Stateful inspection firewall including paket filtering, extended port forwarding, N:N IP address mapping, paket tagging, support for
DNS targets, user-defined rules and notifications
Traffic shaping, bandwidth reservation, DiffServ/TOS, packetsize control, layer-2-in-layer-3 taggingQuality of Service
Intrusion Prevention, IP spoofing, access control lists, Denial of Service protection, detailed settings for handling reassembly,
session-recovery, PING, stealth mode and AUTH port, URL blocker, password protection, programmable reset button
PAP, CHAP, MS-CHAP, and MS-CHAPv2PPP authentication mechanisms
SD-WAN Application Routing in connection with the LANCOM Management CloudSD-WAN Application Routing
ARF (Advanced Routing and Forwarding) up to separate processing of 2 contextsRouter virtualization
HTTP and HTTPS server for configuration by web interface, DNS client, DNS server, DNS relay, DNS proxy, dynamic DNS client, DHCP
client, DHCP relay and DHCP server including autodetection, NetBIOS/IP proxy, NTP client, SNTP server, policy-based routing,
Bonjour-Proxy, RADIUS
HTTP and HTTPS server for configuration by web interface, DHCPv6 client, DHCPv6 server, DHCPv6 relay, DNS client, DNS server,
dynamic DNS client, NTP client, SNTP server, Bonjour-Proxy, RADIUS
VDSL, ADSL1, ADSL2 or ADSL2+ additional with external DSL modem at an ETH port, UMTS/LTEWAN operating mode
PPPoE, Multi-PPPoE, ML-PPP, GRE, EoGRE, PPTP (PAC or PNS), L2TPv2 (LAC or LNS), L2TPv3 with Ethernet-Pseudowire and IPoE (using
DHCP or no DHCP), RIP-1, RIP-2, VLAN, IPv6 over PPP (IPv6 and IPv4/IPv6 dual stack session), IP(v6)oE (autokonfiguration, DHCPv6
or static)
6to4, 6in4, 6rd (static and over DHCP), Dual Stack Lite (IPv4-in-IPv6-Tunnel)Tunneling protocols (IPv4/IPv6)
Monitoring and blocking of login attempts and port scansIntrusion Prevention
Source IP address check on all interfaces: only IP addresses belonging to the defined IP networks are allowedIP spoofing
Filtering of IP or MAC addresses and preset protocols for configuration accessAccess control lists
Protection from fragmentation errors and SYN floodingDenial of Service protection
Detailed settings for handling reassembly, PING, stealth mode and AUTH portGeneral
Filtering of unwanted URLs based on DNS hitlists and wildcard filters. Extended functionality with Content Filter OptionURL blocker
Password-protected configuration access can be set for each interfacePassword protection
Alerts via e-mail, SNMP traps and SYSLOGAlerts
PAP, CHAP, MS-CHAP and MS-CHAPv2 as PPP authentication mechanismAuthentication mechanisms
Anti-theft ISDN site verification over B or D channel (self-initiated call back and blocking)Anti-theft
Adjustable reset button for 'ignore', 'boot-only' and 'reset-or-boot'Adjustable reset button
VRRP (Virtual Router Redundancy Protocol) for backup in case of failure of a device or remote station.VRRP
For completely safe software upgrades thanks to two stored firmware versions, incl. test mode for firmware updatesFirmSafe
LCOS 10.40
Page 4
DATASHEET
LANCOM 884 VoIP
High availability / redundancy
In case of failure of the main connection, a backup connection is established over ISDN. Automatic return to the main connectionISDN backup
Optional operation of an analog or GSM modem at the serial interfaceAnalog/GSM modem backup
Load balancing
VPN redundancy
VPN
IPSec over HTTPS
Certificates
XAUTH
Proadaptive VPN
Algorithms
LANCOM Dynamic VPN
Dynamic DNS
Specific DNS forwarding
Static and dynamic load balancing over up to 4 WAN connections (incl. client binding). Channel bundling with Multilink PPP (if supported
by network operator)
Backup of VPN connections across different hierarchy levels, e.g. in case of failure of a central VPN concentrator and re-routing to
multiple distributed remote sites. Any number of VPN remote sites can be defined (the tunnel limit applies only to active connections).
Up to 32 alternative remote stations, each with its own routing tag, can be defined per VPN connection. Automatic selection may be
sequential, or dependant on the last connection, or random (VPN load balancing)
Line monitoring with LCP echo monitoring, dead-peer detection and up to 4 addresses for end-to-end monitoring with ICMP pollingLine monitoring
Enables IPsec VPN based on TCP (at port 443 like HTTPS) which can go through firewalls in networks where e. g. port 500 for IKE is
blocked. Suitable for client-to-site connections and site-to-site connections. IPSec over HTTPS is based on the NCP VPN Path Finder
technology
Max. number of concurrent active IPSec, PPTP (MPPE) and L2TPv2 tunnels: 3. Unlimited configurable connections.Number of VPN tunnels
Integrated hardware accelerator for 3DES/AES encryption and decryptionHardware accelerator
Integrated, buffered realtime clock to save the date and time during power failure. Assures timely validation of certificates in any caseRealtime clock
Generates real random numbers in hardware, e. g. for improved key generation for certificates immediately after switching-onRandom number generator
One click function in LANconfig to create VPN client connections, incl. automatic profile creation for the LANCOM Advanced VPN Client1-Click-VPN Client assistant
Creation of VPN connections between LANCOM routers via drag and drop in LANconfig1-Click-VPN Site-to-Site
IPSec key exchange with Preshared Key or certificate (RSA signature, ECDSA-Signature, digital signature)IKE, IKEv2
X.509 digital multi-level certificate support, compatible with Microsoft Server / Enterprise Server and OpenSSL. Secure Key Storage
protects a private key (PKCS#12) from theft.
Automatic creation, rollout and renewal of certificates via SCEP (Simple Certificate Enrollment Protocol) per certificate hierarchyCertificate rollout
CRL retrieval via HTTP per certificate hierarchyCertificate revocation lists (CRL)
Check X.509 certifications by using OCSP (Online Certificate Status Protocol) in real time as an alternative to CRLsOCSP Client
XAUTH client for registering LANCOM routers and access points at XAUTH servers incl. IKE-config mode. XAUTH server enables clients
to register via XAUTH at LANCOM routers. Connection of the XAUTH server to RADIUS servers provides the central authentication of
VPN-access with user name and password. Authentication of VPN-client access via XAUTH and RADIUS connection additionally by
OTP token
Configuration of all VPN client connections in IKE ConfigMode via a single configuration entryRAS user template
Automated configuration and dynamic creation of all necessary VPN and routing entries based on a default entry for site-to-site
connections. Propagation of dynamically learned routes via RIPv2 if required
3DES (168 bit), AES-CBC and -GCM (128, 192 or 256 bit), Blowfish (128 bit), RSA (1024-4096 bit), ECDSA (P-256-, P-384-, P-521-curves),
Chacha20-Poly 1305 and CAST (128 bit). OpenSSL implementation with FIPS-140 certified algorithms. MD-5, SHA-1, SHA-256, SHA-384
or SHA-512 hashes
NAT-Traversal (NAT-T) support for VPN over routes without VPN passthroughNAT-Traversal
Enables VPN connections from or to dynamic IP addresses. The IP address is communicated via ISDN B- or D-channel or with the ICMP
or UDP protocol in encrypted form. Dynamic dial-in for remote sites via connection template
Enables the registration of IP addresses with a Dynamic DNS provider in the case that fixed IP addresses are not used for the VPN
connection
DNS forwarding according to DNS domain, e.g. internal names are translated by proprietary DNS servers in the VPN. External names
are translated by Internet DNS servers
Allows the selective forwarding of traffic for IKEv2 depending on the addressed DNS domain.Split DNS
Connecting private IPv4 networksIPv4 VPN
Use of IPv4 VPN over IPv6 WAN connectionsIPv4 VPN over IPv6 WAN
Connecting private IPv6 networksIPv6 VPN
LCOS 10.40
Page 5
DATASHEET
LANCOM 884 VoIP
VPN
Use of IPv6 VPN over IPv4 WAN connectionsIPv6 VPN over IPv4 WAN
Radius
Performance
Routing-Performance
VoIP
Functionality
Call router
SIP registrar
SIP proxy
SIP gateway
SIP trunk
Media proxy
Audio properties
SIP-Codec support
Fax transmission
Auto QoS
RADIUS authorization and accounting, outsourcing of VPN configurations in external RADIUS server in IKEv2, RADIUS CoA (Change
of Authorization)
Transmission of multiple, securely separated networks within a VPN tunnelHigh Scalability VPN (HSVPN)
Data regarding the overall routing performance can be found inside the LANCOM tech paper "Routing-Performance" on
www.lancom-systems.com
10 (up to 40 with VoIP +10 Option)Number of local subscribers
Up to 4 internal ISDN buses each with 2 parallel channels and each up to 10 telephone numbersNumber of local ISDN subscribers
Up to 60 external VoIP connections depending on code conversion, echo canceling and loadNumber of simultaneous VoIP connections
Hold/Request, Swap, Transfer, Call Forwarding (CFU, CFB, CFNR), number display/suppression (CLIP, CLIR), suppression of second call
(Busy on Busy), immediate outgoing line, hunt groups, call diversion, overlap dialing
Hunt group cascades, Call diversion, simultaneously or sequentially. Automatic forwarding after timeout or when busy/unreachableHunt groups
Registration of several local VoIP terminal devices with the same number/ID.Multi login
Central switching of all incoming and outgoing calls. Number translation by mapping, numeral replacement and number supplementation.
Configuration of line and route selection incl. line backup. Routing based on calling and called number, SIP domain and line. Blocking
of telephone numbers or blocks of telephone numbers. Inclusion of local subscribers into the number range of an upstream PBX.
Supplement/remove line-related prefixes or switchboard numbers.
Management of local VoIP users/VoIP PBXs, registration at VoIP providers/upstream VoIP PBXs. Service location (SRV) support. Line
monitoring for SIP trunk, link, remote gateway and SIP PBX line
Up to 25 SIP-provider accounts (up to 55 with VoIP +10 Option), up to 4 SIP PBXs incl. line backup. SIP connections from/to internal
subscribers, SIP providers and SIP PBXs. Automatic bandwidth management and automatic configuration of the firewall for SIP
connections.
Conversion of ISDN telephone calls to VoIP calls, and vice versa. Local ISDN subscribers register as local VoIP users, and local ISDN
subscribers automatically register as VoIP users at upstream VoIP PBXs/with VoIP providers. Number translation between internal
numbers and MSN/DDI
Call switching based on extension numbers to/from VoIP PBXs/VoIP providers (support of the VoIP-DDI functions compliant with ITU-T
Q.1912.5). Mapping of entire VoIP telephone number blocks
Call switching of any numbers to/from SIP PBXs/SIP providers. Mapping of entire SIP telephone number blocksSIP link
Termination and interconnection of multiple media streams. Control of media sessions. IP address and port translation for media stream
packets. Connection of parties at media stream level where a call transfer in SIP (REFER) is not possible
Separation of insecure and secure networks, QoS, management of signaling and voice data, transcodingSession Border Controller (SBC)
RTP, SIPS and SRTPMedia protocols
German Telekom, QSC, Ecotel and SipgateSupported providers
Operation at ISDN exchange line or at ISDN extension line of existing PBXs. Provision of exchange lines or extension linesISDN features
Echo canceling (G.168) with automatic deactivation during fax transmission, automatic adaptive jitter buffer. Inband tone signaling
compliant with EU standards and country-specific. Voice encoding with G.711 µ-law/A-law (64 kbps)
SIP only: G.711 µ-law/A-law (64 kbps), G.722, G.723, G.726, G.729, iLBC, PCM (16, 20 und 24 Bit, Mono und Stereo), OPUS, AAC (LC,
HE HEv2), MPEG Layer II, ADPCM 4SB. DTMF support (Inband, RFC2833, SIP-INFO)
Transmisson of fax via SIP on the LAN/WAN side with T.38 or G.711. Conversion of SIP fax with T.38 and break-in/break-out at the
outside line to ISDN G.711 with service signalisation. Connection and conversion to SIP T.38 or G.711 for SIP or ISDN fax machines.
Compatible to SwyxFax on true G.711 SIP lines.
Automatic dynamic bandwidth reservation per SIP connection. Voice packet prioritization, DiffServ marking, traffic shaping
(incoming/outgoing) and packet-size management of non-prioritized connections compared to VoIP. Independent settings for DiffServ
marking of signaling (SIP) and media streams (RTP)
LCOS 10.40
Page 6
DATASHEET
LANCOM 884 VoIP
VoIP
VoIP monitoring
SIP ALG
Interfaces
WAN: VDSL / ADSL2+
Ethernet ports
Port configuration
USB 2.0 host port
Serial interface
Management and monitoring
Management functions
Monitoring functions
Monitoring statistics
Hardware
Reporting of Call Data Records (CDR) via SYSLOG or e-mail. Status display of subscribers, lines, and connections. Logging of VoIP Call
Manager events in LANmonitor. SYSLOG and TRACE for voice connections. Active monitoring even with SNMP
Automatic network and VoIP integration of LANCOM DECT 510 IP base stationAutoprovisioning
The SIP ALG (Application Layer Gateway) acts as a proxy for SIP communication. For SIP calls the ALG opens the necessary ports for
the corresponding media packets. Automatic address translation (STUN is no longer needed).
VDSL2 compliant with ITU G.993.2, profiles 8a, 8b, 8c, 8d, 12a, 12b, 17a
a
VDSL2 vectoring compliant with ITU G.993.5
a
Compliant to: ADSL2+ over ISDN as per ITU G.992.5 Annex B with DPBO, ADSL2 over ISDN as per ITU G.992.3/5 Annex B/J, ADSL
a
over ISDN as per ITU G.992.1 Annex B (EU, over ISDN)
Supports one virtual ATM circuit (VPI, VCI pair) at a time
a
10/100/1000 Mbps Gigabit EthernetWAN: Ethernet
4 individual 10/100/1000 Mbps Ethernet ports; up to 3 ports can be operated as additional WAN ports with load balancing. Ethernet
ports can be electrically disabled within LCOS configuration. The ports support energy saving according to IEEE 802.3az
Each Ethernet port can be freely configured (LAN, DMZ, WAN, monitor port, off). LAN ports can be operated as a switch or separately.
Additionally, external DSL modems or termination routers can be operated as a WAN port with load balancing and policy-based routing.
DMZ ports can be operated with their own IP address range without NAT
USB 2.0 hi-speed host port for connecting USB printers (USB print server), serial devices (COM port server), USB data storage (FAT file
system); bi-directional data exchange is possible
2x ISDN BRI port (NT) and 2x internal/external ISDN port (NT/TE)ISDN
Serial configuration interface / COM port (8 pin Mini-DIN): 9,600 - 115,000 baud, suitable for optional connection of analog/GPRS
modems. Supports internal COM port server and allows for transparent asynchronous transmission of serial data via TCP
Alternative boot configuration, voluntary automatic updates for LCMS and LCOS, individual access and function rights up to 16
administrators, RADIUS and RADSEC user management, remote access (WAN or (W)LAN, access rights (read/write) adjustable seperately),
SSL, SSH, HTTPS, Telnet, TFTP, SNMP, HTTP, access rights via TACACS+, scripting, timed control of all parameters and actions through
cron job
Two stored firmware versions, incl. test mode for firmware updatesFirmSafe
configurable automatic checking and installation of firmware updatesautomatic firmware update
Device SYSLOG, SNMPv1,v2c,v3 incl. SNMP-TRAPS, extensive LOG and TRACE options, PING and TRACEROUTE for checking connections,
internal logging buffer for firewall events
Extensive Ethernet, IP and DNS statistics; SYSLOG error counter, accounting information exportable via LANmonitor and SYSLOG, Layer
7 Application Detection including application-centric tracking of traffic volume
IPerf is a tool for measurements of the bandwidth on IP networks (integrated client and server)IPerf
Performance monitoring of connectionsSLA-Monitor (ICMP)
Export of information about incoming and outgoing IP trafficNetflow
SD-LAN – automatic LAN configuration via the LANCOM Management CloudSD-LAN
SD-WAN – automatic WAN configuration via the LANCOM Management CloudSD-WAN
1,1 lbs (500 g)Weight
12 V DC, external power adapter (230 V) with bayonet cap to protect against accidentally unpluggingPower supply
Temperature range 0–40° C; humidity 0–95%; non-condensingEnvironment
Robust synthetic housing, rear connectors, ready for wall mounting, Kensington lock; 210 x 45 x 140 mm (W x H x D)Housing
None; fanless design without rotating parts, high MTBFFans
LCOS 10.40
Page 7
DATASHEET
LANCOM 884 VoIP
Hardware
14 wattPower consumption (max)
Declarations of conformity*
EN 60950-1, EN 55022, EN 55024CE
IPv6 Ready GoldIPv6
Made in GermanyCountry of Origin
You will find all declarations of conformity in the products section of our website at www.lancom-systems.com*) Note
DSL cable for IP based communications incl. galvanic signature, 4,25mCable
Power supply unit
Support
Options
LANCOM Public Spot
LANCOM Public Spot PMS Accounting Plus
LANCOM VoIP +10 Option
LANCOM Enterprise Option
LANCOM Management Cloud
LANCOM LMC-A-1Y LMC License
LANCOM LMC-A-3Y LMC License
LANCOM LMC-A-5Y LMC License
Accessories
LANCOM DECT 510 IP (EU)
External power adapter (230 V), NEST 12 V/1.5 A DC/S, coaxial power connector 2.1/5.5 mm bayonet, temperature range from -5 to
+45° C, LANCOM item no. 111301 (EU)/LANCOM item no 110829 (UK)
3 years supportWarranty
Regular free updates (LCOS operating system and LANtools) via InternetSoftware updates
LANCOM Content Filter +10 user (additive up to 100), 1 year subscription, item no. 61590LANCOM Content Filter
LANCOM Content Filter +25 user (additive up to 100), 1 year subscription, item no. 61591LANCOM Content Filter
LANCOM Content Filter +100 user (additive up to 100), 1 year subscription, item no. 61592LANCOM Content Filter
LANCOM Content Filter +10 user (additive up to 100), 3 year subscription, item no. 61593LANCOM Content Filter
LANCOM Content Filter +25 user (additive up to 100), 3 year subscription, item no. 61594LANCOM Content Filter
LANCOM Content Filter +100 user (additive up to 100), 3 year subscription, item no. 61595LANCOM Content Filter
Option to extend the manufacturer´s warranty from 3 to 5 years, item no. 10710LANCOM Warranty Basic Option S
Option to extend the manufacturer´s warranty from 3 to 5 years and replacement of a defective device, item no. 10715LANCOM Warranty Advanced Option S
Hotspot option for LANCOM products, versatile access (via voucher, e-mail, SMS), including a comfortable setup wizard, secure
separation of guest access and internal network, item no. 60642
Extension of the LANCOM Public Spot (XL) Option for the connection to hotel billing systems with FIAS interface (such as Micros Fidelio)
for authentication and billing of guest accesses for 178x/19xx routers, WLCs, and current central-site gateways, item no. 61638
Upgrade for LANCOM VoIP router with 10 additional internal VoIP numbers (additionally up to 40) and 10 external SIP lines (additionally
up to 55) item no. 61423
Software upgrade for the LANCOM 88x VoIP router series to the following functions: 5 active IPSec VPN channels, 16 ARF contexts,
support of enterprise routing protocols (BGP and OSPF), item no. 61409
Only usable with activated LANCOM Enterprise option*)
LANCOM LMC-A-1Y License (1 Year), enables the management of one category A device for one year via the LANCOM Management
Cloud, item no. 50100
LANCOM LMC-A-3Y License (3 Years), enables the management of one category A device for three years via the LANCOM Management
Cloud, item no. 50101
LANCOM LMC-A-5Y License (5 Years), enables the management of one category A device for five years via the LANCOM Management
Cloud, item no. 50102
Professional DECT base station for up to 6 DECT phones, network integration and configuration via LANCOM VoIP router, 4 simultaneous
calls possible, highest voice quality, power supply via PoE or power supply unit, item no. 61901
19" rack mount adaptor, item no. 6150119" Rack Mount
LCOS 10.40
Page 8
ETH 1ETH 2ETH 3ETH 4
VDSL / ADSL
Gigabit Ethernet 10/100/1000
NTNT
USB DC 12 VISDN 3ISDN 4
TE / NTTE / NT
ISDN 1ISDN 2Config (Com)
DATASHEET
LANCOM 884 VoIP
Accessories
For simple, theft-proof mounting of LANCOM devices with plastic housings, item no. 61349LANCOM Wall Mount
For simple, theft-proof mounting of LANCOM devices with plastic housings, item no. 61345LANCOM Wall Mount (White)
LANCOM Serial Adapter Kit
Item number(s)
Chassis drawing
For the connection of V.24 modems with AT command set and serial interface for the connection to the LANCOM COM interface, incl.
serial cable and connection plug, item no. 61500
LANCOM Advanced VPN Client for Windows 7, Windows 8, Windows 8.1, Windows 10, single license, item no. 61600VPN Client Software
LANCOM Advanced VPN Client for Windows 7, Windows 8, Windows 8.1, Windows 10, 10 licenses, item no. 61601VPN Client Software
LANCOM Advanced VPN Client for Windows 7, Windows 8, Windows 8.1, Windows 10, 25 licenses, item no. 61602VPN Client Software
LANCOM Advanced VPN Client for Mac OS X (10.5 Intel only, 10.6 or higher), single license, item no. 61606VPN Client Software
LANCOM Advanced VPN Client for Mac OS X (10.5 Intel only, 10.6 or higher), 10 licenses, item no. 61607VPN Client Software
62082LANCOM 884 VoIP (All-IP, EU, over ISDN)
LCOS 10.40
www.lancom-systems.com
LANCOM Systems GmbH I Adenauerstr. 20/B2 I 52146 Wuerselen I Germany I E-mail info@lancom.de
LANCOM, LANCOM Systems, LCOS, LANcommunity and Hyper Integration are registered trademarks. All other names or descriptions used may be trademarks or registered trademarks of their owners. This document contains statements
relating to future products and their attributes. LANCOM Systems reserves the right to change these without notice. No liability for technical errors and/or omissions. 05/20
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.