Viola Systems M2M User Manual

Viola M2M Gateway Enterprise Edition User Manual
Viola M2M Gateway Enterprise Edition (2505)
Firmware Version 2.4
Document Version 3.0
October 2010
Firmware Version 2.4 2 Document Version 3.0
Copyright and Trademark
Copyright © 2008-2010, Viola Systems Ltd. All rights to this manual are owned solely by Viola Systems Ltd. (referred elsewhere in this User’s Manual as Viola Systems). All rights reserved. No part of this manual may be transmitted or reproduced in any form or by any means without a prior written permission from Viola Systems.
Ethernet™ is a trademark of XEROX Corporation. Windows™ and Internet Explorer™ are trademarks of Microsoft Corporation. Netscape™ is a trademark of Netscape Communications Corporation. All other product names mentioned in this manual are the property of their respective owners, whose rights regarding the trademarks are acknowledged.
Viola Systems Ltd.
Lemminkäisenkatu 14-18 A FI-20520 Turku Finland E-mail: info@violasystems.com
Technical Support
Phone: +358 20 1226 226 Fax: +358 20 1226 220 E-mail: support@violasystems.com Internet: http://www.violasystems.com
Firmware Version 2.4 3 Document Version 3.0
Disclaimer
Viola Systems reserves the right to change the technical specifications or functions of its products or to discontinue the manufacture of any of its products or to discontinue the support of any of its products without any written announcement and urges its customers to ensure that the information at their disposal is valid.
Viola software and programs are delivered “as is”. The manufacturer does not grant any kind of warranty including guarantees on suitability and applicability to a certain application. Under no circumstance is the manufacturer or the developer of a program responsible for any damage possibly caused by the use of a program. The names of the programs as well as all copyrights relating to the programs are the sole property of Viola Systems. Any transfer, licensing to a third party, leasing, renting, transportation, copying, editing, translating, modifying into another programming language or reverse engineering for any intent is forbidden without the written consent of Viola Systems.
Viola Systems has attempted to verify that the information in this manual is correct with regard to the state of products and software on the publication date of the manual. We assume no responsibility for possible errors which may appear in this manual. Information in this manual may change without prior notice from Viola Systems.
Firmware Version 2.4 4 Document Version 3.0
Declaration of Conformity
(according to ISO/IEC Guide 22 and EN 45014)
Manufacturer’s Name: Viola Systems Ltd. Manufacturer’s Address:
Lemminkäisenkatu 14-18 A FI-20520 Turku Finland
declares that this product:
Product Name:
Viola M2M Gateway Enterprise Edition
conforms to the following standards:
EMC: EN 55022 Emission Test (Class A)
1. Radiated Emissions (30-1000MHz)
2. Conducted Emissions (0.15-30MHz)
EN 50082-1 Immunity Test
1. IEC 801-3: Radio Frequency Electromagnetic Field
2. IEC 801-2: Electrostatic Discharge
3. IEC 801-4: Fast Transients, AC Power Ports and Signal cables
Supplementary Information:
“The product complies with the requirements of the Low Voltage Directive 73/23/EEC and EMC directive 89/336/EEC.”
Warning!
This is a Class A product. In a domestic environment this product may cause radio Interference which may make it necessary for the user to take adequate measures.
Manufacturer’s Contact Information:
Viola Systems Ltd. Lemminkäisenkatu 14-18 A FI-20520 Turku Finland Phone: +358 20 1226 226 Fax: +358 20 1226 220
Firmware Version 2.4 5 Document Version 3.0
Warranty and Safety Instructions
Read these safety instructions carefully before using the products mentioned in this manual:
Warranty will be void if the product is used in any way in contradiction with the instructions given in this manual or if the product has been tampered with.
The devices mentioned in this manual are to be used only according to the instructions described in this manual. Faultless and safe operation of the devices can be guaranteed only if the transport, storage, operation and handling of the devices is appropriate. This also applies to the maintenance of the products.
To prevent damage both the product and any terminal devices must always be switched OFF before connecting or disconnecting any cables. It should be ascertained that different devices used have the same ground potential. Before connecting any power cables the output voltage of the power supply should be checked.
This product is not fault-tolerant and is not designed, manufactured or intended for use or resale as on-line control equipment or as part of such equipment in any hazardous environment requiring fail- safe performance, such as in the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life support machines, or weapons systems, in which the failure of Viola Systems manufactured hardware or software could lead directly to death, personal injury, or severe physical or environmental damage.
Firmware Version 2.4 6 Document Version 3.0
Revisions
Date Document
Version
Firmware Version
Description of Changes
10/2010 3.0 2.4 Manual released
Firmware Version 2.4 7 Document Version 3.0
Contents
COPYRIGHT AND TRADEMARK ........................................................................................2
DISCLAIMER..........................................................................................................................3
DECLARATION OF CONFORMITY......................................................................................4
WARRANTY AND SAFETY INSTRUCTIONS.......................................................................5
REVISIONS............................................................................................................................6
1. INTRODUCTION............................................................................................................... 9
1.1 About Viola M2M Gateway...................................................................................................9
1.2 M2M Gateway Features........................................................................................................9
1.3 Packaging information.........................................................................................................10
1.4 Hardware description...........................................................................................................10
1.4.1 Front panel..............................................................................................................10
1.4.2 Back Panel..............................................................................................................10
1.4.3 Product label........................................................................................................... 11
2. NETWORK REQUIREMENTS........................................................................................12
2.1 Connection Principle............................................................................................................12
2.2 Minimum Network Requirements........................................................................................12
2.3 Routing Setup......................................................................................................................13
2.4 Other Network Services......................................................................................................13
2.5 Recommended Network Setup...........................................................................................13
2.6 Using the Second Ethernet Port.........................................................................................14
3. QUICK INSTALLATION...................................................................................................15
3.1 Setting IP Address Using Web Browser.............................................................................15
4. NETWORK CONFIGURATION.......................................................................................18
4.1 Configuration screens..........................................................................................................18
5. VPN CONNECTIVITY..................................................................................................... 19
5.1 VPN requirements...............................................................................................................19
5.2 Available VPN types............................................................................................................19
5.3 Typical connection scheme.................................................................................................19
5.4 Typical connection scheme with routing.............................................................................20
6. SSH-VPN CONFIGURATION......................................................................................... 22
6.1 Introduction to SSH-VPN.................................................................................................... 22
6.2 SSH-VPN Configuration screen..........................................................................................22
6.3 Creating new connection.....................................................................................................23
6.4 Checking connection...........................................................................................................24
6.5 Finalising SSH-VPN setup..................................................................................................24
6.6 Editing existing connection..................................................................................................25
6.7 SSH port configuration........................................................................................................25
7. L2TP-VPN CONFIGURATION........................................................................................26
7.1 Introduction to L2TP-VPN...................................................................................................26
7.2 L2TP-VPN configuration screen..........................................................................................26
7.3 Creating new connection.....................................................................................................27
8. OPENVPN CONFIGURATION........................................................................................28
Firmware Version 2.4 8 Document Version 3.0
9. ADDITIONAL SYSTEM CONFIGURATION....................................................................29
9.1 Changing system password................................................................................................29
9.2 Firewall.................................................................................................................................29
9.2.1 Firewall configuration screen..................................................................................29
9.2.2 Changing firewall rules............................................................................................30
9.3 Date and time......................................................................................................................30
9.3.1 Manual configuration...............................................................................................31
9.3.2 Automatic configuration with NTP...........................................................................31
9.4 Backup.................................................................................................................................31
9.4.1 Backup screen........................................................................................................ 31
9.4.2 Creating backups.................................................................................................... 32
9.4.3 Restoring backups.................................................................................................. 32
9.4.4 Moving backups between units...............................................................................32
9.5 System logs.........................................................................................................................33
9.6 Supportlog............................................................................................................................33
9.7 Factory default settings.......................................................................................................34
10.ADVANCED SETTINGS..................................................................................................35
10.1 Command Line Shell...........................................................................................................35
10.2 Advanced UI Menus............................................................................................................35
10.2.1 System menu.......................................................................................................... 35
10.2.2 Networking menu.................................................................................................... 35
10.2.3 Others menu........................................................................................................... 35
11.TROUBLESHOOTING.....................................................................................................37
12.SPECIFICATIONS ..........................................................................................................38
13.LIMITED WARRANTY.....................................................................................................39
14.TECHNICAL SUPPORT ................................................................................................ 40
Firmware Version 2.4 9 Document Version 3.0
1 Introduction
This document describes how to configure the Viola M2M Gateway product.
1.1 About Viola M2M Gateway
The Viola M2M Gateway is a network device that enables VPN connection between company network and remote Arctic devices. It can also be used to control and monitor Arctic devices in local or remote networks. Concept of the Viola M2M Gateway is described in figure 1.
Figure 1. Viola M2M Gateway Concept
Only a computer with network connection and a HTML browser is required to configure the M2M Gateway. Using the M2M Gateway Web user interface you can configure and view the status of the remote Arctic devices and configure the VPN connection between M2M Gateway and Arctic device. Arctics have a WWW user interface which can be used to configure them using a HTML browser.
For the rest of this documentation, the Viola M2M Gateway is referred as M2M Gateway.
1.2 M2M Gateway Features
The M2M Gateway offers different advanced features for network usage. In most simple usage only VPN feature is used, but M2M Gateway makes possible to make complex network configurations.
Routing
M2M Gateway can forward packets to local Ethernet (eth0) which it is connected to company network. Also it is possible to route packets to second Ethernet (eth1) of M2M Gateway. More complex routing solutions can be made but they need consultation of your local network administrator.
Firewall
The M2M Gateway has internal firewall with graphical user interface. It is possible to connect M2M Gateway directly to the Internet and filter unwanted connections without external firewall. The recommended method is to use a dedicated firewall and install M2M Gateway behind it.
VPN
VPN is used to connect remote Arctic devices to local network. The connection is initiated by Arctic and the M2M Gateway decides based on its configuration does it allow remote Arctic start VPN connection.
Firmware Version 2.4 10 Document Version 3.0
VPN connection can be disabled from M2M Gateway. If the connection is terminated for some reason, it gets connected automatically by back up.
Remote Management
M2M Gateway offers full remote management. Also traditional console access is available using SSH.
1.3 Packaging information
The product package should contain the following items:
Viola M2M Gateway
Power cord
Viola M2M Gateway Quick Start Guide
1.4 Hardware description
1.4.1 Front panel
Table 1: Front panel LED description
LED color Name Description
Green Power Lit when power is on Yellow HDD Lit when IDE hard drive is accessed
Figure 2. M2M Gateway front panel
1.4.2 Back Panel
The M2M Gateway has power connector on the right side of the back panel. Ethernet interfaces are located in the left side of the back panel. See Figure 4 for connector locations. Depending on the network configuration only one of them or both are used. The first Ethernet port (eth0) is always used and it is the left most Ethernet connector located to right from USB connectors.
Figure 3. M2M Gateway back panel
Firmware Version 2.4 11 Document Version 3.0
1. PCI Express expansion
2. PCI Express expansion
3. Power supply, bay #2 *)
4. Power supply, bay #1 *)
5. NIC 2 (eth1) *)
6. NIC 2 (eth1) *)
7. Keyboard ps2 connector
8. Mouse
9. VGA connector
10.Serial connector
11.USB connector
12.USB connector
13.iLO 2 NIC connector **) Mandatory connections
1.4.3 Product label
Product label is found on the bottom of the device and it contains the basic information about the unit such as product name, serial number and Ethernet MAC address.
Figure 4. Product label
Firmware Version 2.4 12 Document Version 3.0
2 Network Requirements
M2M Gateway works properly when the required parameters which are described in this chapter are configured. For your network settings, contact your local network administrator.
Note!
Misconfiguration of the M2M Gateway can seriously hinder your network. Make sure you verify your network configuration with local network administrator.
2.1 Connection Principle
Company Intranet is normally connected to Internet via firewall. Figure 6 shows the M2M Gateway connected to the Demilitarized Zone (DMZ) of the firewall. This configuration allows hosts from Company Intranet to connect via firewall to the M2M Gateway. Other configurations are also possible.
E.g. subnets and proxy ARP can be used.
Figure 5. DMZ Connection
Note!
It is possible that the internal routing in company intranet may require configuration in order to integrate M2M Gateway to an existing network.
2.2 Minimum Network Requirements
The M2M Gateway requires the following settings:
One public IP address for M2M Gateway
SSH port (default 22) unblocked for incoming connections to M2M Gateway from the remote network
Although this configuration is minimal, it can be used for testing and evaluating more complex systems. It is always recommended to consult local network administrator when installing new servers to the public network.
Loading...
+ 28 hidden pages