Lancom IAP-3G User Manual

LANCOM IAP-3G
Professional 3G router for M2M applications in harsh environments
1
High-speed Internet access via HSPA+ with download speeds up to 21 Mbps
1
Backwards compatible with the cellular standards UMTS, EDGE/GPRS
1
For tough environments: IP50 housing and extended temperature range from -20°C to +50°C
1
Ideal for M2M applications with its serial interface and COM-port forwarding
1
Integrated GPS functionality for device positioning
1
1
Flexible power supply with a universal power supply 10-28V
The M2M cellular router LANCOM IAP-3G features an integrated HSPA+ module and achieves data rates of up to 21 Mbps downstream and 5.76 Mbps upstream on
cellular networks. Thanks to its robust full-metal housing and the extended temperature range, the device is ideal for stationary and mobile connectivity for machines and
automated systems in harsh environmentsindependent of wired broadband services. For machine-to-machine communications, the LANCOM IAP-3G features a serial
COM port for COM-port forwarding. This enables systems that do not support IP to be integrated into a company network. The LANCOM IAP-3G also has a Gigabit Ethernet
interface and numerous networking features such as IPsec VPN, VLAN support, and an object-oriented stateful inspection firewall.
More flexibility.
The LANCOM IAP-3G offers exceptional flexibility. Thanks to the widespread coverage of cellular networks, the device guarantees Internet connectivity almost anywhere.
Where HSPA+ is not available, the cellular modem is backwards compatible to UMTS, EDGE and GPRS. Integrated into the LANCOM IAP-3G is a universal power adapter:
Designed for bipolar industrial plug connectors, it allows for power supplies ranging from 10 – 28 volts. The mounting plate supplied with the device contributes to its
flexibility, as the cellular router can be installed of on walls, masts and also on top-hat rails. For mobile applications and installation in public places, the LANCOM IAP-3G
features an integrated GPS module to determine the position of the device. This anti-theft measure ensures that the device stops operating if its location is changed.
More security.
LANCOM guarantees you communications with the highest standards of security from an extensive range of encryption and authentication mechanisms. VLAN technology,
matured quality-of-service functions and bandwidth limitation enable the reliable transmission of data streams. The VPN gateway in the LANCOM IAP-3G with its 5
simultaneous IPsec channels and high-security encryption by 3-DES or AES provides optimal security for VPN connections. Thanks to IPSec-over-HTTPS (based on the NCP
VPN Path Finder technology) secure VPN connections are also available where IPsec is blocked by the cellular networks. The LANCOM IAP-3G furthermore assures network
security with the object-oriented stateful inspection firewall, intrusion prevention, Denial of Service protection and access control by MAC or IP address.
More management.
LCMS, the LANCOM Management System, is a free software package for the LANCOM IAP-3G. It caters for the configuration of the device, remote maintenance and
network monitoring. The central component of LCMS, LANconfig, is used to configure the cellular router and other LANCOM devices on the network. LANmonitor offers
detailed, real-time monitoring of parameters, it provides access to log files and statistics, and it can carry out a detailed trace-protocol analysis. Other functions in LCMS
include the firewall GUI for object-oriented setup of the firewall, automatic backup of configurations and scripts, and the intuitive folder structure with convenient search
function.
More reliability for the future.
From the very start, LANCOM products are designed for a product life of several years. They are equipped with hardware dimensioned for the future. Even reaching back
to older product generations, updates to the LANCOM Operating SystemLCOSare available several times a year, free of charge and offering major features. LANCOM
offers unbeatable safeguarding of your investment.
LANCOM IAP-3G
UMTS modem
UMTS, HSPA+ (HSPA+ with up to 21 Mbps, HSUPA with up to 5.76 Mbps), Edge, and GPRS supportSupported standards*
850/900/1900/2100 MHzUMTS and HSxPA bands
850/900/1800/1900 Mhz (EDGE up to max. 236kbps)EDGE/GPRS bands
Maximum transmission power GSM/EDGE
Firewall
Stateful inspection firewall
Packet filter
Tagging
Quality of Service
Bandwidth reservation
Layer 2/Layer 3 tagging
Security
Authentication mechanisms
High availability / redundancy
VRRP
GSM850 & GSM 900 +32dBm (GMSK) ' GSM850 & GSM 900 +27dBm (8PSK) ' DCS1800 & PCS1900 +29dBm (GMSK) ' DCS1800 & PCS1900 +26dBm (8PSK)
+23dBmMaximum transmission power UMTS/HSxPA
Receive diversity on the aux antennaDiversity support
Multi-SIM is supported on 4G devices only*) Note
Incoming/Outgoing Traffic inspection based on connection information. Trigger for firewall rules depending on backup status, e.g. simplified rule sets for low-bandwidth backup lines. Limitation of the number of sessions per remote site (ID)
Check based on the header information of an IP packet (IP or MAC source/destination addresses; source/destination ports, DiffServ attribute); remote-site dependant, direction dependant, bandwidth dependant
Network Address Translation (NAT) based on protocol and WAN address, i.e. to make internal webservers accessible from WANExtended port forwarding
N:N IP address mapping for translation of IP addresses or entire networksN:N IP address mapping
The firewall marks packets with routing tags, e.g. for policy-based routing; Source routing tags for the creation of independent firewall rules for different ARF contexts
Forward, drop, reject, block sender address, close destination port, disconnectActions
Via e-mail, SYSLOG or SNMP trapNotification
Dynamic bandwidth management with IP traffic shapingTraffic shaping
Dynamic reservation of minimum and maximum bandwidths, totally or connection based, separate settings for send and receive directions. Setting relative bandwidth limits for QoS in percent. Bandwidth control and QoS also for UMTS connections
Priority queuing of packets based on DiffServ/TOS fieldsDiffServ/TOS
Automatic packet-size control by fragmentation or Path Maximum Transmission Unit (PMTU) adjustmentPacket-size control
Automatic or fixed translation of layer-2 priority information (IEEE 802.11p-marked Ethernet frames) to layer-3 DiffServ attributes in routing mode. Translation from layer 3 to layer 2 with automatic recognition of IEEE 802.11p-support in the destination device
Monitoring and blocking of login attempts and port scansIntrusion Prevention
Source IP address check on all interfaces: only IP addresses belonging to the defined IP networks are allowedIP spoofing
Filtering of IP or MAC addresses and preset protocols for configuration accessAccess control lists
Protection from fragmentation errors and SYN floodingDenial of Service protection
Detailed settings for handling reassembly, PING, stealth mode and AUTH portGeneral
Filtering of unwanted URLs based on DNS hitlists and wildcard filters. Extended functionality with Content Filter OptionURL blocker
Password-protected configuration access can be set for each interfacePassword protection
Alerts via e-mail, SNMP traps and SYSLOGAlerts
EAP-TLS, EAP-TTLS, PEAP, MS-CHAP, MS-CHAPv2 as EAP authentication mechanisms, PAP, CHAP, MS-CHAP and MS-CHAPv2 as PPP authentication mechanisms
Network protection via site verification by GPS positioning, device stops operating if its location is changesGPS anti-theft
Adjustable reset button for 'ignore', 'boot-only' and 'reset-or-boot'Adjustable reset button
VRRP (Virtual Router Redundancy Protocol) for backup in case of failure of a device or remote station. Enables passive standby groups or reciprocal backup between multiple active devices including load balancing and user definable backup priorities
For completely safe software upgrades thanks to two stored firmware versions, incl. test mode for firmware updatesFirmSafe
Features as of: LCOS 9.10
Loading...
+ 6 hidden pages