This document is part of the user manual for the installation and configuration of funkwerk devices. For
the latest information and notes on the current software release, please also read our release notes,
particularly if you are updating your software to a higher release version. You will find the latest release
notes under www.funkwerk-ec.com .
Liability
This manual has been put together with the greatest possible care. However, the information contained in this manual is not a guarantee of the properties of your product. Funkwerk Enterprise Communications GmbH is only liable within the terms of its conditions of sale and supply and accepts no liability for technical inaccuracies and/or omissions.
The information in this manual can be changed without notice. You will find additional information and
also release notes for funkwerk devices under www.funkwerk-ec.com .
Funkwerk devices make WAN connections as a possible function of the system configuration. You
must monitor the product in order to avoid unwanted charges. Funkwerk Enterprise Communications
GmbH accepts no responsibility for data loss, unwanted connection costs and damage caused by unintended operation of the product.
Trademarks
funkwerk trademarks and the funkwerk logo, bintec trademarks and the bintec logo, artem trademarks
and the artem logo, elmeg trademarks and the elmeg logo are registered trademarks of Funkwerk Enterprise Communications GmbH.
Company and product names mentioned are usually trademarks of the companies or manufacturers
concerned.
Copyright
All rights reserved. No part of this manual may be reproduced or further processed in any way without
the written consent of Funkwerk Enterprise Communications GmbH. The documentation may not be
processed and, in particular, translated without the consent of Funkwerk Enterprise Communications
GmbH.
You will find information on guidelines and standards in the declarations of conformity under
www.funkwerk-ec.com .
How to reach Funkwerk Enterprise Communications GmbH
Table of ContentsFunkwerk Enterprise Communications GmbH
xbintec R200 Series
Funkwerk Enterprise Communications GmbH
Chapter 1 Introduction
The powerful bintec R232a, bintec R232aw, bintec R232b and bintec R232bw gateways
enable you to connect small networks in a cost-effective way and connect your individual
workstation or small company to the internet and to other partner networks (e.g. a company
head office).
This chapter describes the outstanding features your new bintec gateway offers. It
provides you with an overview of the ways in which your bintec gateway can be used. This
chapter also tells you about the structure and contents of this manual.
Safety precautions
The safety precautions, which are supplied with your device, tell you what you need to take
into consideration when using your bintec gateway.
Installation
How to connect your device is shown in Installation on page 9. This chapter also tells you
what preliminary tasks are necessary for configuration.
1 Introduction
Configuration
How to get your device running is explained in Configuration on page 13. There we show
you how to start up your device within a few minutes from a Windows PC with the help of a
Configuration Wizard and how to install other useful online assistants. At the end of the
chapter, you will be in a position to surf the Internet, send or receive e-mails and set up a
connection to a partner network to access data at your company head office, for example.
Password
If you are already familiar with configuring bintec devices and want to get started right
away, all you really need to know is the factory default user name and password.
User Name: admin
Password: funkwerk
Caution
Remember to change the password immediately when you log in to the device for the
first time. All bintec devices are supplied with the same password, which means they
are not protected against unauthorised access until you change the password. How to
change the passwords is described in chapter Passwords on page 88.
The next chapters describe the technical data and further access and configuration options
for your bintec device. The subsequent chapters contain a complete reference of all configuration options of the Funkwerk Configuration Interface. This manual concludes with a
glossary and then an index.
Workshops
Application-related, step-by-step instructions for the most important configuration tasks can
be found in a separate section of the manual bintec R230a/R230aw/R232b/R232bwWorkshops.
1.1 Possible Applications
Connecting networks
Gateways are used to interconnect networks and to exchange information between the networks. For example, you can use your device to establish a connection to the network of
your Internet Service Provider and use the usual Internet services, such as the World Wide
Web (WWW) or e-mail.
Access to head office
By connecting to another partner network, e.g. your company’s head office, from your
home or branch office, you can conveniently access any information you may need from
the head office, even if this is hundreds of miles away. These local networks are connected
via an ISDN (only bintec R232a, R232b and R232bw) or DSL connection. The size of your
own local network – whether it consists of several computers or just one workstation – is irrelevant.
Your gateway is your link to the outside world
Every device serves as a link between the individual local networks. Within each LAN, the
gateway is connected to the network like a normal computer. Its task is to transmit information as necessary from its own network to an external network (e.g. to the network of your
Internet Service Provider or your head office) and to find the most suitable routes for transmission. Conversely, it receives information and routes it to its own network.
One gateway for everyone
If you have a local network with several computers, you only need one single gateway to
allow all computers in the network access to the Internet or the head office. The lower expenditure on equipment and administration for several computers in the network means
substantial savings. If you used ISDN cards or modems, every workplace would have to be
equipped separately.
2bintec R200 Series
Funkwerk Enterprise Communications GmbH
High-speed Internet access
If you configure high-speed Internet access with the bintec gateway, all the users in the
local network profit from faster Internet access. The bandwidth used permits considerably
faster Internet applications than conventional ISDN or modems.
Automatic dialling and disconnection
Once configured, your device decides independently if and how it is to set up a connection
to the Internet Service Provider. If you enter an external WWW address in your browser, for
example, your gateway determines that the requested address lies outside your own LAN
and establishes a connection to your Internet Service Provider and the Internet automatically. To help you save costs, your gateway disconnects the connection after a predefined
time (short hold) if no more information is exchanged.
Simple data access
If suitably configured, your device enables you to conveniently access data at another site,
e.g. your head office. While running Windows, for example, you can connect a network
drive to a computer at your head office. You then simply click the icon for this link in Windows Explorer and can surf in the directories and data of the remote computer just as if you
were using your own hard disk. Your gateway takes care of setting up and clearing the connection.
1 Introduction
Security/firewall/DynDNS
Your gateway is provided with integrated firewall mechanisms and therefore provides extensive, low-cost features to meet all the requirements for access security. It protects your
network against unauthorised external access. This is achieved with functions such as
NAT, encryption, filters, monitoring and a Stateful Inspection Firewall.
The Stateful Inspection Firewall (SIF) offers effective protection against attacks from the Internet through dynamic packet filtering. Firewall handling is made easier through numerous
pre-configured services. To be able to find partners in spite of dynamic IP addresses, the
devices support the DynDNS function. The implemented function enables you to use the
DynDNS service of leading DynDNS providers, and some providers have been preset. The
security features of the device also include optional web filtering (there is an extra charge
for this, 30-day test version included). Here, all the outgoing Internet enquiries are classified, allowing unwanted contents to be reliably filtered out.
Other security features
With the scheduling function of the devices, times can be defined in which users are granted individual rights, such as for Internet access. The VLAN function of the devices allows
the allocation of users to virtual subnetworks and offers an additional degree of security.
All devices offer the possibility of configuring a "Demilitarised Zone" (DMZ). This is a separate network located between the internal LAN and the Internet. The DMZ is the place for all
services that have to make direct contact with the Internet. If a web or mail server in the
DMZ is attacked, this has no effect on the security of your internal network.
IP Telephony
The application level gateway allows IP telephones in the LAN to establish a connection
with SIP providers without neglecting the security of the WAN connection. To do this, the
SIP proxy monitors the signalling process between IP telephone and SIP provider and
makes the necessary NAT and firewall releases dynamically for the duration of the communication.
Wireless LAN
The wireless interface of the bintec R230aw and bintec R230bw transfers the data at
max. 54 mbps (802.11g) and is compatible with the 11 mbps variant 802.11b in the same
frequency range. Encryption via the WLAN interface can take place via WPA and WPA2.
Virtual WLAN interfaces can be defined via multi-SSID. This means that different rules of
access to the WLAN can be implemented, e.g. to log in internal personnel and external visitors. The Express Setup Wizard is used for simple WLAN configuration.
IPSec
Both devices have a powerful IPSec implementation and have with two active VPN tunnel
licenses ex works. In addition to encryption via AES or 3DES, the devices offer authentication via certificates or preshared keys. In order to optimise the encrypted traffic flow, it can
be compressed using IPComp. The Dead Peer Detection function allows the availability of
the tunnel endpoint to be checked and restores it if inactive. NAT Traversal is also supported, as is the connection of RADIUS or TACACS+ for authentication.
Configuration and maintenance
A number of options are available for configuring your gateway. Configuration with the Express Setup Wizard, Funkwerk Configuration Interface or Setup Tool is independent ofthe operation system. The easiest way to configure the device is by using the Express
Setup Wizard. This configuration assistant guides you through the configuration step by
step and helps you to make the most important settings on your device. Your device is
ready for operation in just a few minutes.
Remote maintenance
The bintec R230a, bintec R230b and bintec R230bw models can also be configured and
maintained remotely. As soon as your device is connected to the ISDN - even in its ex
works state - configuration settings can be made from another location (e.g. by the administrator at head office). This means you can have someone at head office configure the
4bintec R200 Series
Funkwerk Enterprise Communications GmbH
system.
Models
The bintec R230a and bintec R230aw are the successors to the X2301/X2301w gate-
ways. The bintec R232bw second generation includes the first device without a WLAN
function, namely new model bintec R232b.
All four models offer the same features as their predecessors, plus hardware and software
enhancements.
Extra memory and new software features make these devices flexible IP access routers
with an integrated ADSL modem (R232a/aw with annex A, R232b/bw with annex B) and
4-port switch. The support of ADSL2+ allows a high-performance WAN connection and permits download rates of up to 24 mbps. A SIP Proxy controls the transparent communication
with SIP providers, so that the device can be used in VoIP scenarios such as Internet telephony.
bintec R230aw and bintec R230bw also offer WLAN functionality. The WLAN function allows flexible use in wireless environments.
1 Introduction
In addition to a 4-port switch and a further Ethernet port for the LAN/WAN connection, the
bintec R230b and bintec R230bw have an ISDN interface for automatic backup or remote
dial-in.
1.2 About this Manual
Area of validity
This document is valid for bintec devices with system software as of software version
7.8.1.
The bintec user's guide consists of two separate parts: the Reference, and the Workshops.
The guide, which you have in front of you, contains the following chapters:
User's Guide - Reference
ChapterDescription
Quick Install GuideThis contains instructions for how to set up and start up your
device and create a basic configuration in just a few minutes using the Express Setup Wizard (see Quick Install Guide on
page 8).
Technical dataThis section contains a description of all the device's technical
This includes explanations about the different access and configuration methods.
These chapters describe all configuration options of the Funk-werk Configuration Interface. The chapters are arranged in
the same sequence as the navigation menus in the FunkwerkConfiguration Interface.
The individual chapters also contain general explanations on
the subsystem in question.
Monitoring
GlossaryThe glossary contains a reference to the most important tech-
nical terms used in network technology.
IndexThe index lists all the key terms for operating the device and all
the configuration options and gives page numbers so they can
be found easily.
To help you locate information easily, this manual uses the following visual aids:
List of visual aids
Visual aidUse
Identifies general and important points.
6bintec R200 Series
Funkwerk Enterprise Communications GmbH
Visual aidUse
The following typographical elements are used to help you find and interpret the information in this manual:
Typographical elements
Typographical element Use
1 Introduction
Indicates a warning of risk level "Attention" (points out possible
dangers that may cause damage to property if not observed).
Indicates a warning of risk level "Warning" (points out possible
dangers that may cause physical injury or even death if not observed).
•
Menu->Submenu
File->Open
non-proportional
(Courier),
e.g. ping
192.168.1.254
bold, e.g. Windows
Start menu
bold, e.g. biboAdmLoginTable
italic, e.g. noneIndicates values that you enter or that can be configured.
Online: blue and italic,
e.g.
www.funkwerk-ec.com
Indicates lists.
Indicates menus and sub-menus.
Indicates commands that you must enter as written.
Indicates keys, key combinations and Windows terms.
This chapter explains how you set up and start up your device and how you create a basic
configuration in just a few minutes using the Express Setup Wizard.
2.1 Introduction
Your bintec gateway contains extensive features for encrypted data transfer and Internet
access for both individual users and companies.
The basic configuration of your device is carried out using the Express Setup Wizard.
The way to obtain the basic configuration is explained below step-by-step. Detailed knowledge of networks is not necessary. A detailed online help system gives you extra support.
The Companion CD also supplied includes all the tools that you need for the configuration
and management of your device.
The BRICKware contains useful applications for managing your device.
2.2 System requirements
For configuration, your PC must meet the following system requirements:
• Windows 95, Windows 98, Windows ME or Windows NT 4.0 or Windows 2000 or Windows XP.
(The instructions for testing/installing the TCP/IP protocol and setting up the PC apply to
Windows 2000 or Windows XP.)
• Installed network card (Ethernet)
• CD ROM drive
• Microsoft TCP/IP protocol installed (see Configuring a PC on page 17)
• High colour display (more than 256 colours) for correct representation of the graphics
2.3 Presettings
Preconfigured data
Your device is shipped with a pre-defined IP configuration:
8bintec R200 Series
Funkwerk Enterprise Communications GmbH
• IP Address: 192.168.0.254
• Netmask: 255.255.255.0
Use the following access data to configure your device as delivered:
• User Name: admin
• Password: funkwerk
Note
All bintec devices are delivered with the same username and password. As long as
the password remains unchanged, they are not protected against unauthorised use.
Make sure you change the passwords to prevent unauthorised access to your device
(see Access and Configuration on page 51).
Software update
Your device contains the version of the system software available at the time of production.
More recent versions may have since been released.
2 Quick Install Guide
2.4Installation
Your gateway offers a number of connection options:
All you need for this are the cables and antennas supplied with the equipment.
Caution
The use of the wrong mains adapter may damage your device. Only use the mains adaptor supplied with the equipment. If you require foreign adapters/mains units, please
contact our funkwerk service.
Incorrect cabling of the ISDN and ETH interfaces may also damage your device. Connect only the ETH interface of the device to the LAN interface of the computer/hub or a
WAN interface if available and the ISDN interface of the device only to the ISDN connection.
Set up and connect in the following sequence:
(1) Antennas: Screw the two external standard antennas provided to their RSMA connec-
tions (only bintec R230aw and bintec R232bw).
(2) Place your device on a solid, level base.
(3) LAN: For the standard configuration of your device via Ethernet, connect the first
switch port (1) of your device to your LAN using the Ethernet cable supplied. The
device automatically detects whether it is connected to a switch or directly to a PC.
(4) ADSL: Connect the ADSL interface (ADSL) of your device to the DSL output of the
12bintec R200 Series
Funkwerk Enterprise Communications GmbH
splitter using the DSL cable supplied.
(5) Mains connection: Connect the device to a mains socket using the mains adaptor sup-
plied.
Optional connections
• ISDN: Connect the ISDN interface (ISDN) of the device to your ISDN socket using the
ISDN cable provided (only bintec R232a, bintec R232b and bintec R232bw).
• DMZ: Connect the WAN interface (ETH) of your device to the Ethernet connection of
your DMZ using another Ethernet cable (only bintec R232a, bintec R232b and bintecR232bw).
• Other LANs/WANs: Connect any other terminals in your network to the remaining switch
ports (2, 3 or 4) of your device using other Ethernet cables.
• Setting up a serial connection: For alternative configuration possibilities, connect the serial interface of your PC (COM1 or COM2) to the serial interface of the gateway (console).
Use only the serial cable supplied with the equipment. However, configuration via the
serial interface is not provided by default.
The device is now prepared for configuration using the Express Setup Wizard.
2 Quick Install Guide
2.5Configuration
In this chapter, you will learn how to prepare the configuration, carry out the configuration,
make adjustments to the PC configurations in the network if necessary and test the connection when the configuration has been completed.
2.5.1 Preparations
To prepare for configuration, you need to...
• have the data for the basic configuration and the Internet connection to hand and also
gather the data needed for connecting the required WLAN clients.
• check whether the PC from which you want to perform the configuration meets the necessary requirements.
You can also...
• install the BRICKwaresoftware, which provides more tools for working with your device.
This installation is optional and not essential for the configuration or operation of the
device.
You can gather the main data for basic configuration with the Express Setup Wizard
quickly, as you do not require any information that needs in-depth network knowledge. If
necessary, you can use the example values.
Before you start the configuration, you should gather the data for the following purposes:
• Basic configuration (obligatory if your device is in the ex works state)
• Internet access (optional)
• Wireless LAN (optional, only for bintec R230aw and bintec R232bw)
• Company network connection (optional).
The following tables show examples of possible values for the necessary data. You can
enter your personal data in the "Your values" column, so that you can refer to these values
later when needed.
If you configure a new network, you can use the given example values for IP addresses
and netmasks. In cases of doubt, ask your system administrator.
Basic configuration
For a basic configuration of your gateway, you need information that relates to your network environment:
Basic information
Access dataExample valueYour values
IP address of your gateway192.168.0.254
Netmask of your gateway255.255.255.0
Internet access
If you want to set up Internet access, you need an Internet Service Provider (ISP). You also
receive your personal access data from your ISP. The terms used for the required access
data may vary from provider to provider, but the type of information you need for dialling in
is basically the same.
The following table lists the access data that your device also needs for a DSL connection
to the Internet.
Data for Internet access
Access dataExample valueYour values
Provider nameGoInternet
14bintec R200 Series
Funkwerk Enterprise Communications GmbH
Access dataExample valueYour values
ProtocolPPP over Ethernet
Encapsulationbridged-no-fcs
VPI (Virtual Path Identifier)1
VCI (Virtual Circuit Identifier)32
Your user nameMyName
PasswordTopSecret
Some Internet Service Providers, such as T-Online, require additional information:
Additional information for T-Online
Access dataExample valueYour values
User account (12 digits)000123456789
T-Online number (usually 12 digits) 06112345678
Joint user account0001
2 Quick Install Guide
(PPPoE)
Note
To configure T-Online Internet access, in the Username field, enter the following succession of numbers without intervening spaces: User account (12 digits) + T-Online
number (usually 12 digits) + co-user number (for the main user, always 0001). If your
T-Online number is less than 12 digits long, a "#" character is required between the TOnline number and the co-user number. If you use T-DSL, you must add the character
string "@t-online.de" at the end of this string of numbers. You username could, for example, look like this: 00012345678906112345678#0001@t-online.de
Wireless LAN (only bintec R230aw and bintec R232bw)
You can operate your device as an access point and therefore connect individual work stations (e.g. laptops, PCs with wireless card or wireless adapter) by wireless connections to
your local network via WLAN (Wireless LAN) and let them communicate with each other.
The "Data for gateway configuration" table shows the details that are needed to do this.
As data can be transmitted over the air in the WLAN, this data can in theory be intercepted
and read by any attacker with the appropriate resources. Particular attention must therefore
be paid to protecting the wireless connection.
Note the following:
• Follow the security instructions when configuring your WLAN.
• Please also read Sicherheit im Funk-LAN [Security in Wireless LAN] published by the
Federal Office for Information Security, see http://www.bsi.bund.de .
Data for the Wireless LAN configuration
Access dataExample valueYour values
Preshared key for WPA-PSKwithout default
Installation location of your system Germany
Channel to be used for WLAN11
Network name (SSID) for your
WLAN
without default
Visibility of the SSID in the wireless
network
Security settingWPA-PSK
Company network connection
To connect a remote network (e.g. head office), you need to know some data of the remote
terminal that will take your call. The remote terminal must also know your details. You have
to agree this data between you.
Your device and the device at your head office check before every connection to see if they
should take the call from the partner. To protect the network against unauthorised access,
the call is accepted only after correct authentication. This authentication is based on a common password and two codes that you and your partner use for the connection.
Data for connection to a company network
Access dataExample valueYour values
Partner name
(Key of company head office)
Dial-in number:
not visible
BigBoss
0911987654321
(Call number of the company head
office's device)
Local name
(Your own code. Your partner (the
head office) must enter this name
LittleIndian
16bintec R200 Series
Funkwerk Enterprise Communications GmbH
Access dataExample valueYour values
as the partner name on its device.)
2 Quick Install Guide
Password
(Common password for this connection, entered on both devices.)
Network address(es) of the company head office
Netmask(s) of the company head
office
Secret
10.1.1.0
255.255.255.0
2.5.1.2 Configuring a PC
In order to reach your device via the network and to be able to carry out configuration using
the Express Setup Wizard, the PC used for the configuration has to satisfy some pre-
requisites.
• Make sure that the TCP/IP protocol is installed on the PC.
• Assign fixed IP address to your PC.
Checking the TCP/IP protocol
Proceed as follows to check whether you have installed the protocol:
(1) Click the Windows Start button and then Settings -> Network and Dial-up Connec-
tions (Windows 2000) or Settings -> Network Connections (Windows XP).
(2) Click LAN Connection.
(3) Click Properties in the status window.
(4) Look for the Internet Protocol (TCP/IP) entry in the list of network components.
Installing the TCP/IP protocol
If you cannot find the Internet Protocol (TCP/IP) entry, install the TCP/IP protocol as fol-
lows:
(1) First click Properties, then Install in the status window of the LAN Connection.
(2) Select the Protocol entry.
(3) Click Add.
(4) Select Internet Protocol (TCP/IP) and click OK.
(5) Follow the on-screen instructions and restart your PC when you have finished.
Allocate an IP address to your PC as follows:
(1) Select Internet Protocol (TCP/IP) and click Properties.
(2) Choose Use next IP address and enter a suitable IP address.
Your PC should now satisfy all the prerequisites for the configuration of your device.
Entering the gateway IP address in your PC
Then continue by entering the IP address of the gateway in the configuration of your PC as
follows:
(1) In Internet Protocol (TCP/IP) -> Properties under Default gateway, enter the IP ad-
dress of your gateway. If you do not use the pre-configured IP address of the gateway
or have not yet defined an IP address for it, carry out the initial gateway configuration
steps first (see Configuring the Gateway on page 20). You can determine a free IP ad-
dress in your network automatically. Enter this IP address here.
(2) Enter the IP address of your device under Use next DNS server address.
(3) Click OK.
(4) Close the status window with OK.
The computer now has an IP configuration and can access the Internet via the gateway.
2.5.1.3 Installing BRICKware
BRICKware contains a number of programs to help you when working with your device.
The installation is optional.
You only need the Companion CD supplied with your device for the installation. Your PC
should also meet the prerequisites stated in Introduction on page 8.
Elements of BRICKware
ToolDescription
Activity MonitorThe Activity Monitor ensures permanent monitoring of the data
transmitted on your device. It also allows the administrator of
the device to control, under password protection, individual interfaces and connections specifically using certain commands,
e.g. establishing and clearing connections or changing preconfigured Internet providers.
SNMP ManagerThe SNMP Manager provides you with complete access to your
device's configuration. With this application, you can monitor important device events at the same time (SNMP traps).
18bintec R200 Series
Loading...
+ 418 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.