Maipu MP1800-10 User Manual

Maipu Confidential & Proprietary Information Page 1 of 95
V1.2
Maipu Communication Technology Co., Ltd
No. 16, Jiuxing Avenue Hi-Tech Park Chengdu, Sichuan Province P. R. China 610041 Tel: (86) 28-85148850, 85148041 Fax: (86) 28-85148948, 85148139 URL: http:// www.maipu.com Mail: overseas@maipu.com
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 2 of 95
All rights reserved. Printed in the People’s Republic of China.
No part of this document may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language or computer language, in any form or by any means, electronic, mechanical, magnetic, optical, chemical, manual or otherwise without the prior written consent of Maipu Communication Technology Co., Ltd.
Maipu makes no representations or warranties with respect to this document contents and specifically disclaims any implied warranties of merchantability or fitness for any specific purpose. Further, Maipu reserves the right to revise this document and to make changes from time to time in its content without being obligated to notify any person of such revisions or changes.
Maipu values and appreciates comments you may have concerning our products or this document. Please address comments to:
Maipu Communication Technology Co., Ltd
No. 16, JiuXing Avenue, Hi-Tech Park Chengdu, Sichuan Province P. R. China 610041 Tel: (86) 28-85148850, 85148041 Fax: (86) 28-85148948, 85148139 URL: http:// www.maipu.com Mail: overseas@maipu.com
All other products or services mentioned herein may be registered trademarks, trademarks, or service marks of their respective manufacturers, companies, or organizations.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 3 of 95
Contents
Product Introduction ................................................................................ 5
Hardware Specifications .......................................................................................... 5
Functions ............................................................................................................... 6
Product Models ....................................................................................................... 7
Product Shapes ...................................................................................................... 7
Online Login .............................................................................................. 9
Environment Requirement ....................................................................................... 9
Using Preparations .................................................................................................. 9
Configure Computer .............................................................................................. 10
Log into System ................................................................................................... 14
Configuration ......................................................................................... 15
System ................................................................................................................ 15
System Time ...................................................................................................................... 16
Remote Logs ...................................................................................................................... 18
Management Control .......................................................................................................... 18
Configuration Management ................................................................................................. 19
System Upgrade ................................................................................................................. 20
SNMP ................................................................................................................................ 21
Modify Password ................................................................................................................. 22
Restart System .................................................................................................................. 22
Log Out ............................................................................................................................. 23
Network ............................................................................................................... 23
Dial Interface ..................................................................................................................... 23
WAN Interface .................................................................................................................... 29
LAN Interface ..................................................................................................................... 35
Forwarding Mode ................................................................................................................ 36
Dynamic Domain Name ...................................................................................................... 36
Static Route ....................................................................................................................... 37
Dynamic Route ................................................................................................................... 38
Manual Online .................................................................................................................... 40
WIFI Setting....................................................................................................................... 41
Service ................................................................................................................ 42
DHCP Setting ..................................................................................................................... 43
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 4 of 95
Hot Backup ........................................................................................................................ 45
AAA Configuration .............................................................................................................. 47
802.1x Authentication ......................................................................................................... 48
PIN Code Management ....................................................................................................... 50
Regular Online/Offline ......................................................................................................... 55
Disconnection Detection ...................................................................................................... 55
Multi-WAN Port Service ....................................................................................................... 56
Status Firewall ...................................................................................................... 59
Basic Setting ...................................................................................................................... 59
Access Control .................................................................................................................... 60
Port Mapping ...................................................................................................................... 61
MAC-IP Binding .................................................................................................................. 62
QOS .................................................................................................................... 63
Bandwidth Management ..................................................................................................... 63
VPN Configuration ................................................................................................. 64
IPSec ................................................................................................................................. 64
GRE ................................................................................................................................... 71
Certificate Management ...................................................................................................... 73
Status.................................................................................................................. 78
System Logs ...................................................................................................................... 79
System Information ............................................................................................................ 79
IPSec Tunnel Status ............................................................................................................ 80
Dialer Interface Status ........................................................................................................ 81
WAN Status ....................................................................................................................... 84
LAN Status ......................................................................................................................... 85
Route Information .............................................................................................................. 86
DHCP Information .............................................................................................................. 87
Connection Information ....................................................................................................... 87
GPS Status ........................................................................................................................ 88
CLI ...................................................................................................................... 89
System .............................................................................................................................. 89
Interface ............................................................................................................................ 90
3G ..................................................................................................................................... 90
IPSec ................................................................................................................................. 91
Route ................................................................................................................................ 92
Firewall .............................................................................................................................. 93
DHCP&VRRP ......................................................................................................................... 93
Appendix ................................................................................................ 94
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 5 of 95
Product Introduction
This chapter describes the specifications, functions, and product models of
MP1800-10 router, letting you have a primary impression for MP1800-10
router and helping you to use the product better in the future.
1. Hardware specifications
2. Functions
3. Product models
4. Product shapes
Hardware Specifications
1. 3G data
Support two kinds of 3G module, that is, WCDMA and CDMA2000.
2. Interface
Wireless interface: 50Ω/SMA female SIM/UIM card: 3V Series data interface (RJ45): RS-232(DCE) Series data interface rate: 9600 bits/s Ethernet interface: 10/100BaseT/RJ45 auto-sensing
USB interface (only for RM1800-10C, RM1800-10W, RM1800-10)
802.11b/g/n (only for RM1800-10C, RM1800-10W, RM1800-10)
3. Power supply
Voltage: +12VDC
4. Power consumption
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 6 of 95
Idle: 300mA@+12VDC Max.: 800mA@+12VDC
5. Other parameters
Demission: < 100mm×140mm×35mm (excluding antenna and
installation parts)
Weight: < 1000g
Work environment temperature: -25 - +70
Storage temperature: -30 - +70
Relative humidity: < 95% (no condensing)
Functions
1. Basic Features
Convenient, flexible, reliable Support CDMA 2000 and WCDMA Data terminal online forever NTP Remote logs Remote SSH, Telnet, HTTP management Local Firmware upgrade/configuration backup SNMP management Support DDNS Inbuilt with DHCP and VRRP services Firewall and virtual address translation (NAT) Support packet filter Support mobile network traffic statistics Support VPDN and APN private network access
2. Advanced functions Support IPSEC, GRE
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 7 of 95
Support Windows 2008/2003, CMS offline digital certificate
Support Windows 2008/2003, CMS online digital certificate Support dialing on demand and online forever Support static route, black hole route, dynamic route RIP v2 Support PIN code management of SIM card Support AAA login authentication Support 802.1x authentication Support disconnection detection Support multi-WAN port backup Support getting time via 3G Support regular online/offline Support E3G management
Product Models
MP1800-10 router adopts the general basic platform and individual application to adapt the different industry application requirements and network environment of the carrier. Currently, MP1800-10 series router has various models. To distinguish the product models, we describe as follows:
MP1800-10 router models: RM1800-10x
Table 2-1: Product model list
x
Network type
W
WCDMA
C
CDMA2000
No letter
Outer USB 3G
Product Shapes
1. Front Panel
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 8 of 95
RM1800-10x:
Front panel
Back panel
RESET: The reset button; press the button for 2-3s with power and the system resets; press the button for 6-10s and the device restores the factory setting.
CONSOLE: Serial console platform; the baud rate is 9600, 8-bit data bit, no parity, one-bit stop bit.
FE0-FE4: RJ45 Ethernet interface.
USB: Outer USB interface.
ANT0 is 3G antenna, ANT1 is WIFI antenna
The outer power adaptor is DC 12V/1.5A.
Indicator description:
Indicator
Status
Description
SYS
Flash
The system already runs normally
SIM
On
The SIM card is connected normally
3G
Flash
3G has data received and sent
3G signal indicator
On
Indicate the signal intensity. When the signals are strongest, three indicators are all on; when there is no signal, three indicators are all off.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 9 of 95
Online Login
This chapter describes the using requirement, installation wiring, and configuration login of MP1800-10 router, which can help you log into the management system of the product.
1. Environment requirement
2. Using preparations
3. Configure computer
4. Log into system
Environment Requirement
The requirements of MP1800-10 router for the using environment:
Work environment temperature: -25 - +70
Storage temperature: -30 - +70 Relative humidity: < 95% (no condensing)
Using Preparations
To configure using MP1800-10 router, you need to prepare as follows:
One computer:
1. Computer with Ethernet adapter and TCP/IP protocol
2. IE 8.0 browser (other browser also can ensure the normal using of
the functions)
3. It is recommended to adopt 1024x768 resolution to display
One UIM(/SIM) card
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 10 of 95
Caution
The starting order of the device is: Insert SIM card > Insert antenna > Power on. If the starting order is wrong, maybe the functions of the device cannot be used normally.
Configure Computer
The following takes the LAN connection mode and adopts Windows XP as an example to describe the configuration steps of the computer network connection.
1. Method 1:
In LAN, select one computer for configuration and enter Control Panel >
Network Connection, as shown in the following figure. Select Local Connection of the network adapter on the interface.
Configure local connection of the computer
Enter (double-click or right-click) Local Connection > Properties, as shown in the following figure:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 11 of 95
Configure local connection properties of the computer
Select Internet Protocol (TCP/IP) and click Properties to enter the following figure:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 12 of 95
TCP/IP attribute configuration
The configuration is as follows:
IP address: 192.168.10.* (* refers to any integer from 2-254).
Subnet mask: 255.255.255.0
Default gateway: 192.168.10.1
After configuration, click OK.
Caution
1. The method interrupts the communication between the computer and
LAN for a moment.
2. The factory setting of MP1800-10 router LAN interface:
IP address: 192.168.10.1 Subnet mask: 255.255.255.0
2. Method 2
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 13 of 95
In the previous network configuration environment, when you do not want to interrupt the communication between the local PC and LAN, but still can configure MP1800-10 router, you can consider adding route (IP) to realize.
Click Advanced in the above figure 3-3, as shown in Figure 3-3:
Advanced configuration interface of TCP/IP attributes
Click Add (A) in IP address (R) of Figure 3-4, input the desired IP address, as shown in the following figure:
Interface for adding TCP/IP address
After configuration, click Add. In this way, one route to MP1800-10 router is added.
Note
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 14 of 95
If you just configure MP1800-10 router, we recommend you to select Method 2, which can save time.
Log into System
Open and configure the IE browser of the computer and input http://192.168.10.1/ in the address bar.
Web login
Press Enter to enter the login interface of the user, as follows:
User login authentication
When the user logs into the system for the first time, it is necessary to adopt the default user name and password:
User name: admin Password: admin
After inputting correctly, the user can log into the web configuration interface of MP1800-10 router.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 15 of 95
Configuration
This chapter describes how to configure MP1800-10 router via web, the functions, configuration parameters, precautions, and problems of the product.
1. System
2. Network
3. Service
4. Status firewall
5. QoS
6. VPN configuration
7. Status
8. CLI
System
The system tool of MP1800-10 router provides the following functions for you to manage the system:
System time Remote logs Management control Configuration management System upgrade SNMP Modify password System restarting
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 16 of 95
Log out
System Time
MP1800-10 provides three kinds of clock synchronizing modes, that is,
manual setting, NTP network time and get time via 3G module.
1. Manual setting
Enter System > System Time and you can see the interface for setting time manually, as follows:
Interface for setting time manually
Current time: Display current system time
System time setting: Manual setting/time server
Date setting: Set system date
Time setting: Set system time
Time Zone: Specify the time zone of the country against UTC
2. NTP Synchronizing Time Setting
NTP (network time protocol), that is, synchronize time automatically via the local host and network clock server. Enter System > System Time and you can see the following interface for configuring time server:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 17 of 95
NTP configuration interface
Synchronization interval: Set the interval of synchronizing time.
Time server: Specify the domain name or IP address of the server
providing the service of synchronizing time.
Time Zone: Specify the time zone of the country against UTC
Caution
NTP server is not sure to be the server on Internet, but should be the server that MP1800-10 router can access.
3. Setting via 3G module
Get time via 3G module
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 18 of 95
Caution
When setting the time via the 3G module, the device should be inserted with the available SIM card and it can take effect only after restarting the device.
Time Zone: Specify the time zone of the country against UTC
Remote Logs
The system can send the device log information to the remote log server.
Enter System > Remote log and you can see the following configuration interface:
Remote log configuration interface
Enable: Whether to send the device log information to the remote log server.
Remote Log Server IP: Configure the IP address of the remote log server.
Log Source Interface: The source address of the remote log packet is the selected interface address.
Management Control
The management control function of MP1800-10 router can control whether to enable the SSH service, Telnet service or HTTP service. Enter System > Management Control and you can see the following configuration interface:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 19 of 95
Management control configuration interface
Configuration Management
The configuration management function of MP1800-10 provides the backup and recovery for the user configuration. Backup can save the configured parameters to the PC; Recovery can restore the saved configuration parameters to the system.
1. Backup configuration
Enter System > Configuration Management and you can see the following interface:
Backup configuration interface
Click Backup and you can back up the current user configuration of the system.
Caution
Save the backup file to the desired host CD, avoiding being lost.
2. Recover configuration
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 20 of 95
When you need to restore the user configuration to the system, enter System > Configuration Management, click Browse to select the desired backup file, and then click Recover, as follows:
Recover configuration
3. Recover factory configuration
When you want to restore the system to the factory status, enter System > Configuration Management, and click Restore Factory Setting.
System Upgrade
MP1800-10 router can perform the remote web upgrade. Before upgrading, you need to ensure that you have got the target file. During upgrading, enter System > System Upgrade and you can see the following interface:
System upgrading interface
Click Browse to find the target file, click Upload Mirror, and the system starts to upload the mirror. After uploading, you can see the following figure:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 21 of 95
Upgrading process
Click Run to start upgrading system. The upgrading is slow and you can view the upgrade process via the upgrade process bar. After upgrading successfully, the interface turns to the login interface automatically.
Caution
During upgrade, do not power off. Otherwise, the device cannot be used.
SNMP
When you want to configure SNMP, enter System > SNMP and you can see the following interface:
SNMP configuration interface
Enable: Whether to enable SNMP
System location: Input the location of the router
Contact: Input the contact of the administrator of the router
System name: Input the name of the router
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 22 of 95
System description: Input the description of the router
Community name: Specify the community name of SNMP
SNMP management IP: Specify the server IP address to which the Trap
message of the device is sent
Prompt
The above configurations are all set to the nodes in MIB.
Modify Password
MP1800-10 router provides the authority of modifying user password. Enter System > Modify Password and you can set the new password for the system administrator admin, as follows:
Modify password
Restart System
When you want to restart MP1800-10 router via software, enter System
> Restart System and you can see the following interface. Click Restart.
System restarting interface
Caution
After restarting successfully, you need to re-log into the system so that you can configure.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 23 of 95
Log Out
When you want to log out the web configuration interface of MP1800-10 router, enter System > Log out.
Network
MP1800-10 router network setting includes the following functions:
Dialing interface WAN interface LAN interface Forwarding mode Dynamic domain name Static route Dynamic route Get online manually WIFI setting
Dial Interface
1. Basic Setting
Click Network > Dial Interface > Basic Setting, and you can see the basic configuration interface of the mobile network:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 24 of 95
Basic setting of mobile network
Network mode: Set the mobile network access mode (2.5G/3G/auto switchover);
APN: Specifies the APN (Access Point Name) of the mobile carrier;
User name: Set the user name used by dialing (you can get from the
network provider); the maximum length is 128 bits;
Password: Set the password used by dialing (you can get from the network provider); the maximum length is 128 bits.
Enable Back-up account: Set using the standby account to dial. If enabling the item and when the master account dialing fails, use the standby account to dial.
Enable SIM Card Bind: Set the binding function of the SIM card. If enabling the option, bind the IMSI code of the SIM card with the system. When using the 3G module for the first time, record the card number. If using other card subsequently and enabling the option, there is error.
Enable Hardware ID Bind: After enabling the function, carry the hardware ID (hardware ID is MAC address of LAN port; the format of dial user name is $MAC$user name) in the dial user name. LNS adopts the hardware ID, user name, password, and IMSI to authenticate. The function needs LNS and AAA server to cooperate.
For the common user, after completing the above basic parameter configuration and saving, MP1800-10 router performs the wireless network dialing connection automatically after powering on every time. It is convenient to use.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 25 of 95
After ticking Enable standby account, the basic setting interface of the dial interface is as follows:
Basic setting of mobile network
Main Account Recovery Time: After setting standby account dialing successfully, restore the dialing interval of the master account. The unit is minute; the default value is 600 minutes; 0 means not to restore the master account.
Re-dial Count: Set the re-dialing times of each account. By default, it is three times. 0 means always trying to use the master account dialing and do not use standby account.
APN: Specifies the APN (Access Point Name) of the backup mobile carrier;
User name: Set the user name used by dialing (it can be got from the
network provider). The maximum length is 128 bits.
Password: Ser the password used by dialing (it can be got from the network provider). The maximum length is 128 bits.
2. Link Type
Set link connection mode, including online forever and dial on demand.
Enter Network > Dial interface > Link type and you can see the configuration interface of the link type:
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 26 of 95
Online forever
Always on line: Make the network connection be online forever.
Dial on demand
Dial on demand: Trigger dial when there is service data flow. If the router
is configured with the service that needs to use the 3G traffic, such as NTP, remote log and IPSec DPD, the dial on demand function becomes invalid.
Idle time: Set the idle time of the connection; when reaching the idle time, close the connection.
3. Advanced setting
If you are advanced user, enter Network > Dial Interface > Advanced Setting, and you can complete the following advanced parameter
configuration:
Authentication and encryption parameters:
Authentication & encryption parameters
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 27 of 95
CHAP (Challenge-Handshake Authentication Protocol): It is one encrypted authentication mode and can avoid transmit the actual password of the user when setting up the connection. For PPP, the key information does not need to be transmitted in the channel during the authentication and the information switched during each authentication is different, which can avoid monitoring attack and improve the security.
PAP: It is one simple plain text authentication mode. It is required that the key information is transmitted in plain text via the channel, so it is easy to be monitored and leaked by sniffer.
MS CHAP: It is similar to CHAP. MS-CHAP is also one encryption authentication mechanism, using MPPE-based data encryption.
MS2-CHAP: MS-CHAP version 2.
EAP: It is one expansible authentication protocol. The protocol is used by
the authentication in the point-to-point network, such as PPP. It can support various authentication mechanisms. With the expansible authentication protocol, any ID authentication mechanism can authenticate the remote access connection.
Compression and control protocol parameters
Compression & Control protocol
Compression control protocol: Responsible for the configuration on the PPP link and negotiating which compression algorithm to adopt. And adopt the reliable mode to identify the failure of the compression and de­compression mechanism.
Address/control compression: Whether to permit PPP packet address domain and control compression setting.
Protocol domain compression: Whether to enable the protocol domain compression.
VJ TCP/IP header compression: Whether to permit TCP/IP data to perform the Van Jacobson header compression.
Connection ID compression: Whether to permit the connection ID compression.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 28 of 95
Other parameters
Other parameter setting provides you whether to permit using the peer DNS, LCP echo interval, LCP echo failure, packet side processing, and debug IP setting.
Other parameters
Asyn Control Character Map: The asyn control character mapping is one 32-bit set. Each bit indicates one ASCII value, 0-31 ASCII character. Each bit with the value 1 indicates that the corresponding control character should not be in the PPP packet sent by the peer. The mapping table uses the hexadecimal coding (do not need 0x). The least significant bit (00000001) indicates the character 0 and the most significant bit (80000000) indicates the character 31.
Debug: Set whether to output the details of LCP, IPCP negotiation during PPP dialing. By default, it is disabled.
Use Peer DNS: Whether to permit using peer DNS. By default, it is enabled.
Check invalid DNS: If ticking, detect whether the got DNS is valid. If invalid, re-dial.
No Default Route: If ticking, do not add the default route to the dialing interface. Otherwise, after dialing succeeds, add the default route to the dialing interface.
LCP Echo Interval: PPP link control protocol (LCP) echo interval setting. The value range is 1-2147483647.
MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information Page 29 of 95
LCP Echo Failure: PPP link control protocol (LCP) echo failure times setting. The value range is 1-2147483647.
MTU: Maximum transmission packet size setting of MP1800-10 router on the PPP link. Take byte as unit. For LAN, the maximum transmission unit is 1,500 bytes. The maximum packet transmitted on the PPP link can be set smaller.
MRU: The maximum packet size received by MP1800-10 router.
Local IP: Set the local IP of MP1800-10 router when performing PPP IPCP
negotiation.
Remote IP: Set the peer IP of MP1800-10 router when performing PPP IPCP negotiation.
WAN Interface
1. WAN interface
Ethernet-based WAN interface supports various protocols, including static IP, DHCP and PPPoE.
Enter Network > WAN interface > WAN interface and you can see the setting interface of WAN interface:
WAN interface setting
Protocol: Set the protocol used when WAN interface is connected to Internet, including static IP, DHCP, PPPoE or disable.
After selecting the connection mode as static IP, the setting interface of WAN interface is as follows:
Loading...
+ 66 hidden pages