Planet IVR-300W - Network router

IVR-300W - Network router Planet - Free user manual and instructions

Find the device manual for free IVR-300W Planet in PDF.

📄 146 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice Planet IVR-300W - page 7
Pick your language and provide your email: we'll send you a specifically translated version.
Product TypeIndustrial VPN Security Gateway with Wi-Fi 6
ModelIVR-300W
Ports4 x 10/100/1000T RJ45 LAN, 1 x 10/100/1000T RJ45 WAN/LAN
Wireless StandardIEEE 802.11a/b/g/n/ac/ax (Wi-Fi 6)
Wireless SpeedUp to 600 Mbps (2.4 GHz) + 1200 Mbps (5 GHz)
Antenna2 external dual-band RP-SMA antennas (5 dBi)
USB Port1 x USB 3.0 for configuration backup and firmware upgrade
Serial Interface1 x 3-pin terminal block for RS-485
Digital I/O2 Digital Inputs, 2 Digital Outputs
Power InputDual redundant DC 9-54V, terminal block
Power ConsumptionMax 15.6W
Dimensions (W x D x H)50 x 135 x 135 mm
Weight773 g
EnclosureIP30 metal case
Operating Temperature-40°C to 75°C
Storage Temperature-40°C to 85°C
MountingDIN-rail, wall mount, side wall mount
VPN FeaturesIPSec, GRE, PPTP, L2TP, SSL (OpenVPN), up to 60 tunnels
FirewallSPI, DoS/DDoS protection, content filtering, MAC/IP filtering
Routing ProtocolsStatic, RIP, OSPF
ManagementWeb GUI, SNMP v1/v2c/v3, PLANET Smart Discovery, CloudViewer
Maintenance and CleaningDisconnect power before cleaning; wipe with dry cloth; keep ventilation clear; no internal user-serviceable parts
Safety PrecautionsUse only supplied power; avoid moisture and extreme temperatures; follow installation guide for wiring
Spare Parts and RepairabilityAntennas are replaceable (RP-SMA); power supply is external; no other user-replaceable parts; contact dealer for service
General InformationCompliant with CE, FCC; supports IPv4/IPv6; includes captive portal and RADIUS server

Frequently Asked Questions - IVR-300W Planet

How to reset the IVR-300W to factory defaults?
Press and hold the Reset button on the front panel for more than 5 seconds while the device is powered on. The device will reboot and restore all settings to factory defaults.
What is the default IP address and login credentials?
Default IP address is 192.168.1.1. Default username and password are both admin (case-sensitive). It is strongly recommended to change them upon first login.
How to configure the Wi-Fi settings on the IVR-300W?
Access the web interface, go to Wireless menu, and select 2.4GHz WiFi or 5GHz WiFi. You can set SSID, security encryption (e.g., WPA2-PSK), channel, and bandwidth. Default SSIDs are PLANET_2.4G and PLANET_5G.
Can the IVR-300W be mounted on a DIN rail or wall?
Yes, the device supports DIN-rail mounting (with included bracket), wall mount (using the provided wall-mount plate), and side wall mount. Follow the instructions in Chapter 2 of the manual.
What is the maximum number of VPN tunnels supported?
The IVR-300W supports up to 60 VPN tunnels concurrently, including IPSec, GRE, PPTP, L2TP, and SSL (OpenVPN).
How to update the firmware?
Download the latest firmware from PLANET's website. In the web interface, go to Maintenance > Firmware Upgrade. Click Choose File to select the firmware file, then click Upgrade. Alternatively, you can use a USB flash drive (FAT32) via the USB port.
What is the operating temperature range?
The IVR-300W can operate in temperatures from -40°C to 75°C (-40°F to 167°F), making it suitable for harsh industrial environments.
How to enable remote management via the internet?
In the web interface, go to System > Wizard or Security settings to enable Remote Management. You must also configure port forwarding on your router if the device is behind NAT. For cloud management, use PLANET CloudViewer service.
Can I use PoE to power the IVR-300W?
No, the IVR-300W does not support PoE power input. It requires a DC power supply (9-54V) via the terminal block. PoE output is only available on the IVR-300FP model.
How to set up a VPN connection between two IVR-300W devices?
Configure an IPSec VPN: on each device, go to VPN > IPSec and create a tunnel. Set the remote gateway IP (WAN IP or DDNS), pre-shared key, and encryption parameters (e.g., AES-256, SHA-256). Ensure routing and firewall rules allow VPN traffic. Detailed steps are in the manual's VPN section.

User questions about IVR-300W Planet

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Network router in PDF format for free! Find your manual IVR-300W - Planet and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. IVR-300W by Planet.

USER MANUAL IVR-300W Planet

natural_image Four blue network switch units with green connectors and a black cable, no visible text or symbols on the devices themselves.

User's Manual

Industrial 5-Port 10/100/1000T VPN Security Gateway

IVR-100 & IVR-300 Series

Planet IVR-300W - Industrial 5-Port 10/100/1000T VPN Security Gateway - 1

natural_image Man in white shirt and tie using laptop in server rack (no visible text or symbols)

Copyright (C) 2023 PLANET Technology Corp. All rights reserved.

The products and programs described in this User's Manual are licensed products of PLANET Technology, This User's Manual contains proprietary information protected by copyright, and this User's Manual and all accompanying hardware, software, and documentation are copyrighted.

No part of this User's Manual may be copied, photocopied, reproduced, translated, or reduced to any electronic medium or machine-readable form by any means, electronic or mechanical including photocopying, recording, or information storage and retrieval systems, for any purpose other than the purchaser's personal use, and without the prior express written permission of PLANET Technology.

Disclaimer

PLANET Technology does not warrant that the hardware will work properly in all environments and applications, and makes no warranty and representation, either implied or expressed, with respect to the quality, performance, merchantability, or fitness for a particular purpose.

PLANET has made every effort to ensure that this User's Manual is accurate; PLANET disclaims liability for any inaccuracies or omissions that may have occurred. Information in this User's Manual is subject to change without notice and does not represent a commitment on the part of PLANET. PLANET assumes no responsibility for any inaccuracies that may be contained in this User's Manual. PLANET makes no commitment to update or keep current the information in this User's Manual, and reserves the right to make improvements and/or changes to this User's Manual at any time without notice.

If you find information in this manual that is incorrect, misleading, or incomplete, we would appreciate your comments and suggestions.

FCC Compliance Statement

This Equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications.

However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:

  • Reorient or relocate the receiving antenna.
  • Increase the separation between the equipment and receiver.
  • Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
    Consult the dealer or an experienced radio/TV technician for help.

CE mark Warning

Planet IVR-300W - CE mark Warning - 1

The is a class A device, In a domestic environment, this product may cause radio interference, in which case the user may be required to take adequate measures.

Safety

This equipment is designed with the utmost care for the safety of those who install and use it. However, special attention must be paid to the dangers of electric shock and static electricity when working with electrical equipment. All guidelines of this and of the computer manufacture must therefore be allowed at all times to ensure the safe use of the equipment.

WEEE

Planet IVR-300W - WEEE - 1

To avoid the potential effects on the environment and human health as a result of the presence of hazardous substances in electrical and electronic equipment, end users of electrical and electronic equipment should understand the meaning of the crossed-out wheeled bin symbol. Do not dispose

of WEEE as unsorted municipal waste and have to collect such WEEE separately.

Trademarks

The PLANET logo is a trademark of PLANET Technology. This documentation may refer to numerous hardware and software products by their trade names. In most, if not all cases, these designations are claimed as trademarks or registered trademarks by their respective companies.

Revision

User's Manual of PLANET Industrial 5-Port 10/100/1000T VPN Security Gateway

Model: IVR-100, IVR-300, IVR-300W, IVR-300FP

Rev.: 1.2 (June, 2023)

Part No. EM-IVR-100_IVR-300 Series_v1.2

Table of Contents

Chapter 1. Product Introduction....7

1.1 Package Contents....7
1.2 Overview 8
1.3 Features 15
1.4 Product Specifications....18

Chapter 2. Hardware Introduction....23

2.1 Physical Descriptions 23

2.1.1 Front View....23
2.1.2 Top View....27
2.1.3 Wiring the Power Inputs....28
2.1.4 Wiring the Fault Alarm Contact 29
2.1.5 Dimensions 30

2.2 Hardware Installation 34

2.2.1 DIN-rail Mounting 34
2.2.2 Wall Mount Plate Mounting 36
2.2.3 Side Wall Mount Plate Mounting....37
2.2.4 Wi-Fi Antenna Installation 38

Chapter 3. Preparation ....39

3.1 Requirements 39
3.2 Setting TCP/IP on your PC....39

3.2.1 Windows 7/8 39
3.2.2 Windows 10 43

3.3 Planet Smart Discovery Utility....46

Chapter 4. Web-based Management....48

4.1 Introduction....48
4.2 Logging in to the VPN Gateway 48
4.3 Main Web Page....51
4.4 System 53

4.4.1 Wizard 55
4.4.2 Dashboard 62
4.4.3 Status....65
4.4.4 System Service 66
4.4.5 Statistics....67
4.4.6 Connection Status....67

4.4.7 SFP Module Information 68

4.4.8 High Availability....69

4.4.9 RADIUS....70

4.4.10 Captive Portal 72

4.4.11 SNMP 73

4.4.12 NMS 74

4.4.13 Fault Alarm 76

4.4.14 Digital Input / Output 77

4.4.15 Modbus 79

4.4.16 Remote Syslog....80

4.5 Network 81

4.5.1 Priority 82

4.5.2 WAN....83

4.5.3 WAN Advanced 85

4.5.4 LAN 86

4.5.5 Multi-Subnet....86

4.5.6 VLAN 87

4.5.7 UPnP 87

4.5.8 Routing....88

4.5.9 RIP 90

4.5.10 OSPF 90

4.5.11 IGMP 90

4.5.12 IPv6....91

4.5.13 DHCP 92

4.5.14 DDNS....93

4.5.15 MAC Address Clone....95

4.6 Security 96

4.6.1 Firewall....97

4.6.2 MAC Filtering 99

4.6.3 IP Filtering....100

4.6.4 Web Filtering....101

4.6.5 Port Forwarding 102

4.6.6 QoS....103

4.6.7 DMZ 104

4.7 VPN 105

4.7.1 IPSec....107

4.7.2 IPsec Remote Server....110

4.7.3 GRE 110

4.7.4 PPTP 112

4.7.5 L2TP....113

4.7.6 SSL VPN 115
4.7.7 Certificates 116
4.7.8 VPN Connection 116
4.7.9 SD WAN....116

4.8 AP Control 117

4.8.1 Preference 119
4.8.2 AP Search....119
4.8.3 AP Management 120
4.8.4 AP Group Management 121
4.8.5 SSID Profile 122
4.8.6 Radio 2.4GHz Profile 124
4.8.7 Radio 5GHz Profile....125
4.8.8 Statistics AP Status....126
4.8.9 Map It 126
4.8.10 Upload Map....127

4.9 Wireless....128

4.9.1 2.4GHz WiFi....129
4.9.2 5GHz WiFi....130
4.9.3 MAC ACL 131
4.9.4 Wi-Fi Advanced....132
4.9.5 Wi-Fi Statistics 133
4.9.6 Connection Status....133

4.10 Power over Ethernet 134

4.10.1 PoE Configuration....134
4.10.2 PoE Status....136
4.10.3 PoE Schedule 136
4.10.4 PD Alive Check 138

4.11 Maintenance....139

4.11.1 Administrator....140
4.11.2 Date and Time....141
4.11.3 Saving/Restoring Configuration 142
4.11.4 Firmware Upgrade 143
4.11.5 Reboot / Reset 144
4.11.6 Auto Reboot....144
4.11.7 Diagnostics 145

Appendix A: DDNS Application 146

Chapter 1. Product Introduction

Thank you for purchasing PLANET Industrial Security Gateway, IVR-100 and IVR-300 series. The descriptions of these models are as follows

IVR-100Industrial 5-Port 10/100/1000T VPN Security Gateway
IVR-300Industrial 5-Port 10/100/1000T VPN Security Gateway with Redundant Power
IVR-300WIndustrial 5-Port 10/100/1000T + 802.11ax Wi-Fi VPN Security Gateway
IVR-300FPIndustrial 4-Port 10/100/1000T 802.3at PoE + 1-Port 10/100/1000T + 1-Port 1000XSFP VPN Security Gateway

"VPN Gateway" mentioned in the manual refers to the above models.

1.1 Package Contents

The package should contain the following:

Item\ModelIVR-100IVR-300IVR-300WIVR-300FP
VPN Gatewayx 1x 1x 1x 1
Quick Installation Guidex 1x 1x 1x 1
Wall-mount Kitx 1x 1x 1x 1
RJ45 Dust Capx 5x 5x 5x 5
SFP Dust Capx 1
CloudViewer QIGx 1x 1x 1x 1
RS485 3-pin Terminal Block-x 1x 1x 1
Dual band Wi-Fi Antenna--x 2-
Antenna Dust Cap--x 2-

Planet IVR-300W - Package Contents - 1

Note

If any of the above items are missing, please contact your dealer immediately.

1.2 Overview

Powerful Industrial VPN Security Solution

PLANET has launched the IVR-100 and IVR-300 Series Security Gateway for demanding applications. It features five Ethernet ports (4 LANs and 1 WAN), IEEE 11ax Wi-Fi capability (for IVR-300W), one Fiber port (for IVR-300FP), RS485 serial port (for IVR-300 series), and DI and DO interfaces. Incorporating SD-WAN function, it can greatly increase WAN optimization for multiple WAN links to be managed.

Furthermore, its Dual-WAN Failover and Outbound Load Balance features can improve the network efficiency while the web-based interface provides friendly and user experience.

It's ideal for the harsh environment as it can operate stably at temperatures from -40 to 75 degrees C. Its compact IP30 metal case allows either DIN-rail or wall mounting for efficient use of cabinet space.

Enjoy Fast Wi-Fi 6 Industrial Network with Advanced Security SD-WAN WAN Fallover Modbus TCP Hybrid VPN 1800Mbps Wireless Speed 9:54V DC in Cyber Security

Comprehensive Industrial Wireless SD-WAN Gateway Industrial 5-Port 10/100/1000T + 802.11ax Wi-Fi VPN Security Gateway ▶ IVR-300W

Flexible WAN interface Enables Extension of Network Deployment (For IVR-300FP)

The IVR-300FP provides both copper and fiber connectors for WAN interface. With one SFP slot, it supports fiber extension for FTTX application. It allows the administrator to flexibly choose the suitable SFP transceiver according to the transmission distance required to extend the network efficiently. The distance can be extended from 550 meters to 2 kilometers (multi-mode fiber) and 10/20/30/40/50/60/70/120 kilometers (single-mode fiber or WDM fiber). They are well suited for applications to uplink to backbone switch and monitoring center in long distance.

Intelligent SFP Diagnosis Mechanism (For IVR-300FP)

The IVR-300FP supports SFP-DDM (digital diagnostic monitor) function that greatly helps network administrator to easily monitor real-time parameters of the SFP, such as optical output power, optical input power, temperature, laser bias current, and transceiver supply voltage.

Planet IVR-300W - Intelligent SFP Diagnosis Mechanism (For IVR-300FP) - 1

flowchart
graph TD
    A["SFP DDM (Digital Diagnostic Monitor)"] --> B["Voltage"]
    A --> C["Ammeter"]
    A --> D["Temperature"]
    A --> E["Power Transceiver"]
    A --> F["Power Receiver"]

Built-in Unique PoE Functions for Powered Devices Management (For IVR-300FP)

The IVR-300FP is capable of having a maximum of up to 120 watts of power output and can deliver up to 36W for each port. It also features the following special PoE management functions.

PoE Usage Monitoring (For IVR-300FP)

With PoE usage monitoring, it can show the PoE loading of each port, total PoE power usage and system status, such as overload, low voltage, over voltage and high temperature. User can obtain detailed information about the real-time PoE working condition of the IVR-300FP directly.

PoE Schedule (For IVR-300FP)

Under the trend of energy saving worldwide and contributing to environmental protection, the IVR-300FP can effectively control the power supply besides its capability of giving high watts power. The "PoE schedule" function helps you to enable or disable PoE power feeding for each PoE port during specified time intervals and it is a powerful function to help SMBs or enterprises save power and budget. It also increases security by powering off PDs that should not be in use during non-business hours.

Planet IVR-300W - PoE Schedule (For IVR-300FP) - 1

line PoE Schedule | Time Period | Total Consumption (Watts/hr) | | :--- | :--- | | 08:00~17:00 | 36 | | 17:00~08:00 | 24 |

Scheduled Power Recycling (For IVR-300FP)

The IVR-300FP allows each of the connected PoE IP cameras or PoE wireless access points to reboot at a specific time each week. Therefore, it will reduce the chance of IP camera or AP crash resulting from buffer overflow.

Planet IVR-300W - Scheduled Power Recycling (For IVR-300FP) - 1

flowchart
graph TD
    A["IP Camera"] --> B["AP Router"]
    A --> C["IP Phone"]
    A --> D["Door Phone"]
    A --> E["PoE lighting"]
    B --> F["Automatic Reboot"]
    C --> F
    D --> F
    E --> F

PD Alive Check (For IVR-300FP)

The IVR-300FP can be configured to monitor connected PD status in real time via ping action. Once the PD stops working and responding, the IVR-300FP will resume the PoE port power and bring the PD back to work. It will greatly enhance the network reliability through the PoE port resetting the PD's power source and reducing administrator management burden.

PD Alive Check

Planet IVR-300W - PD Alive Check - 1

flowchart
graph LR
    A["Step 1"] --> B["Ping Request"]
    B --> C["Ping Echo"]

Step 2 Checking alive status for 3 times Ping Request No Response!

Planet IVR-300W - PD Alive Check - 3

flowchart
graph LR
    A["Alarm Notification"] --> B["ON"]
    A --> C["OFF"]
    B --> D["Stop"]
    C --> E["Stop"]

Step 4 Restart PoE Device

The IVR-300W is designed with high power amplifier and 2 highly-sensitive antennas which provide stronger signal and excellent coverage even in the wide-ranging or bad environment. With adjustable transmit power option, the administrator can flexibly reduce or increase the output power for various environments, thus reducing interference to achieve maximum performance. Equipped with the next-generation Wi-Fi 6 (802.11ax) wireless network standard, the total bandwidth reaches 1800Mbps, and the 2-stream transmission technology improves the transmission efficiency of multiple devices, making AR/VR/IoT applications smoother. The IEEE 802.11ax also optimizes MU-MIMO (Multi-User MIMO) mechanism to serve multiple devices simultaneously.

Ideal VPN Security Gateway Solution for Factories and Transportations

The IVR-100 and IVR-300 Series provides complete data security and privacy for accessing and exchanging the most sensitive data, built-in IPSec VPN function with DES/3DES/AES encryption and MD5/SHA-1/SHA-256/SHA-384/SHA-512 authentication, and GRE, SSL, PPTP and L2TP server mechanism. The full VPN capability in the IVR-100 and IVR-300 Series makes the connection secure, more flexible, and more capable.

Planet IVR-300W - Ideal VPN Security Gateway Solution for Factories and Transportations - 1

flowchart
graph LR
    A["Industrial VPN Security Gateway"] --> B["Content Filtering"]
    B --> C["VPN Tunnel"]
    C --> D["Failure Switch"]
    D --> E["Network"]
    style A fill:#f9f,stroke:#333
    style B fill:#bbf,stroke:#333
    style C fill:#dfd,stroke:#333
    style D fill:#fff,stroke:#333
    style E fill:#dfd,stroke:#333

Centralized Remote Control of Managed APs

The IVR-100 and IVR-300 Series provides centralized management of PLANET Smart AP series via a user-friendly Web GUI. It's easy to configure AP for the wireless SSID, radio band and security settings. With a four-step configuration process, wireless profiles for different purposes can be simultaneously delivered to multiple APs or AP groups to minimize deployment time, effort and cost.

Planet IVR-300W - Centralized Remote Control of Managed APs - 1

flowchart
graph TD
    A["Central AP Controller"] --> B["Lobby"]
    A --> C["Meeting Room"]
    B --> D["CH48 Tx: 70%"]
    B --> E["CH1 Tx: 70%"]
    B --> F["CH36 Tx: 100%"]
    B --> G["CH12 Tx: 100%"]
    C --> H["CH48 Tx: 35%"]
    C --> I["CH6 Tx: 35%"]
    D --> J["Control Room"]
    E --> J
    F --> J
    G --> J
    H --> J
    I --> J

For example, to configure multiple smart APs of the same model, the IVR-100 and IVR-300 Series allows clustering them to a managed group for unified management. According to requirements, wireless APs can be flexibly expanded or removed from a wireless AP group at any time. The AP cluster benefits bulk provision and bulk firmware upgrade through single entry point instead of having to configure settings in each of them separately.

Simplified Cluster Management with 4 Steps
Planet IVR-300W - Centralized Remote Control of Managed APs - 2

flowchart
graph LR
    A["Search"] --> B["Add Profile"]
    B --> C["Batch Provisioning"]
    C --> D["Map It"]

Wi-Fi Deployments and Authentication with Simplified Management (for IVR-300 Series)

The IVR-300 Series also provides a built-in AP Controller, Captive Portal, RADIUS and a DHCP server to facilitate small and medium businesses to deploy secure employee and guest access services without any additional server. The IVR-300 Series can offer a secure Wi-Fi network with easy installation for your business.

Planet IVR-300W - Wi-Fi Deployments and Authentication with Simplified Management (for IVR-300 Series) - 1

flowchart
graph TD
    A["Captive Portal"] --> B["Free Wi-fi"]
    B --> C["Name"]
    B --> D["E-mail"]
    B --> E["OK"]
    C --> F["WWW"]
    D --> F
    E --> F

Excellent Ability in Threat Defense

The IVR-100 and IVR-300 Series has built-in SPI (stateful packet inspection) firewall and DoS/DDoS attack mitigation functions to provide high efficiency and extensive protection for your network. Thus, virtual server and DMZ functions can let you set up servers in the Intranet and still provide services to the Internet users.

Planet IVR-300W - Excellent Ability in Threat Defense - 1

flowchart
graph LR
    A["DoS/DDoS Attack"] --> B["Blocking DoS Attack"]
    B --> C["Industrial VPN Security Gateway"]
    C --> D["Ethernet Switch"]
    D --> E["1000BASE-T UTP"]
    style A fill:#f9f,stroke:#333
    style B fill:#ccf,stroke:#333
    style C fill:#cfc,stroke:#333
    style D fill:#fcc,stroke:#333
    style E fill:#cff,stroke:#333

Cybersecurity Network Solution to Minimize Security Risks

The cybersecurity feature included to protect the switch management in a mission-critical network virtually needs no effort and cost to install. For efficient management, the IVR-100 and IVR-300 Series are equipped with HTTPS web and SNMP management interfaces. With the built-in web-based management interface, the IVR-100 and IVR-300 Series offers an easy-to-use, platform independent management and configuration facility. IVR-100 and IVR-300 Series supports SNMP and it can be managed via any management software based on the standard SNMP protocol.

Maximizing Work Efficiency with PLANET SD-WAN Gateway

PLANET IVR-100 and IVR-300 Series incorporated in SD-WAN (software-defined wide area network) function can greatly increase WAN optimization for multiple WAN links to be managed. With SD-WAN, users can connect any application across all available network connections at every site. It improves application performance and provides a high-quality user experience for increasing business productivity and reducing IT costs.

Cost-effective Solution for RS-485 to Ethernet Application (for IVR-300 Series.)

The IVR-100 and IVR-300 Series provides a feature that can convert the Serial RS-485 communication to IP networking. Ethernet signal allows two types of segments to connect easily, efficiently and inexpensively. The solution helps users and SIs save expenses as there is no need to replace the existing serial equipment and software system.

Planet IVR-300W - Cost-effective Solution for RS-485 to Ethernet Application (for IVR-300 Series.) - 1

flowchart
graph LR
    A["Workstation"] -->|TCP/IP Protocol| B["IVR-300 Series"]
    B -->|Serial bus RS485| C["Serial Devices"]

Convenient and Reliable Redundant Power System

To facilitate transportation and industrial-level applications, the IVR-100 and IVR-300 Series provides an integrated power solution with a wide range of voltages (9\~54V DC) for worldwide operability, and the IVR-300FP provides an integrated power solution with 48\~54V DC voltages. It also provides dual-redundant, reversible polarity DC power supply inputs for high availability applications.

Ideal VPN Security Gateway

PLANET IVR-100 and IVR-300 Series can work as a VPN security gateway in an industrial application for a company that has a factory and many different divisions. With IPSec/GRE/PPTP/L2TP/SSL VPN solutions, the IVR-100 and IVR-300 Series installed at the headquarters provides branches, vendors, and mobile workers with secure data communication no matter how long the distance would be.

The IVR-100 and IVR-300 Series connects dual WANs with up to two different ISPs. It creates a stable and qualified VPN connection for many important applications such as VoIP, video conferencing and data transmission.

Planet IVR-300W - Ideal VPN Security Gateway - 1

flowchart
graph TD
    subgraph Office
        A["Server (Web/FTP/mail)"] -->|Data| B["Network Unit"]
        C["Internet"] -->|Data| B
        D["Sensor"] -->|Data| B
        E["IP Cam"] -->|Data| B
        F["Robot Arm"] -->|Data| B
    end

    subgraph Factory
        G["100BASE-T UTP"] --> H["RS-485 Access Control"]
        I["100BASE-T UTP with PoE"] --> H
        J["RS-485"] --> H
        K["100BASE-FX Fiber Optic"] --> H
    end

    B --> L["Data"]
    style B fill:#f9f9f9,stroke:#333
    style H fill:#e6f7ff,stroke:#333
    style I fill:#e6f7ff,stroke:#333
    style J fill:#e6f7ff,stroke:#333
    style K fill:#e6f7ff,stroke:#333

1.3 Features

Hardware

■ 4 x 10/100/1000BASE-T RJ45 LAN ports (for IVR-100 and IVR-300/IVR-300W)
■ 4 x 10/100/1000BASE-T RJ45 LAN ports with 4-port IEEE 802.3at PoE+ injector function (for IVR-300FR)
■ 1 1000BASE-X SFP slot for WAN/LAN interface(for IVR-300FR)
■ 1 10/100/1000BASE-T RJ45 WAN/LAN port
■ Dual-WAN failover and Dual-WAN load balancing
■ 1 USB 3.0 port for system configuration backup and firmware upgrade
■ 1 reset button
■ 1 3-pin terminal block (RS485) (for IVR-300 Series)
■ 2 x DIDO (for IVR-300 Series)

Power over Ethernet (for IVR-300FP)

■ Complies with IEEE 802.3at Power over Ethernet Plus, end-span PSE
■ Backward compatible with IEEE 802.3af Power over Ethernet
■ Up to 4 ports of IEEE 802.3af / 802.3at devices powered
■ Supports PoE power up to 36 watts for each PoE port
■ Auto detects powered device (PD)
■ Circuit protection prevents power interference between ports
■ PoE management
■ Total PoE power budget control

◆ Per port PoE function enable/disable
◆ PoE port power feeding priority
◆ Per PoE port power limitation
◆ PD classification detection
◆ PD alive check

RF Interface Characteristics (for IVR-300W)

■ Features 2.4GHz (802.11b/g/n/ax) and 5GHz (802.11a/n/ac/ax) dual band for carrying high load traffic
■ 2T2R MIMO technology for enhanced throughput and coverage
■ Provides multiple adjustable transmit power control
■ High speed up to 1.8Gbps (600Mbps for 2.4GHz or 1200Mbps for 5GHz) wireless data rate

Industrial Case and Installation

■ IP30 metal case
■ Solid DIN-rail, wall-mount or side wall-mount design
■ Supports 6KV DC Ethernet ESD protection
■ Fault alarm for power input failure
■ DC redundant power with reverse polarity protection
■ -40 to 75 degrees C operating temperature

IP Routing Feature

■ Static Route
■ Dynamic Route (RIPv1/v2)

Firewall Security

■ Cybersecurity
■ Stateful Packet Inspection (SPI) firewall
■ Blocks DoS/DDoS attack
■ Content filtering
■ MAC/IP filtering
■ Blocks SYN/ICMP flooding
■ NAT ALGs (Application Layer Gateway)

VPN Features

■ IPSec/Remote Server (Net-to-Net, Host-to-Net), GRE, PPTP Server, L2TP Server, SSL Server/Client (Open VPN)
■ Max. Connection Tunnel Entries: 60 VPN tunnels,
■ Encryption methods: DES, 3DES, AES, AES-128/192/256
■ Authentication methods: MD5, SHA-1, SHA-256, SHA-384, SHA-512

Networking

■ Outbound load balancing for Ethernet WANs
■ Auto-failover between Ethernet network WANs
■ High Availability
■ Captive Portal
■ RADIUS Server
■ Static IP/PPPoE/DHCP client for WAN
■ DHCP server/NTP client for LAN
■ Protocols: TCP/IP, UDP, ARP, IPv4, IPv6
■ Port forwarding, QoS, DMZ, IGMP, UPnP, SNMPv1,v2c, v3
■ MAC address clone
■ DDNS: PLANET DDNS, Easy DDNS, DynDNS and No-IP

Others

■ Setup wizard
■ Dashboard for real-time system overview
■ Support for HTTP or HTTPS
■ Auto reboot
■ PLANET NMS System and Smart Discovery Utility for deployment management
■ PLANET CloudViewer app for real-time monitoring
■ Configuration backup and restoration via remote/USB port
■ Firmware upgrade via remote/USB port

1.4 Product Specifications

ProductIVR-100IVR-300IVR-300WIVR-300FP
Hardware Specifications
Copper Ports5 10/100/1000BASE-T RJ45 Ethernet ports including3 LAN ports (Ports 1 to 3)1 LAN/WAN port (Port 4)1 WAN port (Port 5)
Fiber Port---1 1000BASE-XSFP slot including1 WAN/LAN port(Port 6)
USB Port1 USB 3.0 port
Wireless Connector--Two RP-SMA female connectors
Wireless Antenna--Two 5 dBi external antennas
Serial Interface-1 x 3-pin terminal block for RS485
DI Interfaces-2 Digital Input (DI):Level 0: -24V~2.1V (±0.1V)Level 1: 2.1V~24V (±0.1V)Input Load to 24V DC, 10mA max.
DO Interfaces-2 Digital Output (DO):Open collector to 24V DC, 100mA max.
ConnectorRemovable 6-pin terminal block for power inputPin 1/2 for Power 1, Pin 3/4 for fault alarm, Pin 5/6 for Power 2
Reset Button< 5 sec: System reboot>5 sec: Factory default
EnclosureIP30 metal case
InstallationDIN rail, desktop, wall-mounting
Dimensions (W x Dx H)50 x 87.5 x 135 mm50 x 135 x 135 mm
Weight530g712g773g765g
Power Requirements -DC9~54V DC, 1.0A9~54V DC, 1.8A9~54V DC, 1.8A48~54V DC, 3A
Power ConsumptionNo LoadingMax. 3.8 watts/12.97 BTUMax. 3.7 watts/12.61 BTUMax. 3.8 watts/12.95 BTUMax. 7.56 watts/25.8 BTU
Full LoadingMax. 9 watts/30.71 BTUMax. 8.7 watts/29.66 BTUMax.15.6 watts/53.19 BTUMax. 127 watts/433.34 BTU
LED IndicatorsSystem:P1 (Green)P2 (Green)Fault (Red)Per 10/100/1000RJ45 Ports (Ports1-4 and WAN Port):1000 LNK/ACT(Green)10/100 LNK/ACT(Amber)System:P1 (Green)P2 (Green)Alarm (Red)I/O (Red)Per 10/100/1000RJ45 Ports (Ports1-4 and WAN Port):1000 LNK/ACT(Green)10/100 LNK/ACT(Amber)System:P1 (Green)P2 (Green)Alarm (Red)I/O (Red)Per 10/100/1000RJ45 Ports (Ports1-4and WAN Port):1000 LNK/ACT(Green)10/100 LNK/ACT(Amber)Wi-Fi:2.4G (Green)5G (Green)System:P1 (Green)P2 (Green)Alarm (Red)I/O (Red)Per 10/100/1000RJ45 Ports (Ports1-4):LNK/ACT (Green)PoE-in-Use (Amber)Per 10/100/1000RJ45 Ports (Ports5):LNK/ACT (Green)1000 LNK (Amber)Per 1000BASE-XSFP Interfaces(Port 6):LNK/ACT (Green)
Security Service
Firewall SecurityCybersecurityStateful Packet Inspection (SPI)Blocks DoS/DDoS attack
ALG (Application Layer Gateway)SIP, RTSP, FTP, H.323, TFTP
NATPort forwardingDMZ HostUPnP
Content FilteringMAC filteringIP filteringWeb filtering
Bandwidth ManagementOutbound load balancingFailover for dual-WANQoS (Quality of Service)
Firewall SecurityCybersecurityStateful Packet Inspection (SPI)Blocks DoS/DDoS attack
Operation ModeRouting mode
Routing ProtocolStatic Route, Dynamic Route (RIP), OSPF
VLAN802.1q Tag-based, Port-based, Multi-VLAN
MulticastIGMP Proxy
NAT ThroughputMax. 900Mbps
Outbound Load BalancingSupported algorithms: Weight
ProtocolIPv4, IPv6, TCP/IP, UDP, ARP, HTTP, HTTPS, NTP, DNS, PLANET DDNS, PLANET Easy DDNS, DHCP, PPPoE, SNMPv1/v2c/v3
Key FeaturesHA (High Availability) Captive Portal RADIUS Server/Client AP Control
VPN
VPNIPSec/Remote Server (Net-to-Net, Host-to-Net) GRE PPTP Server L2TP Server SSL Server/Client (Open VPN)
VPN TunnelsMax. 60Max. 60
VPN ThroughputMax. 60MbpsMax. 108Mbps
Encryption MethodsDES, 3DES, AES or AES-128/192/256 encrypting
Authentication MethodsMD5/SHA-1/SHA-256/SHA-384/SHA-512 authentication algorithm
Management
Basic Management InterfacesWeb browser SNMP v1, v2c PLANET Smart Discovery utility and NMS controller supported
Secure Management InterfacesTLSv1.2, SNMP v3
System LogSystem Event Log
OthersSetup wizard Dashboard System status/service Statistics Connection status Auto reboot
DiagnosticsConfiguration backup and restoration via remote/USB portFirmware upgrade via remote/USB port
Standards Conformance
Regulatory ComplianceCE, FCC
Environment
OperatingTemperature: -40 ~ 75 degrees CRelative humidity: 5 ~ 90% (non-condensing)
StorageTemperature: -40 ~ 85 degrees CRelative humidity: 5 ~ 90% (non-condensing)

Advanced Functions

■ Power of Ethernet Specification for IVR-300FP

ModelIVR-300FP
Wireless
PoE StandardIEEE 802.3af / 802.3at PoE+ PSE
PoE Power Supply TypeEnd-span
PoE Power OutputPer port 54V DC, 35 watts (max.)
Power Pin Assignment1/2 (+), 3/6 (-)
PoE Power Budget120 watts (max.)
Max. Number of Class 4 PDs4
PoE ManagementPD Alive CheckScheduled Power RecyclingPoE SchedulePoE Usage Monitoring

■ Wireless Specification for IVR-300W

ModelIVR-300W
Wireless
StandardIEEE 802.11a/n/ac/ax 5GHzIEEE 802.11g/b/n/ax 2.4GHz
Band Mode2.4G & 5G concurrent mode
Antenna5 dBi external antennas with SMA connectors for Wi-Fi
Frequency Range2.4GHzAmerica FCC: 2.412~2.462GHzEurope ETSI: 2.412GHz~2.472GHz
5GHz5.15GHz ~5.875GHz
Operating Channels2.4GHz5GHzAmerica FCC: 1~11Europe ETSI: 1~13America FCC:Non-DFS: 36, 40, 44, 48, 149,153,157,161,165DFS: 52, 56, 60, 64, 100, 104, 108, 112, 116, 132, 136, 140Europe ETSI:Non-DFS: 36, 40, 44, 48DFS: 52, 56, 60, 64, 100, 104, 108, 112, 116, 120, 124, 128, 132, 136, 1405GHz channel list may vary in different countries according to their regulations.
Channel Width
Data Transmission RatesTransmit: 600 Mbps* for 2.4 GHz and 1200 Mbps* for 5 GHzReceive: 600 Mbps* for 2.4 GHz and 1200 Mbps* for 5 GHz*The estimated transmission distance is based on the theory. The actual distance may vary in different environments.
Transmission Power11b: 23dbm+/- 1.5dbm @11Mbps11g: 20dbm+/- 1.5dbm @54Mbps11g/n: 20dBm +/- 1.5dbm @MCS7, HT2017dBm@MCS7,HT4011a: 19.5dBm +/- 1.5dbm @54Mbps11a/n: 19.5dBm+/- 1.5dbm @MCS7, HT2017dBm@MCS7, HT4011ac HT20: 20+/-1.5dBm @MCS811ac HT40: 17+/-1.5dBm @MCS911ac HT80: 14.5+/-1.5dBm @MCS911ax HT20: 20+/-1.5dBm @MCS911ax HT40: 17 +/- 1.5dBm @MCS911ax HT80: 14.5 +/- 1.5dBm @MCS11
Encryption SecurityWEP (64/128-bit) encryption securityWPA / WPA2 (TKIP/AES)WPA-PSK / WPA2-PSK (TKIP/AES)/ WPA3-PSK (TKIP/AES)802.1x Authenticator
Wireless AdvancedWi-Fi Multimedia (WMM)Auto channel selectionWireless output power managementMAC address filtering

Chapter 2. Hardware Introduction

2.1 Physical Descriptions

2.1.1 Front View

IVR-100 Front Panel

P1 P2 Fault PLANET Firewall VPN Dual WAN Reset USB WAN 5 LNK ACT 1000 LAN 3 4 (LAN/WAN) 1 2 IVR-100

LEDColorFunction
P1GreenLights to indicate DC power input 1 has power.
P2GreenLights to indicate DC power input 2 has power.
FaultRedLights to indicate the either power or port fail
1000LNK/ACTGreenLightsIndicates the link through that port is successfully established at 1000Mbps
BlinksIndicates that the Switch is actively sending or receiving data over that port.
100LNK/ACTAmberLightsIndicates the link through that port is successfully established at 100Mbps.
BlinksIndicates that the Switch is actively sending or receiving data over that port.
Ports
USB PortUSB 3.0 port for system configuration backup and restoration.
Reset ButtonPower on the device and press the reset button for less than 5 seconds to reboot it or over 5 seconds to restore it to factory default settings.
Gigabit Ports 1-3It is a LAN port for connecting to a switch.
Gigabit Port 4Default is LAN port. It can be defined as LAN port or WAN port.
Gigabit Port 5It is a WAN port for connecting to a perimeter gateway.

IVR-300 series Front Panel

IVR-300
P1 P2 Alarm I/O PLANET Nursing & Control IVR-300 Reset USB GND TXD+ RxD- RS485 WAN 5 1000 10/100 WAN/LAN 3 4 1 2 LAN

IVR-300W
P1 P2 Alarm 2.4G 5G I/O PLANET IRV-300W 2.4G/5GHz Reset USB GND TxD+ RxD- RS485 WAN 5 1000 10/100 WAN/LAN 3 4 1 2 LAN 2.4G/5GHz

VR-300FP
P1 P2 Alarm I/O PLANET IRV-300FP Firewall VPN PoE Reset USB WANLAN GND TxD+ RxD- RS485 6 WANLAN 5 LNK/ACT 1000 3 4 1 PoE LAN LNK/ACT PoE-In-Use

LED Definition:

  • System:
LEDColorFunction
P1GreenLights to indicate DC power input 1 has power.
P2GreenLights to indicate DC power input 2 has power.
AlarmRedLights to indicate the either power or port fail
I/ORedIndicate Condition of Digital Input or Digital Output has triggered.
2.4GGreenLights up when 2.4G Wi-Fi service is enabled (for IVR-300W)
5GGreenLights up when 5G Wi-Fi service is enabled (for IVR-300W)

- Interface:

300/IVR-300W

Per 10/100/1000Mbps RJ45 Port (Ports 1 to 5)

LEDColorFunction
1000LNK/ACTGreenLightsIndicates the link through that port is successfully established at 1000Mbps
BlinksIndicates that the Switch is actively sending or receiving data over that port.
100LNK/ACTAmberLightsIndicates the link through that port is successfully established at 100Mbps.
BlinksIndicates that the Switch is actively sending or receiving data over that port.

IVR-300FP

Per 10/100/1000Mbps RJ45 Port (Ports 1 to 4)

LEDColorFunction
10/1001000LNK/ACTGreenLightsIndicates the link through that port is successfully established at 1000Mbps
BlinksIndicates that the Switch is actively sending or receiving data over that port.
PoE-In-useAmberLightsIndicates the port is providing DC in-line power.
OffIndicates the connected device is not a PoE PD.

10/100/1000Mbps RJ45 WAN/LAN Port (Port 5)

LEDColorFunction
10/100/1000LNK/ACTGreenLightsIndicates that the port is operating at 1000Mbps, 100Mbps or 10Mbps.
BlinksIndicates that the switch is actively sending or receiving data over that port.
1000 LNKAmberLightsIndicates the port is operating at 1000Mbps
BlinksIndicates that the Switch is actively sending or receiving data over that

1000BASE-X SFP WAN/LAN Port (Port 6)

LEDColorFunction
1000LNK/ACTGreenLightsIndicates the port is operating at 1000Mbps.
BlinksIndicates that the switch is actively sending or receiving data over that port.
Ports
USB PortUSB 3.0 port for system configuration backup and restoration.
Reset ButtonPower on the device and press the reset button for less than 5 seconds to reboot it or over 5 seconds to restore it to factory default settings.
Serial Interface1 x 3-pin terminal block for RS485
Gigabit Ports 1-3It is a LAN port for connecting to a switch.
Gigabit Port 4Default is LAN port.It can be defined as LAN port or WAN port. (for IVR-300/IVR-300W)
Gigabit Port 5Default is WAN port.It is a WAN port for connecting to a perimeter gateway. (for IVR-300/IVR-300W)It can be defined as LAN port or WAN port. (for IVR-300FP)
SFP Port 6(for IVR-300FP)Default is LAN port. It can be defined as LAN port or WAN port.

2.1.2 Top View

The upper panel of the Industrial Gateway consists of one terminal block connector within two DC power inputs.

IVR-100 Top View
Max. fault loading: 24V, 1A 1 2 3 4 5 6 V1+ V1- PWR1 Fault V2+ V2- PWR2 DC Input: 9~48V==, 1A max.

IVR-300/IVR-300W Top View
DI0 DI1 DO0 DO1 GND GND 1 2 3 4 5 6 Max: Fault Alarm Loading: 24V, 1A DC Input: 9-54V==, 1.8A max. V1+ V1- PWR1 Alarm V2+ V2- PWR2

IVR-300FP Top View
DI0 DI1 DO0 DO1 GND GND 1 2 3 4 5 6 Max. Fault Alarm Loading: 24V, 1A DC Input: 48-54V==, 3A max. V1+ V1- PWR1 Alarm V2+ V2- PWR2

2.1.3 Wiring the Power Inputs

The 6-contact terminal block connector on the top panel of Industrial Gateway is used for two DC redundant power inputs. Please follow the steps below to insert the power wire.

Planet IVR-300W - Wiring the Power Inputs - 1

When performing any of the procedures like inserting the wires or tightening the wire-clamp screws, make sure the power is OFF to prevent from getting an electric shock.

  1. Insert positive and negative DC power wires into contacts 1 and 2 for POWER 1, or 5 and 6 for POWER 2.v

DI0 DI1 DO0 DO1 GND GND 1 2 3 4 5 6 Max. Fault Alarm Loading: 24V 1 2 3 4 5 6 DC Input: 9-54V==, 1.8A max. V1+ V1- PWR1 Alarm V2+ V2- PWR2

Planet IVR-300W - Wiring the Power Inputs - 3

To avoid damage, please use the Industrial Gateway under its specification.

  1. Tighten the wire-clamp screws for preventing the wires from loosening.

Planet IVR-300W - Wiring the Power Inputs - 4

natural_image Green electrical connector pinout with four circular holes highlighted in red (no text or symbols)

1 2

3 4

5 6

Power 1

Alarm

Power 2

+ -

+ -

Planet IVR-300W - Wiring the Power Inputs - 5

Note

The wire gauge for the terminal block should be in the range from 12 to 24 AWG.

Planet IVR-300W - Wiring the Power Inputs - 6

PWR1 and PWR2 must provide the same DC voltage while operating with dual power input.

2.1.4 Wiring the Fault Alarm Contact

The fault alarm contacts are in the middle of the terminal block connector as the picture shows below. Inserting the wires, the Industrial Gateway will detect the fault status of the power failure and then forms an open circuit. The following illustration shows an application example for wiring the fault alarm contacts.

1 2 3 4 5 6 Fault Alarm Contacts Fault The Fault Alarm Contacts are energized (CLOSE) for normal operation and will OPEN when failure occurs Insert the wires into the fault alarm contacts

Planet IVR-300W - Wiring the Fault Alarm Contact - 2

Note

  1. The wire gauge for the terminal block should be in the range between 12 and 24 AWG.
  2. Alarm relay circuit accepts up to 24V, max. 1A currents.

2.1.5 Dimensions

IVR-100 Dimensions
Planet IVR-300W - Dimensions - 1

Top View 87.80 Side View PLANET 27.00 87.80 97.10

IVR-300 Dimensions
Top View 1 2 3 4 5 6 1 2 3 4 5 6 Side View PLANET Front View Side View Mounting Kit DIN-Rail Kit Mounting Kit Rear View Bottom View Unit: mm

IVR-300W Dimensions
Top View 1 2 3 4 5 6 1 2 3 4 5 6 Side View PLANET Front View Side View Mounting Kit DIN-Rail Kit Mounting Kit Rear View Bottom View Unit: mm

IVR-300W Dimensions
Planet IVR-300W - Dimensions - 5

2.2 Hardware Installation

This section describes how to install the Industrial Gateway. There are three methods to install the Industrial Gateway -- DIN-rail mounting, wall mounting and side wall mounting. Basic knowledge of networking is assumed.

Please read the following sections and perform the procedures in the order being presented. (The device shown on this chapter is just a representation of the said device.)

2.2.1 DIN-rail Mounting

Step 1: Lightly slide the DIN-rail into the track.

Planet IVR-300W - DIN-rail Mounting - 1

natural_image Hand holding a black electronic device with red arrows pointing to its side, mounted on a wall (no visible text or symbols)

Step 2: Check whether the DIN-rail is tightly on the track.

Planet IVR-300W - DIN-rail Mounting - 2

natural_image Black electronic device with multiple ports mounted on a metal bracket (no visible text or symbols)

Step 3: Connect your device to hub / switch.

A. Connect one end of a standard network cable to the LAN port (port 1) of the device.

B. Connect the other end of the cable to the hub / switch.

Planet IVR-300W - DIN-rail Mounting - 3

The UTP Category 5, 5e or 6 network cabling with RJ45 tips is recommended.

Step 4: Connect your device to internet.

A. Connect one end of a standard network cable to the WAN port (port 5) of the device.

B. Connect the other end of the cable to the LAN port of ISP network device (such as a modem).

Planet IVR-300W - DIN-rail Mounting - 4

If there is only one line connected to the outer network in your network environment, it is suggested that you use WAN port (port 5).

Step 5: Power on the device. When the device receives power, the Power LED should remain solid Green.

2.2.2 Wall Mount Plate Mounting

To install the Industrial Gateway on the wall, please follow the instructions below.

Step 1: Remove the DIN-rail from the Industrial Gateway. Use the screwdriver to loosen the screws to remove the DIN-rail.

Step 2: Place the wall-mount plate on the rear panel and use the screwdriver to screw the wall mount plate tightly on the Industrial Gateway.

Planet IVR-300W - Wall Mount Plate Mounting - 1

natural_image Hand holding a black electronic device with a metal rod extending from it, against a plain white background (no text or symbols visible)

Step 3: Use the hook holes at the corners of the wall mount plate to hang the Industrial Gateway on the wall.

Planet IVR-300W - Wall Mount Plate Mounting - 2

natural_image Black industrial electronic device with ports and a green connector, mounted on a wall against a plain white background (no visible text or symbols)

Step 4: To remove the wall mount plate, reverse the steps above.

Step 5: Proceed with Steps 3, 4 and 5 in Section 2.2.1 DIN-rail Mounting to connect the network cabling and power on the device.

2.2.3 Side Wall Mount Plate Mounting

To install the Industrial Gateway on the wall, please follow the instructions below.

Step 1: Remove the DIN-rail from the Industrial Gateway. Use the screwdriver to loosen the screws to remove the DIN-rail.

Step 2: Place the wall-mount plate on the side panel and use the screwdriver to screw the wall mount plate tightly on the Industrial Gateway.

Planet IVR-300W - Side Wall Mount Plate Mounting - 1

natural_image Close-up of hands using a screwdriver to adjust or install electronic components on a black plastic base (no text or symbols visible)

Step 3: Use the hook holes at the corners of the wall mount plate to hang the Industrial Gateway on the wall.

Planet IVR-300W - Side Wall Mount Plate Mounting - 2

natural_image Black industrial electronic device labeled 'PLAET' with green connector, mounted on a wall (no readable text beyond label)

Step 4: To remove the wall mount plate, reverse the steps above.

Step 5: Proceed with Steps 3, 4 and 5 in Section 2.2.1 DIN-rail Mounting to connect the network cabling and power on the device.

2.2.4 Wi-Fi Antenna Installation

(For IVR-300W only)

Step 1: Fasten the two dual-band antennas to the antenna connectors on the front panel of the IVR-300W.

Step 2: You can bend the antennas to fit your actual needs.

PLANN 2.4G/5GHz Reset USB VANN 1000 10100 VAN/LAN LAN 2.4G/5GHz 2.4G/5GHz 2.4G/5GHz IR5485 GND TiD+ RxD+ Two Wi-Fi RP-SMA Connectors

Figure 2-2: IVR-300W Front Panel

Chapter 3. Preparation

Before getting into the device's web UI, user has to check the network setting and configure PC's IP address.

3.1 Requirements

User is able to confirm the following items before configuration:

  1. Please confirm the network is working properly; it is strongly suggested to test your network connection by connecting your computer directly to ISP.
  2. Suggested operating systems: Windows 7 / 8 / 10.
  3. Recommended web browsers: IE / Firefox / Chrome.

3.2 Setting TCP/IP on your PC

The default IP address of the VPN Gateway is 192.168.1.1, and the DHCP Server is on. Please set the IP address of the connected PC as DHCP client, and the PC will get IP address automatically from the VPN Gateway.

Please refer to the following to set the IP address of the connected PC.

3.2.1 Windows 7/8

If you are using Windows 7/8, please refer to the following:

  1. Click on the network icon from the right side of the taskbar and then click on "Open Network and Sharing Center".

Currently connected to: Unidentified network No Internet access Open Network and Sharing Center 2:41 AM 9/3/2012

2. Click "Change adapter settings".

Control Panel Home Change adapter settings Change advanced sharing settings View your basic network information and set up connections PC (This computer) Unidentified network Internet See full map View your active networks Connect or disconnect Unidentified network Public network Access type: No Internet access Connections: Local Area Connection Change your networking settings Set up a new connection or network Set up a wireless, broadband, dial-up, ad hoc, or VPN connection; or set up a router or access point. Connect to a network Connect or reconnect to a wireless, wired, dial-up, or VPN network connection. Choose homegroup and sharing options Access files and printers located on other network computers, or change sharing settings. Troubleshoot problems Diagnose and repair network problems, or get troubleshooting information. See also HomeGroup Internet Options Windows Firewall

3. Right-click on the Local Area Connection and select Properties.

Local Area Connection Unidentified network Intel(R) PRO/100 Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties

  1. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties or directly double-click on Internet Protocol Version 4 (TCP/IPv4).

Local Area Connection Properties Networking Connect using: Intel(R) PRO/1000 MT Network Connection Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6 (TCP/IPv6) ✓ Internet Protocol Version 4 (TCP/IPv4) ✓ Link-Layer Topology Discovery Mapper I/O Driver ✓ Link-Layer Topology Discovery Responder Install... Uninstall Properties Description Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks. OK Cancel

  1. Select "Use the following IP address" and "Obtain DNS server address automatically", and then click the "OK" button.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the following IP address: IP address: . . . . Subnet mask: . . . . Default gateway: . . . . Obtain DNS server address automatically Use the following DNS server addresses Preferred DNS server: . . . . Alternate DNS server: . . . . Validate settings upon exit Advanced... OK Cancel

3.2.2 Windows 10

If you are using Windows 10, please refer to the following:

  1. In the search box on the taskbar, type "View network connections", and then select View network connections at the top of the list.

Best match View network connections Control panel View network connections

  1. Right-click on the Local Area Connection and select Properties.

Local Area Connection Unidentified network Intel(R) PRO/1000 Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties

  1. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties or directly double-click on Internet Protocol Version 4 (TCP/IPv4).

Local Area Connection Properties Networking Connect using: Intel(R) PRO/1000 MT Network Connection Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6 (TCP/IPv6) ✓ Internet Protocol Version 4 (TCP/IPv4) ✓ Link-Layer Topology Discovery Mapper I/O Driver ✓ Link-Layer Topology Discovery Responder Install... Uninstall Properties Description Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks. OK Cancel

  1. Select "Use the following IP address" and "Obtain DNS server address automatically", and then click the "OK" button.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the following IP address: IP address: .. Subnet mask: .. Default gateway: .. Obtain DNS server address automatically Use the following DNS server addresses Preferred DNS server: .. Alternate DNS server: .. Validate settings upon exit Advanced... OK Cancel

3.3 Planet Smart Discovery Utility

For easily listing the Gateway in your Ethernet environment, the search tool -- Planet Smart Discovery Utility -- is an ideal solution.

The following installation instructions are to guide you to running the Planet Smart Discovery Utility.

  1. Download the Planet Smart Discovery Utility in administrator PC.
  2. Run this utility as the following screen appears.

PLANET Smart Discovery Lite File Option Help Refresh Exit PLANET Networking & Communication MAC Address Device Name Version DeviceIP NewPassword IP Address NetMask Gateway Description Select Adapter: 10.1.0.96 (F8:32:E4:CD:C5:8A) Control Packet Force Broadcast Update Device Update Multi Update All Connect to Device Device Message

Figure: Planet Smart Discovery Utility Screen

Planet IVR-300W - Planet Smart Discovery Utility - 2

If there are two LAN cards or above in the same administrator PC, choose a different LAN card by using the "Select Adapter" tool.

  1. Press the "Refresh" button for the currently connected devices in the discovery list as the screen shows below:

PLANET Smart Discovery Lite File Option Help Refresh Exit PLANET Networking & Communication MAC Address Device Name Version DeviceIP NewPassword IP Address NetMask Gateway Description 1 00-30-4F-00-11-22 IVR-300 v1.2102b220215 192.168.1.1 192.168.1.1 255.255.255.0 0.0.0.0 Industrial VPN Security F Select Adapter: 192.168.1.154 (00:05:18:C5:51:45) Control Packet Force Broadcast Update Device Update Multi Update All Connect to Device Device: IVR-300 (00-30-4F-00-11-22) Get Device Information done.

Figure: Planet Smart Discovery Utility Screen

  1. This utility shows all necessary information from the devices, such as MAC address, device name, firmware version, and device IP subnet address. It can also assign new password, IP subnet address and description to the devices.

  2. After setup is completed, press the "Update Device", "Update Multi" or "Update All" button to take effect. The functions of the 3 buttons above are shown below:

■ Update Device: use current setting on one single device.
■ Update Multi: use current setting on choose multi-devices.
■ Update All: use current setting on whole devices in the list.

The same functions mentioned above also can be found in "Option" tools bar.

  1. To click the "Control Packet Force Broadcast" function, it allows you to assign a new setting value to the device under a different IP subnet address.

  2. Press the "Connect to Device" button and the Web login screen appears.

Press the "Exit" button to shut down the Planet Smart Discovery Utility.

Chapter 4. Web-based Management

This chapter provides setup details of the device's Web-based Interface.

4.1 Introduction

The device can be configured with your Web browser. Before configuring, please make sure your PC is under the same IP segment with the device.

4.2 Logging in to the VPN Gateway

Refer to the steps below to configure the VPN Gateway:

Step 1. Connect the IT administrator's PC and VPN Gateway's LAN port (port 1) to the same hub / switch, and then launch a browser to link the management interface address which is set to http://192.168.1.1 by default.

Planet IVR-300W - Logging in to the VPN Gateway - 1

The DHCP server of the VPN Gateway is enabled. Therefore, the LAN PC will get IP from the VPN Gateway. If user needs to set IP address of LAN PC manually, please set the IP address within the range between 192.168.1.2 and 192.168.1.254 inclusively, and assigned the subnet mask of 255.255.255.0.

Step 2. The browser prompts you for the login credentials. (Both are "admin" by default.)

Default IP address: 192.168.1.1

Default user name: admin

Default password: admin

Default 2.4GHz SSID: PLANET_2.4G (for IVR-300W)

Default 5GHz SSID: PLANET_5G (for IVR-300W)

Planet IVR-300W - Logging in to the VPN Gateway - 2

Administrators are strongly suggested to change the default admin and password to ensure system security.

Web Login Screen as below:

Sign in http://192.168.1.1 Your connection to this site is not private Username admin Password ...... Sign in Cancel

Please follow the wizard to do the first-time account modification.

The password must contain 8\~31 characters, including upper case, lower case, numerals and other symbols

PLANET Networking & Communication STEP 1 - Account Modification 1 Account 2 LAN 3 WAN 4 Security Settings 5 Setup Completed Username admin Password Confirm Password The password must contain 8~31 characters, including upper case, lower case, numerals and other symbols Cancel Next

Figure 4.2-1 Account Modification

After modifying the new account and password, the main screen appears as shown below:

PLANET Monitoring & Communications 2 W Alarm VIO PS PS LAN WAN1 3 1 4 2 System Network Security VPN AP Control PoE Maintenance IVR 300-FP Auto Logout C Wizard Dashboard System Status System Service Statistics Connection Status SFP Module Information High Availability NADIUS Capture Portal SNMP NMS Fault Alarm Digital Input/Output Modbus Remote Syslog Event Log Port Status System Information USB LAN WAN1 ----LAN---- CPU 5% Memory 21.4% PoE Budget

Figure 4.2-2 Web Main Screen

Now, you can use the Web management interface to continue the Security Gateway management or manage the Security Gateway by console interface. Please refer to the user's manual for more.

Administrators are strongly suggested to change the default password and Wi-Fi SSID on the first login to safeguard system security.

Planet IVR-300W - Logging in to the VPN Gateway - 6

  1. For security reason, please change and memorize the new password after this first setup.
  2. Only accept command in lowercase letter under web interface.

4.3 Main Web Page

After a successful login, the main web page appears. The web main page displays the web panel, main menu, function menu, and the main information in the center as shown below

Main Menu Web Panel PLANET Networking & Communications IWR-300F P Wizard Dashboard System Status System Service Statistics Connection Status SFP Module Information High Availability RADIUS Captive Portal SNMP NMS Fault Alarm Digital Input/Output Modbus Remote Syslog Event Log System Network Security VPN AP Control PoE Maintenance Auto Logout Port Status System Information USB LAN WAN1 ----LAN---- 5% CPU 21.4% Memory 1.7% PoE Budget

Figure 4.3-1 Main Web Page

Web Panel

The web panel displays the device's ports as shown below.

Alarm I/O P2 P1 2 W LAN WAN1 4 2 3 1

Figure 4.3-2 Web Panel

ObjectIconFunction
Ethernet portPlanet IVR-300W - Web Panel - 2To indicate the port without the RJ45 plug-in.
Planet IVR-300W - Web Panel - 3To indicate network data is sending or receiving.
Planet IVR-300W - Web Panel - 4To indicate the PoE is in use. (IVR-300FP only)
PoE ConsumptionPlanet IVR-300W - Web Panel - 5To indicate the current PoE consumption. (IVR-300FP only)
SFP portPlanet IVR-300W - Web Panel - 6To indicate the port with the Fiber plug-in. (IVR-300FP only)
Planet IVR-300W - Web Panel - 7To indicate network data is sending or receiving (IVR-300FP only)

The main menu displays the product name, function menu, and main information in the center. Via the Web management, the administrator can set up the device by selecting the functions those listed in the function menu and button as shown below.

System Network Security VPN AP Control PoE Maintenance

Figure 4.3-3 Function Menu

ObjectDescription
SystemProvides System information of the Gateway.
NetworkProvides WAN, LAN and network configurations of the Gateway.
SecurityProvides Firewall and security configurations of the Gateway.
VPNProvides VPN configuration of the Gateway.
AP ControlProvides AP Control configuration of the VPN Security Gateway
PoEProvides PoE Management configuration of industrial wall-mount Gigabit router. (IVR-300FP only)
WirelessProvides wireless configuration of the VPN Security Gateway (IVR-300W only)
MaintenanceProvides firmware upgrade and setting file restore/backup configuration of the Gateway.

Auto Logout ▼

Planet IVR-300W - Main Menu - 2

Planet IVR-300W - Main Menu - 3
Figure 4.3-4 Function Button

ObjectDescription
Planet IVR-300W - Main Menu - 4Click the "Refresh button" to refresh the current web page.
Planet IVR-300W - Main Menu - 5Click the "Logout button" to log out the web UI of the Gateway.

4.4 System

Use the System menu items to display and configure basic administrative details of the Gateway. The System menu as shown below provides the following features to configure and monitor system.

Wizard
Dashboard
System Status
System Service
Statistics
Connection Status
SFP Module Information
High Availability
RADIUS
Captive Portal
SNMP
NMS
Fault Alarm
Digital Input/Output
Modbus
Remote Syslog
Event Log

Figure 4.4-1 System Menu

ObjectDescription
WizardThe Wizard will guide the user to configuring the Gateway easily and quickly.
DashboardThe overview of system information includes connection, port, and system status.
System StatusDisplay the status of the system, Device Information, LAN and WAN.
System ServiceDisplay the status of the system, Secured Service and Server Service
StatisticsDisplay statistics information of network traffic of LAN and WAN.
Connection StatusDisplay the DHCP client table and the ARP table
SFP Module InformationDisplay the physical or operational status of an SFP module via the SFP Module Information page (IVR-300FP only)
High AvailabilityEnable/Disable High Availability on VPN Security Gateway
RADIUSEnable/Disable RADIUS on VPN Security Gateway
Captive PortalEnable/Disable Captive Portal on VPN Security Gateway
SNMPDisplay SNMP system information
NMSEnable/Disable NMS on VPN Security Gateway
Fault AlarmOne relay output for power failure. Alarm relay current carry ability
Digital Input/OutputDigital Input/Output Control Configuration page
ModbusConfigure the Modbus TCP Mode on this page
Remote SyslogEnable Captive Portal on VPN Security Gateway
Event LogDisplay Event Log information

4.4.1 Wizard

The Wizard will guide the user to configuring the Gateway easily and quickly. There are different procedures in different operation modes. According to the operation mode you switch to, please follow the instructions below to configure the Gateway via Setup Wizard as shown below

Planet IVR-300W - Wizard - 1

flowchart
graph LR
    A["1 Account"] --> B["2 LAN"]
    B --> C["3 WAN"]
    C --> D["4 Security Settings"]
    D --> E["5 Setup Completed"]

Figure 4.4-2 Setup Wizard

Step 1: Account Modification

Set up the Username and Password for the Account Modification as shown below.

Planet IVR-300W - Step 1: Account Modification - 1

flowchart
graph LR
    A["1 Account"] --> B["2 LAN"]
    B --> C["3 WAN"]
    C --> D["4 Security Settings"]
    D --> E["5 Setup Completed"]

The password must contain 8\~31 characters, including upper case, lower case, numerals and other symbols

Figure 4.4-3 Account Modification

Step 2: LAN Interface

Set up the IP Address and Subnet Mask for the LAN interface as shown below.

STEP 2 - Network Interface LAN 1 Account 2 LAN 3 WAN 4 Security Settings 5 Setup Completed IP Address 192.168.1.1 Netmask 255.255.255.0 DHCP Server ✓ Start IP Address 192.168.1.100 Maximum DHCP Users 101

Figure 4.4-4 Setup Wizard – LAN Configuration

ObjectDescription
IP AddressEnter the IP address of your VPN Security Gateway The default is 192.168.1.1.
Subnet MaskAn address code that determines the size of the network. Normally use 255.255.255.0 as the subnet mask.
DHCP ServerBy default, the DHCP Server is enabled.If user needs to disable the function, please uncheck the box.
Start IP AddressBy default, the start IP address is 192.168.1.100.Please do not set it to the same IP address of the VPN Security Gateway
Maximum DHCP UsersBy default, the maximum DHCP users are 101, which means the VPN Security Gateway will provide DHCP client with IP address from 192.168.1.100 to 192.168.1.200 when the start IP address is 192.168.1.100.
NextPress this button to the next step.
CancelPress this button to undo any changes made locally and revert to previously saved values.

Step 3: WAN Interface

The VPN Security Gateway supports two access modes on the WAN side as shown in below.

STEP 3 - Network Interface WAN 1 Account 2 LAN 3 WAN 4 Wireless 5 Security 6 Completed WAN1 WAN2 Connection Type DHCP IP Address Netmask Default Gateway DNS Server 1 DNS Server 2

Figure 4.4-5 Setup Wizard – WAN Configuration (IVR-100/IVR-300/IVR-300W)

STEP 3 - Network Interface WAN 1 Account 2 LAN 3 WAN 4 Security Settings 5 Setup Completed WAN1 WAN2 Interface Port 5 - LAN/WAN Connection Type DHCP IP Address Netmask Default Gateway DNS Server 1 DNS Server 2

Figure 4.4-6 Setup Wizard – WAN Configuration (IVR-300FP Only)

Mode 1 -- Static IP

Select Static IP Address if all the Internet port's IP information is provided to you by your ISP. You will need to enter the IP Address, Netmask, Default Gateway and DNS Server provided to you by your ISP. Each IP address entered in the fields must be in the appropriate IP form, which are four octets separated by a dot (x.x.x.x). The VPN Security Gateway will not accept the IP address if it is not in this format. The setup is shown below.

WAN1 WAN2 Interface Port 5 - LAN/WAN Connection Type Static IP Address 210.61.134.96 Netmask 255.255.255.0 Default Gateway 210.61.134.254 DNS Server 1 8.8.8.8 DNS Server 2 8.8.4.4

Figure 4.4-7 WAN Interface Setup – Static IP Setup

ObjectDescription
IP AddressEnter the IP address assigned by your ISP.
NetmaskEnter the Netmask assigned by your ISP.
Default GatewayEnter the Gateway assigned by your ISP.
DNS ServerThe DNS server information will be supplied by your ISP.
NextPress this button for the next step.
PreviousPress this button for the previous step.
CancelPress this button to undo any changes made locally and revert to previously saved values.

Mode 2 -- DHCP Client

Select DHCP Client to obtain IP Address information automatically from your ISP. The setup is shown below.

WAN1 WAN2 Interface Port 5 - LAN/WAN Connection Type DHCP IP Address Netmask Default Gateway DNS Server 1 DNS Server 2

Figure 4.4-8 WAN Interface Setup - DHCP Setup

Step 4: Wireless Setting

(For IVR-300W only)

Set up the Wireless Settings as shown below.

STEP 4 - Network Interface Wireless 1 Account 2 LAN 3 WAN 4 Wireless 5 Security 2.4G WiFi Status Enable Disable SSID PLANET_2.4G Hide SSID Enable Disable Bandwidth 20MHz Channel 6 Encryption Open 5G WiFi Status Enable Disable SSID PLANET_5G Hide SSID Enable Disable Bandwidth 80MHz Channel 36 Encryption Open

Figure 4.4-9 Setup Wizard – Wireless Setting

ObjectDescription
2.4G Wireless StatusAllows user to enable or disable 2.4G Wi-Fi
Wireless Name (SSID)It is the wireless network name. The default 2.4G SSID is “PLANET_2.4G”
Hide SSIDAllows user to enable or disable SSID
BandwidthSelect the operating channel width, “20MHz” or “40MHz”
ChannelIt shows the channel of the CPE. Default 2.4GHz is channel 6.
EncryptionSelect the wireless encryption. The default is “Open”
Wi-Fi MultimediaEnable/Disable WMM (Wi-Fi Multimedia ) function
5G Wireless StatusAllows user to enable or disable 5G Wi-Fi
Wireless Name (SSID)It is the wireless network name. The default 5G SSID is “PLANET_5G”
Hide SSIDAllows user to enable or disable SSID
BandwidthSelect the operating channel width, “20MHz” or “40MHz” or “80MHz”
ChannelIt shows the channel of the CPE. Default 5GHz is channel 36.
EncryptionSelect the wireless encryption. The default is “Open”
Wi-Fi MultimediaEnable/Disable WMM (Wi-Fi Multimedia ) function

Step 5: Security Setting

Set up the Security Settings as shown the setup is shown below.

Planet IVR-300W - Step 5: Security Setting - 1

line STEP 5 - Security Settings | Setting | Option | Value | | :--- | :--- | :--- | | Account | Enable | ○ Disable | | Account | Enable | ○ Disable | | LAN | Enable | ○ Disable | | LAN | Enable | ○ Disable | | WAN | Enable | ○ Disable | | WAN | Enable | ○ Disable | | Wireless | Enable | ○ Disable | | Wireless | Enable | ○ Disable | | Security | Enable | ○ Disable | SPI Firewall Block SYN Flood Block ICMP Flood Block WAN Ping Remote Management ● Enable ○ Disable ● Enable ○ Disable ○ Enable ● Disable ○ Enable ● Disable

Figure 4.4-10 Setup Wizard – Security Setting

ObjectDescription
SPI FirewallThe SPI Firewall prevents attack and improper access to network resources.The default configuration is enabled.
Block SYN FloodSYN Flood is a popular attack way. DoS and DDoS are TCP protocols.Hackers like to use this method to make a fake connection that involves the CPU, memory, and so on.The default configuration is enabled.
Block ICMP FloodICMP is kind of a pack of TCP/IP; its important function is to transfer simple signal on the Internet. There are two normal attack ways which hackers like to use, Ping of Death and Smurf attack.The default configuration is disabled.
Block WAN PingEnable the function to allow the Ping access from the Internet network.The default configuration is disabled.
Remote ManagementEnable the function to allow the web server access of the Gateway from the Internet network.The default configuration is disabled.

Step 6: Setup Completed

The page will show the summary of LAN, WAN and Security settings. The setup is shown below.

STEP 6 - Setup Completed 1 Account 2 LAN 3 WAN 4 Wireless 5 Security 6 Completed LAN Enable: Static IP: 192.168.1.1 / 255.255.255.0 WAN1 Enable: DHCP WAN2 Enable: OFF 2.4G WiFi Enable: ON SSID: PLANET_2.4G Bandwidth: 20MHz Channel: 6 Encryption: Open Hide SSID: Disable 5G WiFi Enable: ON SSID: PLANET_5G Bandwidth: 80MHz Channel: 36 Encryption: Open Hide SSID: Disable Security Settings SPI Firewall: ON Block SYN Flood: ON Block ICMP Flood: OFF Block WAN Ping: OFF Remote Management: OFF

Figure 4.4-11 Setup Wizard – Setup Completed

ObjectDescription
FinishPress this button to save and apply changes.
PreviousPress this button for the previous step.

4.4.2 Dashboard

The dashboard provides an overview of system information including connection, port, and system status. The setup is shown below.

Planet IVR-300W - Dashboard - 1

flowchart
graph LR
    A["Port Status"] --> B["Network Port"]
    B --> C["System Information"]
    C --> D["CPU 5%"]
    C --> E["Memory 21.4%"]
    C --> F["PoE Budget 1.7%"]
    subgraph Port Status
        G["USB"]
        H["LAN"]
        I["WAN1"]
        J["----LAN----"]
    end
    subgraph System Information
        K["5% CPU"]
        L["21.4% Memory"]
        M["1.7% PoE Budget"]

Figure 4.4-12 Dashboard

Planet IVR-300W - Dashboard - 2

gauge | Wireless Status | State | RX (bps) | TX (bps) | | --------------- | ----- | -------- | -------- | | 2.4G | ON | 0 | 0 | | 2.4G | Channel | 6 | | | 2.4G | Client List | 0 | | | 5G | ON | 0 | 0 | | 5G | Channel | 52 | | | 5G | Client List | 0 | | | TX | | 0 | 0 | | TX | TX | 0 | 0 |

Figure 4.4-13 Dashboard - Wireless

WAN/LAN Connection Status

ObjectDescription
Planet IVR-300W - Dashboard - 3The status means WAN is connected to Internet and LAN is connected.
Planet IVR-300W - Dashboard - 4The status means WAN is disconnected to Internet and LAN is connected.
Planet IVR-300W - Dashboard - 5The status means WAN is connected to Internet and LAN is disconnected.

Port Status

ObjectDescription
Planet IVR-300W - Dashboard - 6Ethernet port is in use.
Planet IVR-300W - Dashboard - 7Ethernet port is not in use.
Planet IVR-300W - Dashboard - 8Ethernet port is PoE-in-use (IVR-300FP Only)
Planet IVR-300W - Dashboard - 9USB port is in use.
Planet IVR-300W - Dashboard - 10USB port is not in use.

System Information

ObjectDescription
Planet IVR-300W - Dashboard - 11Display the CPU loading
Planet IVR-300W - Dashboard - 12
Planet IVR-300W - Dashboard - 13Display the memory usage
Planet IVR-300W - Dashboard - 14
Planet IVR-300W - Dashboard - 15Display the PoE Budget
1.7%
PoE Budget

Wireless Status

ObjectDescription
Planet IVR-300W - Dashboard - 16Planet IVR-300W - Dashboard - 17Wireless is in use.
RX: 0 bpsTX: 0 bps
Planet IVR-300W - Dashboard - 18Planet IVR-300W - Dashboard - 19Wireless is not in use.
RX: 0 bpsTX: 0 bps

4.4.3 Status

This page displays system information as shown below.

Device Information

Model NameIVR-300
Firmware Versionv1.2102b220215
Current Time2022-04-22 Friday 16:16:32
Running Time0 day, 07:31:16
Power StatusPWR1:ON, PWR2:OFF
Alarm StatusNormal
DI and DO StatusNormal

WAN1

MAC Address00:30:4F:00:11:23
Connection TypeDHCP
Display NameWAN1
IP Address
Netmask
Default Gateway

LAN

MAC Address00:30:4F:00:11:22
IP Address192.168.1.1
Netmask255.255.255.0
DHCP ServiceEnable
DHCP Start IP Address192.168.1.100
DHCP End IP Address192.168.1.200
Max DHCP Clients101

Figure 4.4-14 Status

For IVR-300W Only

2.4GHz WiFi

StatusON
SSIDPLANET_2.4G
Channel6
EncryptionOpen
MAC AddressA8:F7:E0:00:30:5A

5GHz WiFi

StatusON
SSIDPLANET_5G
Channel36
EncryptionWPA2 Personal (TKIP+AES)
MAC AddressA8:F7:E0:87:85:5D

Figure 4.4-15 Status - Wireless (IVR-300W)

4.4.4 System Service

This page displays system service information as shown below.

Service
#StateServiceDetail
1EnabledDHCP ServiceDHCP Table: 1
2DisabledDDNS ServiceNot enabled
3EnabledSNMP Service
4DisabledQuality of Service
5DisabledHigh Availability
6DisabledRADIUS Service
7DisabledCaptive Portal

Figure 4.4-16 System Service – Server Service

#StateServiceDetail
1EnabledCybersecurityTLS 1.2, TLS 1.3
2EnabledSPI Firewall
3DisabledMAC Filtering(Active / Maximum Entries) 0 / 32
4DisabledIP Filtering(Active / Maximum Entries) 0 / 32
5DisabledWeb Filtering(Active / Maximum Entries) 0 / 32
6DisabledIPSec VPN Server(Active / Maximum Tunnels) 0 / 16
7DisabledGRE(Active / Maximum Tunnels) 0 / 5
8DisabledPPTP(Active / Maximum Tunnels) 0 / 91
9DisabledSSL VPN(Active / Maximum Tunnels) 0 / 100
10DisabledL2TP(Active Tunnels) 0

Figure 4.4-17 System Service – Secured Service

4.4.5 Statistics

This page displays the number of packets that pass through the VPN Security Gateway on the WAN and LAN. The statistics are shown below.

WAN1
Planet IVR-300W - Statistics - 1

line | Time | Speed | |-------|-----------| | 8:30 | 0 B/s | | 8:40 | 0 B/s | | 8:50 | 0 B/s | | 9:00 | 0 B/s | | 9:10 | 0 B/s | | 9:20 | 2.50 KB/s | | 9:30 | 0 B/s |

LAN
Planet IVR-300W - Statistics - 2

line | Time | Speed | |-------|-----------| | 8:30 | 0 B/s | | 8:40 | 0 B/s | | 8:50 | 0 B/s | | 9:00 | 0 B/s | | 9:10 | 0 B/s | | 9:20 | 0 B/s |

Figure 4.4-18 Statistics

4.4.6 Connection Status

The page will show the DHCP Table and ARP Table. The status is shown below.

DHCP Table

NameIP AddressMAC AddressExpiration Time
ENM192.168.1.15400:05:1b:c5:51:45Sat Apr 23 15:39:34 2022

ARP Table

IP AddressMAC AddressARP Type
192.168.1.15400:05:1b:c5:51:45dynamic

Figure 4.4-19 Connection Status

4.4.7 SFP Module Information

This page shows the operational status, such as the transceiver type, speed, wavelength, optical output power, optical input power, temperature, laser bias current and transceiver supply voltage in real time. The SFP Module Information page is shown below.

SFP Module Information
TypeSpeedWave Length(nm)Distance(m)Temperature(C)Voltage(V)Current(mA)Tx power(dBm)Rx power(dBm)
1000Base-LX1000-Base13101000039.05883.311218.9760-6.3451-36.9897

Figure 4.4-20 SFP Module Information

ObjectDescription
TypeDisplay the type of current SFP module; the possible types are:■ 1000BASE-SX■ 1000BASE-LX
SpeedDisplay the speed of current SFP module; the speed value or description is obtained from the SFP module. Different vendors' SFP modules might show different speed information.
Wave Length (nm)Display the wavelength of current SFP module; the wavelength value is obtained from the SFP module. Use this column to check if the wavelength values of two nodes match while the fiber connection fails.
Distance (m)Display the support distance of current SFP module; the distance value is obtained from the SFP module.
Temperature (C)– SFP DDM Module OnlyDisplay the temperature of current SFP DDM module; the temperature value is gotten from the SFP DDM module.
Voltage (V)– SFP DDM Module OnlyDisplay the voltage of current SFP DDM module; the voltage value is gotten from the SFP DDM module.
Current (mA)– SFP DDM Module OnlyDisplay the ampere of current SFP DDM module; the ampere value is gotten from the SFP DDM module.
TX power (dBm)– SFP DDM Module OnlyDisplay the TX power of current SFP DDM module; the TX power value is gotten from the SFP DDM module.
RX power (dBm)– SFP DDM Module OnlyDisplay the RX power of current SFP DDM module; the RX power value is gotten from the SFP DDM module.

4.4.8 High Availability

High Availability (HA) is a redundant system that two IVR VPN Security Gateways can be set up in a master/slave configuration. The master VPN Security Gateway provides the Internet connection but, in the case of hardware or WAN connectivity failure, the slave (backup) VPN Security Gateway automatically takes over Internet connection. It provides redundant hardware and software that make the system available despite failures.

Planet IVR-300W - High Availability - 1

flowchart
graph TD
    A["Computer"] --> B{High Availability?}
    B --> C["Device 1"]
    B --> D{High Availability?}
    D --> E["Device 2"]
    D --> F["Device 3"]

The page will show the High Availability configuration. The High Availability page is shown below.

High Availability Configuration High Availability Username Password Mode Virtual IP address Virtual IP Mask Interface Connected Status Enable Disable Master LAN Apply Settings Cancel Changes

Figure 4.4-21 High Availability

ObjectDescription
High AvailabilityDisable or enable the High Availability function.The default configuration is disabled.
UsernameCreate the username for the HA.
PasswordCreate the password for the HA.
ModeChoose Master or Slave role.
Virtual IP AddressAssign an IP address as a virtual IP.
Virtual MaskAssign a mask address as a virtual mask.
InterfaceUse interface.
Connection StatusDisplay the HA status.

4.4.9 RADIUS

Remote Authentication Dial-In User Service (RADIUS) is a security authentication client/server protocol that supports authentication, authorization and accounting.

Planet IVR-300W - RADIUS - 1

flowchart
graph TD
    A["Device 1"] -->|1| B["Server"]
    C["Device 2"] -->|5| B
    D["Device 3"] -->|6| B
    B -->|1| E["User Interface"]
    B -->|5| F["User Interface"]
    style A fill:#f9f,stroke:#333
    style C fill:#f9f,stroke:#333
    style D fill:#f9f,stroke:#333
    style B fill:#ccf,stroke:#333
    style E fill:#cff,stroke:#333
    style F fill:#cff,stroke:#333

The RADIUS Server page is shown below.

RADIUS Server Client User Account RADIUS Server Mode Server Port Enable Disable 1812 Apply Settings Cancel Changes

Figure 4.4-22 RADIUS Server

ObjectDescription
RADIUSDisable or enable the RADIUS function.The default configuration is disabled.
Server PortUDP port number for authentication

The RADIUS client page is shown below.

RADIUS Server Client User Account Index Name Client IP Address Secret Key Description Delete (up to 16 clients)

Figure 4.4-23 RADIUS Client

ObjectDescription
NameDescribe client's name
Client IP addressDescribe client's IP address
Secret KeyThe RADIUS server and client share a secret key that is used to authenticate the messages sent between server and client.
DescriptionDescribe client's information

4.4.10 Captive Portal

Captive portal service gives the ability to organize a public (or guest) Wi-Fi zone with user authorization. A captive portal is the authorization page that forcibly redirects users who connect to the public network before accessing the Internet.

Planet IVR-300W - Captive Portal - 1

flowchart
graph TD
    A["User with WiFi"] --> B["Free Wi-fi"]
    B --> C["Router"]
    C --> D["WWW"]
    D --> E["Internet"]
    style A fill:#f9f,stroke:#333
    style B fill:#ccf,stroke:#333
    style C fill:#cfc,stroke:#333
    style D fill:#fcc,stroke:#333
    style E fill:#ffc,stroke:#333

The Captive portal page is shown below.

Captive Portal Config Custom Captive Portal Interfaces Authentication Type Enable Disable LAN Subnet 1 Local RADIUS Server

Figure 4.4-24 Captive Portal

ObjectDescription
Captive portalDisable or enable the Captive portal function.The default configuration is disabled.
InterfaceChoose subnet interface■ LAN Subnet 1■ LAN Subnet 2■ LAN Subnet 3■ LAN Subnet 4
Authentication TypeSupport local RADIUS server

4.4.11 SNMP

This page provides SNMP setting as shown below.

SNMP

SNMPEnable Disable
SNMP VersionsSNMP v1,v2c
Read Communitypublic
Write Communityprivate
Engine ID
SNMP v3 Security LevelAuthPRiv
SNMP v3 User Name
SNMP v3 Auth ProtocolMD5
SNMP v3 Auth Password
SNMP v3 Privacy ProtocolDES
SNMP v3 Privacy Password

System Identification

System NameIVR-300
System Description
System Location
System Contactsales@planet.com.tw

Figure 4.4-25 SNMP Configuration Page

ObjectDescription
Enable SNMPDisable or enable the SNMP function.The default configuration is enabled.
Read/Write CommunityAllows entering characters for SNMP Read/Write Community of the VPN Security Gateway
System NameAllows entering characters for system name of the VPN Security Gateway
System LocationAllows entering characters for system location of the VPN Security Gateway
System ContactAllows entering characters for system contact of the VPN Security Gateway
Apply SettingsPress this button to save and apply changes.
Cancel ChangesPress this button to undo any changes made locally and revert to previously saved values.

4.4.12 NMS

The IVR series can support both NMS controller and CloudViewer Sever for remote management.

PLANET's NMS Controller is a Network Management System that can monitor all kinds of deployed network devices, such as managed switches, media converters, routers, smart APs, VoIP phones, IP cameras, etc., compliant with the SNMP Protocol, ONVIF Protocol and PLANET Smart Discovery utility. The CloudViewer is a free networking service just for PLANET products. This service provides simplified network monitoring and real-time network status. Working with PLANET CloudViewer app, user can easily check network status, device information, and port and PoE statuses from Internet.

NMS Configuration screen appears as shown below.

NMS Configuration NMS NMS Controller IP address Authorization Status PLANET NMS Controller - LAN Disable PLANET CloudViewer Server - Internet PLANET NMS Controller - LAN

Figure 4.4-26 NMS Configuration Page

The NMS Controller – LAN Configuration screen appears as shown below.

NMS Configuration NMS PLANET NMS Controller - LAN NMS Controller IP address Authorization Status Unauthorized Apply Settings Cancel Changes Unbind

Figure 4.4-27 NMS Controller – LAN Configuration Page

ObjectDescription
NMS Controller IP addressThe IP address of NMS Controller
Authorization StatusIndicate the authorization status of the switch to NMS Controller

The CloudViewer Server – Internet screen appears as shown below.

NMS Configuration NMS PLANET CloudViewer Server - Internet Email Password Connection Status Not enabled

Figure 4.4-28 CloudViewer Server – Internal Configuration Page

ObjectDescription
• EmailThe email registered on CloudViewer Server
• PasswordThe password of your CloudViewer account
• Connection StatusIndicate the status of connecting CloudViewer Server

4.4.13 Fault Alarm

The IVR series supports a Fault Alarm feature which can alert the users when there is something wrong with the device. With this ideal feature, the users would not have to waste time finding where the issue is. It will help to save time and human resource.

Fault Alarm Feature
DC Power Failure or RJ45 Connection Link Down System Log

This page provides fault alarm setting as shown below.

Fault Alarm Control Configuration
Fault Alarm Output
EnableEnable
RecordSystem Log
EventPower Fail Port Fail
Power AlarmPWR1 PWR2
Port Alarm1 2 3 4 5

Figure 4.4-29 Fault Alarm

ObjectDescription
EnableControls whether Fault Alarm is enabled.
RecordControls whether Record is sending System log or SMS.
EventControls whether Port Failure or Power Failure or both is/are detected.
Power AlarmControls whether faulty PWR1 or faulty PWR2 or both is/are detected.
Port AlarmControls which port or all is/are detected for fault.

4.4.14 Digital Input / Output

The IVR-300/IVR-300W supports Digital Input and Digital Output on its upper panel. This external alarm enables users to use Digital Input to detect and log external device status (such as door intrusion detector), and send event alarm to the administrators. The Digital Output could be used to alarm the administrators if the IVR-300/IVR-300W port shows link down, link up or power failure.

Digital Input
Security OK!! PRI Sensor Door Detector (Door Closed)

Alarm Warning PRI Sensor Intrusion detected Door Detector (Door Open)

Planet IVR-300W - Digital Input / Output - 3

flowchart
graph TD
    A["Alarm Messaging"] --> B["Network"]
    B --> C["Uplink"]
    B --> D["System Log"]

Digital Output
DC Power Failure

RJ45 Cable Link Down

This page provides Digital Input / Output setting as shown below.

Digital Input/Output Control Configuration
Digital Input 0Digital Input 1
EnableEnableEnableEnable
DI ConditionHigh to LowDI ConditionHigh to Low
Event DescriptionEvent Description
ActionSystem LogActionSystem Log
Digital Output 0Digital Output 1
EnableEnableEnableEnable
ActionPower FailPort FailDI 0DI 1ActionPower FailPort FailDI 0DI 1
DO ConditionHigh to LowDO ConditionHigh to Low
Power AlarmPWR1PWR2Power AlarmPWR1PWR2
Port Fail Alarm12345Port Fail Alarm12345

Figure 4.4-30 Digital Input / Output

ObjectDescription
EnableCheck the Enable checkbox to enable Digital Input / output function. Uncheck the Enable checkbox to disable Digital input / output function.
ConditionAs Digital Input: Allows user to select High to Low or Low to High. This means a signal received by system is from High to Low or from Low to High. It will trigger an action that logs a customized message or issue the message from the switch.As Digital Output: Allows user to select High to Low or Low to High. This means that when the switch is power-failed or port-failed, the system will issue a High or Low signal to an external device such as an alarm.
Event DescriptionAllows user to set a customized message for Digital Input function alarm.
ActionAs Digital Input: Allows user to record alarm message to System log, syslog or issues out via SNMP Trap or SMTP.By default, SNMP Trap and SMTP are disabled. Please enable them first if you want to issue alarm message via them.As Digital Output: Allows user to monitor an alarm from port failure, power failure, Digital Input 0 (DI 0) and Digital Input 1(DI 1) which mean if Digital Output has detected these events, then Digital Output would be triggered according to the setting of Condition.
Power AlarmAllows user to choose which power module that needs to be monitored.
Port AlarmAllows user to choose which port that needs to be monitored.

4.4.15 Modbus

The IVR-300/IVR-300W provides a feature that can convert the Serial RS485 communication to IP networking. Ethernet signal allows two types of segments to connect easily, efficiently and inexpensively. The solution helps users and SIs save expenses as there is no need to replace the existing serial equipment and software system.

Convert Serial Communication to IP Networking
Planet IVR-300W - Modbus - 1

flowchart
graph LR
    A["Workstation"] -->|TCP/IP Protocol| B["IVR-300/IVR-300W Server Series"]
    B -->|Serial bus RS485| C["Serial Devices"]

This page provides Modbus Configuration setting as shown below.

Modbus Configuration Modbus TCP Serial device RS-485 Baudrate 9600 Databits 8 Parity None Stopbits 1 TCP Slave Port 502 Enable Disable

Figure 4.4-31 Modbus Configuration

ObjectDescription
Modbus TCPIndicates the Modbus TCP mode operation. Possible modes are:Enabled: Enable Modbus TCP mode operation level: Disabled: Disable Modbus TCP mode operation.
Serial deviceSet up the Modbus Serial device to RS-485
BaudrateSelect the Modbus Baudrate to 300 ~ 115200
DatabitsSet up the Modbus Databits to 8
ParitySet up the Modbus Parity to None, Odd or Even
StopbitsSet up the Modbus Stopbits to 1 or 2
TCP Slave PortSet up the Modbus TCP Slave Port.

4.4.16 Remote Syslog

This page provides remote syslog setting as shown below.

Remote Syslog Enable Syslog Server Port Destination (1~65535)

Figure 4.4-32 Remote Syslog Configuration

ObjectDescription
• EnableControls whether remote syslog is enabled
• Syslog Server IPIndicates the IPv4 host address of syslog server
• Port DestinationConfigure port for remote syslog

4.5 Network

The Network function provides WAN, LAN and network configuration of the VPN Security Gateway as shown below.

Priority WAN WAN Advanced LAN Multi-Subnet VLAN UPnP Routing RIP OSPF IGMP IPv6 DHCP DDNS MAC Address Clone

Figure 4.5-1 Network Menu

ObjectDescription
PriorityAllows setting priority of WAN interface.
WANAllows setting WAN interface.
WAN AdvancedAllows setting WAN Advanced settings.
LANAllows setting LAN interface.
Multi-SubnetAllows setting Multi-Subnet1 ~ Subnet4 interface.
VLANDisable or enable the VLAN function.The default configuration is disabled.
UPnPDisable or enable the UPnP function.The default configuration is disabled.
RoutingAllows setting Route.
RIPDisable or enable the RIP function.The default configuration is disabled.
OSPFDisable or enable the OSPF function.The default configuration is disabled.
IGMPDisable or enable the IGMP function.The default configuration is disabled.
IPv6Allows setting IPv6 WAN interface.
DHCPAllows setting DHCP Server.
DDNSAllows setting DDNS and PLANET DDNS.
MAC AddressCloneAllows setting WAN MAC Address Clone.

4.5.1 Priority

This page provides SD WAN priority setting as shown below.

SD WAN Priority
No.Group NamePathServicesActiveAction

Figure 4.5-2 SD WAN Priority List

SD WAN Configuration Active Group Name Path Service Port or Group Enable Disable SD-WAN To BGP(TCP:179) Border Gateway Protocol

Figure 4.5-3 SD WAN Configuration

ObjectDescription
Active■ Enable / Disable the Active
Group Name■ Setting the Group Name.
Path■ Setting the SD-WAN To / To SD-WAN
Service Port or Group■ Setting the Service Port or Group Border Gateway Protocol

4.5.2 WAN

This page is used to configure the parameters for Internet network which connects to the WAN port of the VPN Security Gateway as shown below. Here you may select the access method by clicking the item value of WAN access type.

WAN1 Configuration

InterfacePort 5 - LAN/WAN
Display NameWAN1
Connection TypeDHCP
IP Address
Netmask
Default Gateway
DNS Server 1
DNS Server 2

WAN2 Configuration

WAN○Enable ●Disable
InterfacePort 6 - SFP
Display NameWAN2
Connection TypeDHCP ▼
IP Address
Netmask
Gateway
DNS Server 1
DNS Server 2

Figure 4.5-4 WAN Configuration

ObjectDescription
WAN Access TypePlease select the corresponding WAN Access Type for the Internet, and fill out the correct parameters from your local ISP in the fields which appear below.
StaticSelect Static IP Address if all the Internet ports' IP information is provided to you by your ISP (Internet Service Provider). You will need to enter the IP address, Netmask, Gateway, and DNS Server provided to you by your ISP.Each IP address entered in the fields must be in the appropriate IP form, which are four octets separated by a dot (x.x.x.x). The VPN Security Gateway will not accept the IP address if it is not in this format.IP AddressEnter the IP address assigned by your ISP.NetmaskEnter the Subnet Mask assigned by your ISP.GatewayEnter the Gateway assigned by your ISP.DNS ServerThe DNS server information will be supplied by your ISP.
DHCPSelect DHCP Client to obtain IP Address information automatically from your ISP.

Planet IVR-300W - WAN - 1
Note

WAN IP, whether obtained automatically or specified manually, should NOT be on the same IP net segment as the LAN IP; otherwise, the VPN Security Gateway will not work properly. In case of emergency, press the hardware-based "Reset" button.

4.5.3 WAN Advanced

This page is used to configure the advanced parameters for Internet area network which connects to the WAN port of your VPN Security Gateway as shown below. Here you may change the setting for Load Balance Weight, Detect Interval, Detect Linkup Threshold, etc.

WAN1 Configuration Load Balance Weight 3 External Connection Detection Enable Disable Detect Interval 5 Seconds Detect Link Up Threshold 8 Time(s) Detect Link Down Threshold 3 Time(s) Custom Detect Host 1 8.8.8.8 Custom Detect Host 2 208.67.222.222

WAN2 Configuration Load Balance Weight 2 External Connection Detection Enable Disable Detect Interval 5 Seconds Detect Link Up Threshold 8 Time(s) Detect Link Down Threshold 3 Time(s) Custom Detect Host 1 8.8.8.8 Custom Detect Host 2 208.67.222.222

Figure 4.5-5 WAN Advanced Configuration

ObjectDescription
Load Balance WeightLoad Balance Weight allows you to set a relative weight (from 1 - 10) for each WAN port.
External Connection DetectionEnable to detect the status of WAN connection.
Detect IntervalSet the detect interval as you need.The recommended value is 5 (default).
Detect Link Up ThresholdSet the times for detecting link up.The recommended value is 8 (default).
Detect Link Down ThresholdSet the times for detecting link down.The recommended value is 3 (default).
Custom Detect HostThe host is used to check whether the internet connection is alive or not.

4.5.4 LAN

This page is used to configure the parameters for local area network which connects to the LAN port of your VPN Security Gateway as shown below. Here you may change the settings for IP address, subnet mask, DHCP, etc.

LAN Configuration IP Address 192.168.1.1 Netmask 255.255.255.0 Apply Settings Cancel Changes

Figure 4.5-6 LAN Configuration

ObjectDescription
IP AddressThe LAN IP address of the VPN Security Gateway and default is 192.168.1.1.
Net MaskDefault is 255.255.255.0.

4.5.5 Multi-Subnet

This page provides multi-subnet setting as shown below.

Multi-Subnet Configuration Name Network DHCP Server LAN Subnet 1 IP Address 192.168.1.1 V Netmask 255.255.255.0 LAN Subnet 2 IP Address 192.168.3.1 Netmask 255.255.255.0 LAN Subnet 3 IP Address 192.168.5.1 Netmask 255.255.255.0 LAN Subnet 4 IP Address 192.168.7.1 Netmask 255.255.255.0 Apply Settings Cancel Changes

Figure 4.5-7 Multi-Subnet Configuration

4.5.6 VLAN

Please refer to the following sections for the details as shown below.

VLAN Configuration VLAN WAN Port WAN VLAN ID Enable Disable UNTAG 2 VLAN Table Name Management Group Subnet LAN Subnet 1 (192.168.1.1) VLAN ID LAN Port 1 LAN Port 2 LAN Port 3 LAN Port 4 Action UNTAG UNTAG UNTAG UNTAG VLAN Table Configuration Name Switch VLAN Subnet VLAN ID LAN Port 1 LAN Port 2 LAN Port 3 LAN Port 4 Add OFF OFF OFF OFF Add

Figure 4.5-8 VLAN Configuration

4.5.7 UPnP

Please refer to the following sections for the details as shown below.

UPnP Configuration UPnP Enable Disable Apply Settings Cancel Changes

Figure 4.5-9 UPnP Configuration

4.5.8 Routing

Please refer to the following sections for the details as shown below.

Routing config list
NumberTypeDestinationNetmaskGatewayInterfaceCommentAction
Current Routing table in the system
NumberDestinationNetmaskGatewayInterface
10.0.0.00.0.0.0192.168.0 180LOCAL
20.0.0.00.0.0.0192.168.1 18WAN1
30.0.0.00.0.0.0192.168.1 19WAN2
4192.168.0.0255.255.255.00.0.0.0LAN
5192.168.1.0255.255.255.00.0.0.0WAN1
6192.168.1.0255.255.255.00.0.0.0WAN2

Figure 4.5-10 Routing Table Configuration

Add a routing rule Type Host ▼ Destination Netmask 255.255.255.255 /32 ▼ Gateway Interface LAN ▼ Comment Apply Settings Cancel Changes

Figure 4.5-11 Routing Setup

Routing tables contain a list of IP addresses. Each IP address identifies a remote VPN Security Gateway (or other network gateway) that the local VPN Security Gateway is configured to recognize. For each IP address, the routing table additionally stores a network mask and other data that specifies the destination IP address ranges that remote device will accept.

ObjectDescription
TypeThere are two types: Host and Net.When the Net type is selected, user does not need to input the Gateway.
DestinationThe network or host IP address desired to access.
Net MaskThe subnet mask of destination IP.
GatewayThe gateway is the router or host's IP address to which packet is sent. It must be the same network segment with the WAN or LAN port.
InterfaceSelect the interface that the IP packet must use to transmit out of the router when this route is used.
CommentEnter any words for recognition.

4.5.9 RIP

Please refer to the following sections for the details as shown below.

RIP Configuration Dynamic Route Enable Disable RIP Versions RIP 2 Apply Settings Cancel Changes

Figure 4.5-12 RIP Configuration

4.5.10 OSPF

Please refer to the following sections for the details as shown below.

OSPF Configuration OSPF Router ID Area ID Enable Disable 0 Apply Settings Cancel Changes

Figure 4.5-13 OSPF Configuration

4.5.11 IGMP

Please refer to the following sections for the details as shown below.

IGMP Configuration IGMP Proxy IGMP Versions Enable Disable Auto Apply Settings Cancel Changes

Figure 4.5-14 IGMP Configuration

4.5.12 IPv6

This page is used to configure parameter for IPv6 internet network which connects to WAN port of the VPN Security Gateway as shown below. It allows you to enable IPv6 function and set up the parameters of the VPN Security Gateway's WAN. In this setting you may change WAN connection type and other settings.

IPv6 - WAN1

Connection TypeDHCP
IPv6 Address
Subnet Prefix Length64
Default Gateway
IPv6 DNS Server 1
IPv6 DNS Server 2

IPv6 - WAN2

Connection TypeDHCP
IPv6 Address
Subnet Prefix Length64
Default Gateway
IPv6 DNS Server 1
IPv6 DNS Server 2

Figure 4.5-15 IPv6 – WAN Configuration

IPv6 - LAN

TypeDelegate Prefix from WAN ○ Static
Static Address
Subnet Prefix Length64

DHCPv6

Address Assign● Stateless ○ Stateful ○ Passthrough ○ Disable

Figure 4.5-16 IPv6 – LAN Configuration

ObjectDescription
Connection TypeSelect IPv6 WAN type either by using DHCP or Static.
IPv6 AddressEnter the WAN IPv6 address.
Subnet Prefix LengthEnter the subnet prefix length.
Default GatewayEnter the default gateway of the WAN port.

4.5.13 DHCP

The DHCP service allows you to control the IP address configuration of all your network devices. When a client (host or other device such as networked printer, etc.) joins your network it will automatically get a valid IP address from a range of addresses and other settings from the DHCP service. The client must be configured to use DHCP; this is something called "automatic network configuration" and is often the default setting. The setup is shown below.

DHCP Configuration DHCP Server Start IP Address Maximum DHCP Users DNS Server Primary DNS Server Secondary DNS Server WINS Lease Time Domain Name Enable Disable 192.168.1.100 101 Automatically Manually 1440 minutes Static DHCP List Index Device Name IP Address MAC Address 00:30:4F:00:00:01 Delete Add

Figure 4.5-17 DHCP Configuration

ObjectDescription
DHCP ServiceBy default, the DHCP Server is enabled, meaning the VPN Security Gateway will assign IP addresses to the DHCP clients automatically.If user needs to disable the function, please set it as disable.
Start IP AddressBy default, the start IP address is 192.168.1.100.Please do not set it to the same IP address of the VPN Security Gateway
Maximum DHCP UsersBy default, the maximum DHCP users are 101, meaning the VPN Security Gateway will provide DHCP client with IP address from 192.168.1.100 to 192.168.1.200 when the start IP address is 192.168.1.100.
Set DNSBy default, it is set as Automatically, and the DNS server is the VPN Security Gateway's LAN IP address.If user needs to use specific DNS server, please set it as Manually, and then input a specific DNS server.
Primary/SecondaryInput a specific DNS server.
WINSInput a WINS server if needed.
Lease TimeSet the time for using one assigned IP. After the lease time, the DHCP client will need to get new IP addresses from the VPN Security GatewayDefault is 1440 minutes.
Domain NameInput a domain name for the VPN Security GatewayDefault is Planet.

4.5.14 DDNS

The VPN Security Gateway offers the DDNS (Dynamic Domain Name System) feature, which allows the hosting of a website, FTP server, or e-mail server with a fixed domain name (named by yourself) and a dynamic IP address, and then your friends can connect to your server by entering your domain name no matter what your IP address is. Before using this feature, you need to sign up for DDNS service providers such as PLANET DDNS (http://www.planetddns.com) and set up the domain name of your choice.

PLANET DDNS website provides a free DDNS (Dynamic Domain Name Server) service for PLANET devices. Whether the IP address used on your PLANET device supporting DDNS service is fixed or dynamic, you can easily connect the devices anywhere on the Internet with a meaningful or easy-to-remember name you gave. PLANET DDNS provides two types of DDNS services. One is PLANET DDNS and the other is PLANET Easy DDNS as shown below.

PLANET DDNS

For example, you've just installed a PLANET IP camera with dynamic IP like 210.66.155.93 in the network. You can name this device as "Mycam1" and register a domain as Mycam1.planetddns.com at PLANET DDNS (http://www.planetddns.com). Thus, you don't need to memorize the exact IP address but just the URL link: Mycam1.planetddns.com.

PLANET Easy DDNS

PLANET Easy DDNS is an easy way to help user to get your Domain Name with just one click. You can just log in to the Web Management Interface of your devices, say, your VPN Security Gateway, and check the DDNS menu and just enable it. You don't need to go to http://www.planetddns.com to apply for a new account. Once you enabled the Easy DDNS, your PLANET Network Device will use the format PLxxxxxx where xxxxxx is the last 6 characters of your MAC address that can be found on the Web page or bottom label of the device. (For example, if the VPN Security Gateway's MAC address is A8-F7-E0-81-96-C9, it will be converted into pt8196c9.planetddns.com)

DDNS Configuration Dynamic DNS Interface DDNS Type PLANET Easy DDNS User Name Password Host Name Interval 120 seconds Connection Status Not enabled Enable Disable WAN1 PLANET DDNS Disable

Figure 4.5-18 DDNS Configuration

ObjectDescription
DDNS ServiceBy default, the DDNS service is disabled.If user needs to enable the function, please set it as enable.
InterfaceUser is able to select the interface for DDNS service.By default, the interface is WAN 1.
DDNS TypeThere are three options:1. PLANET DDNS: Activate PLANET DDNS service.2. DynDNS: Activate DynDNS service.3. NOIP: Activate NOIP service.Note that please first register with the DDNS service and set up the domain name of your choice to begin using it.
Easy DDNSWhen the PLANET DDNS service is activated, user is able to select to enable or disable Easy DDNS.When this function is enabled, DDNS hostname will appear automatically. User doesn't go to http://www.planetddns.com to apply for a new account.
User NameThe user name is used to log into DDNS service.
PasswordThe password is used to log into DDNS service.
Host NameThe host name as registered with your DDNS provider.
IntervalSet the update interval of the DDNS function.
Update StatusShow the connection status of the DDNS function.

4.5.15 MAC Address Clone

Clone or change the MAC address of the WAN interface. The setup is shown below.

MAC Address Clone - WAN1 Clone WAN MAC MAC Address Enable Disable MAC Address Clone - WAN2 Clone WAN MAC MAC Address Enable Disable Apply Settings Cancel Changes

Figure 4.5-19 MAC Address Clone for WAN

ObjectDescription
Clone WAN MACSet the function as enable or disable.
MAC AddressInput a MAC Address, such as A8:F7:E0:00:06:62.

4.6 Security

The Security menu provides Firewall, Access Filtering and other functions as shown below. Please refer to the following sections for the details.

Firewall MAC Filtering IP Filtering Web Filtering Port Forwarding QoS DMZ

Figure 4.6-1 Security menu

ObjectDescription
FirewallAllows setting DoS (Denial of Service) protection as enable.
MAC FilteringAllows setting MAC Filtering.
IP FilteringAllows setting IP Filtering.
Web FilteringAllows setting Web Filtering.
Port Range ForwardingAllows setting Port Forwarding.
QoSAllows setting QoS.
DMZAllows setting DMZ.

4.6.1 Firewall

A "Denial-of-Service" (DoS) attack is characterized by an explicit attempt by hackers to prevent legitimate users of a service from using that service. The VPN Security Gateway can prevent specific DoS attacks as shown below.

Firewall Protection

SPI Firewall

● Enable ○ Disable

DDoS

Block SYN Flood

Block FIN Flood

Block UDP Flood

Block ICMP Flood

Block IP Teardrop Attack

Block Ping of Death

Block TCP packets with SYN and FIN Bits set

Block TCP packets with FIN Bit set but no ACK Bit set

Block TCP packets without Bits set

● Enable ○ Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

30 Packets/Second

30 Packets/Second

30 Packets/Second

5 Packets/Second

System Security

Block WAN Ping

HTTP Port

HTTPS Port

Remote Management

○ Enable ● Disable

80

443

○ Enable ● Disable

Temporarily block when login failed more than

IP blocking period

Blocked IP

0 (0 means no limit)

0 minute(s) (0 means permanent blocking)

0.0.0.0

NATALGs

FTP ALG

TFTP ALG

RTSP ALG

H.323 ALG

RTSPALG

H.323 ALG

SIP ALG

- Enable ○ Disable

● Enable ○ Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

○ Enable ● Disable

Figure 4.6-2 Firewall

ObjectDescription
SPI FirewallThe SPI Firewall prevents attack and improper access to network resources.The default configuration is enabled.
Block SYN FloodSYN Flood is a popular attack way. DoS and DDoS are TCP protocols. Hackers like to use this method to make a fake connection that involves the CPU, memory, and so on.The default configuration is enabled.
Block FIN FloodIf the function is enabled, when the number of the current FIN packets is beyond the set value, the VPN Security Gateway will start the blocking function immediately.The default configuration is disabled.
Block UDP FloodIf the function is enabled, when the number of the current UPD-FLOOD packets is beyond the set value, the VPN Security Gateway will start the blocking function immediately.The default configuration is disabled.
Block ICMP FloodICMP is kind of a pack of TCP/IP; its important function is to transfer simple signal on the Internet. There are two normal attack ways which hackers like to use, Ping of Death and Smurf attack.The default configuration is disabled.
IP TearDropIf the function is enabled, the VPN Security Gateway will block Teardrop attack that is targeting on TCP/IP fragmentation reassembly codes.
Ping Of DeathIf the function is enabled, the VPN Security Gateway will block Ping of Death attack that aims to disrupt a targeted machine by sending a packet larger than the maximum allowable size causing the target machine to freeze or crash.
Block WAN PingEnable the function to allow the Ping access from the Internet network.The default configuration is disabled.
Remote ManagementEnable the function to allow the web server access of the VPN Security Gateway from the Internet network.The default configuration is disabled.

4.6.2 MAC Filtering

Entries in this table are used to restrict certain types of data packets from your local network or Internet through the VPN Security Gateway Use of such filters can be helpful in securing or restricting your local network as shown below.

MAC Filtering MAC Filtering Interface Enable Disable LAN WAN MAC Filtering Rules Index Active Device Name MAC Address Action abc 00:30:4F:00:00:01 Add Apply Settings Cancel Changes

Figure 4.6-3 MAC Filtering Configuration

ObjectDescription
Enable MAC FilteringSet the function as enable or disable.When the function is enabled, the VPN Security Gateway will block traffic of the MAC address on the list.
InterfaceSelect the function works on LAN, WAN or both. If you want to block a LAN device's MAC address, please select LAN, vice versa.
MAC AddressInput a MAC address you want to control, such as A8:F7:E0:00:06:62.
AddWhen you input a MAC address, please click the “Add” button to add it to the list.
RemoveIf you want to remove a MAC address from the list, please click on the MAC address, and then click the “Remove” button to remove it.
Remove AllIf you want to remove all MAC addresses from the list, please click the “Remove All” button to remove all.

4.6.3 IP Filtering

IP Filtering is used to deny LAN users from accessing the public IP address on internet as shown below. To begin blocking access to an IP address, enable IP Filtering and enter the IP address of the web site you wish to block.

IP Filtering IP Filtering Enable Disable IP Filtering Rules No. Active Source IP Destination IP Port Range Protocol Action Add IP Filtering Rule

Figure 4.6-4 IP Filtering Configuration

ObjectDescription
IP FilteringSet the function as enable or disable.
Add IP Filtering RuleGo to the Add Filtering Rule page to add a new rule.

IP Filter Rule Setting Enable Source IP Address / 32 ▼ Anywhere Destination IP Address / 32 ▼ Anywhere Destination Port - Protocol All ▼ Apply Settings Cancel Changes

Figure 4.6-5 IP Filter Rule Setting

ObjectDescription
EnableSet the rule as enable or disable.
Source IP AddressInput the IP address of LAN user (such as PC or laptop) which you want to control.
Anywhere (of source IP Address)Check the box if you want to control all LAN users.
Destination IP AddressInput the IP address of web site which you want to block.
Anywhere (of destination IP Address)Check the box if you want to control all web sites, meaning the LAN user can't visit any web site.
Destination PortInput the port of destination IP Address which you want to block.Leave it as blank if you want to block all ports of the web site.
ProtocolSelect the protocol type (TCP, UDP or all).If you are unsure, please leave it to the default all protocol.

4.6.4 Web Filtering

Web filtering is used to deny LAN users from accessing the internet as shown below. Block those URLs which contain keywords listed below.

Web Filtering Web Filtering Enable Disable Web Filtering Rules No. Active Filter Keyword Action Add Web Filtering Rule

Figure 4.6-6 Web Filtering Configuration

ObjectDescription
Web FilteringSet the function as enable or disable.
Add Web Filtering RuleGo to the Add Web Filtering Rule page to add a new rule.

Web Filtering Active Filter Keyword Enable Disable ex. www.yahoo.com Apply Settings Cancel Changes

Figure 4.6-7 Web Filtering Rule Setting

ObjectDescription
ActiveSet the rule as enable or disable.
Filter KeywordInput the URL address that you want to filter, such as www.yahoo.com.

4.6.5 Port Forwarding

Entries in this table allow you to automatically redirect common network services to a specific machine behind the NAT firewall as shown below. These settings are only necessary if you wish to host some sort of server like a web server or mail server on the private local network behind your VPN Security Gateway's NAT firewall.

Port Forwarding Port Forwarding Enable Disable Port Forwarding Rules No. Rule Name Active External Interface Protocol External Port Range Internal IP Internal Port Range Action

Figure 4.6-8 Port Forwarding Configuration

ObjectDescription
Port ForwardingSet the function as enable or disable.
Add Port Forwarding RuleGo to the Add Port Forwarding Rule page to add a new rule.

Port Forwarding Active Rule Name Protocol Both External Service Port Virtual Server IP Address Internal Service Port Enable Disable Apply Settings Cancel Changes

Figure 4.6-9 Port Forwarding Rule Setting

ObjectDescription
Rule NameEnter any words for recognition.
ProtocolSelect the protocol type (TCP, UDP or both). If you are unsure, please leave it to the default both protocols.
External Service PortEnter the external ports you want to control. For TCP and UDP services, enter the beginning of the range of port numbers used by the service. If the service uses a single port number, enter it in both the start and finish fields.
Virtual Server IP AddressEnter the local IP address.
Internal Service PortEnter local ports you want to control. For TCP and UDP Services, enter the beginning of the range of port numbers used by the service. If the service uses a single port number, enter it in both the start and finish fields.

4.6.6 QoS

Please refer to the following sections for the details as shown below.

QoS - WAN1 Quality of Service ○ Enable ● Disable Upstream 0 Kbps Downstream 0 Kbps

QoS - WAN2 Quality of Service Enable Disable Upstream 0 Kbps Downstream 0 Kbps

Upstream Bandwidth
PriorityMaximum BandwidthBandwidth Value
Premium100 %WAN1 0 Kbps
WAN2 0 Kbps
Express100 %WAN1 0 Kbps
WAN2 0 Kbps
Standard100 %WAN1 0 Kbps
WAN2 0 Kbps
Bulks100 %WAN1 0 Kbps
WAN2 0 Kbps
Downstream Bandwidth
PriorityMaximum BandwidthBandwidth Value
Premium100 %WAN1 0 Kbps
WAN2 0 Kbps
Express100 %WAN1 0 Kbps
WAN2 0 Kbps
Standard100 %WAN1 0 Kbps
WAN2 0 Kbps
Bulks100 %WAN1 0 Kbps
WAN2 0 Kbps

Service Priority Protocol AOL(TCP:5190) Description AOL Instant Messenger protocol Priority Premium Action Add

Network Priority Source Network Protocol Destination Port Range Priority Action ALL -- Premium Add

Figure 4.6-10 QoS Configuration

4.6.7 DMZ

A Demilitarized Zone is used to provide Internet services without sacrificing unauthorized access to its local private network as shown below. Typically the DMZ host contains devices accessible to Internet traffic, such as Web (HTTP) servers, FTP servers, SMTP (e-mail) servers and DNS servers.

DMZ - WAN1 DMZ Enable Disable DMZ IP Address DMZ - WAN2 DMZ Enable Disable DMZ IP Address Apply Settings Cancel Changes

Figure 4.6-11 DMZ Configuration

ObjectDescription
DMZSet the function as enable or disable. If the DMZ function is enabled, it means that you set up DMZ at a particular computer to be exposed to the Internet so that some applications/software, especially Internet/online game can have two way connections.
DMZ IP AddressEnter the IP address of a particular host in your LAN which will receive all the packets originally going to the WAN port/Public IP address above.

4.7 VPN

To obtain a private and secure network link, the VPN (Virtual Private Network) Security Gateway is capable of establishing VPN connections. When used in combination with remote client authentication, it links the business' remote sites and users, conveniently providing the enterprise with an encrypted network communication method. By allowing the enterprise to utilize the Internet as a means of transferring data across the network, it forms one of the most effective and secure options for enterprises to adopt in comparison to other methods.

Planet IVR-300W - VPN - 1

flowchart
graph LR
    A["Industrial VPN Security Gateway"] --> B["Failover Connection"]
    B --> C["Content Filtering"]
    C --> D["VPN Tunnel"]

The VPN menu provides the following features as shown below.

IPsec IPsec Remote Server GRE PPTP L2TP SSL VPN Certificates VPN Connection SD WAN

Figure 4.7-1 VPN Menu

ObjectDescription
IPsecAllows setting IPsec function.
IPsec Remote ServerDisable or enable the IPsec Remote Server function.The default configuration is disabled.
GREAllows setting GRE function.
PPTPAllows setting PPTP function.
L2TPAllows setting L2TP function.
SSL VPNAllows setting SSL VPN function.
CertificatesDownload System CA Certificate
VPN ConnectionAllows checking VPN Connection Status.

4.7.1 IPSec

IPSec (IP Security) is a generic standardized VPN solution. IPSec must be implemented in the IP stack which is part of the kernel. Since IPSec is a standardized protocol it is compatible to most vendors that implement IPSec. It allows users to have an encrypted network session by standard IKE (Internet Key Exchange). We strongly encourage you to use IPSec only if you need to because of interoperability purposes. When IPSec lifetime is specified, the device can randomly refresh and identify forged IKE's during the IPSec lifetime.

This page will allow you to modify the user name and passwords as shown below.

IPsec Configuration IPsec Tunnels ○Enable ●Disable IPsec Tunnel Lists No. Tunnel Name Active Status Action

Figure 4.7-2 IPsec Configuration

ObjectDescription
Add IPSec TunnelGo to the Add IPSec Tunnel page to add a new tunnel.

IPsec Tunnel Active Tunnel Name Type Local Network Local Netmask Remote Host/IP Address Remote Network Remote Netmask Enable Disable Net-to-Net Virtual Private Network 255.255.255.0 /24 255.255.255.0 /24 Detection Dead Peer Detection ✓ Time Interval 30 Seconds Timeout 150 Seconds Action Restart ✓ Authentication Preshare Key

IKE Setting

Phase 1

IKE

v1

○v2

Connection Type

Ma

in ○Aggressive

ISAKMP

AES

128 bit)

SHA1

DH Group

2 (1024)

IKE SA Lifetime

3

The Ground Truth image displays a single, solid horizontal line. According to Rule 2 (UNDERSCORE & LINE RULES), this is a stylistic or background line, not a placeholder underscore. Therefore, the OCR result must ignore it and output nothing or only meaningful text. The provided OCR content is "____", which consists of four underscores. This is an incorrect interpretation of the line as a placeholder, violating the rule that stylistic lines must be ignored. The OCR has hallucinated underscores where none should exist based on the GT's visual context. Hence, the OCR result is inconsistent with the Ground Truth.

hours

Phase 2

ESP

AES

128 bit

SHA1

m = 311

ESP Keylife

1

The Ground Truth image displays a single, solid horizontal line. According to Rule 2 (UNDERSCORE & LINE RULES), this is a stylistic or background line, not a placeholder underscore. Therefore, the OCR result must ignore it and output nothing or only meaningful text. The provided OCR content is "____", which consists of four underscores. This is an incorrect interpretation of the line as a placeholder, violating the rule that stylistic lines must be ignored. The OCR has hallucinated underscores where none should exist based on the GT's visual context. Hence, the OCR result is inconsistent with the Ground Truth.

hours

Perfect Forward Secrecy (PFS)

○Ye

s N

Figure 4.7-3 IPSec Tunnel

ObjectDescription
IPSec Tunnel EnableCheck the box to enable the function.
Tunnel NameEnter any words for recognition.
InterfaceThis is only available for host-to-host connections and specifies to which interface the host is connecting.1. WAN 1.2. WAN 2.
Local NetworkThe local subnet in CIDR notation. For instance, "192.168.1.0".
Local NetmaskThe netmask of this VPN Security Gateway
Remote IP AddressInput the IP address of the remote host. For instance, "210.66.1.10".
Remote NetworkThe remote subnet in CIDR notation. For instance, "210.66.1.0".
Remote NetmaskThe netmask of the remote host.
Dead Peer DetectionSet up the detection time of DPD (Dead Peer Detection).By default, the DPD detection's gap is 30 seconds, over 150 seconds to think that is the broken line.When VPN detects opposite party reaction time, the function will take one of the actions: "Hold" stand for the system will retain IPSec SA "Clear" stand for the tunnel will clean away and waits for the new sessions, "Restart" will delete the IPSec SA and reset VPN tunnel.
Preshare KeyEnter a pass phrase to be used to authenticate the other side of the tunnel. Should be the same as the remote host.
IKESelect the IKE (Internet Key Exchange) version.
Connection Type1. Main.2. Aggressive.
ISAKMPIt provides the way to create the SA between two PCs. The SA car access the encoding between two PCs, and the IT administrator can assign to which key size or Preshare Key and algorithm to use. The SA comes in many connection ways.1. AES: All using a 128-bit, 192-bit and 256-bit key. AES is a commonly seen and adopted nowadays.2. 3DES: Triple DES is a block cipher formed from the DES cipher by using it three times. It can achieve an algorithm up to 168 bits.3. SHA1: The SHA1 is a revision of SHA. It has improved the shortcomings of SHA. By producing summary hash values, it can achieve an algorithm up to 160 bits.4. SHA2: Either 256, 384 or 512 can be chosen5. MD5 Algorithm: MD5 processes a variably long message into a fixed-length output of 128 bits.6. DH Group: Either 1, 2, 5, 14, 15, 16, 17, or 18 can be chosen.
IKE SA LifetimeYou can specify how long IKE packets are valid.
ESPIt offers AES, 3 DES, SHA 1, SHA2, and MD5.1. AES: All using a 128-bit, 192-bit and 256-bit key. AES is a commonly seen and adopted nowadays.2. 3DES: Triple DES is a block cipher formed from the DES cipher by using it three times. It can achieve an algorithm up to 168 bits.3. SHA1: The SHA1 is a revision of SHA. It has improved the shortcomings of SHA. By producing summary hash values,i can achieve an algorithm up to 160 bits.4. SHA2: Either 256, 384 or 512 can be chosen.5. MD5 Algorithm: MD5 processes a variably long message into a fixed-length output of 128 bits.
ESP KeylifeYou can specify how long ESP packets are valid.
Perfect Forward Secrecy (PFS)Set the function as enable or disable.

4.7.2 IPsec Remote Server

This section assists you in setting the IPsec Remote Server Configuration as shown below.

IPsec Remote Server Configuration Remote Access VPN Type Extensible Authentication Protocol Enable Disable IKEv2 MSCHAPv2 Account List Index Username Password Delete Add Authentication Certificate Self-signed certificate Preshare Key IPsec Phase 1 ISAKMP AES(128 bit) SHA1 DH Group 2 (1024) IKE SA Lifetime 3 hours Phase 2 ESP AES (128 bit) SHA1 ESP Keylife 1 hours

Figure 4.7-4 IPsec Remote Server Configuration

4.7.3 GRE

This section assists you in setting the GRE Tunnel as shown below.

GRE Tunnel GRE Tunnel Enable Disable GRE Tunnel Lists No. Name Enable Through Peer WAN IP Addr Peer Subnet Peer Tunnel IP Local Tunnel IP Local Netmask Action Add GRE Tunnel

Figure 4.7-5 GRE Tunnel

ObjectDescription
GRE TunnelSet the function as enable or disable.
Add GRE TunnelGo to the Add GRE Tunnel page to add a new tunnel.

GRE Tunnel Active Tunnel Name Through Peer WAN IP Address Peer Netmask Peer Tunnel IP Address Local Tunnel IP Address Local Netmask Enable Disable LAN Remote IP Address 10.10.10.0/24 10.10.10.2 10.10.10.1 255.255.255.255 /32

Figure 4.7-6 GRE Tunnel Configuration

ObjectDescription
ActiveCheck the box to enable the function.
Tunnel NameEnter any words for recognition.
ThroughThis is only available for host-to-host connections and specifies to which interface the host is connecting.1. LAN.2. WAN 1.3. WAN 2.
Peer WAN IP AddressInput the IP address of the remote host. For instance, "210.66.1.10".
Peer NetmaskThe remote subnet in CIDR notation. For instance, "210.66.1.0/24".
Peer Tunnel IP AddressInput the Tunnel IP address of remote host.
Local Tunnel IP AddressInput the Tunnel IP address of remote host.
Local NetmaskInput the Tunnel IP address of the VPN Security Gateway

4.7.4 PPTP

Use the IP address and the scope option needs to match the far end of the PPTP server; its goal is to use the PPTP channel technology, and establish Site-to-Site VPN where the channel can have equally good results from different methods with IPSec. The PPTP server is shown in Figure 4-8-6.

PPTP Server PPTP Server ○ Enable ● Disable Broadcast ○ Enable ● Disable Force MPPE Encryption ● Enable ○ Disable CHAP ● Enable ○ Disable MSCHAP ● Enable ○ Disable MSCHAP v2 ● Enable ○ Disable DNS1 DNS2 WINS1 WINS2 Server IP Address 192.168.10.1 Clients IP Address Start 192.168.10.10 Clients IP Address End 192.168.10.100 Account List Index Username Password Delete Add

Figure 4.7-7 PPTP Server Configuration

ObjectDescription
PPTP ServerSet the function as enable or disable.
BroadcastEnter any words for recognition.
Force MPPE EncryptionSet the encryption as enable or disable.
CHAPSet the authentication as enable or disable.
MSCHAPSet the authentication as enable or disable.
MSCHAP v2Set the authentication as enable or disable.
DNSWhen the PPTP client connects to the PPTP server, it will assign the DNS server IP address to client.
WINSWhen the PPTP client connects to the PPTP server, it will assign the WINS server IP address to client.
Server IP AddressInput the IP address of the PPTP Server. For instance, "192.168.10.1".
Clients IP Address (Start/End)When the VPN connection is established, the VPN client will get IP address from the VPN Server. Please set the range of IP Address. For instance, the start IP address is "192.168.10.10", the end IP address is "192.168.10.100".
User and PasswordCreate the username and password for the VPN client.

4.7.5 L2TP

This section assists you in setting the L2TP Server as shown below.

L2TP Server L2TP Server Server IP Address Clients IP Address Start Clients IP Address End With IPsec Preshare Key Enable Disable 192.168.50.1 192.168.50.100 192.168.50.200 Enable Disable Account List Index Username Password Delete Add IPsec Phase 1 Connection Type Main Aggressive ISAKMP AES(128 bit) SHA1 DH Group 2 (1024) IKE SA Lifetime 3 hours Phase 2 ESP AES (128 bit) SHA1 ESP Keylife 1 hours

Figure 4.7-8 L2TP Server Configuration

ObjectDescription
L2TP ServerSet the function as enable or disable.
Server IP AddressInput the IP address of the L2TP Server. For instance, "192.168.50.1".
Clients IP Address (Start/End)When the VPN connection is established, the VPN client will get IP address from the VPN Server. Please set the range of IP Address. For instance, the start IP address is "192.168.50.100", the end IP address is "192.168.50.200".
With IPsecSet the function as enable to make the L2TP work with IPsec encryption.
Preshare KeyEnter a pass phrase.
User and PasswordCreate the username and password for the VPN client.
Connection Type1. Main.2. Aggressive.
ISAKMPIt provides the way to create the SA between two PCs. The SA can access the encoding between two PCs, and the IT administrator canassign to which key size or Preshare Key and algorithm to use. The SA comes in many connection ways.1. AES: All using a 128-bit, 192-bit and 256-bit key. AES is a commonly seen and adopted nowadays.2. 3DES: Triple DES is a block cipher formed from the DES cipher by using it three times. It can achieve an algorithm up to 168 bits.3. SHA1: The SHA1 is a revision of SHA. It has improved the shortcomings of SHA. By producing summary hash values, it can achieve an algorithm up to 160 bits.4. SHA2: Either 256, 384 or 512 can be chosen.5. MD5 Algorithm: MD5 processes a variably long message into a fixed-length output of 128 bits.6. DH Group: Either 1, 2, 5, 14, 15, 16, 17, or 18 can be chosen.
IKE SA LifetimeYou can specify how long IKE packets are valid.
ESPIt offers AES, 3 DES, SHA 1, SHA2, and MD5.1. AES: All using a 128-bit, 192-bit and 256-bit key. AES is a commonly seen and adopted nowadays.2. 3DES: Triple DES is a block cipher formed from the DES cipher by using it three times. It can achieve an algorithm up to 168 bits.3. SHA1: The SHA1 is a revision of SHA. It has improved the shortcomings of SHA. By producing summary hash values,it can achieve an algorithm up to 160 bits.4. SHA2: Either 256, 384 or 512 can be chosen.5. MD5 Algorithm: MD5 processes a variably long message into a fixed-length output of 128 bits.
ESP KeylifeYou can specify how long ESP packets are valid.

4.7.6 SSL VPN

This section assists you in setting the SSL Server as shown below.

SSL VPN Server Client OpenVPN Server Port Tunnel Protocol Virtual Network Device Interface VPN Network Netmask Set VPN as Default Gateway Connect Server LAN to Client Encryption Cipher Hash Algorithm Export client.ovpn Remote Client Network IP Netmask Enable Disable UDP TUN LAN 192.168.1.1 192.168.20.0 255.255.255.0 Enable Disable Enable Disable AES-128 CBC SHA1 Export Enable Disable 0.0.0.0 0.0.0.0

Figure 4.7-9 SSL Server Configuration

ObjectDescription
SSL VPN ServerSet the function as enable or disable.
PortSet a port for the SSL Service. Default port is 1194.
Tunnel ProtocolSet the protocol as TCP or UDP.
Virtual Network DeviceSet the Virtual Network Device as TUN or TAP.
InterfaceUser is able to select the interface for SSL service using.
VPN NetworkThe VPN subnet in CIDR notation. For instance, "192.168.20.0".
Network MaskThe netmask of the VPN.
Encryption CipherThere are four encryption types: None, AES-128 CBC, AES-192 CBC or AES-256 CBC.
Hash AlgorithmThere are five types of Hash Algorithm: None, SHA1, SHA1, SHA512 or MD5.
Export client.ovpnExport a configuration for the SSL client. User is able to upload it to VPN client (such as Open VPN software).

4.7.7 Certificates

This page shows the VPN System Certificates status as shown below.

System Certificates System CA Certificate Download System CA Certificate for HTTPS and VPN Server, please install to PC

Figure 4.7-10 System Certificates

4.7.8 VPN Connection

This page shows the VPN connection status as shown below.

VPN Connection Status IPsec GRE PPTP L2TP SSL VPN No. Tunnel Name Connected Time Local IP Remote IP Local Subnet Remote Subnet

Figure 4.7-11 VPN Connection Status

ObjectDescription
VPN Connection StatusClick the IPSec/GRE/.../SSL VPN bookmark to check the current connection status.

4.7.9 SD WAN

This page shows the SD WAN Configuration status as shown below.

SD WAN Configuration SD WAN Enable Disable SD WAN Lists No. Group Name Local Subnet Remote Subnet Gateway Action SD WAN Configuration Group Name IPsec Tunnel Weight Gateway □ 1 WAN1 () □ 1 WAN2 ()

Figure 4.7-12 SD WAN Configuration

4.8 AP Control

The IVR-300/IVR-300W provides centralized management of PLANET Smart AP series via a user-friendly Web GUI. It's easy to configure AP for the wireless SSID, radio band and security settings. With a four-step configuration process, wireless profiles for different purposes can be simultaneously delivered to multiple APs or AP groups to minimize deployment time, effort and cost.

Planet IVR-300W - AP Control - 1

flowchart
graph TD
    A["Control Room"] --> B["Lobby"]
    A --> C["Meeting Room"]
    D["Central AP Controller"] --> E["CH11 Tx: 100%"]
    D --> F["CH12 Tx: 50%"]
    D --> G["CH13 Tx: 100%"]
    D --> H["CH14 Tx: 70%"]
    D --> I["CH15 Tx: 100%"]
    J["Control Room"] --> K["Lobby"]
    J --> L["Meeting Room"]
    M["AP Control"] --> N["CH1 Tx: 100%"]
    M --> O["CH26 Tx: 100%"]
    P["AP Management"] --> Q["CH1 Tx: 70%"]
    P --> R["CH26 Tx: 100%"]
    S["AP Group Management"] --> T["CH1 Tx: 70%"]
    S --> U["CH26 Tx: 100%"]
    V["Radio 2.4G Profile"] --> W["CH1 Tx: 100%"]
    X["Radio SG Profile"] --> Y["CH1 Tx: 100%"]
    Z["Static AP Status"] --> AA["CH1 Tx: 100%"]
    AB["Map II"] --> AC["CH1 Tx: 35%"]
    AD["Upload Map"] --> AE["CH1 Tx: 35%"]

For example, to configure multiple smart APs of the same model, the IVR-300/IVR-300W allows clustering them to a managed group for unified management. According to requirements, wireless APs can be flexibly expanded or removed from a wireless AP group at any time. The AP cluster benefits bulk provision and bulk firmware upgrade through single entry point instead of having to configure settings in each of them separately.

Simplified Cluster Management with 4 Steps

Planet IVR-300W - Simplified Cluster Management with 4 Steps - 1

flowchart
graph LR
    A["Step 1\nSearch"] --> B["Step 2\nAdd Profile"]
    B --> C["Step 3\nBatch Provisioning"]
    C --> D["Step 4\nMap It"]

The AP Control menu provides the following features for managing the system as shown below.

Preference AP Search AP Management AP Group Management SSID Profile Radio 2.4GHz Profile Radio 5GHz Profile Statistic AP Status Map It Upload Map

Figure 4.8-1 AP Control Menu

ObjectDescription
PreferenceEdit region, RO community, RW community
AP SearchSearch APs in the same domain
AP ManagementConfig APs IP Address, Subnet Mask, SSID and Radio Profiles
AP Group ManagementGrouping same model AP
SSID ProfileSetup SSID Profile
Radio 2.4GHz ProfileSetup Radio 2.4GHz Profiles
Radio 5GHz ProfileSetup Radio 5GHz Profiles
Statistics AP StatusShow the status of managed APs
Map ItEdit the map of AP location and coverage
Upload MapSearch APs in the same domain

4.8.1 Preference

On this page, you can choose the device region of FCC or ETSI. Then edit RO community and RW community for public or private use. Select Apply or Reset. This screenshot is as shown below.

AP Preference
Region ETSI RO Community public RW Community private

Figure 4.8-2 AP Preference

Planet IVR-300W - Preference - 2

Device of FCC and device of ETIS cannot be shown at the same time.

On this page, you can add new APs in your AP Control System.

Steps to follow:

Step 1. Press the Search button to discover PLANET devices.
Step 2. After waiting for a while, choose which AP you want to add.
Step 3. Press the Apply button to finish addition.

AP Search Search Apply Filter by Model, MAC, IP 10 (10..1024) Num. MAC Address Device Type Model No. Version Device IP Device Description 1 a8 f7: e0:33:44 56 Wireless WDAP-850AC WDAP-850AC-AP-ETSI-V3.0-Build20210104135430 192.168.1.253

Figure 4.8-3 AP Search of AP Controller

Planet IVR-300W - AP Search - 2

When using AP Search, the AP's IP Address must be the same as WS-Series Switch IP domain.

4.8.3 AP Management

On this page, you can manage your APs, including checking AP online status, configuring AP (IP address, Mask, SSID and Radio profile), rebooting AP, firmware update, and deleting AP in the AP Control system.

AP Managemont Apply Filter by Context 10 (10..32) Online Offline Disable Status AP Group MAC Address Device Type Model No. Version IP Address Device Description Action a8 f7:e0:33:44:56 Wireless WDAP-850AC WDAP-850AC-AP-ETSI-V3.0-Build20210104135430 192.168.1 254

Figure 4.8-4 AP Management of AP Controller

Status:

ObjectDescription
Connection status: online, offline, Wi-Fi disabled
In progress: action in progress
Finished/Successful: action finished and successful.
Failed: action failed.

Action:

ObjectDescription
Setting: edit setting and allocate profile to AP
Link: link to the AP's web page
Firmware Update: Upgrade AP's firmware
Reboot: Reboot the AP
Delete: Delete the AP from the control list LED Control: Control the AP's LED.
Mouse-click in a sequential order: LED blink-> LED off-> LED on

Planet IVR-300W - AP Management - 2

To configure multiple APs at one time, select multiple APs and then choose one of the action icons on the top of the page. The "Link" action is not allowed for multiple APs.

Planet IVR-300W - AP Management - 3

When the setup of AP is done, you need to press the Apply button to complete the setup.

4.8.4 AP Group Management

On the AP Group Management page, you can create AP group and control one or more AP groups.

AP Group Management ■ Nom. Group Name Group Description Action □ 1 Group-WDAP-850-1 Group-WDAP-850

Figure 4.8-5 AP Group Management of AP Controller

Action:

ObjectDescription
Planet IVR-300W - Action: - 1Add new group: Click it to add an AP group.
Planet IVR-300W - Action: - 2Delete selected item: Click it to delete the selected AP group.

AP Group Config Save Back Reset AP Group Configured Group Member Setting Model No WDAP-850AC Current AP Group Members Available Managed APs AP Group Name Group-WDAP-850-1 WDAP-850AC(a8:f7:e0:33:44:56) << Add AP Group Description Group-WDAP-850 Remove>> 2.4G Profile 5G Profile SSID 1 Disable Disable SSID 2 Disable Disable SSID 3 Disable Disable SSID 4 Disable Disable Radio Profile Disable Disable

Figure 4.8-6 AP Group Config of AP Controller

■ Create Group:

  1. Select AP Model No. you want to Add
  2. Type AP Group Name and AP Group Description.
  3. Select AP you want to add in group member setting area and press the Add button.
  4. Select AP Group SSID profile and Radio Profile.
  5. Press the Apply button to finish create AP group.

Planet IVR-300W - ■ Create Group: - 1

To do profile provisioning to multiple AP groups at one time, select multiple AP groups, and then click the "Apply" button.

The "Link" action is not allowed for multiple APs or AP group.

4.8.5 SSID Profile

On the SSID profile configuration page, enter the value that you preferred and then click "Apply" to save the profile.

SSID ProfileFilter by SSID Name10 (10_16)
Num.Model No.SSID NameSSID BroadcastSecurityEncryptionClient IsolationAction
1WDAP-850ACWDAP-850ACP-10FDisabledWPAPersonal (Pre-Shared Key)Enabled

Figure 4.8-7 SSID Profile of AP Controller

SSID Profile Configuration Apply Back Reset SSID Profile Configuration Model No.WDAP-850AC SSID Configuration SSID Name.WDAP-850ACP-10F Hide SSID Client Isolation Enable VLAN Isolation Enable VLAN ID 3 (3 to 4094) Security Configuration Encryption.WPA Authentication Mode.Personal (Pre-Shared Key) Cipher Suite.TKIP Pre-Shared Key Format.Passphrase Pre-Shared Key.WDAP-850ACP-10F

Figure 4.8-8 SSID Profile Configuration of AP Controller

Action:

ObjectDescription
Planet IVR-300W - Action: - 1Add new profile: Click it to add a new profile.
Planet IVR-300W - Action: - 2Delete selected item: Click it to delete the selected profile.
Planet IVR-300W - Action: - 3Edit: Click it to edit the profile.
[wcg7]Delete: Click it to delete the single profile.

4.8.6 Radio 2.4GHz Profile

On the Radio profile configuration page, enter the value that you preferred and then click "Apply" to save the profile.

Radio Profile 2.4GHzFilter by Profile Name10 (10..8)
Num.Model No.Profile NameWireless ModeChannel IDChannel BandwidthTx PowerData RateAction
1WDAP-850ACTest 2.4GHz11b/g/n mixed modeAuto40MHz100%N/A

Figure 4.8-9 2.4GHz Radio Profile of AP Controller

Action:

ObjectDescription
Planet IVR-300W - Action: - 1Add new profile: Click it to add a new profile.
Planet IVR-300W - Action: - 2Delete selected item: Click it to delete the selected profile.
Planet IVR-300W - Action: - 3Edit: Click it to edit the profile.
Planet IVR-300W - Action: - 4Delete: Click it to delete the single profile.

Radio Profile 2.4GHz Configuration

Planet IVR-300W - Action: - 5

Radio Profile Configuration Model No: WDAP-850AC Basic Setting Radio Profile Description Test 2.4GHz Wireless Mode 11b/g/n mixed mode Channel Bandwidth 40MHz Channel Auto Tx Power 100% Client Limit ✓ 64 (0 to 64) RSSI Threshold -95 (-95 to -65) dBm

Figure 4.8-10 2.4GHz Radio Profile Configuration of AP Controller

Action:

ObjectDescription
Apply Button:Click this button to save the settings.
Back Button:Click this button to return to the previous page.
Reset Button:Click this button to reset all fields to default value.

Planet IVR-300W - Action: - 1

Strongly suggest you to keep the values as default except the fields like Channel, Network Mode, Channel Bandwidth, Tx Power, IAPP, and Tx/Rx to prevent any unexpected error or impact on the performance.

Planet IVR-300W - Action: - 2

WMM Capable is not allowed to be disabled.

4.8.7 Radio 5GHz Profile

On the Radio profile configuration page, enter the value that you preferred and then click "Apply" to save the profile.

Radio Profile 5GHz Filter by Profile Name 10 (10..8) Num. Model No. Profile Name Wireless Mode Channel ID Channel Bandwidth Tx Power Date Rate Action 1 WDAP-850AC Test 5GHz-10F 11n/ac mixed mode Auto 40MHz 100% N/A

Figure 4.8-11 5 GHz Radio Profile of AP Controller

Action:

ObjectDescription
Planet IVR-300W - Action: - 1Add new profile: Click it to add a new profile.
Planet IVR-300W - Action: - 2Delete selected item: Click it to delete the selected profile.
Planet IVR-300W - Action: - 3Edit: Click it to edit the profile.
Planet IVR-300W - Action: - 4Delete: Click it to delete the single profile.

Radio Profile 5GHz Configuration

Planet IVR-300W - Action: - 5

Radio Profile Configuration Model No. WDAP-850AC Basic Setting Radio Profile Description Test 5GHz-10F Wireless Mode 11n/ac mixed mode Channel Bandwidth 40MHz Channel Auto Tx Power 100% Client Limit ✓ 64 (0 to 64) RSSI Threshold -95 (-95 to -65) dBm

Figure 4.8-12 5 GHz Radio Profile Configuration of AP Controller

Action:

Apply Button: Click this button to save the settings.

Back Button: Click this button to return to the previous page.

Reset Button: Click this button to reset all fields to default value.

Planet IVR-300W - Action: - 1

  1. Strongly suggest you to keep the values as default except the fields like Channel, Network Mode, Channel Bandwidth, Tx Power, IAPP, and Tx/Rx to prevent any unexpected error or impact on the performance.

  2. WMM Capable is not allowed to be disabled.

4.8.8 Statistics AP Status

On this page, you can observe the current configuration of all managed APs.

Num.StatusMAC AddressIP AddressModel No.NameFirmwareAP Group2.4GHz SSID Profile5GHz SSID Profile2.4GHz Radio Profile50Hz Radio Profile
1a8.17.e0.46.2e.36192.168.0.102WDAP-C7200EWDAP-C7200E-AP-FCC-V3.0-Build20200321122005
2a8.17.e0.3c.5f.ab192.168.0.101WNAP-C3220EWNAP-C3220E-AP-FCC-V3.0-Build20200422115453N/AN/A

Figure 4.8-13 Statistics AP Status of AP Controller

Filter: You can filter the AP list by entering the keyword in the field next to the magnifier icon. The keyword should be in any context that belongs to the fields of this page.

4.8.9 Map It

On this page you can add managed APs to the actual position against the floor map. This is convenient to user to view and adjust the actual deployment by reference to its real transmission power and channel allocation.

Upload Map Map New Map Upload File Choose File No file chosen New Description File Size Bytes Apply

Figure 4.8-14 Upload Map page
Device Description WDAP-C7200E WNAP-C3220E 1 : 30.303030303030305m Cancel AP Group Band Transparency Scale Please draw a straight line to estimate distance with a mouse. What is the physical distance of the draw line? m ▼ Set Cancel 100 50 m 100 m 150 m 200 m 250 m 300 Save test 100

Device Description 1 S WDAP-C7200E ✓ WNAP-C3220E ✓ 0 50 m 100 m 150 m 200 m 250 m 300 m 350 m 100 50 m 100 m 150 m 1:39.21568627450981m Set Save test AP Group Band Transparency Scale Sooj.com.cn

Figure 4.8-15 the simulator page of the wireless signal strong of AP

  1. Click "Scale" to start to reset the map scale.
  2. Press the set button to draw a line on the map. Fill its physical distance in the blank and press Set or Cancel. For example, in the graph below, set the door width to 0.8 m

Planet IVR-300W - Map It - 4
Note

You need to upload map image first before bringing managed APs to the actual position.

4.8.10 Upload Map

On this page, the system allows you to upload your floor map to the system.

Upload Map Map New Map Upload File Choose File No file chosen New Description File Size Bytes Apply

Figure 4.8-16 Upload Map page

Planet IVR-300W - Upload Map - 2
Note

The system allows user to upload up to 10 floor maps.

4.9 Wireless

(For IVR-300W Only)

The IVR-300W is designed with high power amplifier and 2 highly-sensitive antennas which provide stronger signal and excellent coverage even in the wide-ranging or bad environment. With adjustable transmit power option, the administrator can flexibly reduce or increase the output power for various environments, thus reducing interference to achieve maximum performance. Equipped with the next-generation Wi-Fi 6 (802.11ax) wireless network standard, the total bandwidth reaches 1800Mbps, and the 2-stream transmission technology improves the transmission efficiency of multiple devices, making AR/VR/IoT applications smoother. The IEEE 802.11ax also optimizes MU-MIMO (Multi-User MIMO) mechanism to serve multiple devices simultaneously.

The Wireless menu provides the following features as shown below.

2.4GHz WiFi 5GHz WiFi MAC ACL WiFi Advanced WiFi Statistics Connection Status

Figure 4.9-1 Wireless Menu

ObjectDescription
2.4GHz Wi-FiAllow to configure 2.4GHz Wi-Fi.
5GHz Wi-FiAllow to configure 5GHz Wi-Fi.
MAC ACLAllow configure MAC ACL.
Wi-Fi AdvancedAllow to configure advanced setting of Wi-Fi.
Wi-Fi StatisticsDisplay the statistics of Wi-Fi traffic.
Connection StatusDisplay the connection status.

4.9.1 2.4GHz WiFi

This page allows the user to define 2.4GHz WiFi as shown below.

2.4GHz WiFi Configuration Basic Virtual AP1 Virtual AP2 Virtual AP3 Wireless Status Enable Disable Wireless Name (SSID) PLANET_2.4G Hide SSID Enable Disable Bandwidth 20MHz Channel 6 Encryption Open WiFi Multimedia Enable Disable VLAN ID 1 Apply Settings Cancel Changes

Figure 4.9-2 2.4GHz WFI Configuration

ObjectDescription
2.4GHz WFIAllows user to enable or disable 2.4GHz Wi-Fi
2.4GHz WFIIt is the wireless network name. The default 2.4GHz SSID is “PLANET_2.4G”
2.4GHz WFIAllows user to enable or disable SSID
2.4GHz WFISelect the operating channel width, “20MHz” or “40MHz”
2.4GHz WFIIt shows the channel of the CPE. Default 2.4GHz is channel 6.
2.4GHz WFISelect the wireless encryption. The default is “Open”
2.4GHz WFIEnable/Disable WMM (Wi-Fi Multimedia) function

4.9.2 5GHz WiFi

This page allows the user to define 5GHz Wi-Fi as shown below.

5GHz WiFi Configuration Basic Virtual AP1 Virtual AP2 Virtual AP3 Wireless Status Enable Disable Wireless Name (SSID) PLANET_5G Hide SSID Enable Disable Bandwidth 80MHz Channel 36 Encryption Open WiFi Multimedia Enable Disable VLAN ID 1 Apply Settings Cancel Changes

Figure 4.9-3 5 GHz WFI Configuration

ObjectDescription
Wireless StatusAllows user to enable or disable 5GHz Wi-Fi
Wireless Name (SSID)It is the wireless network name. The default 5GHz SSID is “PLANET_5G”
Hide SSIDAllows user to enable or disable SSID
BandwidthSelect the operating channel width, “20MHz” or “40MHz” or “80MHz”
ChannelIt shows the channel of the CPE. Default 5GHz is channel 36.
EncryptionSelect the wireless encryption. The default is “Open”
Wi-Fi MultimediaEnable/Disable WMM (Wi-Fi Multimedia ) function

4.9.3 MAC ACL

This page provides MAC ACL configuration as shown below.

MAC ACL MAC ACL Enable Disable MAC ACL Rules Index Active Device Name MAC Address Action abc 00:30:4F:00:00:01 Add Scan

Figure 4.9-4 MAC ACL Configuration

ObjectDescription
ActiveAllows the devices to pass in the rule
Device NameSet an allowed device name
MAC AddressSet an allowed device MAC address
AddPress the “Add” button to add end-device that is scanned from wireless network and mark them
ScanConnect to client list

4.9.4 Wi-Fi Advanced

This page allows the user to define advanced setting of Wi-Fi as shown below.

WiFi Advanced 2.4GHz Mode 11 AX 5GHz Mode 11 AX 2.4GHz Maximum Associated Clients 32 (Range 1~64) 5GHz Maximum Associated Clients 32 (Range 1~64) 2.4GHz Coverage Threshold -95 (-95dBm ~ -60dBm) 5GHz Coverage Threshold -95 (-95dBm ~ -60dBm) 2.4GHz TX Power Max(100%) 5GHz TX Power Max(100%)

Figure 4.9-5 Wi-Fi Advanced Configuration

ObjectDescription
2.4GHz Mode11AC: Select 802.11B/G or 802.11N/G11AX: Select 802.11B/G or 802.11N/G or 802.11AX
5GHz Mode11AC: Select 802.11A or 802.11AN or 802.11AC11AX: Select 802.11A or 802.11AN or 802.11AC or 802.11AX
2.4GHz Maximum Associated ClientsThe maximum users are 64.
5GHz Maximum Associated ClientsThe maximum users are 64.
2.4GHz Coverage ThresholdThe coverage threshold is to limit the weak signal of clients occupying session. The default is -90dBm.
5GHz Coverage ThresholdThe coverage threshold is to limit the weak signal of clients occupying session. The default is -90dBm.
2.4G TX PowerThe range of transmit power is Max (100%), Efficient (75%), Enhanced (50%), Standard (25%) or Min (15%). In case of shortening the distance and the coverage of the wireless network, input a smaller value to reduce the radio transmission power
5G TX PowerThe range of transmit power is Max (100%), Efficient (75%), Enhanced (50%), Standard (25%) or Min (15%). In case of shortening the distance and the coverage of the wireless network, input a smaller value to reduce the radio transmission power.

4.9.5 Wi-Fi Statistics

This page displays Wi-Fi statistics as shown below.

2.4GHz
Planet IVR-300W - Wi-Fi Statistics - 1

line | Time | Speed | |--------|-----------| | 17:00 | ~0 B/s | | 17:10 | ~0 B/s | | 17:20 | ~1.50 KB/s| | 17:30 | ~0 B/s | | 17:40 | ~0 B/s | | 17:50 | ~0 B/s |

5GHz
Planet IVR-300W - Wi-Fi Statistics - 2

line | Time | Speed | |--------|-----------| | 17:00 | ~0 B/s | | 17:10 | ~0 B/s | | 17:20 | ~1.2 KB/s | | 17:30 | ~0 B/s | | 17:40 | ~0 B/s | | 17:50 | ~0 B/s |

Figure 4.9-6 Wi-Fi Statistics

4.9.6 Connection Status

This page shows the host names and MAC address of all the clients in your network as shown below.

Client List
No.NameMAC AddressSignalConnected Time

Figure 4.9-7 Connection Status

ObjectDescription
NameDisplay the host name of connected clients.
MAC AddressDisplay the MAC address of connected clients.
SignalDisplay the connected signal of connected clients.
Connected TimeDisplay the connected time of connected clients.

4.10 Power over Ethernet

(For IVR-300FP Only)

The PoE menu provides the following features for managing the system.

Planet IVR-300W - Power over Ethernet - 1

flowchart
graph TD
    A["PoE Configuration"] --> B["PoE Status"]
    B --> C["PoE Schedule"]
    C --> D["PoE Alive Check"]

Figure 4.10-1 PoE Menu

ObjectDescription
PoE ConfigurationAllows to centralize management of PoE power for PDs.
PoE StatusDisplays the current PoE usage.
PoE ScheduleAllows centralizing management of PoE power for providing schedule.
PD Alive CheckAllows centralizing management of PoE power for checking PDs alive.

4.10.1 PoE Configuration

This section allows the user to inspect and configure the current PoE configuration setting.

PoE Configuration System PoE Admin Mode Enable Power Supply 51 V Power Limit Mode Consumption Power Allocation 0 / 120 W Port Description PoE Function Schedule Power Mode Priority Device Class Current Used [mA] Powered Used [W] All √ √ AT/AF √ 1 Enable None AT/AF High - - 0 0 2 Enable None AT/AF High - - 0 0 3 Enable None AT/AF High - - 0 0 4 Enable None AT/AF High - - 0 0 Total 0 0 Apply Settings Cancel Changes

Figure 4.10-2 PoE configuration

ObjectDescription
System PoE Admin ModeAllows user to enable or disable PoE function. It will cause all of PoE ports to supply or not to supply power.
PoE FunctionThere are three modes for PoE mode.■ Enable: enable PoE function..■ Disable: disable PoE function.■ Schedule: enable PoE function in schedule mode.
ScheduleIndicates the scheduled profile mode. Possible profiles are:■ Profile1■ Profile2■ Profile3■ Profile4
PriorityThe Priority represents PoE ports priority. There are three levels of power priority named Low, High and Critical.The priority is used in case the total power consumption is over the total power budget. In this case, the port with the lowest priority will be turned off, and power for the port of higher priority will be offered.
Device ClassDisplays the class of the PD attached to the port, as established by the classification process. Class 0 is the default for PDs. The PD is powered based on PoE Class level if the system is working in Classification mode. The PD will return to Class 0 to 4 in accordance with the maximum power
Current Used [mA]The Power Used shows how much current the PD currently is using.
Powered Used [W]The Power Used shows how much power the PD currently is using.

4.10.2 PoE Status

This section provides per port PoE status.

Port Power Consumption
Planet IVR-300W - PoE Status - 1

line | Port Number | AF PoE | AT PoE | | ----------- | ------ | ------ | | 01 | 0 W | 0 W | | 02 | 0 W | 0 W | | 03 | 0 W | 0 W | | 04 | 0 W | 0 W |

Figure 4.10-3 Port Power Consumption

4.10.3 PoE Schedule

This page allows the user to define PoE schedule and scheduled power recycling.

Please press the Add New Rule button to start setting PoE Schedule function. You have to set PoE schedule to profile and then go back to PoE Port Configuration, and select "Schedule" mode from per port "PoE Mode" option to enable you to indicate which schedule profile could be applied to the PoE port.

PoE Schedule Profile Profile 1 Week Day Start Hour Start Min End Hour End Min Reboot Enable Reboot Only Reboot Hour Reboot Min Delete Sun 00 00 23 59 00 00 Add Apply Settings Cancel Changes

Planet IVR-300W - PoE Schedule - 2

line | Day | PoE Schedule | PoE Reboot | |-------|--------------|------------| | Mon | | | | Sun | | | | Wed | | | | Thu | | | | Fri | | | | Sat | | |

Figure 4.10-4 PoE schedule Configuration

ObjectDescription
• ProfileSet the schedule profile mode. Possible profiles are:Profile1Profile2Profile3Profile4
• Week DayAllows user to set week day for defining PoE function by enabling it on the day.
• Start HourAllows user to set what hour PoE function does by enabling it.
• Start MinAllows user to set what minute PoE function does by enabling it.
• End HourAllows user to set what hour PoE function does by disabling it.
• End MinAllows user to set what minute PoE function does by disabling it.
• Reboot EnableAllows user to enable or disable the whole PoE port reboot by PoE reboot schedule. Please note that if you want PoE schedule and PoE reboot schedule to work at the same time, please use this function, and don't useReboot Onlyfunction. This function offers administrator to reboot PoE device at an indicated time if administrator has this kind of requirement.
• Reboot OnlyAllows user to reboot PoE function by PoE reboot schedule. Please note that if administrator enables this function, PoE schedule will not set time to profile. This function is just for PoE port to reset at an indicated time.
• Reboot HourAllows user to set what hour PoE reboots. This function is only for PoE reboot schedule.
• Reboot MinAllows user to set what minute PoE reboots. This function is only for PoE reboot schedule.

4.10.4 PD Alive Check

The VPN Router can be configured to monitor connected PD's status in real-time via ping action. Once the PD stops working and without response, the PoE Switch is going to restart PoE port power, and bring the PD back to work. It will greatly enhance the reliability and reduces administrator management burden.

PoE Alive Configuration

PortModeRemote PD IP AddressInterval Time(10~300s)Retry Count(1~5)ActionReboot Time (30~180s)
All
1Disable192.168.1.10101None30
2Disable192.168.1.11101None30
3Disable192.168.1.12101None30
4Disable192.168.1.13101None30

Figure 4.10-5 PoE Alive Configuration

ObjectDescription
• ModeAllows user to enable or disable per port PD Alive Check function.By default, all ports are disabled.
• Remote PD IP AddressThis column allows user to set PoE device IP address for system making ping to the PoE device. Please note that the PD's IP address must be set to the same network segment with the PoE Switch.
• Interval Time (10~300s)This column allows user to set how long system should issue a ping request to PD for detecting whether PD is alive or dead.Interval time range is from 10 seconds to 300 seconds.
• Retry Count (1~5)This column allows user to set the number of times system retries ping to PD.For example, if we set count 2, it means that if system retries ping to the PD and the PD doesn't response continuously, the PoE port will be reset.
• ActionAllows user to set which action will be applied if the PD is without any response. The PoE Switch Series offers the following 3 actions:■ PD Reboot: It means system will reset the PoE port that is connected to the PD.■ PD Reboot & Alarm: It means system will reset the PoE port and issue an alarm message via Syslog.■ Alarm: It means system will issue an alarm message via Syslog.
• Reboot Time (30~180s)This column allows user to set the PoE device rebooting time as there are so many kinds of PoE devices on the market and they have a different rebooting time.The PD Alive-check is not a defining standard, so the PoE device on themarket doesn’t report reboot done information to the PoE Switch. Thus, user has to make sure how long the PD will take to finish booting, and then set the time value to this column.System is going to check the PD again according to the reboot time. If you are not sure of the precise booting time, we suggest you set it longer.

4.11 Maintenance

The Maintenance menu provides the following features for managing the system as shown below.

Planet IVR-300W - Maintenance - 1

flowchart
graph TD
    A["Administrator"] --> B["Date & Time"]
    B --> C["Save/Restore Configuration"]
    C --> D["Firmware Upgrade"]
    D --> E["Reboot / Reset"]
    E --> F["Auto Reboot"]
    F --> G["Deiagnostics"]

Figure 4.11-1 Maintenance Menu

ObjectDescription
AdministratorAllows changing the login username and password.
Date & TimeAllows setting Date & Time function.
Save/Restore ConfigurationExport the VPN Security Gateway's configuration to local or USB sticker.Restore the VPN Security Gateway's configuration from local or USB sticker.
Firmware UpgradeUpgrade the firmware from local or USB storage.
Reboot / ResetReboot or reset the system.
Auto RebootAllows setting auto-reboot schedule.
DiagnosticsAllows you to issue ICMP PING packets to troubleshoot IP.

4.11.1 Administrator

To ensure the VPN Security Gateway's security is secure, you will be asked for your password when you access the VPN Security Gateway's Web-based utility. The default user name and password are "admin". This page will allow you to modify the user name and passwords as shown below.

Account Password Username admin Password Confirm Password The password must contain 8~31 characters, including upper case, lower case, numerals and other symbols Apply Settings Cancel Changes

Figure 4.11-2 Account and Password Setting page

ObjectDescription
UsernameInput a new username.
PasswordInput a new password.
Confirm PasswordInput password again.

4.11.2 Date and Time

This section assists you in setting the system time of the VPN Security Gateway. You are able to either select to set the time and date manually or automatically obtain the GMT time from Internet as shown below.

Date and Time Current Time Year 2022 Month 4 Day 1 Hour 15 Minute 33 Second 52 Copy Computer Time Time Zone Select (GMT+08:00)Taipei NTP Client Update Enable Disable NTP Server time.nist.gov time.windows.com time.stdtime.gov.tw Apply Settings Cancel Changes

Figure 4.11-3 Date and Time setting page

ObjectDescription
Current TimeShow the current time.User is able to set time and date manually.
Time Zone SelectSelect the time zone of the country you are currently in. The VPN Security Gateway will set its time based on your selection.
NTP Client UpdateOnce this function is enabled, VPN Security Gateway will automatically update current time from NTP server.
NTP ServerUser may use the default NTP sever or input NTP server manually.

4.11.3 Saving/Restoring Configuration

This page shows the status of the configuration. You may save the setting file to either USB storage or PC and load the setting file from USB storage or PC as shown below.

Save/Restore Configuration Configuration Export Export Configuration Import Choose File No file chosen Import

USB Backup/Upload Configuration USB Storage Not Detected Backup Settings to USB Storage Save Load Settings from USB Storage Configuration disabled Upload Unmount *Please format the Storage as FAT32 on a Windows PC before using it for backup*

Figure 4.11-4 Saving/Restoring Configuration

■ Save Setting to PC

ObjectDescription
Configuration ExportPress theExportbutton to save setting file to PC.
Configuration ImportPress theChoose Filebutton to select the setting file, and thenpress theImportbutton to upload setting file from PC.

■ Save Setting to USB Storage

ObjectDescription
USB StorageThe status of USB storage.
Backup Settings to USB StoragePress the Save button to save setting file to USB storage.
Load Settings from USB StoragePress the Unload button to upload setting file from USB storage.
UnmountBefore removing the USB storage from the VPN Security Gateway, please press the Umount button first.

4.11.4 Firmware Upgrade

This page provides the firmware upgrade function as shown below.

Firmware Information

Firmware Version

v1.2102b220218

Last Upgrade Date

N/A

Firmware Upgrade

Select File

Choose File

No file chosen

Upgrade

USB Firmware Upgrade

USB Storage

Not Detected

Load Firmware from USB Storage

Not Found

Upload

Unmount

*Please format the Storage as FAT32 on a Windows PC before using it*

Figure 4.11-5 Firmware Upgrade page

ObjectDescription
Choose FilePress the button to select the firmware.
UpgradePress the button to upgrade firmware to system.

4.11.5 Reboot / Reset

This page enables the device to be rebooted from a remote location. Once the Reboot button is pressed, users have to re-log in the Web interface as shown below.

Reboot / Reset Reboot Button Reboot Reset Button Reset to Default □ I'd like to keep the network profiles. Keep your current network profiles and reset all other configuration to factory defaults.

Figure 4.11-6 reboot/reset page

ObjectDescription
RebootPress the button to reboot system.
Reset to DefaultPress the button to restore all settings to factory default settings.
I'd like to keep the network profiles.Check the box and then press the button to keep the current network profiles and reset all other configurations to factory defaults.

4.11.6 Auto Reboot

This page enables the device to be Auto Rebooted on a Daily basis or based or Selected Week Day. The Web interface is shown below.

Auto Reboot Auto Reboot ○ Enable ● Disable Reboot Type ○ Daily based ● Selected Week Day □ Monday □ Tuesday □ Wednesday □ Thursday □ Friday □ Saturday □ Sunday Time 00 ▼ : 00 ▼ (HH/MM) Apply Settings Cancel Changes

Figure 4.11-7 Auto Reboot Configuration

4.11.7 Diagnostics

The page allows you to issue ICMP PING packets to troubleshoot IP connectivity issues. After you press "Ping", ICMP packets are transmitted, and the sequence number and roundtrip time are displayed upon reception of a reply. The Page refreshes automatically until responses to all packets are received, or until a timeout occurs as shown below.

Diagnostics Ping Trace Route Interface Any Target Host Numbers of Packets Ping Run

Figure 4.11-8 Diagnostics page

ObjectDescription
InterfaceSelect an interface of the VPN Security Gateway
Target HostThe destination IP Address or domain.
Number of PacketsSet the number of packets that will be transmitted; the maximum is 100.
PingThe time of ping.

Planet IVR-300W - Diagnostics - 2

Be sure the target IP address is within the same network subnet of the VPN Security Gateway, or you have to set up the correct gateway IP address.

Appendix A: DDNS Application

Configuring PLANET DDNS steps:

Step 1: Visit DDNS provider's web site and register an account if you do not have one yet. For example, register an account at http://planetddns.com

Step 2: Enable DDNS option through accessing web page of the device.

Step 3: Input all DDNS settings.

PLANET DDNS PLANET Networking & Communication PLANET Website FAQ Support Sign in ID / Email ****** Sign in Forgotten Password / Create A New Account XRT-401F Internet Broadband Router More Info ICA-HM132 2 Mega-Pixel 20M IR Van- Focal Dome IP Camera More Info ICA-HM316 2 Mega-Pixel 11n Outdoor IR IP Camera More Info Access anytime & anywhere Sign-in PLANET DDNS to register a simple domain name to access home device anytime and anywhere. Go! Support & Download You can find drivers, firmware updates, other software and documentation for your PLANET products About DDNS | Term of Usage PLANET Technology Corp. Copyright ©2012 All Rights Reserved.

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : Planet

Model : IVR-300W

Category : Network router