Home
Patton electronic ONSITE SERIES 2603 User's Manual
Contents
1. 119 MIRO eO 120 lag dI 120 Management cese e eise e rre HERR 120 Msg A o 121 Dimension NUR EIER 121 Power and Power Supply ener nennen nete 121 AC universal power supply 121 48 power supply ERR ERR EIU ERE 121 EM nn 122 P 123 123 D OnSite Physical Connectors 124 RJ 45 shielded 10 100 Ethernet 125 RJ 45 non shielded RS 232 console port EIA 561 esses 125 Setia ta 126 V 35 M 34 and DB 25 Connector 126 21 15 Connector 127 48 Connector Re ERE 128 E Command Line Interface CLI Operation 129 E 130 CLI Terminology eic erre OB d p TOO I Ure 130 Local 1
2. 109 8 even ne ni IIR Ese 109 110 WAN SE e At M MN 110 DUAR Wie SFA ees HEURE 110 Vere lhl Cade eg erc e E ed uc Mie 110 e TUE ug MEET 111 108 Models 2603 2621 and 2635 User Manual 12 System Status System Status A quick but thorough summary of the OnSite s status is provided on this webpage but it also has links to the detailed webpages for the key subsystems of the OnSite The webpage is divided into six 6 sections e Port Connection Status connection status of the Ethernet port and a link to the Ethernet Port Configura tion webpage LAN Status displays the local IP address on the Ethernet port the MAC address and links to the LAN nections and DHCP Server web pages e WAN Status parameters and links to the WAN services defined on the serial port PPPoE Status the connection authentication status is available when the PPPoE WAN service is configured and activated Hardware Status shows the time that the OnSite has been operating the current time software version and a link to configure the time including the SNTP client Defined Interfaces provides links to statistics for the defined interfaces Status Port Connection Status Port Type Connected Line State Ethernet ethernet LAN Status Local IP Addr
3. voiced deu tu atus suites erba AE 55 ob WAN DORC sis a ra et 56 HNC c pM rem 56 E Ca 57 I aeu mere d E T T 60 Frame Relay bridged c eatian Cem d otiosi 61 Frame Relay AI IE EIU 02 Frame Relay toited oca esce 63 Frame Relay routed 64 Frame Relay Channel s Routed ome re sadam 65 tor Fiame Rely routed TUS RR S DER 66 PPP routed WAN service for Security 70 70 Valid gateway Toute cce oce 71 SECU TV CO MICU ALOR RONE EIS 24 Define ipl an Intemal _____ ______ _____ 72 Derme por Ta Security Policy hyperlink e sesia eseat ORTE DE EAE PORRER ex es E 73 48 49 50 Jl 52 53 54 22 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 7 72 73 74 Z3 76 77 78 79 80 81 82 83 84 85 86 New Policy linkto configuration WeDpape ose te on bg eate bi 7
4. 102 System 103 5 Client Configuration p 104 105 Configuring Client encre ir e ERE e 105 SNTP Client Mode Configuration Parameters 105 SNTP Client General Configuration Parameters 106 Systeri Clock 106 System NIC 108 nC 109 Port G nnectign Stat 109 110 WAN Status 119 Hardwate Status 110 Defined Interfaces a o 110 Status BD c 111 Contacting Patton for 112 Introd cHOn x eiue tiep e ive d er I P NI 113 Contact informato Ns oet eer terree 113 Patton support headquarters in the USA reist ee ep re ort er ir ep e o ehe E ERE ERR dA 113 Alternate Patton support for Europe Middle East and Africa EMEA 113 Warranty Service and Returned Merchandise Authorizations RMAs 113
5. 22 17 Models 2603 2621 and 2635 User Manual 1 General Information OnSite Series High Speed Routers overview The OnSite Series of gateway routers bridges combine full set of high speed IP routing features and WAN access via PPP IP FR protocols All OnSite routers come with an auto sensing full duplex 10 100Base T Ethernet port MDI X cross over switch console port and internal or external power supply There are three versions in the OnSite series corresponding to a choice of WAN interface The Model 2603 is equipped with an integrated T1 E1 CSU DSU for connection to full and fractional T1 E1 services The Model 2621 is equipped with DTE DCE user configurable X 21 interface The Model 2635 equipped with a V 35 interface presented on a female DB 25 connector and a cable to convert to an M34 F The OnSite routers provide selectable bridging or routing functionality along with advanced IP features such as NAT NAPT Firewall and DHCP A complete set of configurable PPP IP FR WAN protocols allow a wide range of choices when connecting branches via common WAN services The OnSite routers boast easy installa tion offering Console VT 100 Telnet HTTP and SNMP management options The following sections describes the OnSite series features and capabilities General attributes see section General attributes Ethernet see section Ethernet on page 19 Protocol support see section Protocol support on page 19
6. 51 Web Configuration Rein RR Ie eS 51 WAN Service Configuration aceite tpe ete re UE d i fot 52 PPP Conti gration zi neni ete ie nO a Or AR 52 Breed ER 52 PPP Bridged Remote Site Configuration ec 52 Central Site Configuration 2i i E 53 PPP PEE 54 Remote site configutdti n ERROR m Ete ED EI EEUU 54 Central Site Config ration RERO EN ER He iter tie d ie te 57 LMI Management Frame Relay links ertet tte er RU e ERR aeos 58 EMI Configuration ssns 58 Frame Relay Local Management 58 LMI Configuration Options eti ersten ook rn ein ro de E ERE 59 Web Configuration Methods 59 Frame Relay Configuration gem nte e P RERO SERES 60 Frame Relay bridged iet 61 Remote Site Configuration tacet eid Hee rer pbi Rare e 61 Central sit comfiouration 62 Frame Relay Routed sep quince neon rre t TR aide 63 Models 2603 2621 and 2635 User Manual Contents 7 10 Remote Site Configuration 63 Central site configuration iu 66 68
7. 69 Configuring the router HC 69 Configuring the security imtettaces fos teueded 71 Configuring Security 73 IDeleung a security Policy e d 74 Enabling the Firewalls o datur tete ree 74 Firewall 74 Secun ELE A TASE 75 Intrusion Detection System LDS 78 Inttoductionito NAT OUT 80 Enabling isto en e fatur E E 80 Global address pool and reserved map 80 DHCP and DNS Configuration 82 83 Services and features normally associated with each other 83 DEIGPSSrVel E E E 84 Parameters for the DHCP Server subnet nennen nnne nnne enne nennen nennen 86 IP Addresses to be available on this subnet 87 DNS server option Information ERE 88 Default gateway option information 89 Additional option information elena dedos re tese Dennerle putat Debe pae card 89 DHCP Rehy
8. 96 SN Client Com 104 108 112 Compliance 115 118 Cable 122 Oasi Physical Connector sees 124 Command Line Interface CIL D 129 Contents Summary lable Of conterere E 3 _____________________ _____ ____ _ 4 10 12 About this 13 Audience E 13 SLEUCEUTe eee cde dateien E uiu te eret tetra detener 13 eeu I 14 Safe WREN c ee 222 TET i5 General observalonsauscssiesusuu gp ON EN E E 15 Factory default eet eui Audet e cepe E reU 16 Typographical conventionsiused inm this document eee e T 16 General convent 16 1 17 Onsite Speed Routers 18 General attributes 18 19 Protocol Sup RC REPORT PRERBRERI Ee PS
9. TD 7 Out CTS 8 In RTS Rear panel connectors and switches On the rear panel from left to right are the following OnSite Series High Speed Routers overview 21 Models 2603 2621 and 2635 User Manual 1 General Information Power input connector Ethernet connector e MDI X switch e WAN port V 35 X 21 Power connector AC universal power supply The OnSite Series router offers internal or external AC power supply options The internal power supply connects to an AC source via an IEC 320 connector 100 240 200 mA 50 60 Hz The external power supply connects to an external source providing 5 VDC a barrel type connector 48 VDC power supply The DC power supply connects to a DC source via a terminal block e Rated voltage and current 36 60 VDC 400 mA Connect the equipment to a 36 60 VDC source that is electri cally isolated from AC source 36 60 VDC source is to be reliably connected to earth Ethernet port outlined in green Shielded RJ 45 10Base T 100Base TX Ethernet port using pins 1 2 3 amp 6 See MDI X switch for hub or transceiver configuration The following table defines conditions that occur when the MDI X switch is in the out position Signal Signal Direction Name Pin No Output TX 2 Output TX 3 Input RX 4 5 6 Input RX 7 Z 8 MDI X The MDI X push switch operates as follows Whe
10. on this subnet Start of address range p End of address range Use default range Figure 58 DHCP address pool Start of address range Enter the first IP address to be available in the DHCP IP address pool End of address range Enter the last IP address to be available in the DHCP IP address pool Use a default range Checking this box will give you IP address pool of 20 contiguous addresses This set ting when checked overrides anything entered in the Start and End of address range If you have selected Get subnet from IP interface and have checked the Use a default range the first of the twenty IP addresses will be the next sequential address following the IP address of the IP interface For exam ple assume that the IP address of ip1 is 10 10 19 10 16 figure 59 shows that the IP address pool ranges from 10 10 19 11 to 10 10 19 30 Introduction 87 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Parameters for this subnet Edit the definition of the DHCP subnet here If you do not wish to specify the subnet value and subr instead select an interface using the Get subnet from IP interface field The subnet will track the mask belonging to the chosen IP interface 10 Subnet value Subnet mask 55 Get subnet from IP interface lip Maximum lease time 7 seconds Default lease time 4320 7 seconds IP addresses to be
11. You can see the status of the PPP link by going to the PPP web page and paging down until you see the Summary description To get to the Edit PPP web page follow this path Services Configuration WAN Edit gt Edit LMI Management Frame Relay links LMI Configuration Frame Relay Local Management Interface The Frame Relay Local Management Interface LMI is a mech anism that two separate frame relay systems can use to communicate the status of the interface The LMI inter face allows dynamic updates on the status of the DLCI connections and the congestion state of the network The OnSite implements all three versions of LMI available within the frame relay network These are defined in table 3 Table 3 LMI Implementation on the OnSite Protocol Specification Options Available LMI Frame Relay Forum Implementation Agreement User Side IA FRF 1 superseded by FRF 1 1 Annex D ANSI T1 617 User Side Annex A ITU Q 933 referenced in FRF 1 1 User Side Note uses DLCI 0 but ANSI CCITT has also reserved 1 15 Best practice per the recommendation is to use only DLCIs 16 991 for FR data PVCs and DLCIs 0 15 for LMI PVCs WAN Service Configuration 58 Models 2603 2621 and 2635 User Manual 6 WAN Services LMI Configuration Options The Frame Relay Local Management Interface is configurable through either the CLI or web interface on the OnSite Series The following variables are ava
12. 89 Configuration of the DHCP Relay iicet totae troi 89 DNS Relay iani enean na eek aa ERR Paten de eae eee 91 Configuring the DNS Relay 44 eite tpe ie tette eet 91 DP SCEVICES e 93 P Services PP 94 WEB 94 CLI s eeu nere ENDURO HEIDI ERU HEU 94 Associated Ports for the different System IP Services 95 System Configuration 96 Introduction s cese ementi rre rire eet EE EE coves ENSE REP 97 Authentication 97 3 98 Remote 99 M 100 100 hrec 100 O 101 Contents Models 2603 2621 and 2635 User Manual 11 12 13 Website INDORE 101 E 102
13. Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRF 12 If this variable is set to 0 then FRF 12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf For bridged applications the port should be set to fr 9 Click on the Create button 10 Click on System Configuration gt IP Routes gt Create new Ip V4 Route 11 Create the gateway to the remote OnSite by entering the WAN IP address of the remote OnSite in this example enter 192 168 164 3 the Gateway field The other fields should be Destination 0 0 0 0 e Gateway 192 168 164 2 e Mask 0 0 0 0 e Cost 1 Interface frame 0 12 Click on the Update button This concludes the configuration of the remote site Be sure to save the configuration in non volatile memory by System Configuration gt Save gt Click on Save in the main window WAN Service Configuration 67 Chapter7 Security Chapter contents serie teeny err eer eter ee esce ide es eec 69 69 Configuring the security 71 Policies trae
14. The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability e Model 2603 router see Installing an interface cable on the OnSite 2603 s T1 E1 interface port on page 29 Model 2621 router see Installing an interface cable on the OnSite 2621 s X 21 interface port on page 31 Model 2635 router see Installing an interface cable on the OnSite 2635 s V 35 interface port on page 33 Hardware installation 23 Models 2603 2621 and 2635 User Manual Initial Configuration Installing an interface cable on the OnSite 2603 s T1 E1 interface port The OnSite Models 2603 K and 2603 T come with a selectable T1 E1 WAN interface see figure 4 Located on the back of the OnSite the T1 and El interfaces are presented on an RJ 48C connector with selectable line impedances of 100 ohms for and 120 ohms for 1 lines see figure 5 The 2603 K also comes with dual BNC for alternate connection to unbalanced 75 ohm 1 lines see figure 6 on page 30 The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability Crossover MDI X RX IX
15. true To configure it for 10BaseT operation at all times set to false Introduction 42 Models 2603 2621 2635 User Manual 4 Ethernet LAN Port Full Duplex Mode the default value is true for Full Duplex operation Setting it to false configures the Ethernet port to operate only in half duplex mode Rarely do these parameters require a change from their default operation Introduction Auto Negotiation Auto Negotiate Restart Connected Dis Reconnect Count Enable Duplex Check Full Duplex Jabber Jabber Count Link Speed 100 Mode Full Duplex Mode Remote100BTFD Remote100BTHD Remote10BTFD Remote10BTHD Remote Fault Remote Fault Count Update Reset Clear ifEntry true false true 14 true false false 100000 true false false false false true false Figure 20 Configurable Ethernet parameters 43 Chapter5 Serial Port Configuration Chapter contents 45 EO 45 45 ae E IER REM 46 TWEL T terbace 46 Conneunne the l Blink Seres 2603 09 M Operation 525 47 47 Cantigurine the Line Series ty cer o 2 2 48 48 44 Models 2603 2621 and 2635 User Manual 5 Serial Port Configuration WAN Serial
16. 1 Clickon IP routes under Services Configuration in the Configuration Menu 2 Clickon Create new Ip route hyperlink Configuring the router 70 Models 2603 2621 and 2635 User Manual 7 Security Enter 192 168 101 2 in the box adjacent to Gateway Leave Destination and Netmask both as 0 0 0 0 because this is the gateway default route Click on the Update button BO Seeing the green check mark under Valid indicates IP addresses of the WAN service and the gateway are properly configured See figure 43 Edit Routes Existing Routes Valid Destination Gateway Netmask Delete 0000 192 168 101 2 0 0 0 0 Update Reset Figure 43 Valid gateway route Configuring the security interfaces The interfaces and routes have been configured on the OnSite Router The Ethernet side of the OnSite router will be configured to be an internal interface and the WAN side is selected to be the external interface since it is on public side of the modem connection 1 Go to the Security Interface Configuration webpage as follows Configuration Menu gt Services Configu ration gt Security See figure 44 Configuring the security interfaces 71 Models 2603 2621 and 2635 User Manual 7 Security Security Interface Configuration Security State Security Enabled Disabled Firewall Disabled Intrusion Detection Enabled Disabled Change State Security Level Security Level
17. Idle Codes Enabled Power Down Normal ____ Configure and Activate Figure 24 configuration WAN Serial Port Configuration 47 Models 2603 2621 and 2635 User Manual 5 Serial Port Configuration Time Slot Select For a T1 using all 24 time slots enter 1 24 for fractional T1 enter in any format for example 1 2 3 5 or 1 5 10 24 Any entry for timeslots above 24 will return an invalid selection message Line Options Fractional T1 Line Code The 2603 uses B8Zs and AMI B8Zs is the most widely used Line Build Out Select from 100 04 100 Ohm 7 5dB 100 Ohm 15dB and 22 5dB For CSU DSU application use 100 OdB option consult your T1 service provider for more information FDL Mode Options are ANSI T1 403 and Fdl none Consult your T1 service provider if FDL is active on your T1 link Clocking Mode Internal Receive Clock network In most applications clocking for the 2603 will be derived from the T1 network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Enabled Disabled When enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Normal Powered Down When powered down T1 E1 transceiver input and output lines will set to high impedance to protect the device set unit to Normal for regular operation After all options have been selected click on the Con
18. Models 2603 2621 2635 OnSite Series High Speed Routers User Manual Model 2635 WA Crossover Ethernet X21 Important This is a Class A device and is intended for use in a light industrial environment It is not intended nor approved for use in an industrial or residential environment Sales Office 1 301 975 1000 Technical Support 1 301 975 1007 E mail support patton com WWW www patton com Document Number 03328U1 001 Rev C Part Number O7M2600Ser GS Patton Electronics Company Inc 7622 Rickenbacker Drive Gaithersburg MD 20879 USA Tel 1 301 975 1000 Fax 1 301 869 9293 Support 1 301 975 1007 Web www patton com E mail support patton com Copyright 2012 Patton Electronics Company All rights reserved The information in this document is subject to change without notice Patton Elec tronics assumes no liability for errors that may appear in this document Warranty Information The software described in this document is furnished under a license and may be used or copied only in accordance with the terms of such license Patton Electronics warrants all OnSite Series router components to be free from defects and will at our option repair or replace the product should it fail within one year from the first date of the shipment This warranty is limited to defects in workmanship or materials and does not cover customer damage abuse or unautho
19. T1 E1 Yellow Alarm Minor 00 00 00s 0 Generate Clear Reset ALL Alarms ALL Alarms 4 T1 E1 Red Alarm Minor 00 00 00s Figure 70 Alarm Management web page All OnSites have the PP over Threshold and NP over Threshold alarms The Model 2603 has additional alarms for the T1 E1 WAN port An alarm be tested by clicking on the Generate button Similarly by clicking on the Clear button the alarm is cleared that is turned off however the Time and Count parameters Alarm 98 Models 2603 2621 and 2635 User Manual 10 System Configuration remain Only by clicking on the Reset button can you clear the alarm and reset the Time and Count parame ters The parameter definitions are e Alarm Severity there are five categories of severity Critical Major Minor Informational and Ignore Time the time that the last alarm occurred Count the number of instances the alarm has occurred To configure the severity of each alarm and to configure the Alarm Error Log click on Modify Alarms to reach the webpage See figure 71 Alarm Error Log Reporting Log Severity Level Major Log Alarm State Update Alarm Table ID Alarm Name Alarm Severity Update Alarm 1 PP Over Threshold Major Update 2 Over Threshold Major Update 3 Loss of Signal Major Update 4 T1 E1 Red Alarm Minor Update
20. entes ce e eene ee e 37 Web Operation and Configuration ede nieete 37 PC Configuration E 37 Web Browser 37 4 Ethernet LAN Port 40 Inttoductioh t thei naan ieee 41 LAN 41 41 5 Serial Port Configuration scscssssssssssssssssssscsssssscsssssssssssessscosssesessessessssenssssssssssessssesssesssssssassessesesseeseseass 44 WAN Serial Port Configuration P EROR Hore E etra ge Deere eet dS Eee ep ede sait e 45 Serial TAterface rin Dust ttti cats 45 qq 45 Web Interface Configuration 46 TUET Interface Configuration pte ERI me Pe 46 Configuring the OnSite Series 2603 for Operation 47 E 47 Configuring the OnSite Series 2603 for E1 Operation 48 Web Configuratio em 48 6 WAN 50 WAN SERVICES 51 Configuring the OnSite Series 2603 for E1 Operation
21. writing to the SNMP variables or limited to a read only function To delete an entry click on the Del box and click on the Update button Error Log 102 Models 2603 2621 and 2635 User Manual 10 System Configuration SNMP Daemon Settings This allows the user to modify the SNMP settings for this unit Static Variables System Description 2603 Single Port Router System Location 1 System Contact 0 00 System Name 4425 Update Community Table Index Password Management IP Access Del 1 secret 10 10 22 45 Write v Update NEW 0000 Write Create Trap Table Index Password Management IP Del NEWT Create Save SNMP Configuration gt Figure 79 SNMP Daemon configuration The Trap Table identifies the IP address of the SNMP trap along with its password System Tools The System Tools webpage provides two utilities for testing network connectivity The two utilities are ping and traceroute Enter the IP address of the device to ping or traceroute and click the appropriate button The example in shows a successful ping of a PC System Tools This page gives the user access to system tools Ping and Traceroute Controls This allows the box to initiate a Ping or Traceroute request Note that input must be an IP address in the form XXX XXX XXX XXxX 10 10 22 45 Ping Trace Route PING 10 10 22 45 32 data bytes 40 bytes from 10 1
22. 92 DNS Relays contiptiralon completed 2 222 d dore unde RU eden pss dU trn 92 System Services configurati n web page PORA E 94 Authentication web pase showing default supertiser esee dod eria 97 Creating DEW USEE M P 98 Alim Management WEB DIBES saco abr bp es ted S Tg edid S 98 Alarm amp Alarm Error Log configuration __________ 99 Remote Access Telnet access limit 99 Updating SOftWake emm e bee mee ee 100 Save configuration changes in non volatile memory 100 Saving or reloading previously saved configuration files 101 Restanmne to factory cnc quoda os 101 Webpage refresh rates d mdr 101 Eitor Logand Syslog SetUDES 102 SNMP __________________ 103 Pine dnd Traceroute POP GA Pob oque gest qudd er udi Rs 103 SNTP synchronization and server IP a
23. RJ 45 non shielded RS 232 console port EIA 561 The RS 232 serial control port of the OnSite is configured to operate as a DCE Table 8 RS 232 Control Port Pin No Signal Name Direction DSR from OnSite 2 CD from OnSite 3 DTR to OnSite 4 Signal Ground 5 RD from OnSite 6 TD to OnSite 7 CTS from OnSite 8 RTS to OnSite RJ 45 shielded 10 100 Ethernet port 125 Models 2603 2621 and 2635 User Manual D OnSite Physical Connectors Serial port V 35 M 34 and DB 25 Connector The Model 2635 has a DB 25 connector for the V 35 interface table 9 provides the pinouts for the M 34 and DB 25 connectors Table 9 V 35 pinout for M 34 amp DB 25 connectors M 34 DB 25 Signal Name Direction Pin No Pin No A Frame Chassis n a Ground P 2 TD a from DTE R 3 RD a to DTE 4 5 from DTE D 5 CTS to DTE E 6 DSR to DTE B 7 Signal Ground n a F 8 to DTE X 9 RC b to DTE 10 W 11 XTC b from DTE AA 12 TC b to DTE 13 5 14 TD b from DTE Y 15 TC a to DTE T 16 RD b to DTE V 17 RC a to DTE L 18 Local Loopback to DTE 19 H 20 DTR from DTE N 21 Remote Loopback to DTE 22 23 0 24 XTC a from DTE M 25 Test Mode to DTE Serial port 126 Models 2603 2621 and 2635 User Manual OnSite Physical Connectors 21 DB 15 Connector The X 21 interface in the Model 2621 may be configured for either DTE or DCE Default is DCE Table
24. TI E1 Yellow Alarm Minor Update Figure 71 Alarm amp Alarm Error Log configuration The Alarm Error Log can be enabled or disabled The severity level of the Alarm Log can also be configured Similarly each alarm can be set for its own severity level Remote Access The OnSite can be accessed via Telnet known as Remote Access The length of access over a remote connec tion is set on this webpage If set for zero 0 no user can access the OnSite remotely However if a user is authorized for access then the time is the limit before the remote access session is closed Remote Access From this page you may temporarily permit remote administration of this network device Enable Remote Access Allow access for minutes Enable Figure 72 Remote Access Telnet access limit Remote Access 99 Models 2603 2621 2635 User Manual 10 System Configuration Update To upgrade the OnSite to another software version select the software image by clicking on the Browse but ton The software is tar file See figure 73 After selected the software is downloaded to the OnSite Wait until the upload has completed The best way to monitor when the OnSite reboots is to view the process from the RS 232 console port Firmware Update From this page you may update the system software o Select Update File Updates where available may be obtained from Patton Electronics Company New Firmware Im
25. Table 2 Status LED descriptions Continued T1 E1 Link Green Solid green connected Off disconnected LOS Red On indicates a T1 E1 loss of frame condition It also indicates that no T1 E1 signal is detected TD Green Green indicates a binary O condition off indicates a binary 1 or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition Sync Serial Green Green indicates a binary 0 condition off indicates a binary 1 or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition CTS Green ON indicates the CTS signal from the router is active binary 1 off indicates CTS is binary O DTR Green ON indicates the DTR signal from the DTE device attached to the serial port is active binary 1 Ethernet Link Green ON indicates an active 10 100 Base T connec tion 100M Green ON connected to a 100BaseT LAN Off connected to a 10BaseT LAN Tx Green Flashing when transmitting data from the router to the Ethernet Rx Green Flashing when transmitting data from the Ether net to the router Console port Located on the front panel the unshielded RJ 45 RS 232 console DCE port EIA 561 with the pin out listed in the following table Signal Signal Rin No Direction 1 DSR 2 Out CD 3 DTR 4 Signal Ground 5 Out RD 6
26. The 21 port is now configured as a DCE Note When the X 21 port is configured as a DTE the clocking mode for the port must be set for external clock Hardware installation 32 Models 2603 2621 and 2635 User Manual Initial Configuration 4 Re assemble the case The interface cable has been installed go to section Installing the AC power cord on page 34 Installing an interface cable on the OnSite 26355 V 35 interface port The OnSite Model 2635 comes with a V 35 interface presented on a DB 25 female connector see figure 10 The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability The Model 2635 V 35 DB 25 interface is configured internally as a DCE However when using the Patton cable with the 2635 the V 35 interface at the M 34 end of the cable is a DTE see figure 11 In other words the Patton DB 25 to M 34 cable is a sync null modem cable Ethernet connector V 35 Interface connector RJ 45 DB 25 10 100 9 099900000000 5 MDI X Power Ethernet V 35 Interface Hardware installation 33 Models 2603 2621 and 2635 User Manual Initial Configuration Note The OnSite comes with a V 35 cable configured as a tail circuit Use this cable to
27. This application shows configuration for two OnSite units in PPP routed mode An OnSite may be used as the router at the Central site but it is not necessary You can use a third party router as long as it supports PPP routed operation If using a third party router at the Central site review the router s configuration See figure 29 Remote site configuration First configure the IP address on the Ethernet port interface ip1 for 192 168 200 2 24 via the command line CLI The PC will be on the same subnet as the OnSite Ethernet port Once this is done you can complete the configuration using the web pages Figure 29 PPP Routed Application 1 Bring up the web page management system on your browser by entering the IP address of the OnSite 2 On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined WAN Service Configuration 54 Models 2603 2621 and 2635 User Manual 6 WAN Services 3 Click on Create a new service in the main window select PPP routed and click on the Continue button In the Description field enter the description you wish In this example it is called PPP Routed Description PPP Routed Interface 1 WAN IP address 192 168 164 2 255 255 255 255 LLC Header Mode off HDLC Header Mode ON No authentication Username blank Password blank WAN connection PPP routed Description PPProuted 0 Interface WAN a
28. Warranty coverage 113 114 Returns Beara eke 114 forcredit 114 rore ttr te o PR Tad e 114 Shipping Instr ctloDs ueste tesi tiere ttov rere EE 114 Compliance information RR H 115 Cobia anne soos EUR 116 le 116 Mim mE 116 PSION be 116 Radio and TV Interference Part 15 cccccscssccsscssscsscssscsscessesscetcsscesscssscsscssecssesseessesseessesseessessscsasensesasenseegs 116 Declaration of 116 Authorized European R epr sentative eu ge 117 Specifications m 118 General Ch racteristicsu ii ere tette iie etd den Dod it tede turae RI ders 119 ur e M 119 Sync Serial Interface 119 Models 2603 2621 and 2635 User Manual Contents OU We
29. ensure that at end of life you separate this product from other waste and scrap and deliver to the WEEE collection system in your country for recycling General observations e Clean the case with a soft slightly moist anti static cloth Place the unit on a flat surface and ensure air circulation Avoid exposing the unit to direct sunlight and other heat sources Protect the unit from moisture vapors and corrosive liquids 15 Models 2603 2621 and 2635 User Manual About this guide Factory default parameters OnSite Series High Speed Routers have the following factory default parameters Ethernet IP address 192 168 200 10 24 WAN Connection PPP Bridged e Ethernet and serial connections MDI LAN connector Model 2621 X 21 DB 15 port DTE Model 2635 V 35 DB 25 port DCE DTE when using special V 35 cable Model 2603 T T1 configuration RJ 48C 100 ohm interface e Model 2603 K E1 configuration RJ 48C 120 ohm and dual BNC interface 75 ohm Typographical conventions used in this document This section describes the typographical conventions and terms used in this guide General conventions The procedures described in this manual use the following text conventions Table 1 General conventions Convention Meaning Indicates a cross reference hyperlink that points to a figure graphic table or sec tion heading Clicking on the hyperlink jumps you to the refere
30. 12345678 Figure 5 RJ 48C pinout diagram Hardware installation 29 Models 2603 2621 and 2635 User Manual Initial Configuration RX connector connector BNC BNC 10 100 Crossover Power MDI X Ethernet WAN WAN connector RJ 48C Ethernet connector 0 45 Figure 6 Rear view of the 2603 K showing location of Ethernet and WAN connectors The interface cable has been installed go to section Installing the AC power cord on page 34 Hardware installation 30 Models 2603 2621 and 2635 User Manual Initial Configuration Installing an interface cable on the OnSite 2621 s X 21 interface port The OnSite Model 2621 comes with an X 21 interface presented on a female DB 15 connector see figure 7 This interface can be configured as a DTE factory default or as a DCE via internal configuration jumper The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability Ethernet connector X 21 Interface connector RJ 45 DB 15 10 100 Crossover MDI X Power Ethernet X 21 Interface Figure 7 Rear view of the 2621 showing location of Ethernet and X 21 connectors Hardware insta
31. 2635 User Manual Status LEDs 12 System Status The LEDs indicate the status of the Power the WAN Sync Serial port and the Ethernet connection All LED indicators will present the same looking profile e g clear when unlit due to being single color water clear high efficiency LEDs Table 6 Status LED descriptions Power Green ON indicates that power is applied Off indi cates that no power is applied Link Green Solid green connected Off disconnected TD Green Green indicates a binary O condition off indicates a binary l or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition Sync Serial Green Green indicates a binary 0 condition off indicates a binary l or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition CTS Green ON indicates the CTS signal from the router is active binary 1 off indicates CTS is binary 0 DTR Green ON indicates the DTR signal from the DTE device attached to the serial port is active binary 1 Ethernet Link Green ON indicates an active 10 100 BaseT tion 100M Green ON connected to a 100BaseT LAN Off connected to a 10BaseT LAN Tx Green Flashing when transmitting data from the router to the Ethernet Rx Green Flashing when transmitting data from the Ether net to the router Status L
32. 826 P router with RIP RFC 1058 RIPv2 2453 Up to 64 static routes Built in ping and traceroute facilities Integrated DHCP server 2131 DHCP relay agent 2132 RFC 1542 with 8 individual address pools e DNS relay with primary and secondary name server selection NAT 3022 with network address port translation MultiNat with 1 1 Many 1 Many Many mapping Port IP redirection and mapping Frame Relay with Annex A D LMI 1490 and FRF 12 Fragmentation Support Point to point protocol over HDLC PPPoE RFC 2516 Client for autonomous network connection Eliminates the requirement of installing client software on a local PC and allows sharing of the connection across a LAN User configurable PPP PAP RFC 1661 or CHAP 1994 authentication WAN Interfaces e T1 E1 V 35 or X 21 interfaces Available with female RJ 48C dual BNC DB 25 and DB 15 connectors User configurable DTE DCE for 21 Management e User selectable HDLC or Frame Relay WAN datalink connection e Web Based configuration via embedded web server CLI menu for configuration management and diagnostics Local Remote CLI VT 100 or Telnet e SNMPvI 1157 MIB II RFC 1213 OnSite Series High Speed Routers overview 19 Models 2603 2621 and 2635 User Manual 1 General Information Logging via SYSLOG and VT 100 console Console port set at 960
33. 9 IP Services IP Services Certain System Services be enabled or disabled They are DNS Relay FTP TFTP SNMP and the WEB Server The importance of disabling any of these services is an issue of security If you are not using a particular service it is best to disable it By disabling it the associated port is not active which means it is not available to abuse with the intent of unauthorized access IP Services This allows the user to System Services DNS Relay Enabled FTP Enabled Enabled SNMP Enabled WEB Serer Update Figure 67 System Services configuration web page WEB Server The System Service which must be wisely disabled is the WEB Server After you disable the WEB Server from the web page you can no longer access the any of the OnSite s web pages The only way to enable it is through the Command Line Interface CLI CLI Configuration After configuring a terminal emulator to access the OnSite s serial port there are two commands for the enabling or disabling the WEB Server The following command enables the WEB Server so you can access the management web pages via a browser Remember that by only doing this command the change is saved only in volatile memory Be sure to execute the next command to save it in non volatile memory fi webserver enable fi system config save next command disables the WEB server fi webser
34. Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRF 12 If this variable is set to 0 then FRF 12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to for bridged applications the port should be set to fr Click on the Create button Edit Frame Relay Edit Frame Relay Channel Edit Frame Relay Channel Options Name Value Dici 21 Encaps Type BridgedEther Rx Pdu 127 Tx Pdu paso Chnl Segment Size Port Port Class framerelay Create Reset Figure 36 Frame Relay Channel configuration Central site configuration Note Ifyou are using a OnSite at the Central location follow the instructions below otherwise refer to your third party router documentation for configu ration See the web pages for the OnSite above Some parametric values will differ but the process remains the same First configure the IP address of the Ethernet port interface ip1 via the command line CLI for 192 168 172 3 24 The PC IP address 192 168 172 229 must be on the same subnet for configuring the OnSite via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the OnSite 2
35. Log webpage shows recent configuration errors and provides for the configuration of the Syslog See figure 78 Two parameters are configurable for the Syslog Syslog Host enter the IP address of the Syslog Default 0 0 0 0 e Syslog Facility select the type of syslog facility Default disabled s Click on the Update button to activate the selected parameters Default value is a disabled Syslog Error log This page shows recent configuration errors from your router Syslog Settings Syslog Host 0 0 0 0 Syslog Facility disable Update Error log most recent errors last times are in seconds since last reboot When Process Error 1072915200 im Invalid argument failed to the SNTP host to 1072915201 alarm alarm Box State Change to Minor Figure 78 Error Log and Syslog Settings SNMP Daemon For remote management from an SNMP capable management station the OnSite s SNMP Daemon must be configured To identify a specific OnSite configure the Static Variables which the system administrator may use for link identification The Community Table has three configurable parameters e Password this is the password which the remote management station must use to access the OnSite for reading writing the SNMP variables Management IP the IP address of the management station Access select either Write or Read The management station can be authorized to configure the OnSite by
36. On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create new service in the main window select Frame Relay bridged and click on Continue WAN Service Configuration 62 Models 2603 2621 and 2635 User Manual 6 WAN Services 4 Enter the description for the circuit in the Description field This 15 a mandatory field Without a descrip tion you cannot create a WAN service 5 Click on Create a new service in the main window select Frame relay bridged and click on the Configure button 6 Click along the following path Services Configuration gt WAN gt Edit Then click on Edit Frame Relay Channel The configurable parameters are Consult with your service provider for the DLCI number required Encapsulation type Bridged Ether Defines the 1490 encapsulation type to be used the channel In some instances you may need to choose another type Consult your service provider RX Max PDU 8192 Receive side max PDU default 8192 normally not changed from default Max PDU 8192 Transmit side max PDU default 8192 normally not changed from default Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRF 12 If this variable is set to 0 then FRF 12 Frame Relay Fragmentation will be disabled if set to any other value it will set
37. Set Inbound as Block but Outbound as Allow See figure 51 5 Click on Create Firewall Add TCP Port Filter external internal Transport Port Range Direction Type Start End Inbound Outbound e Figure 51 Configuring TCP port filter for FTP After configuring the FTP portfilter you can open an ftp session from Remote to Local however you can issue ftp commands e g login cd etc Because the trigger to permit transfer of data via FTP has not been defined no data can be transferred Data transfer occurs with the commands ls dir get put commands The portfilter allows an ftp control channel but does not allow the use of a secondary data channel for passing data by ftp To enable the FTP data channel add a trigger to open a secondary channel only when data is being passed This minimizes the number of open ports Each open port is a security risk 1 From the Configuration Menu gt Configuration gt Security gt Security Trigger Configuration gt New Trig ger 2 Set the parameters as follows See figure 52 Transport Type tcp Port Number Start 21 Port Number End 21 Allow Multiple Hosts Block Max Activity Interval 3000 Enable Session Chaining Block Enable UDP Session Chaining Block Binary Address Replacement Block Address Translation Type none 3 Click on Create Security Triggers 76 Models 2603 26
38. The maximum value is 30 minutes SNTP Client General Configuration Parameters Current Timezone 4 UTC GMT time US Eastern Standard 5h M Set New Timezone Enter new SNTP transmit packet timeout value seconds 5 Enter new SNTP transmit packet retries value Enter new SNTP automatic resynchronization polling value minutes New Values Figure 82 Timezone and Polling packet configuration System Clock Setting If you are not using a Stratum clock with the SNTP feature you can still configure the internal system clock for a calendar date and time This parameter is on the same web page as the SNTP Client configuration The format is lt Year 4 digits gt lt Month 2 digits gt lt Day 2 digits gt lt Hour 2 digits gt lt Minutes 2 digits gt lt Seconds 2 digits gt The example in figure 83 is set for January 26 2006 at 1 57 50 pm System Clock Setting 106 Models 2603 2621 and 2635 User Manual 11 SNTP Client Configuration Clock Setting Set the system clock yyyy mm dd hh mm ss format 2006 01 26 13 57 50 Set Clock Figure 83 Configuration of the internal system calendar clock After entering the system clock values click on the Set Clock button to save in volatile memory If the OnSite is rebooted either soft or by power cycling the Clock Setting returns to its default value System Clock Setting 107 Chapter 12 System Status Chapter contents
39. Value Update Figure 34 LMI Configuration webpage Frame Relay Configuration The Frame Relay service can be configured for either bridged or routed applications The use of DLCI values since the original publication of the Frame Relay specifications has been modified as to their use For the two octet address format they are as follows DLCI Number Use 0 Used for in channel signaling 1 15 Reserved 16 991 Assigned using Frame Relay connection procedures Verify that none of these values have been assigned to permanent frame relay cells 992 1007 Layer 2 management of FR bearer service 1008 1022 Reserved 1023 Used for in channel layer management WAN Service Configuration 60 Models 2603 2621 and 2635 User Manual 6 WAN Services Frame Relay bridged This application shows configuration for two OnSite units in bridged mode If using a third party router at the Central site review the router s configuration for connection to a remote bridge Remote Site Configuration First configure the IP address of the Ethernet port interface ip1 via the command line CLI for 192 168 200 2 24 The PC must be on the same subnet for configuring the OnSite via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the OnSite 2 On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined C
40. a Bridged WAN service the DHCP server must be on the same subnet as the clients and the OnSite DHCP Server Go to the DHCP Server webpage from the Configuration Menu gt Services Configuration gt DHCP Server The DHCP server default is disabled Click on the Enable button to begin the configuration process Introduction 84 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Patton Home Page Home System Status gt System Configuration V Services Configuration LAN WAN LMI Management routes DHCP server DHCP relay DNS relay Services Security SNTP chent 2 25 z 2 E gt 2 N DHCP Server This page allows creation of DHCP server subnets and DHCP server fixed host mappings You may also enable and disable the DHCP server from here The DHCP server is currently disabled Enable Server Status There are currently no DHCP server subnets defined Create new Subnet O Help There are currently no DHCP server fixed IP MAC mappings defined Create new Fixed Host O Figure 55 DHCP Server web page The server needs to have a subnet of IP addresses which will be allocated when a DHCP client makes a request Define the subnet by clicking on the hyperlink Create new Subnet The next webpage Create new DHCP Server subnet has four sections Parameters for this subnet defines the subne
41. click on Change State 2 Click on Configure Intrusion Detection 3 You may choose which of the parameters to configure and for which value Use Blacklist Default 10 minutes when enabled If IDS has detected an intrusion an external host access to the network is denied for ten minutes Use Victim Protection Default Disabled Victim Protection When enabled Victim Protection protects the victim from an attempted spoofing attack Web spoofing allows an attacker to create a shadow copy of the world wide web WWW All access to the shadow Web goes through the attacker s machine so the attacker can monitor all of the victim s activities and send false data to or from the victim s machine When enabled packets destined for the victim host of a spook ing style attack are blocked Victim Protection Block Duration Default 600 seconds DOS Attack Block Duration Default 1800 seconds 30 minutes A Denial of Service DOS attack is an attempt by an attacker to prevent legitimate users from using a service If a DOS attack is detected all suspicious hosts are blocked by the firewall a set time limit Scan Attack Block Duration Default 86400 seconds Sets the duration for blocking all suspicious hosts The firewall detects when the system is being scanned by a suspicious host attempting to identify any open ports Intrusion Detection System IDS 78 Models 2603 2621 and 2635 User Manual 7 S
42. ee dea UU 73 Deleting a secun 74 Me pue 74 ee RETO E 74 e roin MID cT 5 Derce on ATIS ed erate cere terre utere etc Me 78 Introduction to NAT ER 80 NOUIS ecce eer 80 Globalvadatness and teserved RU E Cae MEAT 80 68 Models 2603 2621 and 2635 User Manual 7 Security Introduction Security provides the ability to setup and enforce security policies The policies define the types of traffic per mitted to pass through a gateway either inbound outbound or both and from which origins the traffic may be allowed to enter Within the security configuration is a stateful firewall A stateful firewall utilizes a security mechanism to main tain information concerning the packets it receives This information is used for deciding dynamically whether or not a packet may pass through Port filters are rules that determine how a packet should be handled The rules define the protocol type the range of source and destination port numbers and an indication whether the packet is allowed or not Security triggers are used with applications that require and create separate sessions The most common exam ple is FTP An FTP client establishes a connection to a server using p
43. enable disable the Alarm Error Log Remote Access enable and set the time limit for a remote user to have access to the OnSite e Update update the OnSite software from here Save to save the OnSite configuration in non volatile memory Backup Restore used to save the OnSite s configuration on a PC or to load a configuration already saved on a Restart to do a soft start of the OnSite or to restore the OnSite to factory defaults Key the key version is used to identify which features are installed in the OnSite e Website Settings configures the refresh rate of the web pages Error Log displays the Syslog Settings and shows recent configuration errors from the OnSite SNMP Daemon to modify the SNMP parameters for the OnSite Tools provides ping and traceroute commands from the OnSite Also used to clear the interface table counters Authentication The OnSite manager controls access to the OnSite s console and web pages The default defined user is supe ruser See figure 68 Authentication This page allows you to control access to your router s console and these configuration web pages Currently Defined Users User May Configure Authenticate Remote End Comment superuser true false Default admin user Edit user Create new user Figure 68 Authentication web page showing default superuser The superuser is the default administrative user and i
44. interconnect the OnSite s V 35 port to a device configured as a DCE Modem a gt Use cable provided DCE with 2635 IPLink OM Figure 11 Connecting 2635 to a DCE device The serial port on the OnSite Model 2635 is configured as a DCE it connects directly to a DTE using a stan dard straight through V 35 cable However in many applications the OnSite s V 35 interface will connect to a DCE modem or multiplexer in this situation use the special cable provided with your Model 2635 This DB 25 M35 cable presents the 2635 s V 35 interface as a DTE for direct connection to a DCE see figure 11 Installing the AC power cord The OnSite router comes with an internal or external power supply This section describes installing the power cord into the OnSite router Do the following The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability Note Do not connect the other end of the power cord to the power outlet at this time 1 If your unit is equipped with an internal power supply go to step 2 Otherwise insert the barrel type con nector end of the AC power cord into the external power supply connector see figure 12 2 Insert the female end of the AC power cord into the internal power supply connector see figure 12 Hardware in
45. n a Enable Firewall to set level Security Interfaces There are currently no Interfaces defined interfaces must be defined and Security enabled to configure Add Interface Policies Triggers and Intrusion Detection Security Policy Configuration y Q Why cant I configure this amQ Why cant configure this Figure 44 Security configuration home page 2 Goto the third section Security Interfaces on the Security Interface Configuration webpage Click on the hyperlink Add interface 3 Select 1 1 beside the Name pull down menu and select internal beside the Interface Type pull down menu Click on Create See figure 45 Security Add Interface New Interface Setup Name gt Interface Type f external Create dmz Return to Interface List Q external Figure 45 Define ip1 interface as Internal 4 click on the hyperlink Add interface to define the WAN interface as external 5 Select 0 beside the Name pull down menu and select external beside the Interface Type pull down menu Click on Create See figure 46 Configuring the security interfaces 72 Models 2603 2621 and 2635 User Manual 7 Security Security Add Interface New Interface Setup Name ppp 0 Interface Type external Create Return to Interface List Q Figure 46 Define 0 interface as External Con
46. or dual BNC 75 ohm connectors The 2603 serial port configuration page appears in figure 23 WAN Serial Port Configuration 46 Models 2603 2621 2635 User Manual Patton Home Page o Home System Status gt System Configuration gt Services Configuration Ethernet 7 TUE Status Co 7 25 2 z 2 e N ation 5 Serial Port Configuration T1 E1 Configuration Configuration Options 1 403 Time Slot Select 1 24 Payload Rate 1536K 24 Line Options I Code Sel o 88 Line Build Out 100 __ FDL Mode Clocking Mode Receive Clock Idle Codes Enabled Power Down Normal Configure and Activate Figure 23 Model 2603 T1 E1 WAN port configuration parameters Configuring the OnSite Series 2603 for Operation Web Configuration Launch Netscape Internet Explorer or similar web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the TI E1 gt Configuration See figure 24 T1 E1 Configuration Configuration Options Time Slot Select 1 24 Payload Rate 1536K 24 Line Options Fractional TIESF ____ Code Sel 825 gt Line Build 100 FDL Mode 1 403 Clocking Mode Receive Clock gt
47. or restore configuration from your computer Backup Configuration Backup configuration to your computer Restore Configuration Restore configuration a previously saved file Configuration File Browse Restore Figure 75 Saving or reloading previously saved configuration files Restart From this webpage you can do a soft reboot of the OnSite or restore the OnSite to factory defaults To restore to factory defaults click on the box for Reset to factory default settings see figure 76 Then click on the Restart button No warning is given before beginning the reboot process You will need to configure the IP address of the Ethernet port again as described in Chapter 3 Initial Configuration Restart Router From this page you may restart your router Restart After restarting please wait for several seconds to let the system come up If you would like to reset all configuration to factory default settings please check the following box Restart Figure 76 Restoring to factory defaults Website Settings The refresh rate of the webpages is a configurable parameter Enter the desired refresh rate in seconds and click on the Update button Default value is 4 seconds See figure 77 Website Settings Refresh Rates Refresh Rate 4 seconds Update Figure 77 Webpage refresh rates Restart 101 Models 2603 2621 and 2635 User Manual 10 System Configuration Error Log The Error
48. premise or branch office and connects to a router or bridge at a ser vice provider location this can be another OnSite router This application shows configuration for two OnSite units in bridged mode If using a third party router at the Central side review the router s configura tion for connection to a remote bridge See figure 27 Remote Central Figure 27 PPP Bridged Application IPlink series Remote First configure the IP address on the Ethernet port interface 1 1 for 192 168 100 2 24 via the command line Once this is done you can complete the configuration using the web pages 1 Bring up the web page management system on your browser by entering the IP address of OnSite 2 Onthe Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create new service in the main window select PPP bridged and click the Configure button WAN Service Configuration 52 Models 2603 2621 and 2635 User Manual 6 WAN Services WAN connection create service Please select the type of service you wish to create Ethernet PPPoE over Ethemet Bridge routed Frame Relay C Frame Relay routed C Frame Relay bridged PPP C PPP routed C PPP bridged Continue gt Figure 28 WAN services options 4 Inthe Description field enter the description you wish This is a mandatory field Without a description you cannot create the WAN service W
49. service provider for DLCI number required Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Choose the encapsulation method best suited for your network needs from the following options Routed IP default value Raw WAN IP address Enter the IP address assigned to the WAN port V 35 X 21 or T1 E1 WAN Service Configuration 66 Models 2603 2621 2635 User Manual 6 WAN Services Enable on this interface In this example leave this option blank Click the Create button 5 6 Go to System Configuration gt WAN gt Edit for Frame Relay Routed service gt Edit TP Interface 7 Enter the WAN IP Address in this example 192 168 164 3 and click on the Create button 8 From the IP Interface web page click on Edit Frame Relay then click on Edit Frame Relay Channel Edit Frame Relay Channel Enter the appropriate information in the following fields Consult with your service provider for the DLCI number required in this example use 45 Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Chose the encapsulation method best suited for your network In this example enter RX Max PDU Enter the number of receive side max PDU in this example it is the default 8192 PDU Enter the number of transmit side max PDU in this example it is the default 8192
50. the DHCP server is enabled or disabled An enabled DHCP server provides IP addresses to DHCP clients attached to the Ethernet port MAC address the MAC address of the Ethernet port WAN Status Displays the basic parameters and status of the WAN port service and a link to the WAN Services configura tion web page IP Address Type indicates whether the IP address of the WAN service is statically assigned or as a DHCP client Default gateway the gateway defined by the Routes submenu item under Services Configuration in the Configuration Menu e Primary DNS DNS client is currently not available Hardware Status The definitions of the parameters are as follows Up Time this is the time since the OnSite was last rebooted either soft or hard power cycle Current Time the time is derived from one of two sources If the OnSite is configured as an SNTP client the time is from an SNTP server If the SNTP client is not configured the time derives from the Clock Set ting as set by the user The Clock Setting is found in the SNTP Client configuration page Version lists the version of the operating software in the OnSite The version information is more detailed than is listed on the Home webpage of the OnSite Set Time a link to the SNTP Client configuration page Defined Interfaces Provides links to operating statistics of the defined interfaces System Status 110 Models 2603 2621 and
51. the first are Cannot be used Must be used e Usually used Use the table like this The feature in this column with the Configured Feature in Column 1 For example 1 The feature DHCP Relay column 2 cannot be used with DHCP Server row 1 column 1 2 The feature Routed column 4 usually is used with DHCP Relay row 2 column 1 Introduction 83 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Table 4 Features and services matrix The feature in this column with Column 1 feature Configured Cannot be Must be acad Usually used be used Rarely used DHCP DHCP Relay Routed Bridged Server NAT DHCP DHCP Server Routed NAT Bridged Relay DNS Relay Routed Bridged DHCP Server or DHCP Relay NAT Bridged Routed DHCP Server DHCP Relay DNS Relay DHCP Cli Routed ent WAN side Static IP Routed WAN side Some comments on figure 4 Routed means a routed WAN service and Bridged means a bridged WAN service DHCP Server and DHCP Relay cannot be used simultaneously NAT can be used only if a Routed WAN service is configured lfa DHCP Server were used with a Bridged WAN service the DHCP server would respond to IP address requests from both interfaces that is the Ethernet and the WAN serial interfaces When NAT is used together with DHCP Relay the WAN service must be routed 3When DHCP Relay is used with
52. 0 22 45 0 128 rtt lt 10ms Figure 80 Ping and Traceroute utilities System Tools 103 Chapter 11 SNTP Client Configuration Chapter contents 105 the SNP Client UOCE 105 SNTP Client Mode Contieuiation Parameters ccce eerte EE 105 106 System Clock Setting 106 104 Models 2603 2621 and 2635 User Manual 11 SNTP Client Configuration Introduction The Simple Network Time Protocol SNTP Client webpage contains the configurable parameters for either setting up the SNTP client or in the abscence of an SNTP server setting the internal clock If you plan the use of an SNTP server you will configure the SNTP Client Mode Configuration Parameters and SNTP Client General Configuration Parameters If you are not accessing an SNTP server you can figure the system clock for a calendar clock setting Configuring the SNTP Client The SNTP Client Mode Configuration Parameters section is for selecting the synchronization mode and entering the IP address of the SNTP Server With the SNTP Client General Configuration Parameters sec tion you will select the time zone and set the transmit packet timeout period retries and polling period SNTP Client Mode Configuration Parameters In this section you configure the synchronization mode and enter the IP address of the SNTP server The OnS
53. 0 bps 8 N 1 settings no flow control Security Packet filtering firewall for controlled access to and from LAN WAN Support for 255 rules in 32 filter sets 16 individual connection profiles DoS Detection protection Intrusion detection Logging of session blocking and intrusion events and Real Time alerts Logging or SMTP on event Password protected system management with a username password for console and virtual terminal Sepa rate user selectable passwords for SNMP RO RW strings Access list determining up to 5 hosts networks which are allowed to access management system SNMP HTTP TELNET Logging or SMTP on events POST POST errors PPP DHCP IP Front Panel Status LEDs and Console Port The OnSite routers have all status LEDs and console port on the front panel of the unit and all other electrical connections are located on the rear panel 10 100 Model 2600 ipLink Gateway High Speed WAN Access Router Console 35 Interface Figure 1 OnSite Series Router Model 2635 shown The status LEDs from left to right are see table 2 for LED descriptions Power Sync Serial TD RD CTS and Ethernet Link 100M Tx and Rx Table 2 Status LED descriptions Power Green ON indicates that power is applied Off indi cates that no power is applied OnSite Series High Speed Routers overview 20 Models 2603 2621 and 2635 User Manual 1 General Information
54. 00 emulation BRRRRRRRRREEMRREERMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMKEKFBBEBEEREE HKIEENMMMM 130 Remote ete e ERR A ERE 130 Using the 130 132 Adding 132 Setting USER PassWOLS 132 cinis nom quete br rU 133 Controlling login access MR 133 Controlling access 133 List of Figures CON KRW mR BR BRR RR US 09 U WH WW 09 Q9 Q9 WN NNN d ON VA O0 OnSite Seres 20 26 TET Applicatiol see ose Oe SUED S won Ve won 26 Rear View of the 2603 T showing location of Ethernet and WAN connectors 29 48 PPP 29 Rear view of the 2603 K showing location of Ethernet and WAN connectors 30 Rear view of the 2621 showing location of Ethernet and X 21 connectors 31 S 32 cs etat R
55. 10 X 21 Interface Model 2621 Pin No Circuit Signal Name Direction Signal Ground or Common Return 2 Transmit from DTE 5 Control a from DTE 4 R Receive Data a to DTE 5 Indication a to DTE 6 5 Signal Timing a to DTE 7 8 Common Return 9 Transmit Data a from DTE 10 Control b from DTE 11 R Receive Data b to DTE 12 Indication b to DTE 13 5 Signal Timing b to DTE 14 15 1 Frame Ground Tronsmit B 9 2 Transmit e owl does 4 Receive A Indication B 12 5 Indication A Signal Timng B 13 al Tinin M 6 Signal Timing A 7 E 8 Signal Ground Figure 85 21 DB 15 connector Serial port 127 Models 2603 2621 and 2635 User Manual D OnSite Physical Connectors RJ 48C Connector The T1 E1 transmit signals not polarity sensitive even though they have the traditional designation of Tip and Ring Table 11 T1 E1 Port Pin No Signal Receive Ring Receive Tip Shield Receive Transmit Ring Transmit Tip Shield Transmit 69 RX T TX 12345678 Figure 86 T1 E1 RJ 48C connector Serial port 128 Appendix Command Line Interface CLI Operation Chapter contents 130 yl aera VG EE 130 tb D eer ER EO 130 130
56. 19 PPP Sup p Ot 19 E a Te E 19 Manasement d 19 20 Hront Ranel Status LEDs and Console 20 21 Rear panel commectors and 21 Poet CODBeCtOI 22 universal power supply OIM IGI 22 6 E po Ethernetport outlined 22 que E 22 DRI UTOR ITE 24 eee EPIS EPUM ERE UE e eMe T EE ERES 25 Applications EH EUER NEUES 26 27 Padwa 28 28 N 28 Installing an interface cable on the OnSite 260375 interface port 29 Installing an interface cable on the OnSite 262175 X 21 interface 31 Contents Models 2603 2621 and 2635 User Manual Installing an interface cable on the OnSite 2635 s V 35 interface 33 Installing the AC power cord 34 Installing the Ethernet neret orte 36 IP address modification
57. 21 and 2635 User Manual 7 Security Security Add Trigger Transport Port Port Allow Max Enable Enable Binary Address Type Number Number Multiple Activity Session UDP Address Translation Start End Hosts Interval Chaining Session Replacement Type Chaining 21 1 Block gt Block Create Figure 52 Adding trigger for FTP data transfer You should now be able to use FTP commands to pass data between Remote and Local Security Triggers 77 Models 2603 2621 and 2635 User Manual 7 Security Intrusion Detection System IDS The security feature in the OnSite Router provides protection from a number of attacks Some attacks cause a host to be blacklisted no traffic from that host is accepted under any circumstances for a period of time Other attacks are simply logged The subsequent table is a summary of the attacks detected Attacking Host Blacklisted Attack _ Ascend Kill UDP yes Echo Chargen UDP no Echo Scan UDP yes WinNuke yes Xmas Tree Scan TCP yes IMAP SYN FIN TCP yes Smurf ICMP If victim protection set SYN FIN RST Flood TCP If scanning threshold exceeded Net Bus Scan TCP yes Back Orifice Scan UDP yes 1 To enable IDS click on Enabled for Intrusion Detection Enabled on the Security Interface Configura tion page Then
58. 3 Deleting a Security Policy essere REO RE _____ _______ 74 Definine ICMP port Alter for pine is quta ex DS e do acted 75 Configuring port filter for FIP PEREAT AR RE S A ae 76 Adding treet for FTD data tran ac iss cs cnc plato ded b eee odes pra lanes E are t 77 NAT Global Address Pool configuration edere hehe e rera ee Irem Rr a aea 81 Reserved map pime configuration dean EON v 81 DHCP Servet web page e HRS HERR SLOPE Ide PERRA He Pep Pes 85 DEGCP server contiguration web page esas deer 86 DHCP Servet subnet parameters 22 cesse bh erre ____________ E 86 DACP IP address suc nia eu Poser odd beue up tub dcn dde 87 Example based default rangeof IP address pool 222242222 2 244 2 4 2 2 aed 88 Gonfipuration of the DNS server IP addresses 15 0 v 2 ege eh qb ex ping 88 DHCP server optional information example aee a doe dba ees 89 DHCP Relay vebDape uso ient oda RUPEM Edd ORO brea dde 90 DHCP Relay seivet list eC abe eT Hd 91 Hyperlink path to tbe DNS Webpape dietus he RA Puta Ais 91 DNS Relay configuration webpage sess es seid meer RR pe eee se Re EE RS ERROR
59. 5 Models 2603 2621 and 2635 User Manual 6 WAN Services Cost 1 Interface frame 0 Create Ip V4Route Name Value Destination 0 0 0 0 Gateway 192 168 164 3 Netmask 0 0 0 0 Cost Interface Update Reset Cancel Figure 40 IP route for Frame Relay routed application 12 Click on the Update button This concludes the configuration of the remote site Be sure to save the configuration in non volatile memory by System Configuration gt Save gt Click on Save in the main window Central site configuration Note Ifyou using an OnSite at the central location follow the instructions below otherwise refer to your third party router documentation for configu ration First configure the IP address of the OnSite s Ethernet port interface via the command line CLI for 192 168 172 3 24 The PC must be on the same subnet for configuring the OnSite via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the OnSite 2 On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined Click on Create a new service in the main window select Frame Relay routed and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service Description FR routed DLCI Enter DLCI number Consult with your
60. AN connection PPP bridged Description Interface fi LLC header mode dialout LLC header mode off HDLC header mode authentication C CHAP or PAP Password Create Verify the settings to be Interface 1 LLC header mode dialout LLC header mode off HDLC header mode on No authentication Leave User name Password blank Click on Create Central Site Configuration If the central site also has an OnSite you may configure as described in this sec tion Refer to the web page images for the Remote OnSite configuration above In this example the IP address of interface 1 is changed to 192 168 100 3 24 WAN Service Configuration 53 Models 2603 2621 and 2635 User Manual 6 WAN Services 1 Bring up the web page management system on your browser by entering the IP address of the OnSite 2 On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create new service in the main window select PPP bridged and click on the Continue button 4 Inthe Description field enter the description you wish for example PPP Bridged Verify the settings to be Interface 1 LLC header mode dialout LLC header mode off HDLC header mode on No authentication Leave User name and Password blank Click on Create PPP Routed
61. CP relay agent RFC 2132 RFC 1542 with 8 individual address pools DNS Relay with primary and secondary Name Server selection NAT RFC 3022 with Network Address Port Translation NAPT for cost effective sharing of a single DSL connection Integrated Application Level Gateway with support for over 80 applications NAT MultiNat with 1 1 mapping NAT Many 1 NAT Many Many mapping NAT Port IP redirection and mapping IGMPv2 Proxy support RFC 2236 Frame Relay with Annex A D LMI RFC 1490 and FRF 12 Fragmentation PPP Support Point to Point Protocol over HDLC PPPoE RFC 2516 Client for autonomous network connection Eliminates the requirement of installing client software on a local PC and allows sharing of the connection across a LAN User configurable PPP PAP RFC 1661 or CHAP RFC 1994 authentication PPP BCP RFC 1638 support for bridged networking support Management Web Based configuration via embedded web server CLI menu for configuration management and diagnostics Local Remote CLI VT 100 or Telnet 1157 MIB II RFC 1213 Logging via SYSLOG and VT 100 console Console port set at 9600 bps 8 bits no parity 1 stop bit no flow control Protocol Support 120 Models 2603 2621 and 2635 User Manual Specifications Security Packet filtering firewall for controlled access to and from LAN WAN Support for 255 rules in 32 filter sets 16 individual connection profile
62. DHCP server Use this section to add a new DHCP server to the DHCP relay s list New DHCP server IP address E 1 Create Figure 63 DHCP Relay server list DNS Relay The DNS Relay webpage contains a configurable list of DNS server IP addresses The OnSite s DNS Relay forwards DNS queries from a client to a pre defined DNS server and DNS server responses to the client You can configure the DNS Relay for two IP addresses These are for access to primary and secondary DNS servers Configuring the DNS Relay Go to the DNS Relay webpage by following the hyperlink path Configuration gt Services Configura tion gt DNS Relay See figure 64 Patton Home Page o Home System Status gt System Configuration Services Configuration LAN WAN LMI Management routes DHCP server DHCP relay DNS relay Z gt e e N Figure 64 Hyperlink path to the DNS Relay webpage Enter the IP address of the primary DNS server see figure 65 and click on the Create button Similarly enter the IP address of the secondary DNS server Introduction 91 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration DNS Relay This page allows you to enter a list of DNS server IP addresses that the DNS relay can forward DNS queries Edit DNS server list Use this section to edit existing DNS server addresses present in the DNS relay s list
63. EDs Chapter 13 Contacting Patton for assistance Chapter contents 113 Contact e cene GER E RE HEREDI NUN er eee E eee eee 113 Patton support headquarters in the USA certe me rete cete de edi e te t Rt baee 113 Alternate Parton support for Europe Middle Hast and Alica EMBA 113 Warranty Service and Returned Merchandise Authorizations 113 e 113 114 2 o ru m E e 114 d PR TED E 114 A a E A e a S 114 re ge ane eee 114 112 Models 2603 2621 and 2635 User Manual 13 Contacting Patton for assistance Introduction This chapter contains the following information e Contact information describes how to contact PATTON technical support for assistance Warranty Service and Returned Merchandise Authorizations RMAs contains information about the RAS warranty and obtaining a return merchandise authorization RMA Contact information Patton Electronics offers a wide array of free technical services If you have questions about any of our other products we recommend you begin your search for answers by using our technical knowledge base Here we have gathered together many of the more commonly asked questions and compiled them into a searchable database to help you quickly solve your problems Patton support headquarters in the USA Online suppor
64. ICMP 2 IGMP 3 GGP 4 IP Enabling the Firewall 74 Models 2603 2621 and 2635 User Manual 7 Security Protocol Number Abbreviation 6 8 9 17 UDP 46 RSVP 47 GRE 89 OSPFIGP 92 MTP 94 IPIP This example continues to allow pings over the firewall 1 From the Configuration Menu gt Configuration gt Security gt Security Policy Configuration gt Port ters gt Add Raw IP Filter 2 Enter 1 for ICMP in the Protocol Number field 3 Set both Inbound and Outbound for Allow See figure 50 4 Click on Create Firewall Add Raw IP Filter external internal Direction Protocol Number Create Inbound Outbound Figure 50 Defining ICMP port filter for ping You can now ping between the two networks Security Triggers Security triggers are used to allow an application to open a secondary port in order to transport data The most common example is FTP This procedure sets up a trigger on the Firewall to permit an FTP session from PC A to PCB but not the reverse 1 First create an outbound only portfilter for FTP and add it to the policy 2 Following the path given in step 1 for the ping portfilter in the previous section click on Add TCP Filter 3 The Port Range is entered as 21 for both Start and End Security Triggers 75 Models 2603 2621 and 2635 User Manual 7 Security 4
65. M 123 122 Models 2603 2621 and 2635 User Manual Cable Recommendations Ethernet Cable Ethernet cable P N 10 2500 refer to RJ 45 shielded 10 100 Ethernet port on page 125 The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt IN age current anticipated temperature flammability and mechanical serviceability Adapter EIA 561 to DB 9 P N 16 561 refer to RJ 45 non shielded RS 232 console port EIA 561 on page 125 The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability Ethernet Cable 123 Appendix OnSite Physical Connectors Chapter contents 125 RS 232 console port ETASSBT 125 Serial MM 126 126 a rer ICE UE EIU ete EIN IE 127 fo BATS cP 128 124 Models 2603 2621 and 2635 User Manual RJ 45 shielded 10 100 Ethernet port D OnSite Physical Connectors Assuming the MDI X switch is in the out position Table 7 Ethernet Port MDI X switch in out position Pin No Signal Name Direction TX from OnSite 2 TX from OnSite 3 RX to OnSite 4 5 6 RX to OnSite 7 8
66. M UE mE E E 32 Rear view or the 2635 showing locationior Ethernet and 7 25 ux acere r iere 2 33 Connecting the 2635 toa DOE device eT __ 34 Power connector location on rear panel Model 26037 T shown sesso eese nme esu Due hanes 25 OnSite front panel LEDs and Console port locations Model 2603 shown 36 38 Model 2621 home enr res os oes ___ 38 29 Ethernet LAN port PNEU sat cee 41 Basic port PEEIDU te od dx eode 42 Advanced Ethernet port 42 Gonfeurble Ethernet cirri ant E Nelo 43 Model 2621 21 port configuration parameters eu Hes 46 Model 2635 46 Model 2603 T MEI WAN port configuration pardmstete xm D ur 47 pli ceric weit LUE dec UE 47 El port M UL IUS E Sa TE 48 enero UI a Et e EU ERE 51 PPP Bridged Application Xn os SY UR DENES SUR SU LS SN Hoe ped oe ced 52 d e 29 PPP Roud Applicaton ewe eode es te 54
67. NS server IP addresses in memory so the DNS relay can forward DNS queries and responses between the host user and the DNS server The DHCP Server will listen for DHCP client requests on a suitable IP interface Typically this is the Ethernet interface named 1 1 by default Note The Ethernet LAN port be configured as a DHCP client to receive its IP address from a DHCP server on the Ethernet LAN If so configured you should not enable the OnSite s DHCP server on the Ethernet interface DHCP Relay functions transparently between DHCP client and a DHCP server The DHCP relay appears as a DHCP server to the DHCP client s point of view The relay operates by forwarding all broadcast client request to known DHCP servers The DHCP relay listens on all available interfaces All relay server communi cation is unicast It is important that valid routes are set up to the server and also to the client Services and features normally associated with each other The following table figure 4 is to give guidance on what services of OnSite features to configure when you have decided to use DHCP Server DHCP Relay or DNS Relay If you are configuring a feature listed in the first column Configured Feature you can determine which other features either cannot be must be usually can be or are rarely used The Rarely used column is listed to be technically correct but it is ill advised to use The three most important columns other than
68. Port Configuration The OnSite Series routers use a sync serial interface X 21 V 35 interface for connection to stan dard WAN services Below are the configuration options for the WAN interface Serial Interface The serial interface configuration menus allow the user to configure the serial interface for HDLC based con nections Variables The following table lists variables that are configurable on the OnSite s software Variable Options Function Clock Mode Internal The clock setting for the serial interface will determine the External source of timing for the serial interface only RX Clock Invert Inverted The clock invert functions could be used to invert the clocks TX Clock Invert that are used on the serial interface It is not recommended to Normal change this parameter unless requested by Patton Electron ics technical support Keep at default Serial Speed Any n x 64 kbps speed Defines the generated speed for internal clock mode opera Speed should be enter ed as the rate i e 512 for 512 kbps or 2048 for 2 048 Mbps tion or the clock that will be received in external clock mode operation TX Data Sample Point Ext Clk Tx Clk WAN Serial Port Configuration When the unit is running in internal clock mode the setting of TX Data SamplePoint will indicate to the system which clock to use to sample the in coming data Some systems require that the data be sample
69. Port Router Software Revision 2 6 3 Jan 13 2006 Status of 2635 Single Port Router Local IP Address 10 10 19 30 PP CPU Usage 1 NP CPU Usage 1 Up Time 2 days 23 hours Current Time Sat 03 Jan 1970 23 30 18 Copyright c 2005 Patton Electronics Co Terms and conditions Figure 16 Model 2635 home page 39 Chapter 4 Ethernet Port Chapter contents dee ok REI UITIUM 41 NE 41 41 40 Models 2603 2621 and 2635 User Manual 4 Ethernet LAN Port Introduction The Ethernet LAN interface port can be configured with two IP addresses a primary and a secondary IP address The configuration web page is found by following the path gt Services Configuration in the Configu ration Menu gt LAN gt Change default LAN port IP address button on the main window The Basic and Advanced Port Attributes of the Ethernet LAN port is found by clicking on the Ethernet hyper link in the OnSite s Configuration Menu the narrow window on the left hand side of the web page Clicking on the View advanced attributes hyperlink leads to a webpage with only a few parameters that could be of interest They are for controlling auto negotiation 100BaseT mode and Full duplex mode LAN Connections The default LAN port s IP address and netmask can be changed on this webpag
70. The first address should be the Primary DNS server and the second address should be the Secondary DNS server You cannot have more than two addresses at a time There are currently no DNS servers in the list Use the section below to add a new DNS server Add new DNS server Use this section to add a new DNS server to the DNS relay s list New DNS server IP address fio fio 4 fi fio Figure 65 DNS Relay configuration webpage You can change the IP address of the DNS servers on the DNS Relay webpage see figure 66 by modifying the IP address requiring the change and clicking on the Update button To delete the IP address of a DNS server check the Delete box then click on the Update button DNS Relay This page allows you to enter a list of DNS server IP addresses that the DNS relay can forward DNS queries Edit DNS server list Use this section to edit existing DNS server addresses present in the DNS relay s list The first address should be the Primary DNS server and the second address should be the Secondary DNS server You cannot have more than two addresses at a time DNS server IP address Delete fio fio fio fio fio fi fin Update Reset Figure 66 DNS Relay configuration completed Introduction 92 Chapter9 Services Chapter contents ee 94 EE 94 94 Associated 95 93 Models 2603 2621 and 2635 User Manual
71. Usine ehe Console 130 tine User ACO Ulta 132 132 132 E NSE met Ene KI 133 Controlling M 133 133 129 Models 2603 2621 and 2635 User Manual Command Line Interface CLI Operation Introduction The modem configuration and status can also be view and modified through the console which is accessible through the RS 232 serial port or through a Telnet session over Ethernet CLI Terminology In order to use the CLI commands you need to understand the following CLI terms Transport A transport is a layer 2 session and everything below it You can create a transport and attach it to a bridge or router so that data can be bridged or routed via the attached transport The CLI supports the following transports e PPPoE Point to Point Protocol over Ethernet Frame Relay PPP Point to Point Protocol over HDLC Ethernet Interface bridges and routers both have interfaces A single transport is attached to a bridge or router via an interface e Object an object is anything that you can create and manipulate as a single entity for example interfaces transports static routes and NAT rules List Objects are numbered entries in a list For example if you have created more than one ethernet trans port the following command ethernet list transports produces a list of numbered t
72. age C 2603_243 tar Browse Update Options Figure 73 Updating software Clicking on Options provides for selecting Firmware Update Configuration If enabled the OnSite will pre vent updating with incorrect software Save To save configuration changes to non volatile memory it is essential to click on the Save button on this webpage See figure 74 If you do not do this all configuration changes are stored only in volatile memory meaning that if the OnSite is restarted all configuration changes are lost Click on the Save button and wait until seeing the message Saved information model to im conf Save configuration Confirm Save Please confirm that you wish to save the configuration There will be a delay while saving as configuration information is written to flash Save Figure 74 Save configuration changes in non volatile memory Backup Restore You may save or use previously saved configurations from this webpage Should you want to save a specific application configuration from the OnSite click on Backup configuration to your computer To reload a previously saved configuration file icf browse and select the file from your computer Click on the Restore button to load into the OnSite See figure 75 Update 100 Models 2603 2621 and 2635 User Manual 10 System Configuration Configuration Backup Restore This page allows you to backup the configuration settings to your computer
73. age and paging down until you see the Summary description In figure 33 the PPP link is in the Establishment phase To get to the Edit PPP web page follow this path Services Configuration gt WAN gt Edit gt Edit PPP WAN Service Configuration 56 Models 2603 2621 and 2635 User Manual 6 WAN Services MRU isco Ip Addr From IPCP Use Ip Addr From IPCP tue Discover DNS Discover Secondary DNS Give DNSto Relay Give DNSto Client Lep Echo Every fio Auto Connect false Idle Timeout Tagged Frame Not Enforced gt Summary enabled up phase Establish Connect State connecting Uptime 0 Idletime 0 NCPRemote Addr Version 1 04 If In Octets 0 Octets 16536 Figure 33 PPP link status Central Site Configuration If the router at the ISP or Central site is another OnSite series follow the instructions below If not consult your third party router user manual for configuration See the web pages for the desktop above Some configurable parameters are different although the process is the same Configure the IP address of the Ethernet port interface ip1 to be 192 168 172 3 24 The PC connected to the Ethernet LAN directly must be on the same subnet in order to access the configuration web pages In this example the PC s IP address is 192 168 172 229 24 Notice that this subnet differs from the subnets of
74. available on this subnet You need to make sure that the start and end addresses offered in this range are within the subnet Alternatively you may check the Use a default range box to assign a suitable default IP address px Start of address range 10 1 411 End of address range 10 19 30 Use a default range da T Figure 59 Example based on default range of IP address pool DNS server option information When a client requests an IP address from a DHOP server the server can also send the IP addresses of the pri mary and secondary DNS servers IP addresses The OnSite can accomplish this in one of two ways neither really having an advantage over the other This section of the configuration page is one method the other is DNS Relay to be described later in this chapter Refer to figure 60 DNS server option information Enter the addresses of Primary and Secondary ONS servers to be provided to DHCP clients on this subnet You may instead allow DHCP server to specify its own IP address by clicking on the Use local host address as DNS server checkbox Primary DNS server address 11 10 1 1 10 Secondary DNS server address 10 f 1 r Use local host address as DNS server Figure 60 Configuration of the DNS server IP addresses Enter the IP addresses of the primary and secondary DNS servers Subsequently the client will receive these addresses when assigned an IP address When the client makes a DNS inquiry it
75. curity Interface Configuration 2 Click on the hyperlink Add Global Address Pool The global IP addresses need to be created and put into the Global Address Pool 3 Set the parameters to the following values See figure 53 Interface Type internal Use Subnet Configuration Use IP Address Range IP Address 100 100 100 101 Subnet Mask IP Address 2 100 100 100 102 Introduction to NAT 80 Models 2603 2621 2635 User Manual 7 Security Click Add Global Address Pool button Add Global Address Pool 0 Add Global Address Pool Interface Use Subnet Configuration IP Address Subnet Mask IP Address 2 Use IP Address Range 100 100 100 101 Add Global Address Pool Figure 53 NAT Global Address Pool configuration 4 Next create a reserved mapping between a global IP address from the global pool and a PC on the side of the internal interface ip1 In this example 10 10 19 11 5 Click on the hyperlink Add Reserved Mapping 6 Set the parameters to the following values See figure 54 Global IP Address 100 100 100 101 Internal IP address 10 10 19 11 Transport Type all Port Number 65535 This port number means all port numbers for TCP or UDP protocols will be mapped 7 Click on Add Reserved Mapping NAT Add Reserved Mapping 0 Add Reserved Mapping Global IP Address Internal IP Add
76. d on one clock or another This is also useful when tail circuits are being created When running in the external clock mode this should be set to Ext Clk 45 Models 2603 2621 and 2635 User Manual 5 Serial Port Configuration Web Interface Configuration The following screen capture shows the variables available to configure the X 21 serial interface Serial Configuration Configuration Options Serial Speed 512K Clock Mode extemal Tx Clock Invert normal Rx Clock Invert normal Enabled true v Configure Figure 21 Model 2621 X 21 serial port configuration parameters The next figure shows the Model 2635 V 35 serial port configuration parameters Serial Configuration Configuration Options Serial Speed 512K Clock Mode extemal Tx Data Sample Ex clock Tx Clock Invert normal gt Rx Clock Invert normal gt Enabled tue Configure Figure 22 Model 2635 V 35 serial port configuration parameters After the serial port has been configured go to WAN Service Configuration on page 52 section WAN Ser vice Configuration on page 52 for router bridge and WAN service configuration T1 E1 Interface Configuration The OnSite Series Model 2603 is equipped with a user selectable T1 E1 interface The interface is sented an RJ 48C 100 ohm connector while the E1 interface can use the RJ 48C 120 ohm
77. ddress 21681642 1 255 255 255 255 LLC header mode HDLC header mode No authentication CHAP or User Password Create Figure 30 PPP Routed Configuration menu 4 Click on Create 5 Go to Services Configuration gt WAN gt Edit for PPP routed gt Edit Interface gt Ipaddr enter the WAN IP Address and Mask in this example 192 168 164 2 and 255 255 255 255 See figure 31 WAN Service Configuration 55 Models 2603 2621 and 2635 User Manual 6 WAN Services 6 Click on Create Edit Ip Interface Options Name Value Ipaddr 192 168 164 2 Mask 255 255 255 255 false v MTU 1500 Name 0 Enabled tue Layer2Session Create Reset Figure 31 Edit IP address of WAN port 7 Click on Services Configuration gt IP Routes gt Create new Ip V4 Route Create the gateway to the remote router by entering the WAN IP address of the remote router in this example enter 192 168 164 3 in the Gateway field See figure 32 8 Click the Update button Create Ip V4Route Name Value Destination moon Gateway 182158184400 Netmask ooo Cost Interface none Cancel Figure 32 Configuring the gateway The other fields should be e Destination 0 0 0 0 e Gateway 192 168 164 3 e Mask 0 0 0 0 e Cost 1 Interface blank You can see the status of the PPP link by going to the PPP web p
78. ddress configuration 105 Timezone and Polling packet confBeuiation sipose GS 106 Configuration of the internal system calendar clock 1 107 System Status subsysteina arise s qup bateau ia D e ales Pu 109 M 127 ON O pick 128 List of Tables ON WNDU KR WN D M ER ER 16 Status LED descriptors 20 TB the E SR ES 58 II REN T 84 Standard numbers tor the System Services oec eso e AUTE Ae Pc 95 UD E ER C Lp pM A Me 111 Ethernet switch in eue ponon ciues E Um 125 DIC 125 126 UM 127 TET 128 12 About this guide This guide describes installing and configuring Patton Electronics OnSite Series High Speed Routers The in
79. dress of 192 168 200 10 to your selected IP address Do the following comments are in brackets fi ip list interfaces enter lists the characteristics of the different interfaces IP Interfaces ID Name IP Address fi ip set interface ipaddress 10 10 19 10 255 255 0 0 lt enter gt Sets the new IP address which you have selected The IP address in this example is for illustrative purposes only fi ip list interfaces enter To see if the change in IP address is correct fi system config save lt enter gt To save the new IP address in flash memory fi The IP address has now been successfully changed Web Operation and Configuration Now that the IP address has been configured for your application you can complete the configuration using any standard web browser PC Configuration In order to connect the PC to the Ethernet LAN to communicate with The OnSite Series router the PC s IP address should be on the same subnet as the router Connect a straight through Ethernet cable between the PC s NIC or PCMCIA Ethernet card and an Ethernet hub or switch Web Browser Do the following 1 Launch a standard web browser such as Netscape Communicator or Internet Explorer IE Hardware installation 37 Models 2603 2621 and 2635 User Manual Initial Configuration 2 Enter the OnSite router s IP address into the URL or Address field of the browser To see the OnSite Series router home page refer to th
80. e Go to gt Services Configura tion in the Configuration Menu gt LAN gt Change default LAN port IP address button on the main window See figure 17 The primary IP address and mask can be modified here but if you do you will no longer be able to access the OnSite s webpages with the previous IP address The interface associated with the Ethernet is named ip1 You can also configure a secondary IP address to the Ethernet LAN port LAN connections This page allows you to change the IP address for the default LAN port The name of the IP interface is ip1 Default LAN Port The Secondary IP Address should be on the same subnet as the Primary IP Address and uses the same Subnet Mask Addresses on other subnets can be added using Virtual Interfaces Primary IP Address Address fo fio ro Subnet Mask 255 255 o 10 Secondary IP Address IP Address o o o 0 Update Note there a short pause between clicking Update and receiving a response Advanced Figure 17 Ethernet LAN port IP address configuration The secondary IP address must be in the same subnet as the primary IP address With primary and secondary IP addresses you can reach the OnSite s webpages via either IP address However you will have to login for each separate IP address Ethernet Port The Ethernet Port Configuration webpage provides a summary of the Ethernet port s performance You reach it by c
81. e PPP support see section PPP Support on page 19 Management see section Management on page 19 WAN interface see section WAN Interfaces on page 19 Security see section Security on page 20 Front panel status LED see section Front Panel Status LEDs and Console Port on page 20 General attributes Compact low cost router bridge 10 100 Ethernet Comprehensive hardware diagnostics Easy maintenance and effortless installation Plug and Play operation for fast and seamless turn up with pre configured WAN and LAN options Built in web configuration Setup allows for standard IP address and unique method for entering IP address and mask without requiring a console connection Default IP address of 192 168 1 1 24 Simple software upgrades obtained Front panel LEDs indicate Power WAN and Ethernet LAN speed and status Convenient and standard RJ connectors for Ethernet Line and Console e Standard one year parts and labor warranty OnSite Series High Speed Routers overview 18 Models 2603 2621 and 2635 User Manual 1 General Information Ethernet e Auto sensing full duplex 10Base T 100Base TX Ethernet Standard RJ 45 connector Built in MDI X cross over switch EEE 802 1d transparent learning bridge 2 P address subnets on Ethernet interface support Complete internetworking with IP RFC 741 TCP RFC 793 UDP RFC 768 ICMP RFC 950 ARP RFC
82. e following Figures Model 2603 is shown in figure 14 Model 2621 in figure 15 Model 2635 in figure 16 Patton Electronics Company 2603 Single Port Router Software Revision 2 6 3 Jan 13 2006 Status of 2603 Single Port Router Local IP Address 10 10 19 10 CPU Usage 1 NP CPU Usage 1 Up Time 101 58 50 Current Time Wed 31 Dec 2003 20 58 41 Figure 14 Model 2603 home page Patton Home Page Home Patton Electronics Company 2621 Single Port Router Software Revision System Status 2 6 3 Jan 13 2006 gt System Configuration Status of 2621 Si Port Rout gt Services Configuration ingle Po puser Ethernet Local IP Address 10 10 19 20 V Serial CPU Usage 1 Configuration NP CPU Usage 0 Status 2 gt e e N 2 N Up Time 2 days 23 hours Current Time Sat 03 Jan 1970 233213 Figure 15 Model 2621 home Hardware installation 38 Models 2603 2621 and 2635 User Manual Initial Configuration Patton Home Page o Home System Status gt System Configuration Services Configuration LAN WAN LMI Management routes DHCP server DHCP relay DNS relay Services Security SNTP client z gt Z gt E Z e e 2635 o Ethernet gt Serial Hardware installation Patton Electronics Company 2635 Single
83. e of shipment Our warranty is limited to defects in work manship or materials and does not cover customer damage lightning or power surge damage abuse or unauthorized modification Introduction 113 Models 2603 2621 and 2635 User Manual 13 Contacting Patton for assistance Outof warranty service Patton services what we sell no matter how you acquired it including malfunctioning products that are no longer under warranty Our products have a flat fee for repairs Units damaged by lightning or other catastro phes may require replacement Returns for credit Customer satisfaction is important to us therefore any product may be returned with authorization within 30 days from the shipment date for a full credit of the purchase price If you have ordered the wrong equipment or you are dissatisfied in any way please contact us to request an RMA number to accept your return Patton is not responsible for equipment returned without a Return Authorization Return for credit policy Less than 30 days No Charge Your credit will be issued upon receipt and inspection of the equipment 30 to 60 days We will add a 2096 restocking charge crediting your account with 8090 of the purchase price Over 60 days Products will be accepted for repairs only RMA numbers RMA numbers are required for all product returns You can obtain an RMA by doing one of the following Completing a request on the RMA Request page in the Support secti
84. ecurity Victim Protection Block Duration Default 600 seconds 10 minutes Sets the duration of the block in seconds Maximum TCP Open Handshaking Count Default 100 Sets the maximum number of unfinished TCP handshaking sessions per second that are allowed by a firewall before a SYN Flood is detected SYN Flood is a DOS attack When establishing normal TCP connections three packets are exchanged 1 A SYN synchronize packet is sent from the host to the network server 2 A SYN ACK packet is sent from the network server to the host 3 An Ack acknowledge packet is sent from the host to the network server If the host sends unreachable source addresses in the SYN packet the server sends the SYN ACK packets to the unreachable addresses and keeps resending them This creates a backlog queue of unacknowledged SYN ACK packets Once the queue is full the system will ignore all incoming SYN request and no legitimate TCP connections can be established Once the maximum number of unfinished TCP handshaking sessions is reached an attempted DOS attack is detected The firewall blocks the suspected attacker for the time limit specified in the DOS Attack Block Duration parameter Maximum Ping Count Default 15 Sets the maximum number of pings per second that are allowed by the firewall before an Echo Storm is detected Echo Storm is a DOS attack An attacker sends oversized ICMP datagrams to the system using the ping command T
85. es Configuration in the OnSite router s Configuration Menu 2 Create a new service 3 Select PPP routed and click on the Continue gt button 4 For this example enter PPP Security Firewall in the Description field See figure 41 5 Click on Create Introduction 69 Models 2603 2621 and 2635 User Manual 7 Security WAN connection PPP routed Description Security Firewall Interface fi WAN IP address 0 0 0 0 255 255 255 255 LLC header mode oft HDLC header mode authentication Password Create Figure 41 PPP routed WAN service for Security Firewall example 6 Click on Edit in the WAN Connections webpage and then click on the Edit Interface hyperlink 7 In the Edit Ip Interface webpage enter the fields as follows and click on the Create button See figure 42 Ipaddr 192 168 101 1 Mask 255 255 255 0 Edit 1 Interface Edit Tcp Mss Clamp Edit Ip Interface Options Name Value Ipaddr 192 168 101 1 Mask 255 255 255 0 Dhep false MTU 1500 Name 0 Enabled tue v Layer2Session Create Reset Figure 42 IP address of PPP routed WAN service The next step in configuring the router is to add the default gateway route The WAN IP address of the routed PPP WAN service at the CO site is 192 168 101 2 so this will be the gateway IP address on the OnSite
86. ess 10 10 19 10 LAN Settings LAN Subnet Mask 255 255 0 0 Act as Local DHCP Server No MAC Address WAN Status IP Address Type WAN Subnet Mask Default Gateway Primary DNS PPPoE Status Connection Authentication Hardware Status Up Time 00 0 00 50 9 Static None 192 1 1 4 None None 00 44 465 DHCP Server Settings IP Address Settings DNS Client Settings Current Time Wed 31 Dec 2003 19 44 37 Set Time Q Version OP Image Software Revision 2 5 3 Kernal 8 2 0 37 Jan 13 2006 Defined Interfaces fr rtd Show Statistics ethO Show Statistics Figure 84 System Status subsystems summary Port Connection Status The Ethernet link goes to the Ethernet Port Configuration webpage This is the same webpage accessed by clicking on the Ethernet menu item in the Configuration Menu Connected indicates whether the Ethernet port sees a received signal System Status 109 Models 2603 2621 and 2635 User Manual 12 System Status LAN Status There are two hyperlinks LAN Settings and DHCP Server Settings which go to the Connections and DHCP Server webpages respectively The other parameters shown in LAN Status are as follows Local IP address the IP address of the Ethernet port LAN subnet mask the subnet mask of the Local IP address e Actas Local DHCP Server indicates Yes as to whether
87. ess and port to an inside address and port Reserved mappings can also be used so that different inside hosts can share a global address by mapping different ports to different hosts For example Host A is an FTP server and Host B is a web server By mapping the FTP port to Host A and the HTTP port to Host B both insides hosts can share the same global address Setting the protocol number to 255 means that the mapping will apply to all protocols Setting the port number to 65535 for TCP or UDP protocols means that the mapping will apply to all port numbers for that protocol Some applications embed address and or port information in the payload of the packet The most notorious of these is FTP For most applications it is sufficient to create a trigger with address replacement enabled How ever there are three applications for which a specific Application Level Gateway is provided FTP NetBIOS and DNS Enabling NAT The configuration of NAT in this example follows on the preceding configuration completed earlier in this chapter 1 to the Security Interface Configuration page by clicking on Security under Configuration in the menu 2 Click on Enable NAT to internal interfaces in the Security Interfaces table NAT is now enabled between the internal LAN and the external WAN interfaces of the firewall Global address pool and reserved map 1 Click on Advanced NAT Configuration on the web page Se
88. figure and Activate button at the bottom of the screen Additionally save the configuration in non volatile memory by going to the System Configuration Save menu This concludes the interface configuration via the web browser go to section WAN Service Configura tion on page 52 for instructions on router bridge and WAN service configuration Configuring the OnSite Series 2603 for E1 Operation Web Configuration Launch Jnternet Explorer or similar web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the 1 1 gt Configuration See figure 25 T1 E1 Configuration Configuration Options Time Slot Select Payload Rate 1984 31 Line Options Channelized 6 703 6 704 Code Sel Line Build 120 Ohm FDLMode _ E Clocking Mode Receive Clock Idle Codes _ Power Down Normal Configure and Activate Figure 25 E1 port configuration WAN Serial Port Configuration 48 Models 2603 2621 and 2635 User Manual 5 Serial Port Configuration Time Slot Select For unframed E1 service Clear Channel go to the Line Option parameter and select Clear Channel 1 G 703 For a full framed E1 enter 1 31 for partially filled E1 enter the range of timeslots using the format for example 1 2 3 5 or 1 5 10 31 Any entry for timeslots above 31 will retu
89. figuring Security Policies Continue the previous example by defining security policies We will add only one Firewall policy called signifying an external zo internal policy between the external and internal interfaces 1 to the last section on the Security Interface Configuration webpage called Policies Triggers and Intru sion Detection Click on the hyperlink Security Policy Configuration See figure 47 Policies Triggers and Intrusion Detection Security Policy Configuration Security Trigger Configuration Configure Intrusion Detection Figure 47 Security Policy Configuration hyperlink 2 Click on the hyperlink New Policy See figure 48 Security Policy Configuration Current Security Policies No Policies Defined New Policy Q Figure 48 New Policy link to configuration webpage 3 Select the parameters so the policy is defined as follows Between interfaces of types external internal Validators will allow traffic Click on Apply Configuring the security interfaces 73 Models 2603 2621 2635 User Manual 7 Security Deleting a security Policy To delete a security policy go to the table of Current Security Policies and click on the Delete button for the selected security policy Security Add Policy Between interfaces of types external internal Validators will allow traffic Selecting allow will block traffic from hosts except
90. ge and WAN service configuration Serial Port Configuration 49 Chapter6 WAN Services Chapter contents E 51 Conheurine the IPLink Senes 2603 for E 51 Web Cone RO coh tok teeta nate a ea 51 52 PPP Con THO MIL SIMI ones 52 DP 52 PPP Bridged Remote Site REESE ROUTE 52 59 54 Remoresite COD 54 Dy LMI Managerment Frame Relay limes e emia 58 JEDE IE EO OD 58 Frame belay Local Management RUNE REESE 58 59 59 Frame Relay LU di 60 Pane le eT eer ea 61 61 Uae ea Mme eee ee ee 62 A ee A eevee 63 Remote Site uere eoo IIR AE EIN 63 eng d mU T eee ec M M 66 50 Models 2603 2621 and 2635 User Manual 6 WAN Services WAN Services Configuring the OnSite Series 2603 Operation Web Configuration Launch Internet Explorer or similar
91. he user change command Changing user settings To change any of the default settings for a user use the following commands For example to change the set tings for user fred system set user fred access default engineer superuser System set user fred maydialin enabled disabled system set user fred mayconfigure enabled disabled For example to change the security level for fred enter system set user fred access engineer Note Only superusers can use the user change command Controlling login access To set user login access for user username use the command all on one line system set login lt username gt access default engineer superuser Controlling user access set user access for user username use the command all on one line system set user lt username gt access default engineer superuser Administering user accounts 133
92. his can cause the system to crash freeze or reboot resulting in denial of service to legiti mate users Maximum ICMP Count Default 100 Sets the maximum number of ICMP packets per second that are allowed by the firewall before an ICMP Flood is detected An ICMP Flood is a DOS attack The attacker tries to flood the network with ICMP packets in order to prevent transmission of legitimate network traffic 4 After selecting the chosen parameters click on Update Intrusion Detection System IDS 79 Models 2603 2621 and 2635 User Manual 7 Security Introduction to The basic steps for configuring NAT are 1 Enable NAT between the internal and external interfaces of the firewall 2 Create global addresses which will be added to the global pool of IP addresses on the WAN interface 3 Create a reserved mapping between a global IP address and the IP address of an internal PC A Global Address Pool is a pool of addresses seen from the outside network Each external interface creates a Global Address Pool with a single address the address assigned to that interface For outbound sessions an address is picked from a pool by hashing the source IP address for a pool index and then hashing again for an address index For inbound sessions it is necessary to create a reserved mapping A reserved mapping is used so that NAT knows where to route packets on inbound sessions The reserved mapping will map a specific global addr
93. ilable for configuration managementType Default Value no_maintanence the managementType variable defines the LMI pro tocol that will be used from the table above The following options are available no_maintenence No maintenance interface will be used for this frame relay connection ITU Network The ITU Q 933 protocol will be used The unit will operate as the Network side of the connection ITU User The ITU Q 933 protocol will be used The unit will operate as the User side of the connection ITU Both NNI The ITU Q 933 protocol will be used The unit will operate as both the Network and User side of the connection ANSI Network The ANSI T1 617 protocol will be used The unit will operate as the Network side of the connection ANSI User The ANSI T1 617 protocol will be used The unit will operate as the User side of the connection ANSI Both NNI The ANSI T1 617 protocol will be used The unit will operate as both the Network and User side of the connection Management State Defines the current state of the DTE side LMI Possible options are as follows Mgt_Port_DOWN Currently the LMI on the DTE side is DOWN Mgt Port UP Currently the LMI on the DTE side is UP Management Auto Start Default Value FALSE The management Auto Start variable allows the user to start the LMI session before any DLCI connections are created within the unit If this variable is set to FALSE the LMI session wi
94. ion Edit Frame Relay Channel Enter the appropriate information in the following fields e Consult with your service provider for the DLCI number required in this example use 45 Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Chose the encapsulation method best suited for your network In this example enter RX Max PDU Enter the number of receive side max PDU in this example it is the default 8192 PDU Enter the number of transmit side max PDU in this example it is the default 8192 Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRF 12 If this variable is set to 0 then FRF 12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf For bridged applications the port should be set to fr 9 Click on the Create button 10 Click on System Configuration IP Routes Create new Ip V4 Route 11 Create the gateway to the remote OnSite by entering the WAN IP address of the remote OnSite in this example enter 192 168 164 3 the Gateway field The other fields should be e Destination 0 0 0 0 Gateway 192 168 164 3 Mask 0 0 0 0 WAN Service Configuration 6
95. ish the job quickly Installation consists of the following Preparing for the installation see section What you will need Installing 1 WAN 21 or V 35 interface cable see section Interface cable installation e Hooking up network cables verifying that the unit will power up and running a HyperTerminal session see section Installing the Ethernet cable on page 36 The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability Changing the IP address from the factory default setting see section IP address modification on page 37 Launching a web browser in preparation for configuring the modem see Web Operation and Configura tion on page 37 What you will need OnSite Series High Speed Router e Ethernet cable with RJ45 plugs on each end included with router e DB9 RJ45 adapter included with router e RJ45 RJ45 straight through cable for connecting to control port included with router PC computer with HyperTerminal or equivalent VT 100 emulation program or an ASCII terminal also called a dumb terminal capable of emulating a VT 100 Interface cable installation An OnSite Series router comes with a WAN V 35 or 21 interface Refer to the appropriate section to install an interface cable on your OnSite router
96. ite supports three synchronization modes unicast mode anycast mode and broadcast mode Unicast is a point to point mode Anycast is a multipoint to point mode Broadcast mode is for use when the SNTP server is on the local network that is the same subnet as the OnSite When Unicast mode is enabled the OnSite sends a request to the server designated in the field containing the SNTP server s IP address See figure 81 This is a point to point communication link The OnSite requests from one server The server sends the timing information directly to the OnSite When disabled the OnSite does not send any requests to any SNTP Server In Broadcast mode the synchronization is with an SNTP server on the local network Since routers do not for ward broadcast IP addresses the SNTP server and OnSite must be on the same subnet With Anycast mode the OnSite s SNTP client sends a request to a designated broadcast address One or more SNTP servers may reply with a unicast message to the OnSite The OnSite communicates with the server first responding After this point the OnSite operates in unicast mode When Anycast is enabled Unicast is auto matically enabled and the IP address of 255 255 255 255 is in the SNTP server s IP address field Anycast takes precedence over Broadcast mode The field Configured IP Address of SNTP Server is the IP address of the dedicated unicast server that the SNTP client will use for synchronization SNTP clie
97. lay from here The DHCP relay is currently disabled Enable Edit DHCP server list Use this section to edit existing DHCP server addresses present in the DHCP relay s list There are currently no DHCP servers in the list Use the section at the bottom of the page to add a new DHCP server Add new DHCP server Use this section to add a new DHCP server to the DHCP relay s list New DHCP server IP address Create Figure 62 DHCP Relay webpage In the third section of the DHCP Relay webpage enter the IP address of a DHCP server and click on the Cre ate button See figure 63 The IP addresses will appear in the section section Edit DHCP server list In the second section you may update or delete the DHCP server IP addresses See figure 63 To update or change a DHCP server IP address enter the desired IP address over the IP address which is no longer valid Click on the Update button With this action you do not need to delete the IP address and sub sequently add a new IP address It is one action To delete a DHCP server IP address check the Delete box for the appropriate IP address and click on the Update button Introduction 90 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Edit DHCP server list Use this section to edit existing DHCP server addresses present in the DHCP relay s list DHCP server IP address Delete o Update Reset Add new
98. lications clocking for the 2603 will be derived from the E1 network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Options are Enabled or Disabled When idle code is Enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Options are Normal and Powerdown When powered down the E1 will put high impedance on the input and output lines to protect the device set unit to Normal for regular operation WAN Services 51 Models 2603 2621 and 2635 User Manual 6 WAN Services Once all options have been selected click on the Configure and Activate button at the bottom of the screen Additionally save the configuration by going to the System Configuration gt Save menu This concludes the E1 interface configuration via the web browser go to section WAN Service Configura tion on page 52 for instructions on router bridge and WAN service configuration WAN Service Configuration The OnSite Series Routers offer various WAN services for the proper transport encapsulation Ethernet Frame Relay and PPP options The Ethernet option is PPPoE bridged only Frame Relay and PPP can be used in either bridged or routed applications PPP Configuration PPP Bridged PPP Bridged Remote Site Configuration The IPlink series routers can be configured as bridges in this situ ation the IPlink typically is at the customer
99. lick on Create a new service in the main window select Frame Relay bridged and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service 5 Click on Create a new service the main window select Frame relay bridged and click on the Configure button See figure 35 WAN connection Frame Relay bridged Description FR bridge DLCI f Encapsulation method Bridged Ethernet z Create Figure 35 Frame Relay bridged creation 6 Click along the following path Services Configuration gt WAN gt Edit Then click Edit Frame Relay Channel See figure 36 The configurable parameters DLCTI Consult with your service provider for the DLCI number required LMI uses DLCI 0 but ANSI CCITT has also reserved 1 15 Best practice the recommendation is to use only DLCIs 16 991 for FR data PVCs and DLCIs 0 15 for LMI PVCs Service Configuration 61 Models 2603 2621 and 2635 User Manual 6 WAN Services Encapsulation type Bridged Ether Defines the RFC 1490 encapsulation type to be used by the channel In some instances you may need to choose another type Consult your service provider RX Max PDU 8192 Receive side max PDU default 8192 normally not changed from default Max PDU 8192 Transmit side max default 8192 normally not changed from default
100. licking on the hyperlink Ethernet in the OnSite s Configuration Menu window The Basic Port Attributes webpage displays the most commonly used Ethernet parameters for determining the performance of the Ethernet port see figure 18 on page 42 Introduction 41 Models 2603 2621 and 2635 User Manual 4 Ethernet LAN Port Ethernet Port Configuration View advanced attributes Basic Port Attributes Name Value MAC 00 a0 ba 00 28 3f Rx Ok 1224338 Rx Broadcast Packets 654397 Rx Error Packets 1305 Tx Ok 2321 Tx Collisions 41 Tx Error Packets 0 100Base false Connected true Full Duplex false Link Speed 100000 Update Reset Clear ifEntry Figure 18 Basic Ethernet port attributes For additional statistical parameters and a few configurable parameters click on the hyperlink View advanced attributes See figure 19 Advanced Ethernet Port Configuration Return to basic attribute list Advanced Port Attributes Name Value Rx No Buffer 0 Rx Error Align 0 Max Multicast Listsize 64 Max Queue a2 Disable false Promiscuous Enable false Figure 19 Advanced Ethernet port attributes The three configurable parameters are all either true or false Auto Negotiation autonegotiation can be enabled default or disabled In some instances autonegotia tion may be problematic if another device on the LAN does not work properly with autonegotiation 100Base Mode the default is for 100BaseT
101. ll begin when the first DLCI channel is created If this variable is set to TRUE the LMI session will begin immediately Full Report Cycle Default Value 6 This variable represents N391 protocol value User Max Errors Default Value 3 Network side N392 protocol value Net Max Errors Default Value 3 Network side N392 protocol value User Error Window Size Default Value 4 User side N393 protocol value Net Error Window Size Default Value 4 Network side N393 protocol value T391 Value Default Value 10 This variable sets the T391 timers in seconds T392 Value Default Value 16 This variable sets the T392 timers in seconds Web Configuration Methods The following documentation defines how to configure the Frame Relay Local Management Interface using the Web Interface the OnSite Series WAN Service Configuration 59 Models 2603 2621 and 2635 User Manual 6 WAN Services All LMI configuration variables are contained under the LMI Management window found through the Ser vices Configuration gt LMI Management link The following screen shows the configuration variables available LMI Management LMI Configuration Management Type no_maintenance Management State Management Auto Start false Full Report Cycle User Max Errors Net Max Errors Bo User Error Window Size Network Error Window Size RN 7391 Value 1392
102. ll define the subnet Subnet value It is necessary to enter the selected value here and the Subnet mask if you do not Get subnet from IP interface See description for the 3rd parameter e Subnet mask Introduction 86 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration The third parameter is e Get subnet from IP interface If you use this option then you will not enter any values in the first two parameters Should you define another subnet and also select Get subnet from IP interface the OnSite uses the Get subnet from IP interface as the ruling parameter and sets Subnet value and Subnet mask appropriately overriding your initial selection The Ethernet interface is always one option However there may be a WAN interface also as an additional option The interface is the DHCP server listening interface It listens for client requests on this interface The two remaining parameters are Maximum lease time the default value is 86 400 seconds Default lease time the default value is 43 200 seconds IP Addresses to be available on this subnet The next section see figure 58 has three parameters IP addresses to be available on this subnet You need to make sure that the start and end addresses offered in this range are within the subnet you defined above Alternatively you may check the Use a default range box to assign a suitable default IP address
103. llation 31 Models 2603 2621 and 2635 User Manual Initial Configuration When the local third party equipment is configured as DTE the Model 3086 X 21 serial port can be config ured as DCE and a regular straight through cable can then be used Do the following to configure the X 21 port as a DCE 1 Open the OnSite s case by inserting a screwdriver into the slots and twist the screwdriver head slightly The top half of the case will separate from the lower half of the case see figure 8 Take caution not to damage any of the PC board mounted components Figure 8 Case being opened with a screwdriver 2 Locate the small daughter board on the Model 2621 board to the right of the DB 9 connector figure 9 shows location of DTE DCE daughter board 4 DCE In this example the DCE DTE strap is X 21 connector configured for DCE because the label on the strap is pointed toward the X 21 connector Figure 9 Location of DTE DCE board 3 The DTE DCE daughter board is installed at the factory with the DTE label and arrows pointing towards the X 21 connector DTE configuration To change to DCE configuration lift the daughter board from the connector turn it around so that the DCE label an arrows point to the X 21 connector and place it back on the connector
104. low the warning instructions to avoid injury caused by electric shock gt WIAD AALS 14 Models 2603 2621 and 2635 User Manual About this guide Safety when working with electricity A This device contains no user serviceable parts The equipment shall be returned to Patton Electronics for repairs or repaired by qualified service personnel Mains Voltage Do not open the case the when the power cord is attached Line voltages are present within the power supply when the power cords are connected The mains outlet that is utilized to power the devise shall be within 10 feet 3 meters of the device shall be easily accessible and pro tected by a circuit breaker For AC powered units ensure that the power cable used meets applica ble standards for the country in which it is to be installed and that it is con nected to a wall outlet which has earth ground For units with an external power adapter the adapter shall be a listed Lim ited Power Source Hazardous network voltages are present in WAN ports regardless of whether power to the unit is ON or OFF To avoid electric shock use caution when near WAN ports When detaching the cables detach the end away from the device first Do not work on the system or connect or disconnect cables during periods of lightning activity In accordance with the requirements of council directive 2002 96 EC on Waste of Electrical and Electronic Equipment WEEE
105. n in the default out position the Ethernet circuitry takes on a straight through MDI configuration and functions as a transceiver It will connect directly to a hub When in the in position the Ethernet circuitry is configured in cross over MDI X mode so that a straight through cable can connect The OnSite Series router s Ethernet port directly to a PC s NIC card OnSite Series High Speed Routers overview 22 OnSite Series High Speed Routers overview 23 Chapter 2 Product Overview Chapter contents HON ee ean E E or ae pe rere er Pere eee Tere errr ee 25 Applications MCMV 26 24 Models 2603 2621 and 2635 User Manual 2 Product Overview Introduction The OnSite Series Router operates as a bridge or a router and has two ports for communication e The Ethernet port Connects to the LAN side of the connection e The Serial port Connects to local DTE devices Model 2621 and 2635 e The port Connects directly to T1 E1 lines Model 2603 The router provides all layer 2 and layer 3 protocols required for end to end link communication When configuring the OnSite router questions must be answered so the OnSite router functions as desired For example when a router or bridge module needs to be activated some questions would be Isa default gateway required Which encapsulation technique is best for this ap
106. nce When you have finished reviewing the reference click on the Go to Previous View Garamond blue type button in the Adobe Acrobat Reader toolbar to return to your starting point Futura bold type Commands and keywords are in boldface font Futura bold italic type Parts of commands which are related to elements already named by the user in boldface italic font Italicized Futura type Variables for which you supply values are in italic font Futura type Indicates the names of fields or windows Garamond bold type Indicates the names of command buttons that execute an action 16 Chapter 1 General Information Chapter contents 18 General ater UE Sd EEUU 18 ecce 19 E EA E 19 SUPPONE E 19 ME 19 19 SECURE t Ad 20 Front Panel Sextus LEDsand Console EIE 20 Console 21 Rese panel conecto and ere eMe d rU 21 EET 22 er 22 owner isu p ply esses R ERE EE e 22 Etherner port outlimed 10 green 22 MIDEX aum t
107. nge are within the subnet you defined above Alternatively you may check the Use a default range box to assign a suitable default address on this subnet Start of address range End of address range Use a default range DNS server option information Enter the addresses of Primary and Secondary ONS servers to be provided to DHCP clients on this subnet You may instead allow DACP server to specify its own IP address by clicking on the Use focal host address as DNS server checkbox Primary DNS server address Secondary DNS server address Use local host address as DNS server Default gateway option information Use local host as default gateway Create Reset Figure 56 DHCP server configuration web page Parameters for the DHCP Server subnet Four parameters are in the section for defining the DHCP subnet See figure 57 Parameters for this subnet Edit the definition of the DHCP subnet here If you do not wish to specify the subnet value and subnet mask by hand you may instead select an interface using the Get subnet from IP interface field The subnet will track the address and subnet mask belonging to the chosen interface Subnet value p NN Subnet mask Get subnet from IP interface Maximum lease time 7 seconds Default lease time 7 seconds Figure 57 DHCP Server subnet parameters The first two parameters are applicable when you wi
108. nt SNTP Client Mode Configuration Parameters SNTP Synchronization mode s Unicast Mode Enabled Disabled Anycast Mode Enabled Disabled Broadcast Mode Enabled C Disabled Set Mode Configured IP Address of SNTP Server 0 0 0 0 Update Figure 81 SNTP synchronization and server IP address configuration Introduction 105 Models 2603 2621 and 2635 User Manual 11 SNTP Client Configuration SNTP Client General Configuration Parameters The general configuration parameters for the SNTP client are for selecting your timezone and setting the poll ing parameters for the client s transmit packets e Current Timezone select the appropriate time zone and click on the Set New Timezone button The next three parameters configure the polling and synchronization process Timeout value The SNTP client will wait for the configured number of seconds of having no response from the server before retrying to send another time synchronization request The maximum timeout value is 30 seconds Default value is 5 seconds Packet retries When no response after the timeout period is received from the SNTP server the OnSite will send another request for the number times configured in this parameter The maximum number of retries is 10 Default value is 2 Polling value in minutes The SNTP client will automatically send a time synchronization request period ically If set to zero 0 the polling mechanism is disabled
109. on at www patton com By calling 1 301 975 1000 and speaking to a Technical Support Engineer e sending an e mail to returns patton com returned units must have the RMA number clearly visible on the outside of the shipping container Please use the original packing material that the device came in or pack the unit securely to avoid damage during ship ping Shipping instructions The RMA number should be clearly visible on the address label Our shipping address is as follows Patton Electronics Company RMA xxxx 7622 Rickenbacker Dr Gaithersburg MD 20879 4773 USA Patton will ship the equipment back to you in the same manner you ship it to us Patton will pay the return shipping costs Warranty Service and Returned Merchandise Authorizations RMAs 114 Appendix A Compliance information Chapter contents UGS comp estates 116 EME 116 116 e 116 TV 116 116 Representative 117 115 Models 2603 2621 and 2635 User Manual A Compliance information Compliance EMC FCC Part 15 Class A EN55022 Class EN55024 Safety UL60950 1 CSA 22 2 No 60950 1 EC EN 60950 1 AS NZS 60950 1 PSTN Regulatory These devices are not intended for connection to the PSTN Radio and TV Interference FCC Part 15 This equipment generate
110. on page 122 provides cable recommendations Appendix D on page 124 describes the router s ports Appendix E on page 129 describes how to use the command line interface CLI For best results read the contents of this guide before you install the router 13 Models 2603 2621 and 2635 User Manual About this guide Precautions Notes cautions and warnings which have the following meanings are used throughout this guide to help you become aware of potential problems Warnings are intended to prevent safety hazards that could result in per sonal injury Cautions are intended to prevent situations that could result in property damage or impaired functioning Note note presents additional information or interesting sidelights The alert symbol and IMPORTANT heading calls attention to important information gt IMPORTANT The alert symbol and CAUTION heading indicate a potential haz ard Strictly follow the instructions to avoid property damage gt shock hazard symbol and CAUTION heading indicate potential electric shock hazard Strictly follow the instructions to avoid property damage caused by electric shock gt 1 gt The alert symbol and WARNING heading indicate a potential safety hazard Strictly follow the warning instructions to avoid personal injury gt WIA The shock hazard symbol and WARNING heading indicate potential electric shock hazard Strictly fol
111. ond command creates a user who can login to the system For example the commands system add user fred user with dialin access system add login joe user with login access creates two new users called fred and joe The accounts are created with no passwords To view details about the new users enter system list users The following information is returned Users May May Access ID Name Conf Dialin Level Comment 2 1 fred disabled ENABLED default user with dialin access 2 joe ENABLED disabled default user with login access 3 admin ENABLED disabled superuser Default admin user Setting user passwords To change the password for the user you are currently logged in as use the command user password Enter the new password twice as prompted Enter new password Again to verify fi Administering user accounts 132 Models 2603 2621 and 2635 User Manual Command Line Interface CLI Operation Note check is made for any current password which may have been set for the user If you wish to change the password for another user enter the command user change lt username gt This command logs you into the system as another user You can then use the user password command to change the password for this user Note Changing to another user means that you lose all superuser privileges Note Only superusers can use t
112. ort 21 but data transfers are done on a separate connection or port The port number and who makes the connection can vary depending on the FTP client To allow FTP to work without triggers you would need to set up port filters allowing the correct port numbers through This is a significant security risk This risk can be avoided by using security triggers Triggers tell the security mechanism to expect these second ary sessions and how to handle them Rather than allowing a range of port numbers triggers handle the situa tion dynamically opening the secondary sessions only when appropriate The triggers work without needing to understand the application protocol or reading the payload of the packet although this does happen when using NAT Triggering allows you to set up a trigger for different application protocols that use multiple sessions The tim eout between sessions and whether or not session chaining are allowed are configurable Session chaining is not needed for FTP but is for NetMeeting Configuring the router The configuration of security assumes that the OnSite router has been configured with a valid IP address for the Ethernet port so that the user may access the modem via the web page If the IP address is still the factory default go to the section in Chapter 3 entitled IP Address Modification In this example the WAN transport between the two OnSite router Routers will be PPP routed 1 Click on under Servic
113. ple shows when the user must provide a parameter fi ip list clear add delete set attach attachbridge detach show interface ping fi ip interface name The name of the interface In this instance the interface name is 1 1 It is important that you do the inquiry to determine whether additional parameters follow fi ip interface 1 1 add delete clear list fi ip interface ipl list secondary ipaddresses fi ip interface ipl list secondaryipaddresses CLI Terminology 131 Models 2603 2621 and 2635 User Manual Command Line Interface CLI Operation ip interface ipl list secondaryipaddresses lt enter gt Secondary IP addresses for interface 1 1 ID IP Address In this example there was not a secondary IP address Now save the entire configuration in nonvolatile FLASH memory with the following command fi system config save Wait for the message that says Configuration Saved then reboot the modem with this command fi system restart Administering user accounts As admin user you can administer user accounts This section summarizes the CLI commands which can be used to administer user accounts Adding new users To add a new user username use the command system add user lt username gt Coment system add login user lt username gt lt Comment gt The first command creates a user who can access the system via a dialin connection using PPP for example The sec
114. plication Frame Relay PPP or another These decisions can be made and implemented more easily if The OnSite Series router s fundamental architecture is understood Also while configuring The OnSite Series router via a browser using the built in server is very intuitive an understanding of the architecture is essential when using the command line interface CLI commands The fundamental building blocks comprise a router or bridge interfaces and transports the router and bridge each have interfaces A transport provides the path between an interface and an external connection For exam ple the Ethernet transport attaches to an Internet Protocol IP interface A transport consists of layer 2 and everything below it Creating a transport and attaching it to a bridge or router s interface enables data to be bridged or routed The supported transports are PPPoE Frame Relay PPPoH and Ethernet Configuring an interface and transport for the router or bridge requires naming the interface and transport before attaching them When using the built in HTTP server web browser this is done automatically But when config uring The OnSite Series router via CLI commands through the RS 232 control port it must be done manually Introduction 25 Models 2603 2621 and 2635 User Manual 2 Product Overview Applications Overview Patton s OnSite Gateway routers deliver all the advanced features for secure reliable and high speed Inte
115. product shall be obeyed The conformity to the above directive is indicated by the CE sign on the device Compliance 116 Models 2603 2621 and 2635 User Manual A Compliance information Authorized European Representative D RM Green European Compliance Services Limited Avalon House Marcham Road Abingdon Oxon OX14 1UD UK Authorized European Representative 117 Appendix Specifications Chapter contents 119 ETT 119 e S E nce AE Ee rte 119 Ra E E 119 Protocol 120 SUP ete ere esce dein were suns 120 Mana es eter eter 120 RELI Up eL TEE eee 121 mcr d T PTT 121 Powerand Power Supply Specification tette e ehe eet 121 121 48 VIDC 121 118 Models 2603 2621 and 2635 User Manual Specifications General Characteristics Compact low cost router bridge 10 100 Ethernet Unlimited host support Comprehensive hardware diagnostics works with any operating system easy maintenance and effortless installation Built in web configuration Setup allows for standard IP address and unique method for entering an IP address and mask WITHOUT
116. ransport objects ID Name Port 1 eth2 ethernet 2 ethl ethernet Local VT 100 emulation A connection is made with the DB9 RJ45 adapter and an RJ45 RJ45 straight through cable Set the data rate to 9 600 baud 8 data bits one stop bits and no parity You may use a dumb terminal or a VT 100 emulation such as HyperTerminal Remote Telnet Establishing a Telnet session displays the same CLI configuration and status parameters on the display Using the Console The console commands needed for the various modes of operation are described in later sections In this sub section are the most basic commands needed for console operation By entering all the high level commands the keywords are seen Introduction 130 Models 2603 2621 and 2635 User Manual E Command Line Interface CLI Operation By entering a keyword followed by a space and the options available will print immediately without press ing enter The previously entered commands are reprinted on the next lines For example fi ethernet After typing the you will not see the add delete set show list clear fi ethernet Then you may enter one of the keywords on the displayed list followed by a space and To continue our example fi ethernet list ports transports fi ethernet list Then fi ethernet list transports fi ethernet list transports lt enter gt Ethernet transports ID Name Port Another exam
117. ress Transport Port Number 100 100 100 101 Set to 0 0 0 0 to use the primary IP address of the 10 10 1941 1 all E 65535 interface 0 Add Reserved Mapping Figure 54 NAT Reserved mapping configuration The PC on the Ethernet side of the OnSite can now communicate with the public or global side through NAT Introduction to NAT 81 Chapter 8 DHCP and DNS Configuration Chapter contents seer tier Sere CeCe PCCP Ree cee eee 83 Services and features normally associated with each other 83 DECP ital a Hanne e 84 dore 86 IP Addresses be available om this Sub el zoe RR EE 87 88 Default 89 Ta 89 T 89 DACP Relag eae 89 Dg ee cec M Mt M 91 Conheonne the DNS Relays eec EE 91 82 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Introduction The routers offer a DHCP Server DHCP Relay capability and DNS Relay incorporated into the OnSite Of the two DHCP features only one can be enabled at a time either DHCP server or DHCP relay DNS relay can hold two D
118. rized modification If the product fails to perform as warranted your sole recourse shall be repair or replacement as described above Under no condition shall Patton Electronics be liable for any damages incurred by the use of this product These damages include but are not limited to the following lost profits lost savings and incidental or consequential damages arising from the use of or inability to use this product Patton Electronics specifically disclaims all other warran ties expressed or implied and the installation or use of this product shall be deemed an acceptance of these terms by the user Note Conformity documents of all Patton products can be viewed online at www patton com under the appropriate product page Summary Table of Contents 5 A gt N 13 gt EE 17 PEM 24 2 IU 27 Eheroct 40 IC m C EI 44 S 50 Nic E 68 and DNS 82 93
119. rn and invalid selection message Line Options Choose from Clear Channel E1 G 703 or Channelized E1 G 703 G 704 Consult with your service provider which option is required Line Code Choose from AMI or HDB3 Most E1 applications use HDB3 Line Build Out Select 120 Ohms if the 1 connection is made via the RJ 48C connector select 75 Ohm if the E1 connection is made via the dual BNC connectors FDL Mode FDL is a 1 application therefore select Fdl none for E1 applications Clocking Mode Options are Internal or Receive Recover Clock network In most applications clocking for the 2603 will be derived from the E1 network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Options are Enabled or Disabled When idle code is Enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Options are Normal and Powerdown When powered down the E1 will put high impedance on the input and output lines to protect the device set unit to Normal for regular operation Once all options have been selected click on the Configure and Activate button at the bottom of the screen Additionally save the configuration by going to the System Configuration Save menu This concludes the 1 interface configuration via the web browser go to section WAN Service Configura tion on page 52 for instructions on router brid
120. rnet data connections They combine ease of use with powerful data routing to make shared Internet connectivity simple and easy With NAT support the OnSite routers offer convenient and economical operation by using a single IP address while the integrated DHCP server automates IP address assignment for connected LAN computers Security is standard with built in firewall and violation alerting features that protect the network from would be intruders 2603 IPLink Figure 3 T1 E1 Application Applications Overview 26 Chapter 3 Initial Configuration Chapter contents eee ene eee EU 28 Nhat you will need 28 te e eel ee a er 28 Installing an interlace cable oo te IPLink 26058 interface port nee 29 Installing an interface cable on the IPLink 2621s eerte 31 Installing an interface Plink 2635 5 V 39 interface Pott xe esee eret eee 33 E ee 34 36 37 Operon and 37 cay le AUN en Ht m 37 Msc ETE 37 27 Models 2603 2621 2635 User Manual Initial Configuration Hardware installation If you are already familiar with OnSite Series Router installation and configuration this chapter will enable you to fin
121. s DoS Detection protection Intrusion detection Logging of session blocking and intrusion events and Real Time alerts Logging or SMTP on event Password protected system management with a username password for console and virtual terminal Sepa rate user selectable passwords for SNMP RO RW strings Access list determining up to 5 hosts networks which are allowed to access management system SNMP HTTP TELNET Logging or SMTP on events POST POST errors PPP DHCP IP Dimensions 1 58H x 4 16W x 3 75D in 10 6H x 4 1W x 8 8D cm Power and Power Supply Specifications The OnSite router may come with either an AC or DC power supply AC universal power supply The OnSite Series router offers internal or external AC power supply options The internal power supply connects to an AC source via an IEC 320 connector 100 240 VAC 200 mA 50 60 Hz The external power supply connects to an external source providing 5 VDC via a barrel type connector 48 VDC power supply Rated voltage and current 36 60 VDC 400 mA The DC power supply connects to a DC source via a terminal block Connect the equipment to a 36 60 VDC source that is electri j cally isolated from the AC source The 36 60 VDC source is to be reliably connected to earth Security 121 Appendix Cable Recommendations Chapter contents ac tela able EIS Ceu IEEE EE EUH does 123 UID
122. s and uses radio frequency energy and if not installed and used properly that is in strict accordance with the manufacturer s instructions may cause interference to radio and television recep tion This equipment has been tested and found to comply with the limits for a Class A computing device in accordance with the specifications in Subpart B of Part 15 of FCC rules which are designed to provide reason able protection from such interference in a commercial installation However there is no guarantee that inter ference will not occur in a particular installation If the equipment causes interference to radio or television reception which can be determined by disconnecting the cables try to correct the interference by one or more of the following measures moving the computing equipment away from the receiver re orienting the receiving antenna and or plugging the receiving equipment into a different AC outlet such that the computing equip ment and receiver are on different branches CE Declaration of Conformity We certify that the apparatus described above conforms to the requirements of Council Directive 2004 108 EC on the approximation of the laws of the member states relating to electromagnetic compatibility and Council Directive 2006 95 EC on the approximation of the laws of the member states relating to electrical equipment designed for use within certain voltage limits The safety advice in the documentation accompanying this
123. s given authority to configure the OnSite but the default settings have disabled the ability to authenticate through a remote connection To enable remote access authentication click on Edit user To add another user account click on Create a new user See figure 69 You will define the new user by Introduction 97 Models 2603 2621 and 2635 User Manual 10 System Configuration creating a Username defining the Password give the user ability to configure the OnSite or read only authority addacomment useful to the administrator Authentication create user Details for new user Username Password R May Configure false May Dial in false Comment Create Reset Cancel and return to Authentication Setup Figure 69 Creating new user Alarm Access the configuration and status of the alarms Alarm Management This page shows the table of alarms reported by the device Alarm State No Alarms Modify Alarms Alarm Error Log Reporting Log Severity Level Major Log Alarm State Enabled Alarm Table ID Alarm Name Alarm Severity Time Generate Clear Active Reset Alarm Condition Alarm 1 Over Threshold Major 00 00 00 0 Generate Clear Reset 2 Over Threshold Major 00 00 00s 0 Generate Clear Reset 3 T1 E1 Loss of Signal Major 00 00 008 0 Generate Clear Reset 0 Generate Clear Reset 5
124. sends the request directly to the appropriate DNS server The OnSite router merely forwards the packet The third parameter is Use local host address as DNS server which is the IP address of the OnSite In this sce nario the client considers the OnSite as a DNS server by sending all requests to the OnSite s IP address The OnSite forwards the request to the DNS servers using the IP address of the actual servers You still need to define the IP addresses of the primary and secondary DNS servers in the section because the OnSite needs to know in order to forward the DNS requests Introduction 88 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Default gateway option information The OnSite is the gateway all client traffic when Use local host as default gateway is checked see figure 61 Additional option information You may wish to provide additional information to the clients on the DHCP subnet Click on the hyperlink Create new DHCP option to access the configuration webpage The options can specify default gateway Domain name IRC server HTTP server e SMTP server POP3 server e NNTP server e WINS server Time servers Refer to figure 61 as an example of multiple options to be sent to the clients Default gateway option information Use local host as default gateway Additional option information Add and remove items from this list to configure additional option informa
125. sole port locations Model 2603 shown Installing the Ethernet cable Do the following The interconnecting cables shall be acceptable for external use and shall be rated for the proper application with respect to volt A age current anticipated temperature flammability and mechanical serviceability 1 Connect the DB9 RJ45 adapter to the DB 9 serial port on the PC or dumb terminal Use the RJ45 RJ45 straight through cable between the adapter and the red marked RJ45 port on the OnSite Router 2 Do not connect the router to the Ethernet LAN at this time 3 On the PC start a terminal emulation session such as or HyperTerminal at 9600 bps 8 data bits 1 stop bit and no parity 4 Plug the AC power cord into The OnSite Series router to power up the router Type superuser for Login and press Enter 6 Then type superuser for the password press Enter Hardware installation 36 Models 2603 2621 and 2635 User Manual Initial Configuration 7 Amessage will display Login Successful By typing the character all the commands will be displayed Login superuser Password Login successful gt 8 Any commands parameters may be seen by entering the command followed space and a question mark fi ethernet The following parameters appear add delete set show list clear IP address modification The first parameter to change is the IP address from the default IP ad
126. stallation 3A Models 2603 2621 and 2635 User Manual Initial Configuration Internal power supply connector Power External power supply connector Figure 12 Power connector location rear panel Model 2603 T shown The OnSite router power supply automatically adjusts to accept an input voltage from 100 to 240 VAC 50 60 Hz Verify that the proper voltage is present before plugging the power cord into the receptacle Failure to do so could result in equipment damage 3 Verify that the AC power cord included with your OnSite router is compatible with local standards If it is not refer to chapter 13 Contacting Patton for assistance on page 112 to find out how to replace it with a compatible power cord 4 Connect the male end of the power cord to an appropriate power outlet Verify that the green Power LED is lit see figure 13 6 Unplug the AC power cord from the OnSite Series router to power down the unit Hardware installation 35 Models 2603 2621 and 2635 User Manual Initial Configuration Model 2603 ipLink Gateway High Speed WAN Access Router EO OOOO VSG L Ethernet d Console iii WAN Link WANTD Ethernet Ethernet Tx Ethernet Rx Console LED LED i LED LED port Link WAN Frame E Ethernet LED LED 100M LED Figure 13 OnSite front panel LEDs and Con
127. structions in this guide are based on the following assumptions e The router may connect to a serial DTE device or T1 E1 line There is a LAN connected to the Ethernet port of the router Audience This guide is intended for the following users Operators Installers Maintenance technicians Structure This guide contains the following chapters and appendices e Chapter 1 on page 17 provides information about router features and capabilities Chapter 2 on page 24 contains an overview describing router operation Chapter 3 on page 27 provides initial configuration procedures e Chapter 4 on page 40 describes configuring the Ethernet LAN interface e Chapter 5 on page 44 describes configuring the serial WAN interfaces Chapter 6 on page 50 describes configuring WAN services Chapter 7 on page 68 describes configuring security for the router Chapter 8 on page 82 describes DHCP and DNS configuration Chapter 9 on page 93 describes configuring IP services e Chapter 10 on page 96 describes system configuration Chapter 11 on page 104 describes SNTP client configuration e Chapter 12 on page 108 provides a summary of the OnSite s status webpage and status LEDs e Chapter 13 on page 112contains information on contacting Patton technical support for assistance Appendix on page 115 contains compliance information for the OnSite routers Appendix B on page 118 contains specifications for the routers Appendix C
128. t available at http www patton com E mail support e mail sent to support patton com will be answered within 1 business day Telephone support standard telephone support is available 5 days a week from 8 00am to 5 00pm EST 1300 to 2200 UTC GMT by calling 1 301 975 1007 e 253 663 5693 Alternate Patton support for Europe Middle East and Africa EMEA Online support available at http www patton inalp com E mail support email sent to support patton inalp com will be answered within 1 day Telephone support standard telephone support is available five days week from 8 00 am to 5 00 pm 0900 1800 UTC GMT by calling 41 0 31 985 25 55 e Fax 441 0 31 985 25 26 Warranty Service and Returned Merchandise Authorizations RMAs Patton Electronics is an ISO 9001 certified manufacturer and our products are carefully tested before ship ment All of our products are backed by a comprehensive warranty program Note Ifyou purchased your equipment from a Patton Electronics reseller ask your reseller how you should proceed with warranty service It is often more con venient for you to work with your local reseller to obtain a replacement Pat ton services our products no matter how you acquired them Warranty coverage Our products are under warranty to be free from defects and we will at our option repair or replace the prod uct should it fail within one year from the first dat
129. t and netmask the origin of the subnet maximum lease time and default lease time P addresses to be available on this subnet either define the IP address range for the DHCP server IP pool or use the default range which is a set of 20 IP addresses DNS server option information enter the IP addresses of the primary and secondary DNS servers which provided to the DHCP clients Default gateway option information You may use the local host as the default gateway figure 56 shows the entire configuration web page for the DHCP server Introduction 85 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Create new DHCP server subnet This page allows you to set up a new DHCP server subnet so that the system can assign IP address subnet mask and option configuration parameters to DHCP clients Parameters for this subnet Define your new DHCP subnet here If you do not wish to specify the subnet value and subnet mask by hand you may instead select an interface using the Get subnet from interface field A suitable subnet will be created based on the address and subnet mask belonging to the chosen interface Subnet value Subnet mask Get subnet from IP interfac none Maximum lease time 86400 seconds Default lease time 43200 seconds IP addresses to be available on this subnet You need to make sure that the start and end addresses offered in this ra
130. the WAN service link and also the Ethernet port of the remote OnSite which we just configured 1 Bring up the web page management system on your browser by entering the IP address of the IPlink 192 168 172 3 2 On Menu go to Service Configuration then to WAN Delete the default WAN services already defined 3 Click on Create a new service in the main window select PPP routed and click on the Continue button In the Description field enter the description In this example it is called PPP Routed Description PPP Routed Interface 1 e WAN IP address and Mask 192 168 164 3 255 255 255 255 LLC Header Mode off HDLC Header Mode ON No authentication WAN Service Configuration 57 Models 2603 2621 and 2635 User Manual 6 WAN Services Username blank Password blank Click on the Create button 4 Go to Services Configuration gt WAN gt Edit for PPP routed gt Edit TP Interface gt Ipaddr enter the WAN IP Address and Mask in this example 192 168 164 3 and 255 255 255 255 Click on Create Go to Configuration Menu Configuration IP Routes Click on Create new Ip V4 Route 7 Create the gateway to the remote OnSite by entering the WAN IP address of the remote OnSite in this example enter 192 168 164 2 in the Gateway field 8 Click OK The other fields should be e Destination 0 0 0 0 e Gateway 192 168 164 2 e Mask 0 0 0 0 e Cost 1 Interface blank
131. the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to for bridged applications the port should be set to fr Click on the Create button This conclude the central site configuration Frame Relay Routed This application shows the configuration for two OnSite units in routed mode If using a third party router at the Central site review the router s configuration for connection to a remote bridge Remote Central Figure 37 Frame Relay routed application Remote Site Configuration First configure the IP address of the OnSite s Ethernet port interface ip1 via the command line CLI for 192 168 100 2 24 The PC must be on the same subnet for configuring the OnSite via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the OnSite WAN Service Configuration 63 Models 2603 2621 and 2635 User Manual 6 WAN Services 2 On Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined Click on Create a new service in the main window select Frame Relay routed and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service See figure 38 WAN connection Frame Relay routed Description FRro
132. those hosts which have validators Apply Figure 49 Deleting a Security Policy Enabling the Firewall At this point both security and the firewall can be enabled and the network is secure All the interfaces which have been defined are protected that is all traffic has been blocked between the internal ip1 and external ppp 0 interfaces Only traffic which has validators is allowed to pass through and at this moment there no validators 1 Return to the Security page 2 Under Security State select Enabled for Security Click on Change State 3 Next select Enabled for Firewall Click on Change State The network is now secure All the interfaces which have been defined are protected and all traffic is blocked between different the different interface types That is all traffic is blocked between the external and internal interfaces The next section describes how to configure the Firewall for allowing certain types of data transfer to occur between the PC s on different networks Firewall Portfilters Next we configure the Firewall to permit certain types of data transfer between the PCs in general hosts on the different networks This is done by the implementation of Firewall portfilters Portfilters are individual rules that determine what kind of traffic can pass between two interface types For the Protocol Number below the different types are defined as Abbreviation 1
133. tion you would like the DHCP server to give to clients on this subnet Name Value Delete default gateway 10 11 12 13 domain name idealnetdomain rn nntp server 10 15 1 1 netbios name servers 10 10 1 11 10 10 1 12 O Create new DHCP option Update Reset Figure 61 DHOP server optional information example DHCP Relay With this webpage you can enter list of IP addresses for DHCP servers When a client requests IP address it uses one of the DHCP addresses listed in the DHCP relay webpage The OnSite forwards or relays the request to the DHCP server Note Do not use the OnSite s DHCP server if the DHCP Relay is enabled Configuration of the DHCP Relay The DHCP Relay webpage has three sections See figure 62 Enable disable The button the first section enables or disables the DHCP relay on the OnSite router Introduction 89 Models 2603 2621 and 2635 User Manual 8 DHCP and DNS Configuration Edit DHCP server list The IP addresses of DHCP servers can be updated reset or deleted from the list Add new DHCP server the IP addresses of the DHCP servers are added to the DHCP relay list in this sec tion In the first section of the DHCP Relay webpage click on the Enable button on the DHCP Relay webpage DHCP Relay This page allows you to enter a list of DHCP server IP addresses that the relay will forward DHCP packets to You may also enable and disable the DHCP re
134. use of a console connection Default IP address of 192 168 200 10 24 Simple software upgrade using FTP into FLASH memory Front panel LEDs indicate Power WAN Ethernet LAN speed and status Field Factory Default Option Standard 1 year warranty Ethernet e Auto sensing Full Duplex 10Base T 100Base TX Ethernet Standard RJ 45 and built in MDI X cross over switch EEE 8021 d transparent learning bridge up to 1 024 addresses 81 address subnets on Ethernet interface Sync Serial Interface ITU T X 21 or V 35 interface Available with female DB 25 and DB 15 connectors User configurable DTE DCE for X 21 T1 E1 Interface Line Rate 1 544 Mbps T1 and 2 048 Mbps E1 RJ 48C connector also includes dual BNC for E1 connections e DSX 1 levels for connection to local T1 E1 device PBX e Nx56 64 kbps with full DSO mapping e AMI B8ZS 1 AMI HDB3 E1 ESF coding and framing T1 General Characteristics 119 Models 2603 2621 and 2635 User Manual Specifications Protocol Support Complete internetworking with IP RFC 741 TCP RFC 793 UDP RFC 768 ICMP RFC 950 ARP RFC 826 IP Router with RIP RFC 1058 RIPv2 RFC 2453 Up to 64 static routes with user selectable priority over RIP OSPF routes Built in ping and traceroute facilities Integrated DHCP Server RFC 2131 Selectable general IP leases and user specific MAC IP parings Selectable lease period DH
135. uted 1 DLCI moo Encapsulation method Routed gt Use DHCP 6 WAN IP address 192 168 164 2 Enable NAT on this interface Figure 38 Frame Relay routed configuration Description FR routed DLCI Enter DLCI number Consult with your service provider for DLCI number required Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Choose the encapsulation method best suited for your network needs from the following options Routed IP default value Raw WAN IP address Enter the IP address assigned to the WAN port V 35 X 21 or T1 E1 Enable NAT on this interface In this example leave this option blank Click the Create button Go to System Configuration gt WAN gt Edit for Frame Relay Routed service gt Edit Interface Enter the WAN IP Address in this example 192 168 164 2 and click on the Create button From the Interface web page click on Edit Frame Relay then click Edit Frame Relay Channel See figure 39 WAN Service Configuration 64 Models 2603 2621 2635 User Manual 6 WAN Services Edit Frame Relay Edit Frame Relay Channel Edit Frame Relay Channel Options Name Value Dici 41 Encaps Type RoutedlP Rx Pdu 127 Tx Pdu 127 Chnl Segment Size hp o Port ho Port Class framerelay Create Reset Figure 39 Frame Relay Channel Routed configurat
136. ver disable IP Services 94 Associated Ports for the different System IP Services This section is for information purposes only Consult the table to identify which ports are associated with the different System IP Services Table 5 Standard port numbers for the System Services System IP Service WEB Server 80 80 IP Services 95 Chapter 10 System Configuration Chapter contents 97 ELA UNO cs E 97 Mo 98 NEMO RE ACCESS ne rca Dt D T 99 100 100 Beate kage 100 Escape v d 101 E A A 101 102 re t He Le e 102 rcu M gts 103 96 Models 2603 2621 and 2635 User Manual 10 System Configuration Introduction The System Configuration item on the Configuration Menu opens to provide access to twelve 12 different items They are Authentication allows you to control access to the OnSite s console and web configuration pages Alarm shows the Alarm Table and CPU Usage Settings You can configure the alarm severity for each of the alarms and
137. web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the 1 1 gt Configuration See figure 26 T1 E1 Configuration Configuration Options Time Slot Select INN Payload Rate 1984K 31 Line Options Channelized E1 G 703 G 704 Code Sel Line Build Out 120 Ohm X FDL Mode Fd none gt Clocking Mode Receive Clock Idle Codes Enabled Power Down Normal ___ Configure and Activate Figure 26 E1 port configuration Time Slot Select For unframed E1 service Clear Channel go to the Line Option parameter and select Clear Channel E1 G 703 For a full framed E1 enter 1 31 for partially filled E1 enter the range of timeslots using the format for example 1 2 3 5 or 1 5 10 31 Any entry for timeslots above 31 will return and invalid selection message Line Options Choose from Clear Channel E1 G 703 or Channelized E1 G 703 G 704 Consult with your service provider which option is required Line Code Choose from AMI or HDB3 Most E1 applications use HDB3 Line Build Out Select 120 Ohms if the E1 connection is made via the RJ 48C connector select 75 Ohm if the E1 connection is made via the dual BNC connectors FDL Mode FDL is a T1 application therefore select Fdl none for E1 applications Clocking Mode Options are Internal or Receive Recover Clock network In most app
Download Pdf Manuals
Related Search
Related Contents
Surebonder 9615A-300-3 Instructions / Assembly Schlage BE469NX V CAM 716 Instructions / Assembly User Manual Double Seat Swivel Wheel Jogging Stroller User`s Manual USER MANUAL - Future Mobility Healthcare Copyright © All rights reserved.
Failed to retrieve file