Planet ICG-2210W-NR - Network router

ICG-2210W-NR - Network router Planet - Free user manual and instructions

Find the device manual for free ICG-2210W-NR Planet in PDF.

📄 118 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice Planet ICG-2210W-NR - page 6
Pick your language and provide your email: we'll send you a specifically translated version.
Product Type Industrial 5G NR Compact Cellular Wireless Gateway
Model ICG-2210W-NR
Brand Planet
Dimensions (W x D x H) 76 x 23.5 x 106 mm
Weight 285 g
Power Input 9~36 V DC, 14.4 W max
Operating Temperature -40°C to 75°C
Ethernet Ports 2 x 10/100/1000BASE-T RJ45 (1 WAN/LAN, 1 LAN)
Cellular Support 5G NR (NSA/SA), LTE FDD/TDD, WCDMA; DL up to 2.4 Gbps
SIM Slots 2 x micro SIM with failover
Wireless Standard IEEE 802.11a/b/g/n/ac, dual-band 2.4 GHz & 5 GHz
Wireless Speed Up to 150 Mbps (2.4 GHz) + 433 Mbps (5 GHz)
VPN Protocols IPSec, PPTP, L2TP, OpenVPN, GRE; up to 30 tunnels
Firewall SPI, DoS/DDoS protection, content filtering
Serial Ports 1 x RS232, 1 x RS485
Management Web (HTTP/HTTPS), SNMP v1/v2c/v3, SSHv2, Telnet, Planet Smart Discovery Utility
Mounting DIN-rail, wall-mount (kit included)
Enclosure IP30 metal case
Antennas 4 x 5G NR (5 dBi SMA), 1 x Wi-Fi (2 dBi)
LED Indicators PWR, SYS, Internet (5G/4G), Wi-Fi, LAN LNK/ACT
Regulatory Compliance CE, FCC

Frequently Asked Questions - ICG-2210W-NR Planet

How do I install the SIM card?
Insert a micro SIM card into the slot located on the front panel. Ensure the card is properly oriented and push until it clicks. To remove, press the card inward to eject.
How to reset the device to factory defaults?
Hold the reset button for more than 5 seconds while the device is powered on. Release the button; the device will reboot with factory settings. The default IP is 192.168.1.1, username admin, password cg + last 6 characters of MAC ID (in lowercase).
What is the default login for the web interface?
Default IP: 192.168.1.1. Username: admin. Password: cg followed by the last 6 lowercase characters of the MAC address (e.g., cg123456). Check the device label for the MAC ID.
How to set up automatic failover between 5G and wired WAN?
Go to Setup > Basic Setup > WAN Setup. Configure the primary WAN (e.g., DHCP or PPPoE) and enable the cellular backup. The device automatically switches if the primary connection fails.
What are the operating temperature limits?
The ICG-2210W-NR operates from -40°C to 75°C, making it suitable for harsh industrial environments. Storage temperature is -40°C to 85°C.
How to update the firmware?
Download the latest firmware from Planet's website. Go to Administration > Firmware Upgrade, choose the file, and click Upgrade. Do not power off or press reset during the process.
How do I configure a VPN connection?
Navigate to VPN and select the desired protocol (e.g., IPSec, OpenVPN). Fill in the server/client settings, authentication, and encryption parameters. Save and enable the tunnel.
What is the default SSID and Wi-Fi password?
Default SSID for 2.4 GHz: PLANET_2.4G; for 5 GHz: PLANET_5G. Wi-Fi security is disabled by default; it is recommended to enable WPA2 encryption in the wireless settings.
How do I mount the device on a DIN rail?
Attach the included DIN-rail mounting kit to the back of the gateway. Snap the device onto the DIN rail, ensuring it clicks securely. For wall mounting, use the provided wall-mounting kit.
The device is not connecting to the internet. What should I check?
Verify that the SIM card is active and properly inserted. Check the cellular signal strength on the status page. Ensure the WAN cable is connected and the correct connection type (DHCP/PPPoE) is set. Also check the Keep Online Detection settings.

User questions about ICG-2210W-NR Planet

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Network router in PDF format for free! Find your manual ICG-2210W-NR - Planet and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. ICG-2210W-NR by Planet.

USER MANUAL ICG-2210W-NR Planet

User's Manual

Industrial 5G NR Compact Cellular Wireless Gateway

ICG-2210W-NR

Man in white shirt and black tie using laptop in server rack (no visible text or symbols)

Copyright (C) 2025 PLANET Technology Corp. All rights reserved.

The products and programs described in this User's Manual are licensed products of PLANET Technology, This User's Manual contains proprietary information protected by copyright, and this User's Manual and all accompanying hardware, software, and documentation are copyrighted.

No part of this User's Manual may be copied, photocopied, reproduced, translated, or reduced to any electronic medium or machine-readable form by any means, electronic or mechanical including photocopying, recording, or information storage and retrieval systems, for any purpose other than the purchaser's personal use, and without the prior express written permission of PLANET Technology.

Disclaimer

PLANET Technology does not warrant that the hardware will work properly in all environments and applications, and makes no warranty and representation, either implied or expressed, with respect to the quality, performance, merchantability, or fitness for a particular purpose.

PLANET has made every effort to ensure that this User's Manual is accurate; PLANET disclaims liability for any inaccuracies or omissions that may have occurred. Information in this User's Manual is subject to change without notice and does not represent a commitment on the part of PLANET. PLANET assumes no responsibility for any inaccuracies that may be contained in this User's Manual. PLANET makes no commitment to update or keep current the information in this User's Manual, and reserves the right to make improvements and/or changes to this User's Manual at any time without notice.

If you find information in this manual that is incorrect, misleading, or incomplete, we would appreciate your comments and suggestions.

FCC Radiation Exposure Statement

This equipment complies with FCC RF radiation exposure limits set forth for an uncontrolled environment. This equipment should be installed and operated with a minimum distance of 20 centimeters between the radiator and your body.

This transmitter must not be co-located or operating in conjunction with any other antenna or transmitter. The antennas used for this transmitter must be installed to provide a separation distance of at least 20 cm from all persons and must not be co-located or operating in conjunction with any other antenna or transmitter.

FCC Caution:

To assure continued compliance, for example, use only shielded interface cables when connecting to computer or peripheral devices. Any changes or modifications not expressly approved by the party responsible for compliance could void the user's authority to operate the equipment.

This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions:

(1) This device may not cause harmful interference
(2) This device must accept any interference received, including interference that may cause undesired operation.

CE Compliance Statement

This device meets the RED directive 2014/53/EU of EU requirements on the limitation of exposure of the general public to electromagnetic fields by way of health protection.

The device complies with RF specifications when the device used at 20 cm from your body.

Safety

This equipment is designed with the utmost care for the safety of those who install and use it. However, special attention must be paid to the dangers of electric shock and static electricity when working with electrical equipment. All guidelines of this and of the computer manufacture must therefore be allowed at all times to ensure the safe use of the equipment.

WEEE

Planet ICG-2210W-NR - WEEE - 1

To avoid the potential effects on the environment and human health as a result of the presence of hazardous substances in electrical and electronic equipment, end users of electrical and electronic equipment should understand the meaning of the crossed-out

wheeled bin symbol. Do not dispose of WEEE as unsorted municipal waste and have to collect such WEEE separately.

Trademarks

The PLANET logo is a trademark of PLANET Technology. This documentation may refer to numerous hardware and software products by their trade names. In most, if not all cases, these designations are claimed as trademarks or registered trademarks by their respective companies.

Revision

User's Manual of PLANET Industrial 5G NR Compact Cellular Wireless Gateway

Model: ICG-2210W-NR

Rev.: 1.1 (March, 2025)

Part No. EM-ICG-2210W-NR_v1.1

Table of Contents

Chapter 1. Product Introduction......6

1.1 Package Contents....6
1.2 Overview....7
1.3 Features....10
1.4 Product Specifications ....12

Chapter 2. Hardware Introduction ......15

2.1 Physical Descriptions....15
2.2 Hardware Installation ....16
2.2.1 SIM Card Installation....16
2.2.2 5G NR and Wi-Fi Antenna Installation....17
2.2.3 Wiring the Power Inputs....18
2.2.4 Grounding the Device ....18

Chapter 3. Preparation ....19

3.1 Requirements....19
3.2 Setting TCP/IP on your PC 20
3.3 Planet Smart Discovery Utility....25

Chapter 4. Web-based Management....27

4.1 Introduction ......27
4.2 Logging in to the Cellular Gateway....27
4.3 Main Web Page....29
4.4 Setup....30

4.4.1 Basic Setup....30
4.4.1.1 WAN Setup 30
4.4.1.2 Network Setup 35

4.4.2 DDNS 38

4.4.3 MAC Address Clone 39

4.4.4 Advanced Routing ....40

4.4.5 VLANs....42

4.4.6 Networking....43

4.4.6.1 Bridging....43
4.4.6.2 Port Setup 45
4.4.6.3 DHCPD 46

4.5 Wireless 47

4.5.1 Basic Setting....47
4.5.2 Wireless Security....50

4.6 Services 52
4.7 VPN....57

4.7.1 PPTP....57
4.7.2 L2TP 60
4.7.3 OPENVPN 63
4.7.4 IPSEC 69
4.7.5 GRE 73

4.8 Security 75

4.8.1 Firewall....75

4.9 Access Restrictions....79

4.9.1 WAN Access 79
4.9.2 MAC Filtering 81
4.9.3 Packet Filtering....83

4.10 NAT 84

4.10.1 Port Forwarding 84
4.10.2 Port Range Forwarding....85
4.10.3 DMZ 86

4.11 QoS Setting....87

4.11.1 Basic 87
4.11.2 Classify 89

4.12 Applications....90

4.12.1 Serial Applications 90

4.13 Administration 93

4.13.1 Management....93
4.13.2 Keep Alive 96
4.13.3 Commands....97
4.13.4 Factory Defaults....98
4.13.5 Firmware Upgrade....99
4.13.6 Backup....100

4.14 Status....101

4.14.1 Router 101
4.14.2 WAN....104
4.14.3 LAN....107
4.14.4 Wireless....109
4.14.5 Bandwidth 112
4.14.6 Sys Info....114

Appendix A: DDNS Application 118

Chapter 1. Product Introduction

Thank you for purchasing PLANET Industrial 5G NR Compact Cellular Wireless Gateway, ICG-2210W-NR. The description of this model is as follows:

Model NameDescription
ICG-2210W-NRCompact Industrial 5G NR Cellular Wireless Gateway with 2-Port 10/100/1000T

"Cellular Gateway" mentioned in the manual refers to the above model.

1.1 Package Contents

The package should contain the following:

Cellular Gateway x 1QR Code Sheet5G NR Antenna x 4
Planet ICG-2210W-NR - Package Contents - 1Planet ICG-2210W-NR - Package Contents - 2Planet ICG-2210W-NR - Package Contents - 3
Wi-Fi Antenna x 1DIN-rail Mounting Kit6-pin Terminal Block x 1
[XTH4]Planet ICG-2210W-NR - Package Contents - 4Planet ICG-2210W-NR - Package Contents - 5
DB9 to 3 pins (2 3 5)DC AdapterRJ45 Dust Cap x 2
Planet ICG-2210W-NR - Package Contents - 6Planet ICG-2210W-NR - Package Contents - 7Planet ICG-2210W-NR - Package Contents - 8
RJ45 UTP Ethernet Cable x 1Wall Mounting Kit
Planet ICG-2210W-NR - Package Contents - 9Planet ICG-2210W-NR - Package Contents - 10
Planet ICG-2210W-NR - Package Contents - 11 NoteIf any of the above items are missing, please contact your dealer immediately.

Note

1.2 Overview

Powerful 5G NR and Wi-Fi 5 Industrial Network Solution

PLANET ICG-2210W-NR is an industrial-grade wireless cellular gateway for demanding mobile applications. Packed with cutting-edge features, including 5G NR (new radio) technology, dual WAN, and two micro SIM slots, it goes further with dual high-speed Gigabit Ethernet LAN ports and WAN/LAN ports, 802.11ac Wi-Fi capability, and serial RS232/RS485 communication interface. With a compact design, the ICG-2210W-NR is perfect for confined spaces or vehicular applications. The addition of ICG-2210W-NR failover ensures uninterrupted connectivity in dynamic environments. Tailored for versatility, it excels in harsh industrial environments and vehicular systems. Whether in tight quarters, mobile setups, or challenging industrial settings, the ICG-2210W-NR gateway ensures seamless and reliable connectivity. Its adaptability, coupled with advanced features, makes it the ideal solution for compact spaces and demanding applications.

Small but Powerful Wireless Gateway with 5G NR for Mobile & M2M Networking 5G NR Dual SIM Redundancy Cellular/Ethernet WAN Failover Hybrid VPN Compact Size 5G 24Gbps Download Speed Wi-Fi 106mm 76mm

Automatic Failover between 5G NR and Gigabit WAN

The ICG-2210W-NR boasts Gigabyte Ethernet wired WAN and 5G NR interfaces with seamless failover capabilities, ensuring continuous Internet access. It provides the flexibility to prioritize between 5G NR and wired WAN connections. In case of a primary WAN interface failure, the secondary interface swiftly restores the connection, ensuring uninterrupted connectivity at all times.

graph LR A["Internet"] -->|Cable| B["5G NR"] B --> C["Failover"] C --> D["Industrial 5G NR Cellular Gateway"] style A fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style C fill:#cfc,stroke:#333 style D fill:#fcc,stroke:#333

Ultra-Fast Speed 4G/5G Network

The ICG-2210W-NR supports 5G NR DL speed of 2.4 Gbps faster than 4G LTE DL speed of 1 Gbps. The wide spectrum bandwidth accelerates internet speeds and reduces network latency for premium and time-sensitive connectivity services. The ICG-2210W-NR also supports multi-band connectivity including LTE FDD/TDD, WCDMA and GSM for a wide range of applications.

*The real 5G NR/4G LTE data rate is dependent on local service provider.

Up to download speed 2.4 Gbps
5G 10x faster than 4G

Dual SIM Design

To enhance reliability, the ICG-2210W-NR is equipped with dual micro SIM slots that support failover and roaming over to ensure uninterrupted connectivity for mission-critical cellular communications. It provides a more flexible and easier way for users to create an instant network sharing service via 5G-NR in public places like transportations, outdoor events, etc.

SIM 1 SIM 2

Ideal High-Availability VPN Security Cellular Gateway Solution for Industrial Environment

The ICG-2210W-NR provides complete data security and privacy for accessing and exchanging the most sensitive data, built-in IPSec VPN function with DES/3DES/AES encryption and MD5/SHA-1/SHA-256/SHA-384/SHA-512 authentication, and GRE, SSL, PPTP and L2TP server mechanism. The full VPN capability in the ICG-2210W-NR makes the connection secure, more flexible, and more capable.

graph LR A["Industrial 5G NR Cellular Gateway"] --> B["Failover Connection"] B --> C["Content Filtering"] C --> D["VPN Tunnel"] D --> E["Factory Building"]

PLANET ICG-2210W-NR, adopting the IEEE 802.11ac Wave 2 standard, provides a high-speed transmission of power and data, meaning two remote nodes in the 5GHz frequency band can be bridged.

The 2.4GHz wireless connection can also be used simultaneously.

Excellent Ability in Threat Defense

The ICG-2210W-NR has built-in SPI (stateful packet inspection) firewall and DoS/DDoS attack mitigation functions to provide high efficiency and extensive protection for your network. Thus, virtual server and DMZ functions can let you set up servers in the Intranet and still provide services to the Internet users.

graph LR A["DoS/DDoS Attack"] --> B["Blocking DoS Attack"] B --> C["Industrial Cellular Gateway"] C --> D["Ethernet Switch"] D --> E["1000BASE-T UTP"] style A fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style C fill:#cfc,stroke:#333 style D fill:#fcc,stroke:#333 style E fill:#cff,stroke:#333

Cybersecurity Network Solution to Minimize Security Risks

The cybersecurity feature included to protect the switch management in a mission-critical network virtually needs no effort and cost to install. For efficient management, the ICG-2210W-NR is equipped with HTTPS web and SNMP management interfaces. With the built-in web-based management interface, the ICG-2210W-NR offers an easy-to-use, platform independent management and configuration facility. The ICG-2210W-NR supports SNMP and it can be managed via any management software based on the standard SNMP protocol.

1.3 Features

Key Features

  • 5G NR (NSA/SA)/4G LTE network with dual micro SIM design for cellular network redundancy
    • Automatic failover between 5G NR and Gigabit WAN
  • Complies with IEEE 802.11ac and IEEE 802.11a/b/g/n/ac standards
    • 1 serial port (RS485) for Modbus applications and 1 serial port (RS232)
  • SSL VPN and robust hybrid VPN (IPSec/PPTP/L2TP over IPSec)
    • Stateful packet inspection (SPI) firewall and content filtering
  • Blocks DoS/DDOS attack, port range forwarding
  • -40 to 75 degrees C operating temperature; DIN-rail and fanless designs

Hardware

• 1 x 10/100/1000BASE-T RJ45 WAN/LAN port, auto-negotiation, auto MDI/MDI-X
• 1 x 10/100/1000BASE-T RJ45 LAN port, auto-negotiation, auto MDI/MDI-X
- 4 x 5G NR antennas
- 2 x micro SIM card slots
- 1 x 2dB antenna
- 1 x reset button

Cellular Interface

• Supports multi-band connectivity with 5G NR (NSA/SA), LTE-FDD, LTE-TDD, and WCDMA
• Built-in SIM and broadband backup for network redundancy
• Four detachable antennas for 5G NR connection
• LED indicators for connection status

RF Interface Characteristics

  • Features 2.4GHz (802.11b/g/n/ax) and 5GHz (802.11a/n/ac/ax) dual band for carrying high load traffic
    • 2T2R MIMO technology for enhanced throughput and coverage
  • Provides multiple adjustable transmit power control
    • High-speed wireless data rate of up to 600Mbps (150Mbps for 2.4GHz or 433Mbps for 5GHz)

IP Routing Feature

  • Static Route
  • Dynamic Route
  • OSPF

Firewall Security

  • Cybersecurity
    • Stateful Packet Inspection (SPI) firewall
  • Blocks DoS/DDoS attack
  • Content Filtering
    • MAC Filtering and IP Filtering
    • NAT ALGs (Application Layer Gateway)
  • Blocks SYN/ICMP Flooding

VPN Features

  • IPSec/Remote Server (Net-to-Net, Host-to-Net), GRE, PPTP Server, L2TP Server, SSL Server/Client (Open VPN)
    • Max. Connection Tunnel Entries: 30 VPN tunnels,
    • Encryption methods: DES, 3DES, AES, AES-128/192/256
  • Authentication methods: MD5, SHA-1, SHA-256, SHA-384, SHA-512

Networking

  • Outbound load balancing for Ethernet WANs
    • Auto-failover between Ethernet WANs and cellular network
    • Static IP/PPPoE/DHCP client for WAN
    • DHCP server/NTP client for LAN
  • Protocols: TCP/IP, UDP, ARP, IPv4, IPv6
    • Port forwarding, QoS, DMZ, IGMP, UPnP, SNMPv1,v2c, v3
  • MAC address clone
    • DDNS: PLANET DDNS, Easy DDNS, DynDNS and No-IP

Others

• Supported access by HTTP or HTTPS
- Auto reboot

1.4 Product Specifications

ProductICG-2210W-NR
Hardware Specifications
Ethernet2 10/100/1000BASE-T RJ45 Ethernet ports including1 LAN port1 WAN/LAN port
Serial Interface1 RS232 and 1 RS485
SIM Interface2 micro SIM card slots
Cellular Antenna5 dBi external antennas with SMA connectors for 5G-NR
Reset Button< 5 sec: System reboot> 5 sec: Factory default
EnclosureIP30 metal case
InstallationDIN rail, wall-mounting
LED IndicatorsSystem:PWR (Green)SYS (Green)Internet LNK/ACK(Green)Wi-Fi (Green)
Dimensions (W x Dx H)76 x 23.5 x 106 mm
Weight285 g
Power Requirements - DC9~36V DC IN
Power Consumption14.4 W / 49.1BTU
Multi Band Support
5G NR ModuleEAU:Sub-6: n1/n3/n5/n7/n8/n20/n28/n38/n40/n41/n75/n76/n77/n78/n79LTE-FDD: B1/B3/B5/B7/B8/B20/B28/B32LTE-FDD: B38/B40/B41/B42/B43WCDMA: B1/B5/B8NA:Sub-6: n2/n5/n7/n12/n14/n25/n30/n48/n41/n70/n66/n71/n77/n78LTE FDD: B2/B4/B5/B7/B12/B13/B29/B30/B66/B71LTE TDD: B41/B46(LAA)/B48
Data Transmission Throughput2.4Gbps (DL)/500Mbps (UL) for NR1Gbps (DL)/200Mbps (UL) for LTE42Mbps (DL)/5.76Mbps (UL) for HSPA+
Wireless
StandardIEEE 802.11a/n/ac 5GHzIEEE 802.11g/b/n 2.4GHz
Band Mode2.4G & 5G concurrent mode
Frequency Range2.4GHzAmerica FCC: 2.412~2.462GHzEurope ETSI: 2.412GHz~2.472GHz
5GHz5.15GHz ~5.875GHz
Operating Channels2.4GHzAmerica FCC: 1~11Europe ETSI: 1~13
5GHzAmerica FCC:Non-DFS: 36, 40, 44, 48, 149,153,157,161,165Europe ETSI:Non-DFS: 36, 40, 44, 48DFS: 52, 56, 60, 64, 100, 104, 108, 112, 116, 120, 124, 128, 132, 136, 1405GHz channel list may vary in different countries according to their regulations.
Channel Width20MHz, 40MHz, 80MHz
Data Transmission RatesTransmit: 150 Mbps* for 2.4 GHz and 433 Mbps* for 5 GHzReceive: 150 Mbps* for 2.4 GHz and 433 Mbps* for 5 GHz*The estimated transmission distance is based on the theory. The actual distance will vary in different environments.
Transmission Power11b: 23dbm+/- 1.5dbm @11Mbps11g: 20dbm+/- 1.5dbm @54Mbps11g/n: 20dBm +/- 1.5dbm @MCS7, HT2017dBm@MCS7,HT4011a: 19.5dBm +/- 1.5dbm @54Mbps11a/n: 19.5dBm+/- 1.5dbm @MCS7, HT2017dBm@MCS7, HT4011ac HT20: 20+/-1.5dBm @MCS811ac HT40: 17+/-1.5dBm @MCS911ac HT80: 14.5+/-1.5dBm @MCS9
Encryption SecurityWEP (64/128-bit) encryption securityWPA / WPA2 (TKIP/AES)WPA-PSK / WPA2-PSK (TKIP/AES)802.1x Authenticator
Wireless AdvancedWi-Fi Multimedia (WMM)Auto channel selectionWireless output power managementMAC address filtering
Advanced Functions
VPNIPSec/Remote Server (Net-to-Net, Host-to-Net)GREPPTP ServerL2TP ServerSSL Server/Client (Open VPN)
VPN TunnelsMax. 30
VPN ThroughputMax. 50Mbps
EncryptionMethodsDES, 3DES, AES or AES-128/192/256 encrypting
AuthenticationMethodsMD5/SHA-1/SHA-256/SHA-384/SHA-512 authentication algorithm
Management
Basic ManagementInterfacesWeb browserSNMP v1, v2cPLANET Smart Discovery utility
SecureManagementInterfacesSSHv2, TLSv1.2, SNMP v3
System LogSystem Event Log
OthersSetup wizardDashboardSystem status/serviceStatisticsConnection statusAuto rebootDiagnostics
Standards Conformance
RegulatoryComplianceCE
Environment
OperatingTemperature: -40 ~ 75 degrees CRelative humidity: 5 ~ 90% (non-condensing)
StorageTemperature: -40 ~ 85 degrees CRelative humidity: 5 ~ 90% (non-condensing)

Chapter 2. Hardware Introduction

2.1 Physical Descriptions

Front View

PWR SYS Internet Wi-Fi PLANET Networking & Communication Industrial 5G NR Compact Cellular Wireless Gateway ICG-2210W-NR PWR-RS232-RS485 VCC GND TX RX B A WAN/LAN LAN SIM12↑

LED Definition:

LEDColorFunction
PWRGreenLights to indicate the gateway has power.
SYSGreenBlinks to indicate the system has work normally.
InternetGreenLights to indicate the establishment of an internet connection via 5G or wired.
Blinks to indicate the establishment of an internet connection via 4G.
Wi-FiGreenLights to indicate that Wi-Fi is enabled.
RJ45 LNK/ACTGreenBlinks to indicate the link through that port is successfully established at 10/100/1000Mbps.

2.2 Hardware Installation

Refer to the illustration and follow the simple steps below to quickly install your Cellular Gateway.

2.2.1 SIM Card Installation

Insert the SIM card into the interface shown below.

SIM 1 SIM 2

• A micro SIM card with 5G NR and 4G LTE subscription

Planet ICG-2210W-NR - SIM Card Installation - 2
Mini SIM card

Planet ICG-2210W-NR - SIM Card Installation - 3
Micro SIM card

Planet ICG-2210W-NR - SIM Card Installation - 4
Nano SIM card

2.2.2 5G NR and Wi-Fi Antenna Installation

Fasten the 5G NR antenna extensions to the 5G NR connectors and the wireless antenna to the wireless connector.

PLANET INDUSTRIAL 5G NR Compact Cellular Wireless Gateway ICG-221MW-NR Wi-Fi: One RP-SMA Female Connector 5G NR: Four SMA Female Connectors

2.2.3 Wiring the Power Inputs

The 6-contact terminal block connector on the bottom panel of Cellular Gateway is used for DC power inputs. Please follow the steps below to insert the power wire.

Planet ICG-2210W-NR - Wiring the Power Inputs - 1

When performing any of the procedures like inserting the wires or tightening the wire-clamp screws, make sure the power is unplugged to prevent from getting an electric shock.

  1. Insert positive and negative DC power wires into contacts VCC and GND.
  2. Tighten the screws for preventing the wires from loosening.

Close-up of a green plastic electrical connector with four slots and three circular holes, no text or symbols visible.

1 2 3 4 5 6 VCC GND Tx Rx B A + -

2.2.4 Grounding the Device

User MUST complete grounding wired with the device; otherwise, a sudden lightning could cause fatal damage to the device. EMD (Lightning) DAMAGE IS NOT COVERED UNDER WARRANTY.

Chapter 3. Preparation

Before getting into the device's web UI, user has to check the network setting and configure PC's IP address.

3.1 Requirements

User is able to confirm the following items before configuration:

  1. Please confirm the network is working properly; it is strongly suggested to test your network connection by connecting your computer directly to ISP.
  2. Suggested operating systems: Windows 7 / 8 / 10./11
  3. Recommended web browsers: Microsoft Edge / Chrome. / Firefox

3.2 Setting TCP/IP on your PC

The default IP address of the cellular gateway is 192.168.1.1, and the DHCP Server is on. Please set the IP address of the connected PC as DHCP client, and the PC will get IP address automatically from the VPN cellular gateway

Please refer to the following to set the IP address of the connected PC.

Windows 7/8

If you are using Windows 7/8, please refer to the following:

  1. Click on the network icon from the right side of the taskbar and then click on "Open Network and Sharing Center".

Currently connected to: Unidentified network No Internet access Open Network and Sharing Center 2:41 AM 9/3/2012

  1. Click "Change adapter settings".

Control Panel Home Change adapter settings Change advanced sharing settings View your basic network information and set up connections PC (This computer) Unidentified network Internet See full map View your active networks Connect or disconnect Unidentified network Public network Access type: No Int…

  1. Right-click on the Local Area Connection and select Properties.

Local Area Connection Unidentified network Intel(R) PRO/100 Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties

  1. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties or directly double-click on Internet Protocol Version 4 (TCP/IPv4).

Local Area Connection Properties Networking Connect using: Intel(R) PRO/1000 MT Network Connection Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6 (TCP/IPv6)…

  1. Select "Use the following IP address" and "Obtain DNS server address automatically", and then click the "OK" button.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the…

Windows 10

If you are using Windows 10, please refer to the following:

  1. In the search box on the taskbar, type "View network connections", and then select View network connections at the top of the list.

Best match View network connections Control panel View network connections

  1. Right-click on the Local Area Connection and select Properties.

Local Area Connection Unidentified network Intel(R) PRO/1000 Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties

  1. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties or directly double-click on Internet Protocol Version 4 (TCP/IPv4).

Local Area Connection Properties Networking Connect using: Intel(R) PRO/1000 MT Network Connection Configure... This connection uses the following items: Client for Microsoft Networks QoS Packet Scheduler File and Printer Sharing for Microsoft Networks Internet Protocol Version 6 (TCP/IPv6) Internet…

  1. Select "Use the following IP address" and "Obtain DNS server address automatically", and then click the "OK" button.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the…

3.3 Planet Smart Discovery Utility

For easily listing the cellular gateway in your Ethernet environment, the search tool -- Planet Smart Discovery Utility -- is an ideal solution.

The following installation instructions are to guide you to running the Planet Smart Discovery Utility.

  1. Download the Planet Smart Discovery Utility in administrator PC.
  2. Run this utility as the following screen appears.

PLANET Smart Discovery Lite File Option Help Refresh Exit PLANET Networking & Communication MAC Address Device Name Version DeviceIP NewPassword IP Address NetMask Gateway Description Select Adapter: 10.1.0.96 (F8:32:E4:CD:C5:8A) Control Packet Force Broadcast Update Device Update Multi Update All C…

Figure 3-1-6: Planet Smart Discovery Utility Screen

Planet ICG-2210W-NR - Planet Smart Discovery Utility - 2

If there are two LAN cards or above in the same administrator PC, choose a different LAN card by using the "Select Adapter" tool.

  1. Press the "Refresh" button for the currently connected devices in the discovery list as the screen shows below:

PLANET Smart Discovery Lite File Option Help Refresh Exit PLANET Networking & Communication MAC Address Device Name Version DeviceIP NewPassword IP Address NetMask Gateway Description 1 54-D0-B4-39-6B-A3 ICG-2210W-NR v1.0 192.168.1.1 192.168.1.1 255.255.255.0 192.168.1.254 ICG-2210W-NR Select Adapte…

Figure 3-1-7: Planet Smart Discovery Utility Screen

  1. This utility shows all necessary information from the devices, such as MAC address, device name, firmware version, and device IP subnet address. It can also assign new password, IP subnet address and description to the devices.
  2. After setup is completed, press the "Update Device", "Update Multi" or "Update All" button to take effect. The functions of the 3 buttons above are shown below:

■ Update Device: use current setting on one single device.
■ Update Multi: use current setting on choose multi-devices.
■ Update All: use current setting on whole devices in the list.

The same functions mentioned above also can be found in "Option" tools bar.

  1. To click the "Control Packet Force Broadcast" function, it allows you to assign a new setting value to the device under a different IP subnet address.
  2. Press the "Connect to Device" button and the Web login screen appears.

Press the "Exit" button to shut down the Planet Smart Discovery Utility.

Chapter 4. Web-based Management

This chapter provides setup details of the device's Web-based Interface.

4.1 Introduction

The device can be configured with your Web browser. Before configuring, please make sure your PC is under the same IP segment with the device.

4.2 Logging in to the Cellular Gateway

Refer to the steps below to configure the cellular gateway:

Step 1. Connect the IT administrator's PC and cellular gateway LAN port to the same hub / switch, and then launch a browser to link the management interface address which is set to https://192.168.1.1 by default.

Planet ICG-2210W-NR - Logging in to the Cellular Gateway - 1

The DHCP server of the cellular gateway is enabled. Therefore, the LAN PC will get IP from the VPN cellular gateway. If user needs to set IP address of LAN PC manually, please set the IP address within the range between 192.168.1.2 and 192.168.1.254 inclusively, and assigned the subnet mask of 255.255.255.0.

Planet ICG-2210W-NR - Logging in to the Cellular Gateway - 2

The following steps are based on the firmware version before September of 2024.

Step 2. The browser prompts you for the login credentials.

Default IP address: 192.168.1.1

Default user name: admin

Default Password: admin

Default SSID (2.4G): PLANET_2.4G

Default SSID (5G): PLANET_5G

If you log in to the Web page for the first time, you can see the page shown below, prompting the user whether to modify the default username and password of the 5G industrial cellular gateway. If you need to enter the user-defined username and password, click the "Change Password" button to apply.

Your Router is currently not protected and uses an unsafe default username and password combination, please change it using the following dialog!

Router Password

Router Username

Router Password

Re-enter to confirm

admin

●●●●●

•••••

Figure 4-2-1: Account Setting Screen
Planet ICG-2210W-NR - Logging in to the Cellular Gateway - 3

The following steps are based on the firmware version of September of 2024 or after.

When the following dialog box appears, please enter the default user name and password. Refer to Figure 4-2-2 to determine your initial login password.

Default IP Address: 192.168.1.1

Default Username: admin

Default Password: cg + the last 6 characters of the MAC ID in lowercase

Default SSID (2.4G): PLANET_2.4G

Default SSID (5G): PLANET_5G

Find the MAC ID on your device label. The default password is "cg" followed by the last six lowercase characters of the MAC ID.

Planet ICG-2210W-NR - Logging in to the Cellular Gateway - 4

MAC ID: A8F7E0XXXXXX

Default Password: cgxxxxxx

("x" means the last 6 digits of the MAC address.

All characters should be in lowercase.)

Figure 4-2-2: MAC ID Label
Planet ICG-2210W-NR - Logging in to the Cellular Gateway - 5

Administrators are strongly suggested to change the default admin and password to ensure system security.

4.3 Main Web Page

After a successful login, the main web page appears. The web main page displays the menu and the system information.

Menu
PLANET Industrial 5G NR Compact Cellular Wireless Gateway with 2-Port 10/100/1000T File name: ICG-2210W NR v1.0 (On: 18 2023 18:54:43) std Time: 09:26:15 up 17 ms, load average 0.51, 0.37, 0.08 WAN TPV: 0.0.0.6, RISP WAN IP: 0.0.0.0 Menu Setup Wireless Services VPN Security NAT Access Restrictions Q…

Figure 4-3-1: Main Web Page

4.4 Setup

The Setup screen is the first screen you will see when accessing the cellular gateway. Most users will be able to configure the cellular gateway and get it working properly using only the settings on this screen. Some Internet Service Providers (ISPs) will require that you enter specific information, such as User Name, Password, IP Address, Default Gateway Address, or DNS IP Address. This information can be obtained from your ISP, if required.

4.4.1 Basic Setup

This page is used to configure the parameters for Internet network which connects to the WAN port of the cellular gateway. Here you may select the access method by clicking the item value of WAN access type.

4.4.1.1 WAN Setup

■ Disable

Forbid the setting of WAN port connection type

Main WAN Connection Type

Connection Type

Disabled

Planet ICG-2210W-NR - ■ Disable - 1

■ Static IP

Select Static IP Address if all the Internet port's IP information is provided to you by your ISP. You will need to enter the IP Address, Subnet Mask, Gateway and DNS Server provided to you by your ISP. Each IP address entered in the fields must be in the appropriate IP form, which are four octets separated by a dot (x.x.x.x). The cellular gateway will not accept the IP address if it is not in this format.

Main WAN Connection Type

Connection Type

WAN IP Address

Subnet Mask

Gateway

Static DNS 1

Static DNS 2

Static DNS 3

Planet ICG-2210W-NR - ■ Static IP - 1

ObjectDescription
WAN IP AddressEnter the IP address assigned by your ISP.
Subnet MaskEnter the Subnet mask assigned by your ISP.
GatewayEnter the Gateway assigned by your ISP.
Static DNS 1/2/3The DNS server information will be supplied by your ISP.

■ Automatic Configuration – DHCP

Select DHCP Client to obtain IP Address information automatically from your ISP.

Main WAN Connection Type

Connection Type

Automatic Configuration - DHCP

DHCP-4G

Main WAN Connection Type

Connection Type

User Name

Password

APN

Fixed WAN IP

Allow these authentication

Connection type

PIN

dhcp-4G

Planet ICG-2210W-NR - DHCP-4G - 2

Planet ICG-2210W-NR - DHCP-4G - 3

Planet ICG-2210W-NR - DHCP-4G - 4

Planet ICG-2210W-NR - DHCP-4G - 5

Planet ICG-2210W-NR - DHCP-4G - 6

Planet ICG-2210W-NR - DHCP-4G - 7

The IP address of the WAN port is obtained in DHCP-4G/5G mode. The Auto connection type is a default, and at the same time, the NSA and SA are offered. This option is best set to separate SA or separate NSA according to the actual network environment.

■ PPPoE

Main WAN Connection Type

Connection Type

User Name

Password

PPPoE

Planet ICG-2210W-NR - ■ PPPoE - 2

ObjectDescription
User NameLogin users' ISP (Internet Service Provider)
PasswordLogin users' ISP

Main WAN Connection Type Connection Type 3G Link 1 User Name Password □ Unmask Dial String *99***1# (UMTS/3G/3.5G)▼ APN PIN □ Unmask Connection type Auto▼ Allow these authentication ✓ PAP ✓ CHAP ✓ MS-CHAP ✓ MS-CHAPv2

ObjectDescription
UsernameLogin users' ISP (Internet Service Provider)
PasswordLogin users' ISP
Dial StringDial number of users' ISP
APNAccess point name of users' ISP
PINPIN code of users' SIM card

■ dhcp-bkup4G

Main WAN Connection Type Connection Type dhcp-bkup4G User Name Password APN Fixed WAN IP Enable Disable Allow these authentication PAP CHAP Connection type Auto PIN Keep Online Detection Ping Detection Interval 120 Sec.

Primary Detection Server IP

Backup Detection Server IP

Enable Dial Failure to Restart

Fixed WAN Netmask Address

STP

Bridge Mode

Band

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 2

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 3

Enable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 4

Disable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 5

Enable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 6

Disable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 7

Enable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 8

Disable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 9

Enable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 10

Disable

Planet ICG-2210W-NR - ■ dhcp-bkup4G - 11

(Default: 10 minutes)

■ Keep Online Detection

This function is used to detect whether the Internet connection is active. If users set it and when the Cellular gateway detect the connection is inactive, it will redial to users' ISP immediately to make the connection active. If the network is busy or the user is in private network, we recommend that Cellular gateway mode will be better.

Keep Online Detection

Detection Interval

Primary Detection Server IP

Backup Detection Server IP

Ping 120 Sec. 8 8 8 8 8 8 4 4

ObjectDescription
NoneDo not set this function
PingSend ping packet to detect the connection when choosing this method. Users should also configure "Detection Interval", "Primary Detection Server IP" and "Backup Detection Server IP" items.
RouteDetect connection with route method when choosing this method.Users should also configure "Detection Interval", "Primary Detection Server IP" and "Backup Detection Server IP" items.
PPPDetect connection with PPP method when choosing this method.Users should also configure "Detection Interval" item.
Detection IntervalTime interval between two detections; unit is second.
Primary DetectionServer IPThe server is used to respond the cellular gateway detected packet.This item is only valid for the "Ping" and "Route" method.
Backup DetectionServer IPThe server is used to respond the cellular gateway detected packet.This item is valid for the "Ping" and "Route" method.

Note: When users choose the "Route" or "Ping" method, it's quite important to make sure that the "Primary Detection Server IP" and "Backup Detection Server IP" are usable and stable, because they have to respond the detected packet frequently.

STP

STP (Spanning Tree Protocol) can be applied to loop network. By employing specific algorithms, the system achieves path redundancy and transforms a loop network into a tree-based network without introducing loops. This prevents message hyperplasia and infinite circulation within the network loop.

STP

Planet ICG-2210W-NR - STP - 1

Enable

Planet ICG-2210W-NR - STP - 2

Disable

■ Optional Configuration

Optional Settings

Router Name

PLANET Cellular Wireless G

Host Name

Planet ICG-2210W-NR - Optional Settings - 1

Domain Name

Planet ICG-2210W-NR - Optional Settings - 2

MTU

Planet ICG-2210W-NR - Optional Settings - 3

Planet ICG-2210W-NR - Optional Settings - 4

Force Net Card Mode

Planet ICG-2210W-NR - Optional Settings - 5

ObjectDescription
Router NameSet the cellular gateway name
Host NameProvided by ISP
Domain NameProvided by ISP
MTUAuto (1500) and manual (1200-1492 in PPPOE/PPTP/L2TP mode, 576-16320 in other modes)
Force Net Card ModeForce to set the speed of WAN port

4.4.1.2 Network Setup

Router IP

Router IP

Local IP Address19216811
Subnet Mask2552552550
ObjectDescription
Local IP AddressIP address of the cellular gateway
Subnet MaskThe subnet mask of the cellular gateway

■ Multiple LAN IP

The cellular gateway offers several LAN IP addresses for web access.

Multiple LAN IP

ChooseNUMIP ADDRNETMASK
1192.168.3.4255.255.255.0
2192.168.3.100255.255.255.0
DeleteAdd0. 0. 0. 00. 0. 0. 0

■ Network Address Server Settings (DHCP)

These configurations pertain to the setup of the Dynamic Host Configuration Protocol (DHCP) server within the cellular gateway functionality. The cellular gateway can serve as a network DHCP server. DHCP server automatically assigns an IP address to each computer in the network. If they choose to enable the DHCP server option of the of cellular gateway, users can set all the computers on the LAN to automatically obtain an IP address and DNS, and make sure no other DHCP server is in the network.

Network Address Server Settings (DHCP)

DHCP TypeDHCP Server
DHCP ServerEnableDisable
Start IP Address192.168.1100
Maximum DHCP Users100
Client Lease Time1440 minutes
Static DNS 100
Static DNS 200
Static DNS 300
WINS00
Use DNSMasq for DHCP
Use DNSMasq for DNS
DHCP-Authoritative
ObjectDescription
DHCP ServerKeep the default “Enabled” for the DHCP server option of the cellular gateway to be operational. If users have already had a DHCP server on their network or users do not want a DHCP server, select Disable
Start IP AddressEnter a numerical value for the DHCP server to start with when issuing IP addresses. Do not start with 192.168.1.1 (the cellular gateway has its own IP address).
Maximum DHCP UsersEnter the maximum number of PCs that users want the DHCP server to assign IP addresses to. The absolute maximum is 253 if 192.168.1.2 is users' starting IP address.
Client Lease TimeThe Client Lease Time is the amount of time a network user will be allowed to connect to the cellular gateway with their current dynamic IP address. Enter the amount of time, in minutes, that the user will be "leased", using this dynamic IP address.
Static DNS (1-3)The Domain Name System (DNS) is how the Internet translates domain or website names into Internet addresses or URLs. Users' ISP will provide them with at least one DNS Server IP address. If users wish to utilize another, enter that IP address in one of these fields. Users can enter up to three DNS Server IP addresses here. The cellular gateway will utilize them for quicker access to functioning DNS servers.
WINSThe Windows Internet Naming Service (WINS) manages each PC's interaction with the Internet. If users use a WINS server, enter thatserver's IP address here. Otherwise, leave it blank.
DNSMasqUsers' domain name in the field of local search increases the expansion of the host option to adopt DNSMasq that can assign IP addresses and DNS for the subnet. If DNSMasq is selected, DHCPD service is used for the subnet IP address and DNS.

DHCP Forwarder

Network Address Server Settings (DHCP)

DHCP Type

DHCP Server

DHCP Forwarder ▼

Planet ICG-2210W-NR - Network Address Server Settings (DHCP) - 1

■ Time Settings

Select time zone of your location. To use local time, leave the checkmark in the box next to Use local time. And to adjust time by the system and refresh to get the time of the web, user can set to modify the time of the system. The time settings can be manually adjusted if the system fails to connect to the NTP server, enabling users to make necessary time adjustments

Time Settings

NTP Client

Time Zone

Summer Time (DST)

Server IP/Name

Planet ICG-2210W-NR - Time Settings - 1

Enable

Planet ICG-2210W-NR - Time Settings - 2

Disable

UTC-12:00

none

Planet ICG-2210W-NR - Time Settings - 3

Adjust Time

Auto

Planet ICG-2210W-NR - Adjust Time - 1

Planet ICG-2210W-NR - Adjust Time - 2

ObjectDescription
NTP ClientGet the system time from NTP server
Time ZoneTime zone options
Summer Time (DST)Set it (depending on users' location)
Server IP/NameIP address of NTP server, up to 32 characters. If blank, the system will find a server by default

4.4.2 DDNS

If user's network has a permanently assigned IP address, users can register a domain name and have that name linked with their IP address by public Domain Name Servers (DNS). However, if their Internet account uses a dynamically assigned IP address, users will not know in advance what their IP address will be, and the address can change frequently. In this case, users can use a commercial dynamic DNS service, which allows them to register their domain to their IP address and will forward traffic directed at their domain to their frequently-changing IP address.

DDNS DDNS Service PLANET DDNS Domain Name Account Password Unmask DDNS Do not use external ip check Yes No

Options Force Update Interval 720 (Default: 720 min, Range: 5 - 720)

DDNS Status DDNS function is disabled

ObjectDescription
DDNS ServiceCellular gateway currently supports PLANET DDNS, PLANET easyDDNS, DynDNS, NO-IP, easyDNS, TZO, DynSIP and Custom based on the user.
UsernameUsers register in DDNS server, up to 64 characters for password
Host NameUsers register in DDNS server, not limited to input characters for now
Typedepending on the server
WildcardSupports wildcard or not, the default is OFF. ON means*.host.3322.org is equal to host.3322.org
Don’t Use External IP CheckEnable or disable the function of 'do not use external IP check'.
Force Update IntervalThe unit is a day; attempt to trigger the dynamic DNS update to the server at specified intervals.
DDNS StatusDDNS Status shows connection log information

4.4.3 MAC Address Clone

Some ISPs need the users to register their MAC address. The users can clone the cellular gateway MAC address to their MAC address registered in ISP if they do not want to re-register their MAC address

MAC Clone Enable Disable Clone LAN(VLAN) MAC A8: F7: E0: 39: 6B: 9F Clone WAN MAC 04: 42: 1A: B9: 01: 44 Get Current PC MAC Address Clone LAN(Wireless) MAC A8: F7: E0: 39: 6B: A1

ObjectDescription
Clone MAC addressCan clone three parts: Clone LAN MAC, Clone WAN MAC,and Clone Wireless MAC.

Note: The MAC address comprises 48 characters and cannot be assigned as a multicast address; the first byte must be an even value. The MAC address for the network bridge, br0, is determined by the smaller value between the wireless MAC address and the LAN port MAC address.

4.4.4 Advanced Routing

On the Routing screen, you can set the routing mode and settings of the cellular gateway. Gateway mode is recommended for most users.

Operating Mode Operating Mode Gateway Static Routing Select set number 1 () Delete Route Name Metric 0 Destination LAN NET 0.0.0.0 Subnet Mask 0.0.0.0 Gateway 0.0.0.0 Interface LAN & WLAN Show Routing Table

ObjectDescription
Operating ModeIf the cellular gateway is hosting your Internet connection, select Gateway mode. If another router exists on your network, select Router mode.
Dynamic RoutingDynamic Routing enables the cellular gateway to automatically adjust to physical changes in the network's layout and exchange routing tables with other routers. The cellular gateway determines the network packets' route based on the fewest number of hops between the source and destination.
Subnet MaskThe Subnet Mask determines which portion of an IP address is the network portion, and which portion is the host portion
GatewayIP address of the gateway device that allows for contact between the cellular gateway and the network or host.
InterfaceIndicate users whether the Destination IP Address is on the LAN and WLAN (internal wired and wireless networks), the WAN (Internet), or Loopback (a dummy network in which one PC acts like a network, necessary for certain software programs)

Click "Show Routing Table" for the Routing Table Entry List.

Routing Table Entry List

Destination LAN NETSubnet MaskGatewayInterface
192.168.1.0255.255.255.00.0.0.0LAN & WLAN
192.168.3.0255.255.255.00.0.0.0LAN & WLAN
192.168.3.0255.255.255.00.0.0.0WAN

Refresh

dose

4.4.5 VLANs

VLANs function is to divide different VLAN ports by users' will. The system accommodates 14 VLAN ports, ranging from VLAN1 to VLAN14. Users can only allocate two ports independently, as the LAN port and WAN port cannot be separated into individual VLAN ports simultaneously.

VLAN
Planet ICG-2210W-NR - VLANs - 1

4.4.6 Networking

4.4.6.1 Bridging

Create Bridge Bridge 0 br0 STP Off Prio 32768 MTU 1500 Add Assign to Bridge Add Current Bridging Table Bridge Name STP enabled Interfaces br0 no vlan3 ath0 ath1 Auto-Refresh is On

ObjectDescription
Bridging: Create BridgeCreates a new empty network bridge for later use. STP means Spanning Tree Protocol and with PRIO users can set the bridge priority order. The lowest number has the highest priority.
Bridging: Assign to BridgeAllows users to assign any valid interface to a network bridge.Consider setting the Wireless Interface options to Bridged if they want to assign any Wireless Interface here. Any system specific bridge setting can be overridden here in this field.
Current Bridging TableShows current bridging table

Create steps as shown below:

Click 'Add' to create a new bridge for the configuration shown below:

Create Bridge Bridge 0 br0 STP Off Prio 32768 MTU 1500 Bridge 1 b01 STP On Prio 32768 MTU 1500 Delete Add

Create bridge option: the first br0 means bridge name. Select on/off spanning tree protocol. Prio means priority level of STP; the smaller the number, the higher the level. MTU means maximum transfer unit whose default is 1500. Delete if it is not needed. And then click 'Save' or 'Add' for bridge properties as shown below:

Create Bridge Bridge 0 br0 STP Off Prio 32768 MTU 1500 Delete Bridge 1 b01 STP On Prio 32768 MTU 1500 Delete IP Address 0.0.0.0 Subnet Mask 0.0.0.0 Add

Enter a relevant bridge IP address and subnet mask. Click 'Add' to create a bridge.

Note: Only creating a bridge can be applied.

Assign to Bridge Assignment 0 br1 Interface eth1 Prio 63 Delete Add

Assign to Bridge option: To assign a different port to create a bridge. For example, assigned port (wireless port) is ra0 in br1 bridge as shown below:

Prio means priority level: It will work if multiple ports are within the same bridge. The smaller the number is, the higher the level will be. Click 'Add' to take it effect.

Note: The interface corresponding to WAN ports should not be bound. This bridge function is primarily designed for LAN ports and should not be bound to WAN ports. In the event of a successful binding, the bridge binding list in the current bridging table appears as follows:

Current Bridging Table Bridge Name STP enabled Interfaces br0=no vlan3 ath0 ath1 br1=yes eth1 Auto-Refresh is On

To enable the br1 bridge to have the same functionality as a DHCP-assigned address, users need to configure multiple DHCP functions. Refer to the documentation on multi-channel DHCPD for more information.

4.4.6.2 Port Setup

Set the port property; the default is not set

Port Setup

Network Configuration eth1○ Unbridged● Default
Network Configuration vlan1○ Unbridged● Default
Network Configuration vlan3○ Unbridged● Default
Network Configuration vlan2○ Unbridged● Default
Network Configuration br1○ Unbridged● Default
Network Configuration br0○ Unbridged● Default

Choose "unbridged" to set the port's own properties.

Network Configuration eth1● Unbridged ○ Default
MTU1500
Multicast forwarding○ Enable ● Disable
Masquerade / NAT● Enable ○ Disable
IP Address0. 0. 0. 0
Subnet Mask0. 0. 0. 0
ObjectDescription
MTUMaximum transfer unit
Multicast ForwardingEnable or disable multicast forwarding
Masquerade/NATEnable or disable Masquerade/NAT
IP AddressSet IP address, making sure not to conflict with other ports or bridges
Subnet MaskSet the port's subnet mask

4.4.6.3 DHCPD

Multiple DHCP Server DHCP 0 br1 On Start 100 Max 50 Leasetime 3600 Delete Add

Multiple DHCPD: Using "multiple DHCP service"

Click on 'Add' in the multiple DHCP server settings to access the relevant configuration options. The first field is for specifying the port or bridge name (excluding eth0). The second field determines whether DHCP is enabled for this entry. 'Start' denotes the starting address, 'Max' indicates the maximum number of assigned DHCP clients, and 'Lease time' represents the client lease time in seconds. After configuring, click 'Save' or 'Apply' to implement the changes.

Note: Configuration for the next entry can only be done one at a time. After configuring, click 'Save' to proceed to the next configuration; simultaneous configuration of multiple DHCP entries is not supported.

4.5 Wireless

4.5.1 Basic Setting

Wireless Physical Interface w10 [2.4 GHz]

Wireless Network

Planet ICG-2210W-NR - Wireless Physical Interface w10 [2.4 GHz] - 1

Enable

Planet ICG-2210W-NR - Wireless Physical Interface w10 [2.4 GHz] - 2

Disable

Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1]

Wireless Mode

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 1

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 2

Wireless Network Mode

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 3

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 4

Wireless Network Name (SSID)

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 5

Wireless Channel

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 6

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 7

Channel Width

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 8

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 9

Extension Channel

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 10

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 11

Wireless SSID Broadcast

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 12

Enable

Planet ICG-2210W-NR - Physical Interface ath0 - SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1] - 13

Disable

Virtual Interfaces

Add

Wireless Physical Interface w10_5G [5 GHz]

Wireless Network

Planet ICG-2210W-NR - Wireless Physical Interface w10_5G [5 GHz] - 1

Enable

Planet ICG-2210W-NR - Wireless Physical Interface w10_5G [5 GHz] - 2

Disable

Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2]

Wireless Mode

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 1

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 2

Wireless Network Mode

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 3

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 4

Wireless Network Name (SSID)

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 5

Wireless Channel

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 6

Channel Width

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 7

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 8

Wireless SSID Broadcast

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 9

Enable

Planet ICG-2210W-NR - Physical Interface ath1 - SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2] - 10

Disable

Virtual Interfaces

Add

ObjectDescription
Wireless NetworkAllows user to enable or disable Wi-Fi radio
Wireless ModeSupports AP, Client, and Repeater modes.
Wireless Network Mode2.4 GHzMixed: Supports 802.11b, 802.11g and 802.11n wireless devices.BG-Mixed: Supports 802.11b and 802.11g wireless devices.B-only: Only supports the 802.11b standard wireless device.G-only: Only supports the 802.11g standard wireless device.NG-Mixed: Supports 802.11g and 802.11n wireless devices.N-only: Only supports the 802.11g standard wireless devices.5 GHzna: Supports 802.11a and 802.11n wireless devices.ac: Support 802.11ac wireless devices.
Wireless Network Name (SSID)It is the wireless network name.The default 2.4GHz SSID is “PLANET_2.4G”The default 5GHz SSID is “PLANET_5G”
Wireless ChannelIt shows the channel of the CPE.
Channel WidthSelect the operating channel width.2.4GHz: “20MHz”, “40MHz” or “Auto”5GHz: “20MHz”, “40MHz”, “80MHz” or “Auto”
Extension ChannelChannel for 40MHz (2.4GHz); you can choose upper or lower.
Wireless SSID BroadcastAllows user to enable or disable SSID broadcasting

Virtual Interfaces

Virtual Interfaces ath01 SSID [PLANET_2.4G_1]

Wireless Network Name (SSID)

Wireless SSID Broadcast

AP Isolation

PLANET_2.4G_1

Planet ICG-2210W-NR - Virtual Interfaces - 1

Enable

Planet ICG-2210W-NR - Virtual Interfaces - 2

Disable

Planet ICG-2210W-NR - Virtual Interfaces - 3

Enable

Planet ICG-2210W-NR - Virtual Interfaces - 4

Disable

Add

Remove

Virtual Interfaces

Virtual Interfaces ath11 SSID [PLANET_5G_1]

Wireless Network Name (SSID)

Wireless SSID Broadcast

AP Isolation

PLANET_5G_1

Planet ICG-2210W-NR - Virtual Interfaces - 1

Enable

Planet ICG-2210W-NR - Virtual Interfaces - 2

Disable

Planet ICG-2210W-NR - Virtual Interfaces - 3

Enable

Planet ICG-2210W-NR - Virtual Interfaces - 4

Disable

Add

Remove

Virtual Interfaces : Click Add to add a virtual interface. Click on Remove to remove the virtual interface.

ObjectDescription
Wireless Network Name (SSID)It is the wireless network name.The default 2.4GHz SSID is “PLANET_2.4G_1”The default 5GHz SSID is “PLANET_5G_1”
Wireless SSID BroadcastAllows user to enable or disable SSID broadcasting
AP IsolationThis setting isolates wireless clients, so access to and from other wireless clients are stopped.

Note: Save your changes after changing the "Wireless Mode". Click on the "Wireless Network Mode," "Wireless Width," and "Broadband" options to proceed to configure the additional settings.

4.5.2 Wireless Security

Wireless security options are used to configure the security of your wireless network. It has a total of seven wireless security modes. Disabled by default, it is not a safe mode. For a safe mode, click

Apply to take effect immediately.

Wireless Security w10

Physical Interface ath0 SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1]

Security Mode

Disabled

Wireless Security w10_5G

Physical Interface ath1 SSID [PLANET_ICG-2210W-NR_5G] HWAddr [A8:F7:E0:39:6B:A2]

Security Mode

Disabled

Security mode supports WEP, WPA Personal, WPA Enterprise, WPA2 Personal, WPA2 Enterprise, WPA2 Personal Mixed and WPA2 Enterprise Mixed.

Security Mode Authentication Type Default Transmit Key Encryption ASCII/HEX Passphrase Key 1 WEP Open Shared Key 1 64 bits 10 hex digits/5 ASCII ASCII HEX Generate

■ WEP

ObjectDescription
Authentication TypeOpen or shared key
Default Transmit KeySelect Key 1
EncryptionThere are two levels of WEP encryption, 64-bit (40-bit) and 128-bit. To utilize WEP, select the desired encryption bit, and enter a passphrase or up to four WEP keys in the hexadecimal format. If you are using 64-bit (40-bit), then each key must consist of exactly 10 hexadecimalcharacters or 5 ASCII characters. For 128-bit, each key must consist of exactly 26 hexadecimal characters. Valid hexadecimal characters are "0"-"9" and "A"-"F".
ASCII and HEXFor ASCII, the keys are either 5-bit ASCII characters or 13-bit ASCII characters.For HEX, the keys consist of either 10-bit or 26-bit hex digits.
PassphraseThe letters and numbers are used to generate a key.
Key1Fill out or generate the passphrase.

Note: WEP is a basic encryption algorithm that is less secure than WPA. Use of WEP is discouraged due to security weaknesses, and one of the WPA modes should be used whenever possible. Only use WEP if you have clients that can only support WEP (usually older, 802.11b-only clients).

■ WPA Personal/WPA2 Personal/WPA2 Person Mixed

Wireless Security w10

Physical Interface ath0 SSID [PLANET_ICG-2210W-NR_2.4G] HWAddr [A8:F7:E0:39:6B:A1]

Security Mode

WPA Algorithms

WPA Shared Key

Key Renewal Interval (in seconds)

WPA Personal

TKIP+AES

●●●●●●●

3600

Planet ICG-2210W-NR - ■ WPA Personal/WPA2 Personal/WPA2 Person Mixed - 1

□ Unmask

(Default: 3600, Range: 1 - 99999)

ObjectDescription
WPA AlgorithmsTKIP/AES/TKIP+AES, dynamic encryption keysTKIP+AES is self-applicable (TKIP or AES)
WPA Shared KeyBetween 8 and 63 ASCII characters or hexadecimal digits.
Key Renewal Interval(In seconds )1-99999
ASCII and HEXFor ASCII, the keys are either 5-bit ASCII characters or 13-bit ASCII characters.For HEX, the keys consist of either 10-bit or 26-bit hex digits.
PassphraseThe letters and numbers are used to generate a key.
Key1Fill out or generate the passphrase.

4.6 Services

DHCP Server

DHCP assigns IP addresses to users' local devices. While the main configuration is on the setup page users can program some nifty special functions here.

DHCP Server Additional DHCPd Options Static Leases MAC Address Host Name IP Address Client Lease Time 00:11:22:33:44:55ouse test-PC 192.168.1.20 86400 minutes Add Remove

Static Leases: If users want to assign certain hosts a specific address, then they can define them here. This is also the way to add hosts with a fixed address to the local DNS service (DNSMasq) of the cellular gateway

ObjectDescription
Additional DHCPd OptionsSome extra options users can set by entering them
MAC AddressThe MAC address of specific client to which you want to assign.
Host NameThe specific name of the client.
IP AddressThe specific IP address to which you want to assign.
Client Lease TimeIP address release time.

DNSMasq

DNSmasq is a local DNS server. It will resolve all host names known to the cellular gateway from DHCP (dynamic and static) as well as forwarding and caching DNS entries from remote DNS servers. Local DNS enables DHCP clients on the LAN to resolve static and dynamic DHCP host names. There are some extra options you can set by entering them in Additional DNS Options.

DNSMasq

DNSMasq

Local DNS

No DNS Rebind

Additional DNSMasq Options

Planet ICG-2210W-NR - DNSMasq - 1

Enable

Planet ICG-2210W-NR - DNSMasq - 2

Disable

Planet ICG-2210W-NR - DNSMasq - 3

Enable

Planet ICG-2210W-NR - DNSMasq - 4

Disable

Planet ICG-2210W-NR - DNSMasq - 5

Enable

Planet ICG-2210W-NR - DNSMasq - 6

Disable

ObjectDescription
Local DNSEnables DHCP clients on the LAN to resolve static and dynamic DHCP host names.
No DNS RebindWhen enabled, it can prevent an external attacker to access the internal Web interface of the cellular gateway. It is a security measure.
Additional DNSMasq OptionsSome extra options users can set by entering them in Additional DNS Options.
IP AddressThe specific IP address to which you want to assign.For example:Static Allocation: Dhcp-host=AB:CD:EF:11:22:33,192.168.0.10,myhost,myhost.domain,12hMax Lease Number: Dhcp-lease-max=2DHCP Server IP Range: Dhcp-range=192.168.0.110,192.168.0.111,12h

SNMP

SNMP

SNMP

Location

Contact

Name

RO Community

RW Community

Planet ICG-2210W-NR - SNMP - 1

Enable

Planet ICG-2210W-NR - SNMP - 2

Disable

Default Location

Default Contact

ICG-2210W-NR

public

private

ObjectDescription
Enable SNMPDisable or enable the SNMP function.The default configuration is disabled.
LocationAllows entering characters for system location of the cellular gateway.
ContactAllows entering characters for system contact of the cellular gateway.
NameAllows entering characters for system name of the cellular gateway.
RO CommunityAllows entering characters for SNMP Read Community of the cellular gateway
RW CommunityAllows entering characters for SNMP Write Community of the cellular gateway

Location: Equipment location

Contact: Contact this equipment management

Name: Device name

RO Community: SNMP RO community name; the default is public, only to read. RW Community:

SNMP RW community name; the default is private, Read-write permissions

- Secure Shell

Enabling SSHd allows users to access the Linux OS of their cellular gateway with an SSH client

Secure Shell

SSHd

Planet ICG-2210W-NR - Secure Shell - 1

Enable

Planet ICG-2210W-NR - Secure Shell - 2

Disable

SSH TCP Forwarding

Planet ICG-2210W-NR - Secure Shell - 3

Enable

Planet ICG-2210W-NR - Secure Shell - 4

Disable

Password Login

Planet ICG-2210W-NR - Secure Shell - 5

Enable

Planet ICG-2210W-NR - Secure Shell - 6

Disable

Port

22

(Default: 22)

Authorized Keys

Empty rectangular frame with no text, symbols, or markings

ObjectDescription
SSH TCP ForwardingEnable or disable to support the TCP forwarding.
Password LoginAllows login with the cellular gateway password (username is admin)
PortPort number for SSHd (default is 22)
Authorized KeysHere users paste their public keys to enable key-based login (more secure than a simple password)

System log

Enable Syslog to capture system messages. By default, they will be collected in the local file /var/log/messages. To send them to another system, enter the IP address of a remote syslog server.

System Log

Syslogd● Enable ○ Disable
Syslog Out Mode○ Net ● Console ○ Web
Cache Log○ Enable ● Disable

System Log

SyslogdEnable Disable
Syslog Out ModeNet Console Web
Remote Server
Cache LogEnable Disable
Cache Log Interval(s)300
ObjectDescription
Syslog Out ModeNet: The log information output to a syslog serverConsole: The log information output to console port
Password LoginAllows login with the cellular gateway password (username is admin)
Remote ServerIf net mode is chosen, users should input a syslog server's IP Address and run a syslog server program on it.

Telnet

Enable a telnet server to connect to the cellular gateway with telnet. The username is admin and the password is the cellular gateway's password.

Telnet

Telnet● Enable○ Disable

Note: If users use the cellular gateway in an untrusted environment (for example as a public hotspot), it is strongly recommended to use SSHd and deactivate telnet.

■ WAN Traffic Counter

WAN Traffic Counter

ttraff Daemon

Planet ICG-2210W-NR - ■ WAN Traffic Counter - 1

Enable

Planet ICG-2210W-NR - ■ WAN Traffic Counter - 2

Disable

ttraff Daemon: Enable or disable WAN traffic counter function

4.7 VPN

4.7.1 PPTP

PPTP (Point-to-Point Tunneling Protocol) is a network protocol for secure communication over a public network. Commonly used in VPNs, it establishes a secure tunnel for transmitting data by encapsulating it within Internet Protocol (IP) packets. While widely supported, PPTP is considered less secure than more modern VPN protocols due to vulnerabilities.

■ PPTP Server

A VPN technology by Microsoft and remote access vendors -- It is implemented in Windows XP. Configuring this allows you to access your LAN at home remotely.

PPTP Server PPTP Server Enable Disable Broadcast support Enable Disable Force MPPE Encryption Enable Disable DNS1 DNS2 WINS1 WINS2 Server IP Client IP(s) CHAP-Secrets

ObjectDescription
Broadcast SupportEnable or disable broadcast support of PPTP server
Force MPPE EncryptionEnable of disable force MPPE encryption of PPTP data
DNS1/DNS2/WINS1/WINS2Set DNS1/DNS2/WINS1/WINS2
Server IPInput IP address of the cellular gateway as PPTP server, different from LAN address
Client IP(s)A list or range of IP addresses for remotely connected machines.This range should not overlap with the DHCP range (For example, 192.168.0.2,192.168.0.3), a range (For example, 192.168.0.1-254 or 192.168.0-255.2) or some combination (For example, 192.168.0.2,192.168.0.5-8).
CHAP SecretsA list of usernames and passwords for the VPN login; one user per line (For example, joe * joespassword *). For more details, look up the pppd main page.

Note: Client IP must be different from IP assigned by cellular gateway DHCP. The format of CHAP Secrets is user * password *.

■ PPTP Client

A VPN Client that enables you to connect to VPN servers by Microsoft and remote access vendors. Configuring this allows the cellular gateway to VPN in a remote network.

PPTP Client

PPTP Client Options Server IP or DNS Name Remote Subnet Remote Subnet Mask MPPE Encryption mppe stateless MTU 1450 MRU 1450 (NDefault: 1450) NAT Enable Disable Fixed IP Enable Disable User Name DOMAIN\Username Password Unmask

ObjectDescription
Server IP or DNS NameThe IP address or DNS Name of the VPN server that you would like to connect to
Remote SubnetRemote Subnet of the network you are connecting to
Remote Subnet MaskRemote Subnet Mask of the network you are connecting to
MPPE EncryptionEnable or disable Microsoft Point-to-Point EncryptionThe type of security to use for the connection. If you are connecting to another cellular gateway you need (For example, mppe is required).But if you are connecting to a Windows VPN server you need (For example, mppe is required, no40,no56, stateless) or (For example, mppe is required, no40,no56, stateful)
MTUDefault Maximum Transmission Unit (Default: 1450)
MRUDefault Maximum Receiving Unit (Default: 1450)
NATNetwork Address Translation
UsernameEnter the Username that you will use to connect to the VPN server. If you are connecting to another LINUX-based PPTP server you just need to enter the Username (like admin). But if you are connecting to a Windows VPN server you need to enter the servername and username (Like DOMAIN\UserName).
PasswordEnter the password of the username

4.7.2 L2TP

L2TP (Layer 2 Tunneling Protocol) is a network protocol that facilitates the creation of virtual private networks (VPNs). It operates at the data link layer and combines the strengths of PPTP and L2F. L2TP provides secure communication by creating tunnels for transmitting data over the Internet, often used in conjunction with IPsec for enhanced security.

L2TP Server

A VPN technology by Microsoft and remote access vendors -- It is implemented in Windows XP. Configuring this allows you to access your LAN at home remotely.

L2TP Server L2TP Server Options Enable Disable Force MPPE Encryption Enable Disable Server IP Client IP(s) Tunnel Authentication Password Unmask CHAP-Secrets

ObjectDescription
Force MPPE EncryptionEnable or disable force MPPE encryption of L2TP data
Server IPInput IP address of the cellular gateway as L2TP server, different from LAN address
Client IP(s)A list or range of IP addresses for remotely connected machines.This range should not overlap with the DHCP range (For example, 192.168.0.2,192.168.0.3), a range (For example, 192.168.0.1-254 or 192.168.0.0-192.168.255.2) or some combination (For example, 192.168.0.2,192.168.0.5-192.168.0.8).
CHAP SecretsA list of usernames and passwords for the VPN login, one user per line (like joe * joespassword *). For more details, look up the l2tp main page.

Note: Client IP must be different from IP assigned by cellular gateway DHCP.

L2TP Client

A VPN Client that enable you to connect to VPN servers by Microsoft and remote access vendors.

Configuring this allows the cellular gateway to VPN in a remote network.

L2TP Client
L2TP Client Options Tunnel name User Name Password Tunnel Authentication Password Gateway (L2TP Server) Remote Subnet Remote Subnet Mask MPPE Encryption MTU MRU NAT Fixed IP Require CHAP Refuse PAP Require Authentication Enable Disable Enable Disable Yes No Yes No Yes No

ObjectDescription
Tunnel nameSet an alias name
UsernameEnter the UserName that you will use to connect to the VPN server. If you are connecting to another LINUX-based PPTP server you just need to enter the Username (like admin). But if you are connecting to a Windows VPN server you need to enter the servername and username (Like DOMAIN\\UserName).
PasswordEnter the password of the username
Gateway (L2TP Server)L2TP server's IP Address or DNS Name
Remote SubnetRemote Subnet of the network you are connecting to
Remote Subnet MaskRemote Subnet Mask of the network you are connecting to
MPPE EncryptionEnable or disable Microsoft Point-to-Point EncryptionThe type of security to use for the connection. If you are connecting to another cellular gateway you need (For example, mppe is required).But if you are connecting to a Windows VPN server you need (For example, mppe is required, no40, no56, stateless) or (For example, mppe is required, no40, no56, stateful)
MTUDefault Maximum Transmission Unit (Default: 1450)
MRUDefault Maximum Receiving Unit (Default: 1450)
NATNetwork address translation
Require CHAPEnable or disable support for chap authentication protocol
Refuse PAPEnable or disable or refuse to support the pap authentication
Require AuthenticationEnable or disable support for authentication protocol

4.7.3 OPENVPN

OpenVPN is an open-source software application that implements virtual private network (VPN) techniques for secure communication over the internet. It uses custom security protocols, including SSL/TLS, for encryption, and supports various configurations. Known for its flexibility and robust security features, OpenVPN is widely used for remote access and site-to-site VPN connections.

■ OPENVPN Server

OpenVPN Server/Daemon

Start OpenVPN ServerEnableDisable
Start TypeWAN UpSystem
Config viaServerDaemon
Server modeRouter (TUN)Bridge (TAP)
Network0.0.0.0
Netmask0.0.0.0
Port1194(Default: 1194)
Tunnel ProtocolUDP(Default: UDP)
Encryption CipherAES-128 CBC
Hash AlgorithmSHA256
ObjectDescription
Start TypeWAN Up: start after on-lineSystem: start when boot up
Config viaServer: Page configurationDaemon: config File configuration
Server ModeRouter (TUN): route modeBridge (TAP): bridge mode
NetworkIn Router (TUN) mode, network address allowed by OPENVPN server
NetmaskIn Router (TUN) mode, netmask allowed by OPENVPN server
DHCP-Proxy modeIn Bridge (TAP) mode, enable or disable DHCP-Proxy mode
Pool start IPIn Bridge (TAP) mode, pool start IP of the client allowed by OPENVPN server
Pool end IPIn Bridge (TAP) mode, pool end IP of the client allowed by OPENVPN server
GatewayIn Bridge (TAP) mode, the gateway of the client allowed by OPENVPN server
NetmaskIn Bridge (TAP) mode, netmask of the client allowed by OPENVPN server
PortListen port of OPENVPN server
Tunnel ProtocolUCP or TCP of OPENVPN tunnel protocol
Encryption CipherBlowfish CBC, AES-128 CBC, AES-192 CBC, AES-256 CBC, AES512 CBC
Hash AlgorithmHash algorithm provides a method of quick access to data, including SHA1, SHA256, SHA512, MD5

■ Advanced Options

Advanced Options Enable Disable TLS Cipher None Use LZO Compression Adaptive Redirect default Gateway Enable Disable Allow Client to Client Enable Disable Allow duplicate cn Enable Disable TUN MTU Setting 1500 (Default: 1400) Tunnel UDP Fragment (Default: Disable) MSS-Fix/Fragment across the tunnel…

ObjectDescription
TLS CipherTLS (Transport Layer Security) encryption standard supports AES-128/256-CBC-SHA256 and AES-256-GCM-SHA384
Use LZO CompressionEnable or disable use LZO compression for data transfer
Redirect Default GatewayEnable or disable redirect default gateway
Allow Client to ClientEnable or disable allow client to client
Allow Duplicate cnEnable or disable allow duplicate cn
TUN MTU SettingSet the value of TUN MTU
TCP MSSMSS of TCP data
Client Connect ScriptDefine some client script by user self
Public Server Cert
CA Cert
Private Server Key
DH PEM
Additional Config
TLS Auth Key
Certificate Revoke List
ObjectDescription
Public Server CertServer certificate
CA CertCA certificate
Private Server KeyThe key selected by the server
DH PEMPEM of the server
Additional ConfigAdditional configurations of the server
CCD-Dir DEFAULT fileOther file approaches
TLS Auth KeyAuthority key of Transport Layer Security
Certificate Revoke ListConfigure some revoke certificates

■ OPENVPN Client

OpenVPN Client

Start OpenVPN Client

Server IP/Name

Port

Tunnel Device

Tunnel Protocol

Encryption Cipher

Hash Algorithm

User Pass Authentication

Advanced Options

CA Cert

Public Client Cert

Private Client Key

Planet ICG-2210W-NR - OpenVPN Client - 1

Enable

Planet ICG-2210W-NR - OpenVPN Client - 2

Disable

0.0.0.0

1194

(Default: 1194)

Planet ICG-2210W-NR - OpenVPN Client - 3

V

Planet ICG-2210W-NR - OpenVPN Client - 4

p ∨

Planet ICG-2210W-NR - OpenVPN Client - 5

6-128 CBC

Planet ICG-2210W-NR - OpenVPN Client - 6

4256

Planet ICG-2210W-NR - OpenVPN Client - 7

Enable

Planet ICG-2210W-NR - OpenVPN Client - 8

Disable

Planet ICG-2210W-NR - OpenVPN Client - 9

Enable

Planet ICG-2210W-NR - OpenVPN Client - 10

Disable

ObjectDescription
Server IP/NameIP address or domain name of OPENVPN server
PortListen port of OPENVPN client
Tunnel DeviceTUN: Router modeTAP: Bridge mode
Tunnel ProtocolUDP and TCP protocol
Encryption CipherBlowfish CBC, AES-128 CBC, AES-192 CBC, AES-256 CBC,AES512 CBC
Hash AlgorithmHash algorithm provides a method of quick access to data, includingSHA1, SHA256, SHA512, MD5

Advanced Options Enable Disable TLS Cipher None Use LZO Compression Adaptive NAT Enable Disable Bridge TAP to br0 Enable Disable IP Address Subnet Mask TUN MTU Setting 1500 (Default: 1500) Tunnel UDP Fragment (Default: Disable) MSS-Fix/Fragment across the tunnel Enable Disable nsCertType verificatio…

ObjectDescription
TLS CipherTLS (Transport Layer Security) encryption standard supports AES-128/256-CBC-SHA256 and AES-256-GCM-SHA384
Use LZO CompressionEnable or disable use LZO compression for data transfer
NATEnable or disable NAT through function
Bridge TAP to br0Enable or disable bridge TAP to br0
Local IP AddressSet IP address of local OPENVPN client
TUN MTU SettingSet MTU value of the tunnel
TCP MSSMSS of TCP data
TLS Auth KeyAuthority key of Transport Layer Security
Additional ConfigAdditional configurations of OPENVPN server
Policy-based RoutingInput some defined routing policy

CA Cert

Public Client Cert

Private Client Key

Empty rectangular frame with no text, symbols, or markings

Empty rectangular frame with no text, symbols, or markings

Empty rectangular frame with no text, symbols, or markings

ObjectDescription
CA CertCA certificate
Public Client CertClient certificate
Private Client KeyClient key

4.7.4 IPSEC

IPSec (IP Security) is a generic standardized VPN solution. IPSec must be implemented in the IP stack which is part of the kernel. Since IPSec is a standardized protocol it is compatible to most vendors that implement IPSec. It allows users to have an encrypted network session by standard IKE (Internet Key Exchange). We strongly encourage you to use IPSec only if you need to because of interoperability purposes. When IPSec lifetime is specified, the device can randomly refresh and identify forged IKE's during the IPSec lifetime.

Show IPSEC connection and status of current cellular gateway on IPSEC page.

Connection status and control

NumNameTypeCommon NamestatusAction
Add
ObjectDescription
NameThe name of IPSEC connection
TypeThe type and function of current IPSEC connection
Common NameLocal subnet, local address, opposite end address and opposite end subnet of current connection
StatusConnection status:Closed: This connection does not launch a connection request to opposite endNegotiating: This connection launch a request to opposite end, is under negotiating. The connection has not been established yetEstablish: The connection has been established, enabled to use this tunnel
ActionThe action of this connectionDelete: To delete the connection, also will delete IPSEC if IPSEC has set upEdit: To edit the configure information of this connection, reload this connection to make the configuration effective after editReconnect: This action will remove current tunnel, and re-launch tunnel establish requestEnable: When the connection is enabled, it will launch tunnel establish request when the system reboot or reconnect; otherwise, the connection will not do it

Click Add to add a new IPSEC connection

To choose IPSEC mode and relevant functions in this part, it currently supports tunnel mode client, tunnel mode server and transfer mode.

Type
Planet ICG-2210W-NR - IPSEC - 1

Planet ICG-2210W-NR - IPSEC - 2

Planet ICG-2210W-NR - IPSEC - 3

This part contains basic address information of the tunnel

Connection

Name

Local WAN Interface

Local Subnet

Local Id

WAN

Planet ICG-2210W-NR - IPSEC - 4

Enabled

Peer WAN address

Peer subnet

Peer ID

Planet ICG-2210W-NR - IPSEC - 5

Planet ICG-2210W-NR - IPSEC - 6

Planet ICG-2210W-NR - IPSEC - 7

Planet ICG-2210W-NR - IPSEC - 8

ObjectDescription
NameTo indicate this connection name
EnabledIf enabled, the connection will send tunnel connection request when it is rebooted or reconnected; otherwise, it is disabled.
Local WAN InterfaceLocal address of the tunnel
Remote Host AddressIP/domain name of end opposite; this option cannot fill in if tunnel mode server is used.
Local SubnetIPSec local protects subnet and subnet mask, i.e. 192.168.1.0/24; this option cannot fill in if transfer mode is used.
Remote SubnetIPSec opposite end protects subnet and subnet mask, i.e.192.168.7.0/24; this option cannot fill in if transfer mode is used.
Local IDTunnel local end identification, IP and domain name are available.
Remote IDTunnel opposite end identification, IP and domain name are available.

This part contains configure information of connected detection.

Detection

Enable DPD Detection ✓ Time Interval 60 (S) Timeout 60 (S) Action restart ✓

ObjectDescription
Enable DPD DetectionEnable or disable this function; giving a tick means to enable
Time IntervalSet time interval of connected detection (DPD)
TimeoutSet the timeout of connected detection
ActionSet the action of connected detection

This part contains relevant setting of IKE, ESP, negotiation mode, etc.

Advanced Settings

Enable advanced settings √

Phase 1

IKE Encryption

IKE Lifetime

AES (256 bit)

0 hours

IKE Integrity

MD5

IKE Grouptype

Group2(1024)

Phase 2

ESP Encryption

ESP Keylife

AES (256 bit)

0 hours

ESP Integrity

SHA2 (512)

ESP Grouptype

NULL

Enable IKEv2

☐ IKE aggressive mode allowed. Avoid if possible (preshared key is transmitted in clear text)!

√ Perfect Forward Secrecy (PFS)

ObjectDescription
Enable Advanced SettingsEnable to configure 1st and 2nd phase information; Otherwise, it will automatically negotiate according to opposite end.
IKE EncryptionIKE-phased encryption mode
IKE IntegrityIKE-phased integrity solution
IKE GrouptypeDH exchange algorithm
IKE LifetimeSet IKE lifetime, current unit is hour, the default is 0
ESP EncryptionESP encryption type
ESP IntegrityESP integrity solution
ESP KeylifeSet ESP keylife, current unit is hour, the default is 0
IKE Aggressive Mode AllowedNegotiation mode will adopt aggressive mode if it is ticked; it will be main mode if it is not ticked.
Negotiate Payload CompressionGive a tick to enable PFS; to disable PFS, don’t tick it.

Choose "use shared encryption option" or "certificate authentication option". "shared encryption option" is currently used.

Authentication

Planet ICG-2210W-NR - Authentication - 1

Use a Pre-Shared Key:

Planet ICG-2210W-NR - Authentication - 2

Generate and use the X.509 certificate

4.7.5 GRE

GRE (Generic Routing Encapsulation) protocol is a network layer protocol (such as IP or IPX) where data packets are encapsulated, so these encapsulated data packets are transmitted using the Generic Routing Encapsulation (GRE) Tunnel technology, which operates at the network layer and employs the Layer Two Tunneling Protocol (L2TP) for Virtual Private Network (VPN) communication.

GRE Tunnel GRE Tunnel Enable Disable Number 1 () Delete Status Disable Name Through WAN(Static IP) Peer Wan IP Addr Peer Subnet (eg:192.168.1.0/24) Peer Tunnel IP Local Tunnel IP Local Netmask NAT Enable Disable MTU 1476 (Default: 1476) Keepalive Enable Disable Retry times 10 Interval 60 Fail Action…

ObjectDescription
NumberSwitch on/off GRE tunnel app
StatusSwitch on/off someone's GRE tunnel app
NameGRE tunnel name
ThroughThe GRE packet transmit interface
Peer Wan IP AddrThe remote WAN address
Peer SubnetThe remote gateway local subnet, e.g. 192.168.1.0/24
Peer Tunnel IPThe remote tunnel IP address
Local Tunnel IPThe local tunnel IP address
Local NetmaskNetmask of local network
KeepaliveEnable or disable GRE Keepalive function
Retry timesRetry attempts in case of failure to detect GRE (Generic Routing Encapsulation) keepalive.
IntervalThe time interval of GRE keepalive packet sent
Fail ActionThe action will be executed after the failure.

"View GRE tunnels" keys can view the information of GRE

GRE Tunnels list Number Name Enable Through Peer Wan IP Addr Peer Subnet Peer Tunnel IP Local Tunnel IP Local Netmask Keepalive Retry bines Interval Fail Action 1 Test No WAN 192.168.10.123 192.168.2.0/24 10.1.10.1 10.1.10.100 255.255.255.0 No 0 0 Hold Refresh Close

4.8 Security

4.8.1 Firewall

Firewall enhances network security and uses SPI to check the packets in the network. To use firewall protection, choose to enable otherwise disable. Only enable the SPI firewall or other firewall functions such as filtering proxy, block WAN requests, etc., are used.

■ Firewall Protection

Firewall Protection

SPI Firewall

Planet ICG-2210W-NR - Firewall Protection - 1

Enable

Planet ICG-2210W-NR - Firewall Protection - 2

Disable

■ Additional Filters

Additional Filters

□ Filter Proxy
Filter Cookies
□ Filter Java Applets
Filter ActiveX

ObjectDescription
Filter ProxyWan proxy server may reduce the security of the gateway. Filtering Proxy will refuse any access to any WAN proxy server. Click the checkbox to enable the function otherwise disable.
Filter CookiesCookies are the Web data stored in your computer. When you interact with the site, the cookies will be used. Click the checkbox to enable the function otherwise disable.
Filter Java AppletsIf you decline to use Java, you may encounter difficulties accessing web pages that rely on Java programming. Click the checkbox to enable the function; otherwise, it remains disabled.
Filter ActiveXIf you choose not to use ActiveX, you might face limitations in opening web pages that require ActiveX programming. Click the checkbox to enable the function; otherwise, it will remain disabled.

■ Prevent WAN Request

Block WAN Requests

√ Block Anonymous WAN Requests (ping)
√ Filter IDENT (Port 113)
√ Block WAN SNMP access

ObjectDescription
Block Anonymous WAN Requests (ping)By checking the "Block Anonymous WAN Requests (ping)" box, you can activate this feature and prevent your network from being pinged or detected by other internet users. This adds an extra layer of security, making it more challenging for unauthorized access to your network.The default setting for this feature is enabled; choose to disable it if you wish to allow anonymous internet requests.
Filter CookiesEnabling this feature can prevent port 113 from being scanned from outside. Click the checkbox to enable the function; otherwise, leave it disabled.
Filter Java AppletsThis feature prevents the SNMP connection requests from the WAN.

■ Impede WAN DoS/Bruteforce

Impede WAN DoS/Bruteforce

□ Limit SSH Access
□ Limit Telnet Access
□ Limit PPTP Server Access
□ Limit L2TP Server Access

ObjectDescription
Limit SSH AccessThis feature restricts access requests from the WAN via SSH, allowing a maximum of two connection requests per minute from the same IP.Any additional access requests will be automatically dropped.
Limit Telnet AccessThis feature restricts access requests from the WAN through Telnet, allowing up to two connection requests per minute from the same IP.Any additional access requests will be automatically dropped.
Limit PPTP Server AccessWhen establishing a PPTP Server in the cellular gateway, this feature limits access requests from the WAN via SSH, allowing a maximum of two connection requests per minute from the same IP. Any new access request beyond this limit will be automatically dropped.
Limit L2TP Server AccessWhen configuring an L2TP Server in the cellular gateway, this feature restricts access requests from the WAN via SSH. It allows a maximum of two connection requests per minute from the same IP, automatically dropping any new access requests beyond this limit.

Log Management

The cellular gateway can keep logs of all incoming or outgoing traffic for your Internet connection. To keep activity logs, select Enable. To stop logging, select Disable. When selecting enable, the following page will appear.

Log

Log

Log Level

Planet ICG-2210W-NR - Log - 1

Enable

Planet ICG-2210W-NR - Log - 2

Disable

Low

Planet ICG-2210W-NR - Log - 3

Options

Dropped

Rejected

Accepted

Disable

Disable ▼

Disable ▼

Incoming Log

Outgoing Log

ObjectDescription
Log LevelSet this to the required log level. Set Log Level higher to log more actions.
OptionsWhen you choose to enable this feature, the corresponding connection will be logged in the journal; when disabled, the connections will not be recorded.
Incoming LogTo see a temporary log of the cellular gateway's most recent incoming traffic, click the Incoming Log button.
Outgoing LogTo see a temporary log of the cellular gateway's most recent outgoing traffic, click the Outgoing Log button.

Incoming Log Table Source IP Protocol Destination Port Number Rule Refresh Close

Outgoing Log Table LAN IP Destination URL/IP Protocol Service/Port Number Rule Refresh Close

After making the necessary adjustments, click the "Save Settings" button to save your changes. Alternatively, click the "Cancel Changes" button to discard any modifications that have not been saved.

4.9 Access Restrictions

4.9.1 WAN Access

This screen allows you to block or allow specific kinds of Internet usage. You can set up Internet access policies for specific PCs and set up filters by using network port numbers. This feature allows you to customize up to 10 different Internet Access Policies for particular PCs.

Access Policy Policy 1 () Delete Summary Status Enable Disable Policy Name PCs Edit List of clients Deny Internet access during selected days and hours. Filter

Days Everyday Sun Mon Tue Wed Thu Fri Sat ✓ □ □ □ □ □ □ □

Times 24 Hours From 0 : 00 To 0 : 00

Website Blocking by URL Address

Website Blocking by Keyword

PCsThe part is used to edit client list; the strategy is only effective for the PC in the list.
DaysChoose the day of the week you would like your policy to be applied.
TimesEnter the time of the day you would like your policy to be applied.
Website Blocked by URL AddressYou can block access to certain websites by entering their URL.
Website Blocked by KeywordYou can block access to certain website by the keywords contained in their webpage.

After clinking "Edit List of Clients", it would pop-up new window, as shown below:

List of clients

Enter the IP Address of the clients

IP 01192.168.150
IP 02192.168.10
IP 03192.168.10
IP 04192.168.10
IP 05192.168.10
IP 06192.168.10

Enter the IP Range of the clients

IP Range 01192.168.100.1~192168100100
IP Range 020.0.0.0~0000

Save

Apply Settings

Cancel Changes

Close

4.9.2 MAC Filtering

MAC filtering is a security feature used in networks to control device access based on their unique Media Access Control (MAC) addresses. By specifying allowed MAC addresses, the filter permits only authorized devices to connect, enhancing network security by preventing unauthorized access and protecting against potential intruders or unapproved devices.

Mac Filter Setting
Enable Mac Filter Policy Enable Disable Accept only the data packets conform to the following rules Del Num MAC □ 1 00:11:22:33:44:55 Add Filter Rule MAC (FF:FF:FF:FF:FF:FF) Add

ObjectDescription
Discard packets that conform to the following rulesOnly discard the matching URL address in the list.
Accept only the data packets that conform to the following rulesReceive only with custom rules of network address; discard all other URL addresses.

Set up Internet access policy

  1. Select the policy number (1-10) in the drop-down menu.
  2. For this policy to be enabled, click the radio button next to "Enable"
  3. Enter a name in the Policy Name field.
  4. Click the Edit List of PCs button.

  5. On the List of PC screen, specify PCs by IP address or MAC address. Enter the appropriate IP addresses into the IP fields. If you have a range of IP addresses to filter, complete the appropriate IP Range fields. Enter the appropriate MAC addresses in the MAC fields.

  6. Click the Apply button to save your changes. Click the Cancel button to cancel your unsaved changes. Click the Close button to return to the Filters screen.

  7. If you want to block the listed PCs from Internet access during the designated days and time, then keep the default setting, Deny. If you want the listed PCs to have Internet filtered during the designated days and time, then click the radio button next to Filter.

  8. Set the days when access will be filtered. Select Everyday or the appropriate days of the week.

  9. Set the time when access will be filtered. Select 24 Hours, or check the box next to From and use the drop-down boxes to designate a specific time period.

  10. Click the Add to Policy button to save your changes and activate it.

  11. To create or edit additional policies, repeat steps 1-9.

  12. To delete an Internet Access Policy, select the policy number, and click the Delete button.

Note:

  1. The default factory value of policy rules is "filtered". If the user chooses the default policy rules for "refuse", and editing strategies to save or directly to save the settings. If the strategy edited is the first, it will be automatically saved into the second, if not the first; keep the original number.

  2. Turning off the power of the cellular gateway or rebooting the cellular gateway can cause a temporary failure. After the failure of the cellular gateway, if cannot automatically synchronized NTP time server, you need to recalibrate to ensure the correct implementation of the relevant period control function.

4.9.3 Packet Filtering

Packet filtering is a network security method that selectively allows or blocks data packets based on predefined criteria such as source or destination IP addresses, ports, or protocols. It helps secure networks by controlling the flow of data, preventing unauthorized access, and mitigating potential threats through the analysis and filtering of network packets.

Packet Filter Setting Enable Packet Filter Enable Disable Policy Discard packets conform to the following rules Del Num Source IP SPorts Destination IP DPorts Pro Interface Dir Add Filter Rule Dir OUTPUT Interface Main WAN Pro TCP/UDP SPorts 1- 65535 DPorts 1- 65535 Source IP IP Address 0. 0. 0. 0/…

ObjectDescription
Enable Packet FilterEnable or disable “packet filter” function
PolicyThe filter rule’s policy is that you can choose the following optionsDiscard The Following--Discard packets conform to the following rules, accept all other packetsOnly Accept The Following--Accept only the data packets that conform to the following rules. Discard all other packets
Add Filter Rule Dir(Direction)Input: Packet from WAN to LANOutput: Packet from LAN to WAN
InterfaceThe interface will be used by the function.
Pro (Protocol)Packet protocol type
Sports (Source Ports)Packet's source port
DPorts (Destination Ports)Packet's destination port
Source IPPacket's source IP address
Destination IPPacket's destination IP address

Note: "Source Port", "Destination Port", "Source IP", and "Destination IP" could not be all empty; you'll have to input at least one of these four parameters.

4.10 NAT

4.10.1 Port Forwarding

Port Forwarding allows you to set up public services on your network, such as web servers, ftp servers, e-mail servers, or other specialized Internet applications. Specialized Internet applications are any applications that use Internet access to perform functions such as videoconferencing or online gaming. When users send this type of request to your network via the Internet, the cellular gateway will forward those requests to the appropriate PC. If you want to forward a whole range of ports, see Port Range Forwarding.

Forwards
Delete Num Application Protocol Source Net Port from IP Address Port to Enable 1 FTP Both 192.168.1.0/24 20 192.168.100.21 21 Add

ObjectDescription
ApplicationEnter the name of the application in the field provided.
ProtocolChose the right protocol TCP, UDP or Both. Set this to what the application requires.
Source NetForward only if sender matches this IP/net (like 192.168.1.0/24)
Port fromEnter the number of the external port (the port number seen by users on the Internet).
IP AddressEnter the IP Address of the PC running the application.
Port toEnter the number of the internal port (the port number is used by the application).
EnableClick the Enable checkbox to enable port forwarding for the application.

Check all values and click Save Settings to save your settings. Click the Cancel changes button to cancel your unsaved changes.

4.10.2 Port Range Forwarding

Port Range Forwarding allows you to set up public services on your network, such as Web servers, ftp servers, e-mail servers, or other specialized Internet applications. Specialized Internet applications are any applications that use Internet access to perform functions such as videoconferencing or online gaming. When users send this type of request to your network via the Internet, the cellular gateway will forward those requests to the appropriate PC. If you only want to forward a single port, see Port Forwarding.

Port Range Forward

Forwards

ApplicationStartEndProtocolIP AddressEnable
web-tftp8008100Both192.168.1.16
game900010000Both192.168.1.16

Forwards

DeleteNumApplicationStartEndProtocolIP AddressEnable
1frp2121Both▼192.168.100.21
200Both▼0.0.0.0
ObjectDescription
ApplicationEnter the name of the application in the field provided.
StartEnter the number of the first port of the range you want to see by users on the Internet and forwarded to your PC.
EndEnter the number of the last port of the range you want to see by users on the Internet and forwarded to your PC.
ProtocolChoose the right protocol: TCP, UDP or both. Set this to what the application requires.
IP AddressEnter the IP Address of the PC running the application.
EnableClick the checkbox to enable port forwarding for the application.

Check all values and click Save Settings to save your settings. Click the Cancel changes button to cancel your unsaved changes.

4.10.3 DMZ

The DMZ (Demilitarized Zone) hosting feature allows one local user to be exposed to the Internet for use of a special-purpose service such as Internet gaming or video conferencing. DMZ hosting forwards all the ports at the same time to one PC.

DMZ

Use DMZ

DMZ Host IP Address

Planet ICG-2210W-NR - DMZ - 1

Enable

Planet ICG-2210W-NR - DMZ - 2

Disable

192.168.1.

Planet ICG-2210W-NR - DMZ - 3

ObjectDescription
DMZ Host IP AddressTo expose one PC to the Internet, select Enable and enter the computer's IP address in the DMZ Host IP Address field. To disable the DMZ, keep the default setting Disabled.

Check all values and click Save Settings to save your settings. Click the Cancel changes button to cancel your unsaved changes.

4.11 QoS Setting

4.11.1 Basic

Bandwidth management prioritizes the traffic on your cellular gateway. Interactive traffic (telephony, browsing, telnet, etc.) gets priority and bulk traffic (file transfer, P2P) gets low priority. The main goal is to allow both types to live side by side without unimportant traffic disturbing more critical things. All of this is automatic.

QoS allows control of the bandwidth allocation to different services, netmasks, MAC addresses and the four LAN ports.

QoS

Main WAN QoS Settings

Start QoS

Port

Packet Scheduler

Uplink (kbps)

Downlink (kbps)

Planet ICG-2210W-NR - Main WAN QoS Settings - 1

Enable

Planet ICG-2210W-NR - Main WAN QoS Settings - 2

Disable

WAN

HTB

0

0

Bkup WAN QoS Settings

Start QoS

Port

Packet Scheduler

Uplink (kbps)

Downlink (kbps)

Planet ICG-2210W-NR - Bkup WAN QoS Settings - 1

Enable

Planet ICG-2210W-NR - Bkup WAN QoS Settings - 2

Disable

WAN

HTB

0

0

ObjectDescription
Uplink (kbps)In order to use bandwidth management (QoS) you must enter bandwidth values for your uplink. These are generally 80% to 90% of your maximum bandwidth.
Downlink (kbps)In order to use bandwidth management (QoS) you must enter bandwidth values for your downlink. These are generally 80% to 90% of your maximum bandwidth.

■ HTB Setting

HTB Prio Setting Uplink

PriorityBand rangeBand value
Premium75% -75%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Express15% -15%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Standard10% -10%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Bulk1% -1%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps

HTB Prio Setting Downlink

PriorityBand rangeBand value
Premium75% -75%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Express15% -15%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Standard10% -10%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps
Bulk1% -1%Main WAN : 0 -- 0 kbpsBkup WAN : 0 -- 0 kbps

4.11.2 Classify

Netmask Priority
Delete Net Protocol src Port Range dst Port Range Priority 192.168.1.50/32 both 1-- 65535 1-- 65535 Standard 192.168.1.150/32 both 1-- 65535 1-- 65535 Standard Add 0.0.0.0 TCP/UDP 1-- 1-- / 0 65535 65535

MAC Priority
Delete Num MAC Address Priority 1 00:11:22:33:44:55 Standard 2 00:22:33:44:55:66 Standard 3 00:33:44:55:66:77 Standard Add 00 : 00 : 00 : 00 : 00 : 00

Netmask Priority: You may specify priority for all traffic from a given IP address or IP Range.

MAC Priority: You may specify priority for all traffic from a device on your network by giving the device a specifying priority and entering its MAC address

Check all values and click Save Settings to save your settings. Click the Cancel changes button to cancel your unsaved changes.

4.12 Applications

4.12.1 Serial Applications

There is a console port on cellular gateway. Normally, this port is used to debug the cellular gateway. This port can also be used as a serial port. The cellular gateway has embedded a serial to TCP program. The data sent to the serial port is encapsulated by TCP/IP protocol stack and then is sent to the destination server. This function can work as a DTU (Data Terminal Unit).

Serial Applications Serial Applications Enable Disable Center Configure Server center count 1 Center 1 Protocol Modbus TCP Listen port 5001 Apply protocol COM1 Enable Disable Binding Center Data Center 1 Baudrate 115200 Databit 8 Stopbit 1 Parity None Flow Control Hardware RS485 Enable Disable Bindi…

ObjectDescription
BaudrateBaud rate indicates the number of bytes per second transported by device, commonly used baud rate is 115200, 57600, 38400 or 192000.
DatabitThe data bits can be 4, 5, 6, 7 and 8 that constitute a character. The ASCII code is usually used, starting from the most significant bit.
StopbitIt marks the end of a character data. It is a high level of 1, 1.5 and 2.
ParityUse a set of data to check the data error.
Flow ControlIncluding the hardware part and software part in two ways.
Enable Serial TCP FunctionEnable the serial to TCP function
Protocol TypeThe protocol type to transmit data.UDP (DTU): Data transmitted with UDP protocol, work as an IP modem device with application protocol and heartbeat mechanism.Pure UDP – Data transmitted with standard UDP protocol.TCP (DTU): Data transmitted with TCP protocol, work as an IP modem device with application protocol and heartbeat mechanism.Pure TCP: Data transmitted with standard TCP protocol; cellular gateway is the client.TCP Server: Data transmitted with standard TCP protocol; cellular gateway is the server.TCST: Data transmitted with TCP protocol, using a custom data
Server AddressThe data service center's IP address or domain name.
Server PortThe data service center's listening port.
Device IDThe ID of the cellular gateway.
Device NumberThe phone number of the cellular gateway.
Heartbeat IntervalThe time interval to send heartbeat packet. This item is valid only when you choose UDP (DTU) or TCP (DTU) protocol type.
TCP Server Listen PortThis item is valid when Protocol Type is “TCP Server”.
Custom Heartbeat PacketThis item is valid when Protocol Type is “TCST”.
Custom Registration PacketsThis item is valid when Protocol Type is “TCST”.

3.5 mm Terminal Interface Definition:

Using 6-pin terminal 3.5 mm of the interface, power, and function of RS232 and RS485. Specific definitions are as follows:

6-pin 3.5 mm Terminal Interface Definition
NumberDefinitionSignal DescriptionExtended Function
1VCCPositive device's power supply terminal
2GNDNegative device's power supply terminalRS232 common ground
3TXRS232 transmitting end
4RXRS232 receiving end
5BRS485 B end
6ARS485 A end

4.13 Administration

4.13.1 Management

The Management screen allows you to change the cellular gateway settings. On this page, you will find most of the configurable items of the cellular gateway code.

Router Password

Router Username

Router Password

Re-enter to confirm

..........

The new password must not exceed 32 characters in length and must not include any spaces. Enter the new password a second time to confirm it.

Note: Default username is admin. It is strongly recommended that you change the factory default password of the cellular gateway, which is admin. All users who try to access the cellular gateway Web-based utility or setup wizard will be prompted for the cellular gateway password.

Web Access

This feature allows you to manage the cellular gateway using either HTTP protocol or the HTTPS protocol. If you choose to disable this feature, a manual reboot will be required. You can also activate or inactivate the cellular gateway information Web page. It's now possible to protect the password on this page.

Web Access

Protocol

Auto-Refresh (in seconds)

Enable Info Site

Info Site Password Protection

Planet ICG-2210W-NR - Web Access - 1

HTTP

Planet ICG-2210W-NR - Web Access - 2

HTTPS

Planet ICG-2210W-NR - Web Access - 3

Planet ICG-2210W-NR - Web Access - 4

Enable

Planet ICG-2210W-NR - Web Access - 5

Disable

Planet ICG-2210W-NR - Web Access - 6

Enabled

ObjectDescription
ProtocolThis feature allows you to manage the cellular gateway using either HTTP protocol or the HTTPS protocol.
Auto-RefreshEnable or disable the login system information page.
Enable Info SiteEnable or disable the login system information page
Info Site Password ProtectionEnable or disable the password protection feature of the system information page

■ Remote Access

This feature allows you to manage the cellular gateway from a remote location, via the Internet. To disable this feature, keep the default setting disabled. To enable this feature, select Enable, and use the specified port (default is 8088) on your PC to remotely manage the cellular gateway. You must also change the cellular gateway default password to one of your own, if you haven't already.

To remotely manage the cellular gateway, enter https://xxx.xxx.xxx.xxx:8088 (the x's represent the cellular gateway Internet IP address, and 8088 represents the specified port) in your web browser's address field. You will be asked for the cellular gateway password.

If you use https you need to specify the url as https://xxx.xxx.xxx.xxx:8088 (not all firmwares do support this without rebuilding with SSL support).

Remote Access

Web GUI Management

Remote Protocol

Web GUI Port

Local Web GUI Port

Remote SSH

Remote SSH Port

Telnet Management

Planet ICG-2210W-NR - Remote Access - 1

Enable

Planet ICG-2210W-NR - Remote Access - 2

Disable

Planet ICG-2210W-NR - Remote Access - 3

8088

80

Planet ICG-2210W-NR - Remote Access - 4

Enable

Planet ICG-2210W-NR - Remote Access - 5

Disable

Planet ICG-2210W-NR - Remote Access - 6

22

Planet ICG-2210W-NR - Remote Access - 7

Enable

Planet ICG-2210W-NR - Remote Access - 8

Disable

(Default: 8088, Range: 1 - 65535)

(Default: 80, Range: 1 - 65535)

(Default: 22, Range: 1 - 65535)

ObjectDescription
SSH ManagementYou can also enable SSH to remotely access the cellular gateway by Secure Shell. Note that SSH daemon needs to be enabled in Services page.
Telnet ManagementEnable or disable remote Telnet function

Note: If the Remote Router Access feature is enabled, anyone who knows the cellular gateway's Internet IP address and password will be able to alter the cellular gateway's settings.

Cron

The cron subsystem schedules execution of Linux commands. You'll need to use the command line or startup scripts to use this.

Cron Cron Enable Disable Additional Cron Jobs

■ Remote Management

Web remote management refers to the technology enabling the remote monitoring, configuration, troubleshooting, and updating of devices or systems through a web interface. It allows administrators to oversee and control distant equipment, facilitating real-time monitoring, centralized configuration, and efficient issue resolution.

Remote Management Remote Management Enable Disable Protocol V1.0 V2.0 Remote Login Server IP Remote Login Server Port 44008 (Default: 44008, Range: 1 - 65535) Heart Interval 60 (Default: 60Sec.Range: 1 - 999) Flow Upload Interval 300 (Default: 300Sec.Range: 1 - 86400) Device Code SN Device Type Desc…

4.13.2 Keep Alive

The user can schedule regular reboots for the cellular gateway.

Schedule Reboot

Schedule Reboot

Interval (in seconds)

At a set Time

Planet ICG-2210W-NR - Schedule Reboot - 1

Enable

Planet ICG-2210W-NR - Schedule Reboot - 2

Disable

Planet ICG-2210W-NR - Schedule Reboot - 3

3600

Planet ICG-2210W-NR - Schedule Reboot - 4

Planet ICG-2210W-NR - Schedule Reboot - 5

Planet ICG-2210W-NR - Schedule Reboot - 6

Planet ICG-2210W-NR - Schedule Reboot - 7

ObjectDescription
Interval (in seconds)Regularly reboot the DUT at a specific time
At a set TimeAt a specific date time each week or every day

Note:

For date-based reboots, Cron must be activated. See Management for Cron activation.

4.13.3 Commands

User can run command lines directly via the Web interface.

Command Shell

Commands

Run Commands

Save Startup

Save Shutdown

Save Firewall

Save Custom Script

ObjectDescription
Run CommandYou can run command lines via the Web interface. Fill in the text area with your command and click Run Commands to submit.
StartupYou can save some command lines to be executed at startup's cellular gateway. Fill in the text area with commands (only one command by row) and click Save Startup.
ShutdownYou can save some command lines to be executed at shutdown's cellular gateway. Fill in the text area with commands (only one command by row) and click Save Shutdown.
FirewallEach time the firewall is started, it can run some custom iptables instructions.
Custom ScriptCustom script is stored in /tmp/custom.sh file. You can run it manually or use cron to call it. Fill in the text area with script's instructions (only one command by row) and click Save Custom Script.

4.13.4 Factory Defaults

This page provides "return all configuration settings to the original settings".

Reset router settings

Any settings you have saved will be lost when the default settings are restored. After restoring the cellular gateway, it is accessible under the default IP address 192.168.1.1 and the default password is admin.

4.13.5 Firmware Upgrade

This page provides the firmware upgrade function

Firmware Upgrade

Please select a file to upgrade

Choose file No file chosen

WARNING

Upgrading firmware may take a few minutes. Do not turn off the power or press the reset button!

Upgrade

Note:

When you upgrade the firmware of cellular gateway, you could lose its configuration settings, so make sure you write down the cellular gateway settings before you upgrade its firmware.

Note:

Upgrading firmware may take a few minutes.

Do not turn off the power or press the reset button!

4.13.6 Backup

Backup Configuration

Backup Settings

Click the "Backup" button to download the configuration backup file to your computer.

Restore Configuration

Restore Settings

Please select a file to restore

Choose file

No file chosen

WARNING

Only upload files backed up using this firmware and from the same model of router. Do not upload any files that were not created by this interface!

Backup

Restore

ObjectDescription
Backup SettingsYou may back up your current configuration in case you need to reset the cellular gateway back to its factory default settings. Click the Backup button to back up your current configuration.
Restore SettingsClick the Browse... button to look for a configuration file that is currently saved on your PC. Click the Restore button to overwrite all current configurations with the ones in the configuration file.

Note:

Only restore configurations with files backed up using the same firmware and the same model of cellular gateway.

4.14 Status

4.14.1 Router

The system status of the cellular gateway.

System

Router NamePLANET Cellular Wireless Gateway
Router ModelICG-2210W-NR
Firmware VersionICG-2210W-NR v1.0 (Dec 19 2023 18:36:09) std
MAC AddressA8:F7:E0:39:6B:A0
Host Name
WAN Domain Name
LAN Domain Name
Current TimeFri, 19 Jan 2024 09:54:30
Uptime4 min
ObjectDescription
Router NameName of the cellular gateway that can be changed
Router ModelModel of the cellular gateway that cannot be changed
Firmware Versionsoftware version information
MAC AddressMAC address of WAN that can be changed
Host NameHost name of the cellular gateway that can be changed
WAN Domain NameDomain name of WAN that can be changed
LAN Domain NameDomain name of LAN that cannot be changed
Current TimeLocal time of the system
UptimeOperating uptime if the system is powered on

Memory

Total Available505960 kB / 524288 kB97%
Free430336 kB / 505960 kB85%
Used75624 kB / 505960 kB15%
Buffers4992 kB / 75624 kB7%
Cached13060 kB / 75624 kB17%
Active11404 kB / 75624 kB15%
Inactive9756 kB / 75624 kB13%
ObjectDescription
Total AvailableThe total availability of RAM
FreeThe cellular gateway will reboot if the memory is less than 500kB.
UsedThe total availability of memory minus free memory
BuffersUsed memory for buffers
CachedThe memory used by high-speed cache memory
ActiveActive use of buffer or cache memory
InactiveNot often used in a buffer or cache memory

Network

IP Filter Max Connections16384
Active IP Connections891%
ObjectDescription
IP Filter Maximum PortsPreset is 4096, available to remanage
Active IP ConnectionsReal-time monitoring of active IP connections of the system,

Active IP Connections Table

Active IP Connections

95

No.ProtocolTimeout (s)Source AddressRemote AddressService NameState
1 TCP98192.168.1.150192.168.1.180 TIME_WAIT
2 TCP119192.168.1.150192.168.1.180 TIME_WAIT
3 TCP17192.168.1.150192.168.1.180 TIME_WAIT
4 TCP67192.168.1.150192.168.1.180 TIME_WAIT
5 UDP32192.168.0.25192.168.0.25453 UNREPLIED
6 TCP2192.168.1.150192.168.1.180 TIME_WAIT
7 Unknown512192.168.1.1224.0.0.2UNREPLIED
8 TCP38192.168.1.150192.168.1.180 TIME_WAIT
9 TCP49192.168.1.150192.168.1.180 TIME_WAIT
10 TCP3571192.168.1.15020.90.152.133443 ESTABLISHED
11 TCP58192.168.1.150192.168.1.180 TIME_WAIT
12 UDP5192.168.1.150192.168.1.153 UNREPLIED
13 TCP49192.168.1.150192.168.1.180 TIME_WAIT
14 TCP101192.168.1.150192.168.1.180 TIME_WAIT
15 TCP95192.168.1.150192.168.1.180 TIME_WAIT
16 TCP17192.168.1.150192.168.1.180 TIME_WAIT
17 TCP64192.168.1.150192.168.1.180 TIME_WAIT
18 Unknown509192.168.1.1224.0.0.1UNREPLIED
19 TCP49192.168.1.150192.168.1.180 TIME_WAIT
20 TCP2192.168.1.150192.168.1.180 TIME_WAIT
21 UDP15192.168.1.150192.168.1.153 UNREPLIED
22 TCP73192.168.1.150192.168.1.180 TIME_WAIT
23 TCP70192.168.1.150192.168.1.180 TIME_WAIT
24 TCP61192.168.1.150192.168.1.180 TIME_WAIT
25 UDP15192.168.0.25192.168.0.25453 UNREPLIED
26 TCP40192.168.1.150192.168.1.180 TIME_WAIT
ObjectDescription
Active IP ConnectionsTotal active IP connections
ProtocolConnection protocol
TimeoutsConnection timeouts, unit is second
Source AddressSource IP address
Remote AddressRemote IP address
Service NameConnecting service port
StatusDisplayed status

4.14.2 WAN

The internet connection status of the cellular gateway.

Configuration Type

Connection TypeAutomatic Configuration - DHCP
Connection Uptime0:00:30
IP Address25.18.247.159
IPV6 Address2001:b400:e158:98f:231:38ff:fe38:3436
Subnet Mask255.255.255.192
Gateway25.18.247.160
DNS 1168.95.1.1
DNS 2168.95.192.1
DNS 3
ObjectDescription
Connection TypeDisabled, static IP, automatic configurations -- DHCP, PPPOE, PPTP, L2TP, 3G/UMTS,DHCP-4G/5G
Connection UptimeConnecting uptime; if disconnected, it will display “Not available”.
IP AddressIP address of cellular gateway (WAN)
Subnet MaskSubnet mask of cellular gateway (WAN)
GatewayThe gateway of cellular gateway (WAN)
DNS1, DNS2, DNS3DNS1/DNS2/DNS3 of Cellular gateway (WAN)
-89 dBm
5G Signal Status
4G/3G Signal Status-91 dBm
NetworkFDD LTE
BANDLTE BAND 7+NR N78
ObjectDescription
5G Signal StatusSignal intensity of the module in 5G NR way
4G/3GSignal StatusSignal intensity of the module in LTE/3G/UMTS way
NetworkIP address of cellular gateway (WAN)
BANDSubnet mask of cellular gateway (WAN)

Total Traffic

Incoming (MBytes)9
Outgoing (MBytes)4

Traffic by Month
| Day | Value (MB) | |---|---| | 1 | 0 | | 2 | 0 | | 3 | 0 | | 4 | 0 | | 5 | 0 | | 6 | 0 | | 7 | 0 | | 8 | 0 | | 9 | 0 | | 10 | 0 | | 11 | 0 | | 12 | 0 | | 13 | 0 | | 14 | 0 | | 15 | 0 | | 16 | 0 | | 17 | 0 | | 18 | 18 | | 19 | 0 | | 20 | 0 | | 21 | 0 | | 22 | 0 | | 23 | 0 | | 24 | 0 | | 25 | 0 | |…

Previous Month Next Month

ObjectDescription
Total FlowStatistics on the flow from the last power-off until now, including
Monthly FlowThe flow of a month; unit is MB
Last MonthThe flow of last month
Next MonthThe flow of next month

Data Administration

Backup

Restore

Delete

ObjectDescription
BackupBackup data administration
RestoreRestored data administration
DeleteDeleted data administration

4.14.3 LAN

The Local network status of the cellular gateway.

LAN Status

MAC AddressA8:F7:E0:39:6B:9F
IP Address192.168.1.1
IPV6 Address
Subnet Mask255.255.255.0
Gateway192.168.1.254
Local DNS0.0.0.0
ObjectDescription
MAC AddressMAC Address of the LAN Ethernet port
IP AddressIP Address of the LAN port
Subnet MaskSubnet Mask of the LAN port
GatewayGateway of the LAN port
Local DNSDNS of the LAN port

Active Clients

Host NameIP AddressMAC AddressConn. CountRatio [16384]
ENM-NB-KIN192.168.1.15004:42:1a:b9:01:44800%
ObjectDescription
Host NameHost name of LAN client
IP AddressIP address of the client
MAC AddressMAC address of the client
Conn. CountConnection count caused by the client
RatioThe ratio of 4096 connection

DHCP Status

DHCP ServerEnabled
DHCP DaemonDNSMasq
Start IP Address192.168.1.100
End IP Address192.168.1.199
Client Lease Time1440 minutes

DHCP Clients

Host NameIP AddressMAC AddressClient Lease TimeDelete
ENM-NB-KIN192.168.1.15004:42:1A:B9:01:441 day 00:00:00
ObjectDescription
DNCP ServerEnable or disable the cellular gateway that works as a DHCP server
DHCP DaemonThe agreement allocated using DHCP including DNSMasq and uDHCPd Starting IP
AddressThe starting IP Address of the DHCP server's Address pool
Ending IP AddressThe ending IP Address of the DHCP server's Address pool

DHCP Clients

Host NameIP AddressMAC AddressClient Lease TimeDelete
DESKTOP-P45PKJ3192.168.1.169A0:A3:F0:49:96:2F1 day 00:00:00
ENM-NB-KIN192.168.1.15004:42:1A:B9:01:441 day 00:00:00
*192.168.1.11990:E8:68:53:3D:9F1 day 00:00:00
ObjectDescription
Client Lease TimeThe lease time of DHCP client
Host NameHost name of LAN client
IP AddressIP address of the client
MAC AddressMAC address of the client
ExpiresThe expiry the client rents the IP address

4.14.4 Wireless

The wireless status of the cellular gateway.

2.4G Wireless Status

MAC AddressA8:F7:E0:39:6B:A1
RadioRadio is On
ModeAP
NetworkMixed
SSIDPLANET_ICG-2210W-NR_2.4G
Channel5 (2.432 GHz)
TX Power20 dBm
Rate200 Mb/s
Encryption - Interface wI0Enabled, WPA2 Personal Mixed

5.8G Wireless Status

MAC AddressA8:F7:E0:39:6B:A2
RadioRadio is On
ModeAP
Networkac
SSIDPLANET_ICG-2210W-NR_5G
Channel149 (5.745 GHz)
TX Power18 dBm
Rate433.3 Mb/s
Encryption - Interface wl0_5GEnabled, WPA2 Personal Mixed
ObjectDescription
MAC AddressMAC address of wireless client
RadioDisplay whether radio is on or not
ModeWireless mode
NetworkWireless network mode
SSIDWireless network name
ChannelWireless network channel
TX PowerReflected power of wireless network
RateReflected rate of wireless network
Encryption-InterfaceEnable or disable Encryption-Interface wI0

2.4G Wireless Packet Info

Received (RX)60067 OK, no error100%
Transmitted (TX)12378 OK, no error100%

5.8G Wireless Packet Info

Received (RX)32809 OK, no error100%
Transmitted (TX)10056 OK, no error100%
ObjectDescription
Received (RX)Received data packet
Transmitted (TX)Transmitted data packet

2.4G Wireless Nodes

Clients

MAC AddressInterfaceUptimeTX RateRX RateRssiMin RssiMax Rssi
a0:a3:f0:49:96:2fath000:01:31200M180M514559

5.8G Wireless Nodes

Clients

MAC AddressInterfaceUptimeTX RateRX RateRssiMin RssiMax Rssi
90:e8:68:53:3d:9fath100:06:04433M40M31332
ObjectDescription
MAC AddressMAC address of wireless client
InterfaceInterface of wireless client
UptimeConnecting uptime of wireless client
TX RateTransmit rate of wireless client
RX RateReceive rate of wireless client
SignalThe signal of wireless client
NoiseThe noise of wireless client
SNRThe signal to noise ratio of wireless client
Signal QualitySignal quality of wireless client

Neighbor's Wireless Networks

SSIDModeMAC AddressChannelRssiNoisebeaconOpendtimRateJoin Site
WAC510AP80:CC:9C:A9:49:201-56-950on2Join
PLANET_6F_APAPA8:F7:E0:34:31:321-67-950on1Join
6F LABAPA8:F7:E0:B2:31:FA1-61-950on2Join
WDAP-C1800AX-2.4GAPB2:F7:E0:B2:31:FA1-62-950on2Join
U6LiteAPD0:21:F9:ED:FE:096-57-950on3Join
PLANET_WDAP-C3000AX_2.4GAPA8:F7:E0:00:33:036-48-950on2Join
ENM-2.4GAP44:18:47:01:00:1011-53-950on1Join
ENM_2.4G_TESTAP00:E0:61:60:9F:A611-56-950on1Join
KINLAPA8:F7:E0:A1:B2:C9149-55-950on2Join
PLANET_6F_AP(5G)APA8:F7:E0:34:31:33149-78-950on1Join

Refresh Close

ObjectDescription
SSIDThe name of wireless network nearby
ModeOperating mode of wireless network nearby
MAC AddressMAC address of the wireless nearby
ChannelThe channel of the wireless nearby
RssiSignal intensity of the wireless nearby
NoiseThe noise of the wireless nearby
BeaconSignal beacon of the wireless nearby
OpenThe wireless nearby is open or not
DtimDelivering traffic indication message of the wireless nearby
RateSpeed rate of the wireless nearby
Join SiteClick to join wireless network nearby

4.14.5 Bandwidth

The Bandwidth Monitoring of LAN Graph and WAN Graph

Abscissa axis: Time

Vertical axis: Speed rate

Bandwidth Monitoring - LAN
| Time | Value | |------|-----------| | Start | 96.82 Mbps| | Out | 876 Kbps | | Peak | 150 Mbps | | Final | 50 Mbps | | Baseline | 100 Mbps |

Bandwidth Monitoring - WAN
| Metric | Value | |--------|-----------| | In | 843 Kbps | | Out | 97.54 Mbps| | 150 Mbps | 150 Mbps | | 100 Mbps | 100 Mbps | | 50 Mbps | 50 Mbps |

The Bandwidth Monitoring of Wireless Graph

Abscissa axis: Time

Vertical axis: Speed rate

Bandwidth Monitoring - Wireless (wifi0)
| Time | Value | |------|-----------| | Start | 0 Kbps | | Peak | 100 Mbps | | End | 50 Mbps |

Bandwidth Monitoring - Wireless (wifi1)
| Time to Bytes/s | Value | | --------------- | --------- | | In | 30 Kbps | | Out | 34 Kbps |

4.14.6 Sys Info

Router

Router NamePLANET Cellular Wireless
Gateway
Router ModelICG-2210W-NR
LAN MACA8:F7:E0:39:6B:9F
WAN MACA8:F7:E0:39:6B:A0
Wireless MACA8:F7:E0:39:6B:A1
WAN IP25.15.167.100
BKUP WAN IP192.168.3.135
LAN IP192.168.1.1
ObjectDescription
Router NameThe name of the cellular gateway
Router ModelThe model of the cellular gateway
LAN MACMAC address of LAN port
WAN MACMAC address of WAN port
Wireless MACMAC address of the wireless
WAN IPIP address of WAN port
LAN IPIP address of LAN port

Wireless

RadioRadio is On
ModeAP
NetworkMixed
SSIDPLANET_ICG-2210W-NR-2.4G
Channel11 (2.462 GHz)
TX Power20 dBm
Rate200 Mb/s
ObjectDescription
RadioDisplay whether radio is on or not
ModeWireless mode
NetworkWireless network mode
SSIDWireless network name
ChannelWireless network channel
TX PowerReflected power of wireless network
RateReflected rate of wireless network

Wireless Packet Info

Received (RX)2417387 OK, no error
Transmitted (TX)482438 OK, no error
ObjectDescription
Received (RX)Received data packet
Transmitted (TX)Transmitted data packet

Clients

MAC AddressInterfaceUptimeTX RateRX RateRssiMin RssiMax Rssi
a0:a3:f0:49:96:2fath000:11:19200M180M514059
ObjectDescription
MAC AddressMAC address of wireless client
InterfaceInterface of wireless client
UptimeConnecting uptime of wireless client
TX RateTransmit rate of wireless client
RX RateReceive rate of wireless client
SignalThe signal of wireless client
NoiseThe noise of wireless client
SNRThe signal to noise ratio of wireless client
Signal QualitySignal quality of wireless client

Services

DHCP ServerEnabled
radauthDisabled
ObjectDescription
DHCP ServerThe status of DHCP Server
radauthThe status of radauth

Memory

Total Available494.1 MB / 512.0 MB
Free362.1 MB / 494.1 MB
Used132.0 MB / 494.1 MB
Buffers7.6 MB / 132.0 MB
Cached21.7 MB / 132.0 MB
Active21.7 MB / 132.0 MB
Inactive11.1 MB / 132.0 MB
ObjectDescription
Total AvailabilityThe total availability of RAM
FreeThe cellular gateway will reboot if the memory is less than 500kB.
UsedThe total availability of memory minus free memory
BuffersUsed memory for buffers with the total available memory minus allocated memory
CachedThe memory used by high-speed cache memory
ActiveActive use of buffer or cache memory
InactiveNot often used in a buffer or cache memory

DHCP Clients

Host NameIP AddressMAC AddressClient Lease Time
DESKTOP-P45PKJ3192.168.1.169xx:xx:xx:xx:96:2F1 day 00:00:00
*192.168.1.150xx:xx:xx:xx:01:441 day 00:00:00
ENM-NB-KIN192.168.1.119xx:xx:xx:xx:3D:9F1 day 00:00:00
ObjectDescription
Host NameHost name of LAN client
IP AddressIP address of the client
MAC AddressMAC address of the client
ExpiresThe expiry the client rents the IP address

Appendix A: DDNS Application

Configuring PLANET DDNS steps:

Step 1: Visit DDNS provider's web site and register an account if you do not have one yet. For example, register an account at https://planetddns.com

Step 2: Enable DDNS option through accessing Web page of the device.

Step 3: Input all DDNS settings.

PLANET DDNS PLANET Networking & Communication PLANET Website FAQ Support Sign in ID / Email ****** Sign in Forgotten Password / Create A New Account XRT-401F Internet Broadband Router More Info ICA-HM132 2 Mega-Pixel 20M IR Van- Focal Dome IP Camera More Info ICA-HM316 2 Mega-Pixel 11n Outdoor IR IP…

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : Planet

Model : ICG-2210W-NR

Category : Network router