK
The “machine network” page is displayed.
Remark :
The IP domain of the machine network must mandatorily be different from the IP domain of the factory
network. Otherwise the IP addresses of each device of the machine must be modified.
The IP domain of the machine network must also be different form the IP domain of the remote PC.
Otherwise, the translation option described hereafter must be selected.
“IP address” & ”Netmask” parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address will have to be entered to display the administration server of the router.
«Are machine IP network (LAN) and remote maintenance PC IP network overlapping? Question :
If the answer is Yes, enter the translated IP domain assigned to the machine.
Depending on the router RAS model, the following interfaces are provided.
Ethernet WAN (all models),
Cellular,
Wi-Fi as a client,
Ethernet LAN (all models),
1.2 Ethernet / WAN interface
Select the “Set-up > WAN > Ethernet” menu
Ethernet WAN port
« Speed / Duplex» parameter :
Select 10 or 100 Mb/s & full or half duplex.
IP set-up of the Ethernet WAN port
« Connection type » list :
The Ethernet choice is the usual choice to set a connection to the Internet.
The PPPOE choice must be selected only in a particular situation :
It If it it selected, the router RAS sets a PPP connection over Ethernet towards a service provider for instance.
It is useful when a modem, not supporting PPOE, is connected to the Ethernet WAN port of the router RAS.
Do not select PPOE except in the situation described above.
That parameter defines the priority of the path when more than one path
is selected (Cellular & Ethernet WAN, for instance).
The router will use as a priority the path to which the highest value is
assigned; the other pat wil be used as a backup path.
« PPP login» et « PPP password » parameters
Enter the login and password of the PPP connection
« Obtain an IP address automatically » checkbox:
Leave that checkbox selected if the IP address on the WAN interface is
assigned by a DHCP server.
Otherwise unselect that checkbox and enter the IP address, the
netwmask and the default gateway address.
« Obtain the DNS server IP address automatically » checkbox:
Leave that checkbox selected if the DNS servers IP address are
assigned by a DHCP server.
Otherwise unselect that checkbox and enter the IP addresses of the DNS
servers.
« NAT» checkbox :
If that option is selected, the source IP address of any IP frame coming
from a device connected to the LAN interface and routed to the WAN
interface , is replaced by the router WAN IP address.
Remark : Select that checkbox if a device of the LAN interface needs to
set a connection with a device connected to the Internet (FTP server …)
The SIM 1 is used first ; the SIM 2 is used as backup
1.3 Cellular network interface
Two SIM cards can be inserted in the router to allow the use of two different cellular networks .
The network corresponding o the SIM card Nr1 is the main network, while the other one is the backup
network.
To set-up the cellular network interface, select Set-up > WAN interface
« Connection type » list :
Select the « cellular” choice.
“Priority” parameter
That parameter defines the priority of the path when more than one path is selected (Cellular & Ethernet
WAN, for instance).
The router will use first the interface having received the highest priority; the other interface will be used as a
backup path.
“SIM card” parameter
It is possible to select the SIM card Nr1, or the SIM card Nr2 or both.
1.3.1 SIM 1 or SIM 2 set-up
Setting-up the SIM card 1 or the SIM card 2 is identical. We describe hereafter the SIM 1 set-up.
SIM 1 : Modem set-up
« Modem initialisation string » parameter :
Leave that field empty.
« APN » parameter :
Enter the label of the gateway (APN) to the Internet - or to other services - provided by the mobile service
provider.
« PIN code » parameter :
Enter the SIM card pin code.
As long as the PIN code has not been correctly entered, the OPERATION led indicator flashes (red color).
The router RAS is supposed to connect to the best cellular relay available.
However, in particular situations, it may be useful to force the router RAS to use a particular service.
That parameter gives the choice to select either the LTE 4G service, or the UMTS 3G service or the GPRSEDGE service.
The default value is “AUTO”; in that case, the router RAS selects the best available connection.
Cellular IP interface set-up
«Login» & « Password» parameters :
Enter the login and password of the subscription.
Remark : That parameters are generally not required.
« Obtain an P address automatically » checkbox :
The IP address of the cellular interface of the router RAS is usually assigned by the service provider over the
air.
Otherwise, enter the IP address assigned to the cellular interface of the router.
« Obtain the DNS server IP address automatically » checkbox:
Leave that checkbox selected if the DNS servers IP address are assigned by a DHCP server.
Otherwise unselect that checkbox and enter the IP addresses of the DNS servers.
« NAT» checkbox :
If that option is selected, the source IP address of any IP frame coming from a device connected to the LAN
interface and routed to the WAN interface , is replaced by the router WAN IP address.
Remark : Select that checkbox if a device of the LAN interface needs to set a connection with a device
connected to the Internet (FTP server …).
1.3.2 Using the SIM cards 1 and 2
Each SIM card can be associated to two different mobiles data services.
In the subsequent text, the cellular service associated to the SIM card 1 is referred to as Network 1 and the
cellular service associated to the SIM card 2 as the Network 2.
The network 1 is first service tested at power-up.
If the Network 1 remains in failure during the period of time T1, the router switches to the network 2.
If the Network 2 is functioning properly, the router uses that cellular network at least during the period of
time T3.
On expiry of that period, the router switches back to the network 1 and checks if it is available. If it is not the
router goes on using the Network 2.
At any time, If the network 2 does not work correctly during the period of time T2, the router switches to
Network 1.
The periods of time T1, T2 and 3 can be set.
We advise not to select too small values of the T1, T2 and T3 parameters. :
Example :
T1 Network 1 failure confirmation time = 20 mn
T1 Network 2 failure confirmation time = 20 mn
T3 Minimum connection time on network 2 = 12 hours
«Network 1 failure confirmation time » parameter
See above.
Value : 5, 10, 20, 30, 60 mn
«Network 2 failure confirmation time » parameter
See above.
Value : 5, 10, 20, 30, 60 mn
«Minimum connection time on Network 2» :
See above.
Value : 1, 12, 24 hours, 5 days, never.
1.3.3 Cellular connection control
The router RAS checks permanently that the cellular connection is properly set thanks to the PPP protocol
established with the cellular infrastructure router.
However, with particular mobile service providers, or in particular situations, that PPP connection is declared
active while the data transmission service is not provided by the mobile service provider.
It is why the router RAS is able to ping a particular server to check if the data service is really provided. If it
is not, the PPP connection is reset.
That function must be enabled only if connection defects are noticed.
To implement that function, enter the parameters hereafter.
«IP address of the server» parameter :
Enter the IP address of the device to which the router RAS will send a periodic ICMP message (PING)
«PING Interval” parameter :
Enter the period of the PINGs
Value : 30 s, 1, 2, 5, 10, 20, 30, 60 mn
«Number of retries» parameter :
Enter the number of retries before resetting the PPP connection.
Value : 1, 2, 4, 8, 12
Remark :
The Wi-Fi scanner makes possible to detect the Wi-Fi networks around the router RAS.
To use the Wi-Fi scanner, select the Diagnostic > Tools > Wi-Fi scanner menu.
To set-up the Wi-Fi interface as a client to reach the Internet,
Select Set-up > WAN interfaces > Wi-Fi
Select the « Enable » checkbox
Wi-Fi modem set-up
« Network name (SSID) » parameter :
Enter the name assigned to the Wi-Fi network to which the router RAS has to connect.
Attention : The SSID is case sensitive.
« Authentification » parameter :
Select WPA or WEP or None according to the access point set-up.
« Key » parameter :
Enter the WPA or WEP key according to the access point set-up.
Wi-Fi WAN IP set-up
« Wi-Fi WAN priority» parameter :
Saisir la valeur 10.
« Obtain an IP address automatically » checkbox:
Leave that checkbox selected if the IP address on the WAN interface is assigned by a DHCP server.
Otherwise unselect that checkbox and enter the IP address, the netwmask and the default gateway address.
« Obtain the DNS server IP address automatically » checkbox:
Leave that checkbox selected if the DNS servers IP address are assigned by a DHCP server.
Otherwise unselect that checkbox and enter the IP addresses of the DNS servers.
« NAT» checkbox :
If that option is selected, the source IP address of any IP frame coming from a device connected to the LAN
interface and routed to the WAN interface , is replaced by the router WAN IP address.
Remark : Select that checkbox if a device of the LAN interface needs to set a connection with a device
connected to the Internet (FTP server …)
Two remote users can simultaneously connect to
the LAN network; one will receive the IP address
192.168.12.2 and the other 192.168.12.3.
Remote users IP pool end
192.168.12.3
IP addresses available for the
devices of the LAN network
192.168.12.4 to
192.168.12.254
LAN interface
2.1 Overview
Ethernet switch or hub
The LAN interface consists of 1 to 4 switched Ethernet 10/100 BT RJ45 connectors.
An option enables to shape a hub instead of a switch for test purposes for instance.
IP address of the router RAS on the LAN interface
A fixed IP address must be assigned to the LAN interface of the router RAS.
DHCP server
The router RAS can also behave like a DHCP server for the devices on the LAN interface.
Remote users IP addresses allocation
If remote users PCs are supposed to connect to the devices of the LAN network, a pool of IP addresses
belonging to the LAN network has to be reserved for them.
The addresses reserved for the remote users must not be allocated to other devices of the LAN network.
Example :
Identification of the devices connected to the LAN network
The identification of the devices connected to the LAN network can be stored into the router.
The access to an identified device can then e allocated individually to the remote users.
Wi-Fi access point
When the optional Wi-Fi interface is set-up as an access point, the devices connected to the router RAS
through that Wi-Fi network belong to LAN network.
As a consequence, their IP address belong to the IP domain of the LAN network.
If the checkbox is selected, the LAN ports behaves like a hub.
LAN network
« IP address » & « netsmask » parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address is also the IP address of the administration server of the router.
« Default gateway » parameter :
If another router is connected to the LAN network giving access to other networks, and acting as the default
gateway for the router RAS, enter the address of the router.
Remark : leave that field empty, if no othe rrouter is conected to the LAN network.
«Automatic management of the remote users» checkbox :
If that checkbox is selected, the router RAS allocates automatically an unused IP address of the LAN
network to a remote user when he connects.
Unselect that checkbox to set-up the pool of fixed IP addresses which can be allocated to the remote users.
That IP addresses must belong to the LAN domain.
Remark : the selected Wi-Fi mode must be entered in each Wi-Fi client (tablet …).
« RF channel» :
Select a traffic channel in the list.
Remark :
It is preferable to select an unused channel at the location where the router RAS is installed.
Use the Wi-Fi scanner to display the channels used by the Wi-Fi networks active at the same location.
The router RAS can behave like a DHCP server over the LAN interface.
In that case, a pool of addresses must be reserved ; the addresses of the pool are automatically distributed
to the devices of the LAN acting as DHCP clients.
The addresses of the LAN domain which do not belong to that pool can be allocated as fixed IP addresses to
particular devices.
Remark
Many Wi-Fi office devices like tablets or smartphones do not support a fixed IP address.
Select the Set-up > LAN interface > DHCP server
“IP address pool start” & “IP addresses pool end” parameters :
Enter the first and the last IP address reserved to the DHCP server.
« IP address » & « netsmask » parameters :
Enter the IP address assigned to the router over the LAN interface.
That IP address is also the IP address of the administration server of the router.
« Default gateway » parameter :
If another router is connected to the LAN network giving access to other networks, and acting as the default
gateway for the router RAS, enter the address of the router.
The M2Me_Connect connection is a VPN set from the router RAS to the M2Me_Connect server.
The VPN can be transported in UDP or TCP.
Select the Set-up > Remote access > M2Me_Connect
« TCP port » & « UDP ports » parameters :
Enter the selected UDP and TCP ports the router will have to test to set the M2Me VPN.
The router RAS will try to set the M2Me connection successively with the selected UDP and TCP ports
beginning with UDP.
If a proxy server filters outgoing connections, unselect the No Proxy checkbox and enter the Proxy server
parameters :
the type of the proxy server (HTTP, SOCKS5)
the proxy IP address and port number
the type of required authentication (None, basic, NTLM) if the proxy is http
Test the M2Me connection
Pour commander la connexion du routeur au service M2Me_Connect, cliquer le bouton « Connecter
maintenant ».
Pour vérifier que la connexion s’effectue normalement, sélectionner le menu « Diagnostic » puis « Etat
réseau » puis « M2Me ».
Lorsque la connexion aboutit, le message « Connecté » s’affiche dans le champ « Etat » ainsi que le N° de
port et le protocole utilisé.
Attention : Do not forget to copy the product key of the router RAS (ABOUT menu); it is used by the M2Me
software of the remote PC to set the connection to the router RAS.
Once the M2Me connection has een set, remote users must be registered in the user list and access rights
must be assigned to each of them.
Remark : Providing a secure remote access service requires three steps :
Step 1 : The remote connection set-up itself described in this paragraph.
Step 2 : The user list set-up described in the next paragraph.
Step 3 : The access rights definition described in the next paragraph.
4.1 Advantages of a remote access connection
Using a remote connection to access to a machine provides the following advantages :
Remote users identification
The remote user login and password are registered in the user list.
When he connects, the login and password of the remote user, and optionaly the certificate of his PC are
checked.
The certificate can be delivered by ETIC TELECOM or by another authority.
Selective access rights
Individual access rights can be assigned to each remote user according to his identity.
Transparent connection
Once the remote connection has been launched, the PC receives automatically an IP address of the network.
The user can access to each authorized device of the network.
Data encryption
Data is encrypted from end to end.
PC, Tablet, smartphone
The solutions provided by the ETIC router are suitable as well for Windows PCs or tablets or smartphones
(Androïd or IOS).
4.3 HTTPS connection and portal for smartphones, tablets or PCs
4.3.1 Overview
The ETIC router can behave like a HTTPS server for remote users.
In addition, the HTTPS server can behave like a HTTPS to HTTP gateway to give a secure remote access to
HTML / HHTP pages embedded in devices.
It means that a simple HTML / HTTP unsecure server can be used remotely through the internet in a safe way.
When a remote user connects to the ETIC router using an HTTPS secure connection, the portal displays the
list of the html servers to which he has the right to access.
That list can include as well HTTPS native servers or HTTP unsecured server.
The remote user just has to select one server in the list.
To enable the HTTPS portal through the LAN interface,
Select Set-up > Remote access > Remote access server
Select the «Enable the HTTPS proxy » menu
To give access to the HTTPS portal through the Internet (WAN),
Select Set-up > Security > Administration rights
Select the « Use HTTPS for set-up operation » checkbox
Important remark :
When the HTTPS portal is enabled, the access to the administration server and to the HTTPS portal from the
LAN or from the WAN are organised according to the table below :
4.3.3 Operation
To access to the HTTPS internet portal from the Internet,
Launch the browser
Enter : https:// « Internet IP address of the ETIC router»
Enter the login and password when the identification window is displayed.
The Web portal page displays the list of the web servers to which it is possible to connect according to the
user identity.
The remote user can be authenticated with a password or with a password and a certificate.
The data is encrypted.
On the remote PC side, one can use a standard OpenVPN client or, if the PC is running Windows, the
M2Me_Secure software which is simple to install, set-up and use.
To set-up the OpenVPN connection,
Select the OpenVPN checkbox
« TCP port » & « UDP ports » parameters :
Select UDP or TCP and the port number.
Attention :
If OpenVPN VPNs between routers must also be set, the selected protocol (TCP or UDP) and port number of
the OpenVPN VPN must different from the protocol and port number of the remote user connection.
«Remote users authentification» parameter :
Select the “Login / password” value or the “Login/password & certificate” value if the certificate of he remote
PC must be checked.
In that case, the certificate of the remote PC must be stored in the ETIC router (see the table at the top of the
page).
It is possible to differentiate a remote user connection intended for PCs and another remote user connection
intended for smartphones.
The protocol (TCP or UDP) or the port number of the smartphone connection must be different from the
ones intended for PCs.
Select the smartphone remote user connection
« TCP port » & « UDP ports » parameters :
Select UDP or TCP and the port number.
Attention :
If VPN between routers must also be set, the selected protocol and port number of the OpenVPN VPN must
different from the protocol and port number of the remote user connection.
«Remote users authentification» parameter :
Select the “Login / password” value or the “Login/password & certificate” value if the certificate of he remote
PC must be checked.
In that case, the certificate of the remote PC must be stored in the ETIC router (see the table at the top of the
page).
It is necessary to register at least one remote use in the user list.
The users list is able to register 25 authorised remote users forms.
Each user form stores the identity of the user (Login and password), his email address to send alarm emails
and his mobile telephone number to send alarm SMS to him.
To display the user list,
select the Set-up> Remote access> User list menu
Remark : Coming from factory, the user list is empty.
An IPSec VPN tunnel allows to connect two networks in a safe and transparent way : Each device of the first
network can exchange data with any device of the other network.
25 IPSec connections can be set by one ETIC router.
Glossary
The router which initiates the IPSec VPN is called the initiator; the other one is called the responder.
Preshared key authentication
Only one preshared key can be stored in one ETIC router; it is used by all the VPNs and also by the
L2TP/IPSec remote user connection.
Certificate authentication
The authentication of the two participants to the VPN connection can also be carried-out with certificates.
Coming from factory , a certificate produced by ETIC TELECOM is registered in the ETIC router.
Other kinds of X509 certificates can be added. (see the Set-up>Security>X509 certificate).
The certificate used by each participant to the VPN must be delivered by the same authority.
Setting-up an IPSec tunnel in the case where the source IP address is modified along the way from the
initiator to the responder router.
To provide a strong mutual authentication, each router checks the source IP address of the frames it
receives is the authentical IP address.
It is why, the IPSec tunnel requires a particular setup when the IP address of the initiator or the responder is
not fixed and / or when intermediate routers replace the source IP address by their own address (NAT).
It is what happens, in particular, in the case of cellular networks.
Two set-up solutions are possible :
Solution 1 : Use a certificate for authentication instead of a preshared key
Solution 2 : if the preshared key authentication method is used, an IKE code (IKE ID) needs to be assigned to
each router. See the IPSec set-up paragraph hereafter.
Select the Enable checkbox.
Select the Advanced parameters checkbox if a preshared key is used and if intermediate routers translate
the source P address.
Assign a name to the connection.
The different IP addresses used during the set-up are described by the drawing below.
« Authentification » parameter :
Select preshared key or certificate.
« Connection » parameter :
Select Initiator if the current router is supposed to initiate the VPN.
Authentication section– Case 1 : Use of a certificate
Remark : Both certificates must be delivered by the same authority
« My SubjectAlt name » parameter:
Enter the 'SubjectAltName' value of the active certificate of the current router.
If the active certificate is an ETIC TELECOM certificate, that field is the email field.
Remote « SubjectAlt name » parameter :
Enter the 'SubjectAltName' value of the active certificate of the remote router.
If the active certificate is an ETIC TELECOM certificate, that field is the email field.
Authentication section– Case 2 : Use of a preshared key
« Preshared key » and « Passwords match » parameter :
Enter and confirm the preshared key.
The maximum length of the key is 40 characters.
« Local IKE ID» & « Peer IKE ID » parameters :
That identifiers make possible to set a preshared key VPN even if intermediate routers modifiy the source IP
address.
The router receiving an IP frame checks the IKE ID of the remote router in place of its source IP address.
Network section
« Remote LAN IP address » & « Remote LAN Netmask” parameters :
Enter the IP address and netmask of the remote LAN network
The purpose of IKE phase two is to negotiate the IPSec parameters (general parameters, encryption, SA lifetime…).
The result of the IKE phase 2 is the encrypted tunnel between the two routers.
«Protocol » parameter :
This parameter enables to set-up the IPSec transport protocol.
AH insures authentication only but does not encrypt the transported data.
ESP ensures routers authentication and data encryption.
ESP will be preferred.
«Data encryption algorithm » parameter :
Recommended value : AES
«Authentication algorithm» parameter :
SHA1 provides a better security than MD5.
«PFS» checkbox :
With PFS disabled, initial keying material is created during the key exchange in phase-1 of the IKE
negotiation. In phase-2 of the IKE negotiation, encryption and authentication session keys will be extracted
from this initial keying material. By using PFS, Perfect Forwarding Secrecy, completely new keying material
will always be created upon re-key. Should one key be compromised, no other key can be derived using that
information.
«DH group» parameter (only if the PFS option is enabled) :
Recommended value: Group 2.
«Life-time» parameter (only if the PFS option is enabled) :
Enter the phase 2 key life-time.
DPD section
DPD Keep-alive period” parameter : :
A DPD is a message sent periodically by each end-point to the other one to make sure that the VPN must be
left active.
This parameters sets the amount of time (in seconds) between two of these requests.
“Connection death time-out” parameter :
This parameter defines the maximum amount of time (in seconds) a VPN connection will stay established if
no traffic or no DPD keep-alive message are received from the remote point.
The router which receives the connection is
called the VPN server
The connection is an ingoing connection
OpenVPN type VPN connection
8.1 Overview
An OpenVPN VPN tunnel allows to connect two networks in a safe and transparent way : Each device of the
first network can exchange data with any device of the other network.
25 OpenVPN connections can be set by one ETIC router.
Glossary
The router which initiates the OpenVPN VPN is called the VPN client the other one is called the VPN server.
Login and password authentication
Each OpenVPN connection can be authentified using the Login & password of the VPN client.
Certificate authentication
The authentication of the two participants to the VPN connection can also be carried-out using certificates
in addition to a Login and password.
Coming from factory , a certificate produced by ETIC TELECOM is registered in the ETIC router.
Other kinds of X509 certificates can be added. (see the Set-up>Security>X509 certificate).
The certificate used by each participant to the VPN must be delivered by the same authority.
NAT translation insensitivity
While IPSEC is sensitive to address translation of the source IP address by intermediate routers, OpenVPN is
not.
The reasons is the source IP address is not checked by OpenVPN to authenticate the remote router; Open
VPN authenticates the remote router with a Login password and certificate.
That characteristic makes OpenVPN very easy to implement in many situations and in particular when a
cellular router is used.
Implementation easiness
The transport level of OpenVPN is TCP or UDP; the port number can be selected
That characteristic makes OpenVPN very easy and reliable to implement in many situations and in particular
when a cellular router is used.
If the ETIC router behaves like a VPN server, it means that the ETIC router has to receive at least one ingoing
connection, the set-up has to be carried-out in two steps :
Step 1 : Configuration of the parameters of the OpenVPN server.
Only one server can be set-up.
Step 2 : Configuration of the ingoing, and possibly outgoing, connections.
The VPN server is unique; it can accept up to 25 ingoing connections from VPN clients.
VPN client set-up
If the ETIC router behaves only like a VPN client, the set-up consists only of configuring the outgoing
connection (one or several).
Set-up rules
Common parameters
The following parameters are common for the server and for all the clients supposed to set a VPN to that
server :
Transport protocol (UDP or TCP) and port number.
Encryption algorithm (Blowfish, AES 256, AES192, AES128, 3DES).
Authentication (MD5, SHA1).
IP domains
The IP domain of the LAN and of the remote LAN must be different.
Example :
LAN network : 192.168.1.0 netmask 255.255.255.0
Remote LAN : 192.168.2.0 netmask 255.255.255.0
The OpenVPN server router assigns automatically an IP address to the VPN client router.
That VPN IP address must not be confused with the WAN interface IP address.
Leave the default values 172.16..0 and 255.255.0.0
“Connection death time-out” parameter :
A control message (also called Keep-alive message) is sent periodically by the VPN server router to make
sure that the VPN must be left active.
This parameter defines the period of the control messages.
As a consequence, it sets the maximum amount of time a VPN connection will stay established before being
cleared if no response to the VPN control message is received from the remote router.
Remark :
The value of this parameter must be selected carefully ; If the VPN has been cleared, for any reason, the
router will wait during that period of time before lauching the VPN again.
“Packet retransmit time-out” parameter:
This parameters sets the amount of time (in seconds) the server will wait for the response to the keep-alive
control message before repeating it.
AES provides a better encryption than 3DES, and SHA-1 a better authentication than MD5.
« Priority » parameter :
Enter a an intermediate value : 100 for instance.
« Push local route to VPN clients » parameter :
If that checkbox is selected, the server broadcasts to the clients the route to the IP domain of its local
network.
Leave that checkbox selected.
«Push static routes to VPN clients » parameter :
If that checkbox is selected, the server broadcasts to the clients the static routes which have been set-up int
the VPN server.
Leave that checkbox selected.
Two solutions exist to enable a device connected to a VPN client router to exchange data with another
device connected to another VPN client router.
The first one is to program a static route in both VPN client routers.
The second one is to select the “Push clients routes” option.
If that option is selected, the VPN server broadcast to all the VPN clients the route to each of them.
In that way, each device of the network can exchange data with each other device.
Programming static routes is not necessary.
If that option is not selected, a device connected to a VPN client ETIC router can exchange data with a
device connected to the LAN network of the VPN server, but not with a device connected to one other
VPN client ETIC router.
If it is necessary static routes must be programmed in both routers RAS.
st
« 1
specific route to push» & « 2nd specific route to push» parameters :
Thess parameters allow to broadcast specific routes from the VPN server to the clients.