BEC Technologies MX-200A ODU - Router

MX-200A ODU - Router BEC Technologies - Free user manual and instructions

Find the device manual for free MX-200A ODU BEC Technologies in PDF.

📄 153 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice BEC Technologies MX-200A ODU - page 6
Pick your language and provide your email: we'll send you a specifically translated version.
Product Type 4G/LTE Outdoor Router (Category 6)
Brand BEC Technologies
Model MX-200A ODU
Dimensions (W x D x H) 8.5 x 7.5 x 3 in (257 x 227 x 91 mm)
Weight Under 4 lbs (approx. 1.8 kg)
Enclosure Rating IP67 (dust-tight, waterproof)
Power Supply PoE (Power over Ethernet) IEEE 802.3at compliant
Ethernet Ports 2 x Gigabit Ethernet (1 PoE PD)
SIM Slot 1 x SIM slot (industrial-grade recommended)
Maximum Data Rate Downlink 300 Mbps, Uplink 50 Mbps
Antenna Technology High gain MIMO directional antenna (cross-polarized)
Network Modes LTE, UMTS, GSM; supports IPv4, IPv6, dual stack
VPN Support IPSec, PPTP, L2TP, GRE, OpenVPN
Firewall SPI, DoS prevention, access control, URL filter
Management Web GUI, SNMP, TR-069, BECentral cloud
Dual WAN Failover/failback, load balancing, protocol binding
Mounting Wall or pole mount (included kit)
Grounding Mandatory earth grounding (wire included)
Operating Temperature Industrial grade for rugged environments
Package Contents Router, PoE injector, grounding wire, mounting kit, cable glands

Frequently Asked Questions - MX-200A ODU BEC Technologies

How do I reset the MX-200A ODU to factory default settings?
Press and hold the RESET button on the rear panel for more than 6 seconds, then release. After that, power cycle the device. The default web login is admin/admin for administrator.
What type of SIM card does the router require?
The MX-200A ODU uses a standard SIM card. It is recommended to use an industrial-grade SIM card for reliability. Insert the SIM with gold contacts facing down until it clicks.
Can I use the router with a standard PoE switch?
Yes, the MX-200A ODU is compliant with IEEE 802.3at PoE+. You can use any 802.3at capable PoE injector or switch. The supplied PoE injector is for indoor use only.
How do I access the router's web interface?
Connect a PC to the LAN port, set your PC to obtain an IP automatically, then open a browser and go to http://192.168.1.254. Default username/password is admin/admin (or unique password on device label).
Is the MX-200A ODU weatherproof?
Yes, the enclosure is rated IP67, meaning it is dust-tight and can withstand immersion in water up to 1 meter for 30 minutes. It is designed for outdoor use in harsh conditions.
What is the maximum data speed of this router?
The MX-200A ODU is a Category 6 LTE Advanced device supporting carrier aggregation, with downlink speeds up to 300 Mbps and uplink up to 50 Mbps.
Does the router support IPv6?
Yes, it supports IPv4, IPv6, and dual-stack operation. You can configure the WAN interface for IPv4, IPv6, or both.
How do I connect the router to a 4G/LTE network?
Insert a valid SIM card, power on the router, and log into the web GUI. Go to Interface Setup > Internet and select 4G/LTE as the WAN interface. Configure the APN and authentication details from your mobile provider.
Can I use both the 4G/LTE and Ethernet WAN connections simultaneously?
Yes, the MX-200A ODU supports Dual WAN with failover/failback and load balancing. You can configure primary and backup WAN interfaces in Configuration > Dual WAN.
How do I update the firmware?
Download the latest firmware from BEC Technologies support website. Log into the web GUI, go to Maintenance > Firmware & Configuration, choose the firmware file, and click Upgrade. Do not power off during the process.

User questions about MX-200A ODU BEC Technologies

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Router in PDF format for free! Find your manual MX-200A ODU - BEC Technologies and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. MX-200A ODU by BEC Technologies.

USER MANUAL MX-200A ODU BEC Technologies

4G/LTE Outdoor Router

Exterior view of a BEC antenna device mounted on a metal pole (no visible text or symbols)

Copyright@ 2017 BEC Technologies Inc. All rights reserved.

BEC Technologies reserves the right to change and make improvement to this manual at any time without prior notice.

No part of this document may be reproduced, copied, transmitted in any form or by any means without prior written permission from BEC Technologies, Inc.

Support Contact Information

Contact Support: http://bectechnologies.net/support/.

Telephone: +1 972 422 0877

TABLE OF CONTENTS

SUPPORT CONTACT INFORMATION ......1

CHAPTER 1: INTRODUCTION ....1

INTRODUCTION TO YOUR ROUTER....1

FEATURES & SPECIFICATIONS....3

HARDWARE SPECIFICATIONS....5

APPLICATION DIAGRAM 5

CHAPTER 2: PRODUCT OVERVIEW......6

IMPORTANT NOTE FOR USING THIS ROUTER 6

PACKAGE CONTENTS......6

DEVICE DESCRIPTION 7

MOUNTING KIT INSTALLATION 8

ROUTER INSTALLATION INSTRUCTIONS 12

CHAPTER 3: BASIC INSTALLATION .....15

NETWORK CONFIGURATION – IPv4 16

Configuring PC in Windows 10 (IPv4)....16

Configuring PC in Windows 7/8 (IPv4)....18

Configuring PC in Windows Vista (IPv4) 20

NETWORK CONFIGURATION – IPv6 22

Configuring PC in Windows 10 (IPv6)....22

Configuring PC in Windows 7/8 (IPv6)....24

Configuring PC in Windows Vista (IPv6) 26

DEFAULT SETTINGS.... 28

CHAPTER 4: DEVICE CONFIGURATION .....29

LOGIN TO YOUR DEVICE 29

STATUS.... 31

Device Info 31

System Status 32

System Log 32

3G/4G-LTE Status....33

Statistics 35

DHCP Table....38

IPSec Status....39

PPTP Status 40

L2TP Status....41

GRE Status....41

OpenVPN Status....42

ARP Table 43

VRRP Status....43

QUICK START 44

DEVICE CONFIGURATION 47

Interface Setup....47

Internet 47

LAN....55

Loopback....59

Dual WAN....60

General Setting....60

Outbound Load Balance 64

Protocol Binding 65

Advanced Setup 67

Firewall.... 67

Routing....68

Dynamic Routing 69

NAT....71

VRRP....76

Static DNS....77

QoS....78

Time Schedule 80

Mail Alert 81

VPN 82

IPSec....82

PPTP Server 92

PPTP Client 94

L2TP 101

GRE Tunnel 108

OpenVPN 113

OpenVPN Server 113

OpenVPN Client 115

Access Management 120

Device Management 120

SNMP 121

Syslog 123

Universal Plug & Play 124

Dynamic DNS (DDNS) 125

Access Control 127

Packet Filter 129

CWMP (TR-069).... 133

Parental Control 135

BECentral Management 136

Maintenance 137

User Management 137

Certificate Management 139

Time Zone....141

Firmware & Configuration.... 142

System Restart.... 143

Auto Reboot 144

Diagnostics Tool.... 145

CHAPTER 5: TROUBLESHOOTING .....147

Problems with the Router 147

Problem with LAN Interface 147

APPENDIX: PRODUCT SUPPORT & CONTACT

148

CHAPTER 1: INTRODUCTION

Introduction to your Router

Congratulations on your purchase of the MX-200A ODU (Outdoor 4G/LTE Router).

This unit is an industrial-grade 4G/LTE Outdoor Router designed for mission critical operation in rugged, harsh environments. The MX-200A ODU is a Category 6 device supporting LTE Advanced and Carrier Aggregation and come with 2 Gigabit Ethernet ports. The IP67 rated enclosure will withstand dirt, harmful ingress of water, humidity and extreme temperatures for years of dependable operation. The Embedded high gain MIMO directional antenna provides improved signal quality, increased signal range and coverage across multiple frequency bands. Physical size and weight (under 4lbs) were key design considerations, thus the MX-200A ODU can be mounted directly on exterior walls, chimneys, lightweight poles and used for retrofitting applications such as the replacement of older generation wireless technology.

Innovative MIMO Antenna Technology

Homes and businesses with a weak or nonexistent wireless signal can benefit from the extended range and reach of the MX-200A ODU Multiple MIMO antenna technology options allow service providers to select the optimal solution for their environment or application whether LOS (Line of Sight) or NLOS (Non-Line of Sight). Physical size and weight were key design considerations of the MX-200A ODU; it can be mounted directly on exterior walls, chimneys, lightweight poles and used for retrofitting applications such as the replacement of older generation wireless technology.

Designed for Challenging / Rugged Deployments

The MX-200A ODU is designed for the toughest industrial environments. With IP67 hardened enclosure with industrial-grade components, the MX-200A ODU can be installed in manufacturing plants, industrial automation, stadiums, convention halls, stadium facilities, school campuses, or virtually any venue requiring a robust wireless solution. The MX-200A ODU of 4G/LTE Outdoor routers creates value, enables new growth opportunities and helps operators maximize network ROI.

4G/LTE Mobility

With 4G/LTE-based Internet connection (4G/LTE embedded module, requires an additional SIM card), you can access to the Internet through 4G/LTE whether you are seated at your desk or taking a cross-country trip.

4G/LTE Management Center

The MX-200A ODU Mobile Management Center visually displays its current 4G/LTE signal status also calculates the total amount of hours or data traffic used per month, allowing you to manage your 4G/LTE monthly subscriptions.

IPv6 Supported

Internet Protocol version 6 (IPv6) is a version of the Internet Protocol that is designed to succeed IPv4. IPv6 has a vastly larger address space than IPv4. The router is already supporting IPv6, you can use it in IPv6 environment no need to change device. The dual-stack protocol implementation in an operating system is a fundamental IPv4-to-IPv6 transition technology. It implements IPv4 and IPv6 protocol stacks either independently or in a hybrid form. The hybrid form is commonly implemented in modern operating systems supporting IPv6.

Quick Start Wizard

Support a WEB GUI page to install this device quickly. With this wizard, simple steps will get you connected to the Internet immediately.

Firmware Upgradeable

Device can be upgraded to the latest firmware through the WEB based GUI.

Features & Specifications

  • Outdoor 4G for high speed mobile connectivity
  • Category 6 UE, data rates of up to 300Mbps(DL) / 50Mbps (UL)
  • 4G embedded with a built-in SIM card slot
    • High-speed 4G connection up to downlink 300 Mbps and uplink 50Mbps data rate
    • 4G Management Center for connection monitoring
  • Firewall security with DoS prevention and SPI
    • Quality of Service control
  • Syslog monitoring
  • Ease of Use with Quick Installation Wizard
  • Ideal solution for Industrial, Oil & Gas, Mining, Marine, Manufacturing Plants, Urban / Rural and Remote Connectivity

Operational Mode

- Bridge or Routed mode

Network Protocols and Features

  • IPv4, IPv6 or IPv4 / IPv6 Dual Stack
    • NAT, static (v4/v6) routing and RIP-1 / 2
  • DHCPv4 / v6
    • Universal Plug and Play (UPnP) Compliant
    • Dynamic Domain Name System (DDNS)
    • Virtual Server and DMZ
  • SNTP, DNS proxy
    • IGMP snooping and IGMP proxy
  • MLD snooping and MLD proxy

Firewall

• Built-in NAT Firewall
• Stateful Packet Inspection (SPI)
- DoS attack prevention including Land Attack, Ping of Death, etc
- Access control
• IP&MAC filter, URL Content Filter
- Password protection for system management
- VPN pass-through

Quality of Service Control

  • IEEE 802.1Q VLAN
  • Outbound Load Balancing (Round Robin, Weight or IP Hash)

Management

  • Quick Installation wizard
  • Web-based GUI for remote and local management (IPv4/IPv6)
  • Firmware upgrades and configuration data upload and download via web-based GUI
    • Supports DHCP server / client / relay
    • Supports SNMP v1, v2, v3, MIB-I and MIB-II
    • TR-069 supports remote management
    • BECentral Cloud-Based Remote Management

Hardware Specifications

Physical interface

• 10/100/1000 Gigabit Ethernet LAN with IEEE802.3at compliant Gigabit PoE PD
• SIM slot: (for the SIM card from Telco / ISP)

Physical Specifications

  • Dimensions (W*H*D): 8.5" x 7.5" x 3"(257mm x 227mm x 91mm)
    • IP-67 Grade Enclosure

Application Diagram
graph TD A["BEC MX-200A-ODU"] -->|4G/LTE| B["Base Station"] A --> C["PoE Injector"] C --> D["modem"] D --> E["switch"] F["Power Cable"] --> D G["RJ-45 Ethernet Cable"] --> D H["5GHz Wi-Fi"] --> D

CHAPTER 2: PRODUCT OVERVIEW

Important Note for Using This Router

BEC Technologies MX-200A ODU - Important Note for Using This Router - 1
Attention

√ Do not remove, open or repair the case yourself. Contact with your Internet Service Provider or have it repaired at a qualified service center.
√ Use the supplied PoE (Power-over-Ethernet) injector for indoor only or with any 802.3at capable PoE injectors to connect with the MX-200A ODU
√ It is mandatory to earth ground the MX-200A ODU. Improper grounding not only could damage the unit but also all equipments connected to it.

Package Contents

√ The MX-200A ODU 4G/LTE Outdoor Router
√ Gigabit Power-over-Ethernet (PoE) Injector
√ Grounding Wire
√ Mounting Kit
√ M25 Cable Gland x 2

Device Description

SIM LAN LAN(PoE)

CONNECTORSDESCRIPTION
SIMInsert the SIM card into the SIM slot.Press the reset button to reset device or restore to factory default settings
Gigabit LANConnect it with an Ethernet-enable device.
Gigabit LAN(PoE)Connect it with the supplied PoE injector, 802.3at compliant, using an Ethernet cable.

Mounting Kit Installation

1. Attach the Articulation Pole to the Enclosure

Attach the articulation pole to the back of the MX-200A ODU using M6*16 screws and washers.

A -45 or +45 degree adjustment Cross-Polarized Antenna Dual-Polarized Antenna

2. Wall or Pole Mounting

2.1 Mounting on Wall

Fix the T-formed Bracket to the wall using wood/ drywall screws.

Technical line drawing of a mechanical component with screws and a fan assembly (no text or symbols)

2.2 Mounting on a Pole

2.2.1a Mounting for pole smaller than 1.5" (38mm)

Attach the T-formed Bracket and the W-bar to the pole then use M6x60 bolts, spring washer and washer to fix the mounting kit onto the pole.

Technical line drawings of mechanical components with bolts and fasteners (no text or symbols)

2.2.1b Mounting for pole larger than 1.5" (38mm)

Fix the T-formed Bracket to the pole by using the stainless hose clamp.

Technical line drawing of a mechanical fan or impeller assembly (no text or symbols)

3. Mounting the MX-200A ODU to the T-formed Bracket

Attach the articulation pole (the MX-200A ODU enclosure) to the T-formed bracket by using M8x40 bolts, nut, spring washer and washer.

Cross-Polarized Antenna – The original of the source position, the nominal position, is seeing the BEC logo when facing toward the MX-200A ODU,

Technical line drawings of mechanical components, showing front and side views with no visible text or symbols

Dual-Polarized Antenna – From the nominal position, adjusting and rotating the MX-200A ODU in -45 or +45, anticlockwise or clockwise, degree angle.

Technical line drawings of mechanical components with no visible text or symbols

4. Position Adjustment

Find the location and best angle for getting the strongest signal from the base station. The MX-200A ODU must be directed towards the nearest base station.

Adjusting the router position to get a better reception and/or fine-tuning the router orientation (in horizontal/vertical position or 45 degree angle position) to have the best signal strength

BEC TECHNOLOGIES

5. Grounding the CPE to Complete the Installation

Attach the grounding wire to the CPE and tighten the screw

Diagram illustrating a plug-in socket with labeled pins and a magnified view showing the insertion direction.

Router Installation Instructions

1. Power on your MX-200A ODU

Step 1: Assemble M25 cable gland

BEC Technologies MX-200A ODU - Power on your MX-200A ODU - 1
A

BEC Technologies MX-200A ODU - Power on your MX-200A ODU - 2
B

BEC Technologies MX-200A ODU - Power on your MX-200A ODU - 3
C

BEC Technologies MX-200A ODU - Power on your MX-200A ODU - 4

D
BEC Technologies MX-200A ODU - Power on your MX-200A ODU - 5

Step 2: Unscrew the LAN (PoE) port and insert the supplied outdoor Ethernet cable (RJ-45) through material A-D, and then connect the RJ-45 Ethernet cable into the LAN (PoE) port.

A B C D

Step 3:

3.1: Insert Ⓐ at the back end of Ⓓ
3.2: clip Ⓑ on Ⓒ
3.3: keep Ⓑ close to Ⓓ
3.4: then tighten Ⓐ.

Diagram showing a cable being inserted into a socket, with no text or symbols present

Step 4: Insert the other end of outdoor Ethernet cable (RJ-45) to the supplied Gigabit PoE injector, IEEE 802.1 at compliant, Power+Data (P+D)/OUT port. Connect another Ethernet cable (RJ-45) directly to the Data/IN port and the other end of cable to a switch or broadband router. Plug the PoE power cable to an electrical outlet to power on your MX-200A ODU.

graph TD A["PC / Laptop"] --> B["6300NXL"] B --> C["POE injector"] C --> D["Electrical outlet"] D --> E["LTE Outdoor CPE"] E --> F["Ground Cable"] C --> G["P+D/OUT"] G --> H["Data/IN"] H --> I["PC / Laptop"] style A fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style C fill:#cfc,stroke:#333 st…

2. Set up your 4G/LTE Internet Connection

Step 1: Unscrew the cap of SIM card slot.

SIM LAN

Step 2: Slide the SIM card with the mental contacts (gold plate) facing down to the SIM slot then push it all the way in until you hear the clicking sound.

BEC Technologies MX-200A ODU - Set up your 4G/LTE Internet Connection - 2
Attention

It is recommended to use an industrial-grade SIM card.

SIM LAN

Symbolic image of a computer with a 'No' prohibition sign overlaid on it, indicating no restrictions or blocked access.

Step 3: Screw the cap back tightly.

BEC Technologies MX-200A ODU - Set up your 4G/LTE Internet Connection - 5
Warning

Please power off your MX-200A ODU before inserting or removing the SIM card.

SIM LAN

CHAPTER 3: BASIC INSTALLATION

The router can be configured with your web browser. A web browser is included as a standard application in the following operating systems: Windows Vista / 7 / 8, Linux, Mac OS, etc. The product provides an easy and user-friendly interface for configuration.

PCs must have an Ethernet interface installed properly and be connected to the router either directly or through an external repeater hub, and have TCP/IP installed or configured to obtain an IP address through a DHCP server or a fixed IP address that must be in the same subnet as the router. The default IP address of the router is 192.168.1.254 and the subnet mask is 255.255.255.0 (i.e. any attached PC must be in the same subnet, and have an IP address in the range of 192.168.1.1 to 192.168.1.253). The best and easiest way is to configure the PC to get an IP address automatically from the router using DHCP. If you encounter any problems accessing the router's web interface it may also be advisable to uninstall any kind of software firewall on your PCs, as they can cause problems accessing the 192.168.1.254 IP address of the router. Users should make their own decisions on how to best protect their network.

Please follow the steps below for your PC's network environment installation. First of all, please check your PC's network components. The TCP/IP protocol stack and Ethernet network adapter must be installed. If not, please refer to your Windows-related or other operating system manuals.

BEC Technologies MX-200A ODU - CHAPTER 3: BASIC INSTALLATION - 1
Attention

Any TCP/IP capable workstation can be used to communicate with or through the MX-200A ODU. To configure other types of workstations, please consult the manufacturer's documentation.

Network Configuration – IPv4

Configuring PC in Windows 10 (IPv4)

  1. Click

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv4) - 1

  1. Click

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv4) - 2

Settings

  1. Then click on Network and Internet.

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv4) - 3

  1. Under Related settings, select Network and Sharing Center

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv4) - 4

Related settings

Change adapter options

Change advanced sharing options

Network and Sharing Center

HomeGroup

Internet options

Windows Firewall

  1. When the Network and Sharing Center window pops up, select and click on Change adapter settings on the left window panel.

Control Pond Home Manage wireless networks Change adapter settings Change advanced sharing settings View your basic network information and set up connections TEST-PC (This computer) BGS10N-CNC Internet View your active networks Connect or disconnect BGS10N-CNC Public network Access types: Internet…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Network and Internet ▶ Network Connections ▶ Organize ▼ Enable this network device Diagnose this connection Rename this connection Local Area Connection Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties Network Extender Disconnected Network Extender SSLVPN Adapter W…

  1. Select Internet Protocol Version 4 (TCP/IPv4) then click Properties.

Local Area Connection Properties Networking Sharing Connect using: Broadcom 570x Gigabit Integrated Controller Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6…

  1. In the TCP/IPv4 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the…

Configuring PC in Windows 7/8 (IPv4)

  1. Go to Start. Click on Control Panel.
  2. Then click on Network and Internet.

  3. When the Network and Sharing Center window pops up, select and click on Change adapter settings on the left window panel.

Control Panel Adjust your computer's settings System and Security Review your computer's status Back up your computer Find and fix problems Network and Internet View network status and tasks Choose homegroup and sharing options Hardware and Sound View devices and printers Add a device Adjust commonl…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Control Panel Home Manage wireless networks Change adapter settings Change advanced sharing settings View your basic network information and set up connections TEST-PC (BGS10N-CNC) Internet View your active networks Connect or disconnect BGS10N-CNC Public network Access types Connections Internet Wi…

Network and Internet Network Connections Organize Disable this network device Diagnose this connection Rename this connection Local Area Connection Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties Network Extender Disconnected Network Extender SSLVPN Adapter Wirele…

  1. Select Internet Protocol Version 4 (TCP/IPv4) then click Properties.

Local Area Connection Properties Networking Sharing Connect using: Broadcom 570x Gigabit Integrated Controller Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6…

  1. In the TCP/IPv4 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the…

Configuring PC in Windows Vista (IPv4)

  1. Go to Start. Click on Network.
  2. Then click on Network and Sharing Center at the top bar.
  3. Then click on Network and Sharing Center at the top bar.

Network Organize Views Network and Sharing Center Add a printer Add a wire This computer is not connected to a network. Click to connect... Favorite Links Name Category Workgroup Network location Documents Pictures Music Recently Changed Searches Public

  1. When the Network and Sharing Center window pops up, select and click on Manage network connections on the left window pane.

Network and Internet ▶ Network and Sharing Center Search Tasks View computers and devices Connect to a network Set up a network network Manage network connections Diagnose and repair Network and Sharing Center TEST1-WHQL (This computer) Internet Not connected You are currently not connected to any n…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Network and Internet ▶ Network Connections ▶ Organize ▶ Views ▶ Disable this network device ▶ Diagnos Name Status Device Name Connectivity Network Cate Dial-up (2) Network Extender Disconnected Network Extender SSLVPN A... Standalone Network Extende Disconnected ISDN WAN Device LAN or High-Speed Int…

  1. Select Internet Protocol Version 4 (TCP/IPv4) then click Properties.

Local Area Connection Properties Networking Connect using: Intel(R) 82566DM Gigabit Network Connection Configure... This connection uses the following items: Client for Microsoft Networks QoS Packet Scheduler File and Printer Sharing for Microsoft Networks Internet Protocol Version 6 (TCP/IPv6) Inte…

  1. In the TCP/IPv4 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 4 (TCP/IPv4) Properties General Alternate Configuration You can get IP settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IP settings. Obtain an IP address automatically Use the…

Network Configuration – IPv6

Configuring PC in Windows 10 (IPv6)

  1. Click

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv6) - 1

  1. Click

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv6) - 2

Settings

  1. Then click on Network and Internet.

BEC Technologies MX-200A ODU - Configuring PC in Windows 10 (IPv6) - 3

  1. Under Related settings, select Network and Sharing Center

Related settings Change adapter options Change advanced sharing options Network and Sharing Center HomeGroup Internet options Windows Firewall

  1. When the Network and Sharing Center window pops up, select and click on Change adapter settings on the left window panel.

Network and Internet Network and Sharing Center Search Control Panel Control Panel Home Manage wireless networks Change adapter settings Change advanced sharing settings View your basic network information and set up connections TEST-PC (This computer) BGS10N-CNC Internet See full map View your acti…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Network and Internet > Network Connections > Organize Disable this network device Diagnose this connection Rename this connection Local Area Connection Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties Network Extender Disconnected Network Extender SSLVPN Adapter Wi…

  1. Select Internet Protocol Version 6 (TCP/IPv6) then click Properties.

Local Area Connection Properties Networking Sharing Connect using: Broadcom 570x Gigabit Integrated Controller Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6…

  1. In the TCP/IPv6 properties window, select the Obtain an IPv6 address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 6 (TCP/IPv6) Properties General You can get IPv6 settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IPv6 settings. Obtain an IPv6 address automatically Use the following IPv6 ad…

Configuring PC in Windows 7/8 (IPv6)

  1. Go to Start. Click on Control Panel.
  2. Then click on Network and Internet.

Control Panel Search Control Panel Adjust your computer's settings View by: Category System and Security Review your computer's status Backup your computer Find and find applications Network and Internet View network status and tasks Choose homegroup and sharing options Hardware and Sound View devic…

  1. When the Network and Sharing Center window pops up, select and click on Change adapter settings on the left window panel.

Control Panel Home Manage wireless networks Change adapter settings Change advanced sharing settings View your basic network information and set up connections TEST-PC (This computer) BGS10N-CNC Internet See full map View your active networks Connect or disconnect BGS10N-CNC Public network Access ty…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Network and Internet > Network Connections Organize Disable this network device Diagnose this connection Rename this connection Local Area Connection Disable Status Diagnose Bridge Connections Create Shortcut Delete Rename Properties Network Extender Disconnected Network Extender SSLVPN Adapter Wire…

  1. Select Internet Protocol Version 6 (TCP/IPv6) then click Properties.

Local Area Connection Properties Networking Sharing Connect using: Broadcom 570x Gigabit Integrated Controller Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6…

  1. In the TCP/IPv6 properties window, select the Obtain an IPv6 address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 6 (TCP/IPv6) Properties General You can get IPv6 settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IPv6 settings. Obtain an IPv6 address automatically Use the following IPv6 ad…

Configuring PC in Windows Vista (IPv6)

  1. Go to Start. Click on Network.
  2. Then click on Network and Sharing Center at the top bar.

  3. When the Network and Sharing Center window pops up, select and click on Manage network connections on the left window pane.

Network Organize Views Network and Sharing Center Add a printer Add a wire This computer is not connected to a network. Click to connect... Favorite Links Name Category Workgroup Network location Documents Pictures Music Recently Changed Searches Public

Network and Internet ▶ Network and Sharing Center Search Tasks View computers and devices Connect to a network Set up a connection or network Manage network connections Diagnose and repair Network and Sharing Center TEST1-WHQL (This computer) Internet Not connected You are currently not connected to…

  1. Select the Local Area Connection, and right click the icon to select Properties.

Network and Internet ▶ Network Connections ▶ Organize ▶ Views ▶ Disable this network device ▶ Diagnos Name Status Device Name Connectivity Network Cate Dial-up (2) Network Extender Disconnected Network Extender SSLVPN A... Standalone Network Extender Disconnected ISDN WAN Device LAN or High-Speed In…

  1. Select Internet Protocol Version 6 (TCP/IPv6) then click Properties.

Local Area Connection Properties Networking Sharing Connect using: Broadcom 570x Gigabit Integrated Controller Configure... This connection uses the following items: ✓ Client for Microsoft Networks ✓ QoS Packet Scheduler ✓ File and Printer Sharing for Microsoft Networks ✓ Internet Protocol Version 6…

  1. In the TCP/IPv6 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting.
  2. Click OK again in the Local Area Connection Properties window to apply the new configuration.

Internet Protocol Version 6 (TCP/IPv6) Properties General You can get IPv6 settings assigned automatically if your network supports this capability. Otherwise, you need to ask your network administrator for the appropriate IPv6 settings. Obtain an IPv6 address automatically Use the following IPv6 ad…

Default Settings

Before configuring the router, you need to know the following default settings.

Web Interface: (Username and Password)

Administrator

√ Username: admin
√ Password: A unique12-digit password can be found on the device label.

User

√ Username: user
√ Password: user

BEC Technologies MX-200A ODU - User - 1

If you ever forget the username/password to login to the router, you may press the RESET button up to 6 seconds then release it to restore the factory default settings.

Caution: After pressing the RESET button for more than 6 seconds then release it, to be sure you power cycle the device again.

Device LAN IP Settings

√ IP Address: 192.168.1.254
√ Subnet Mask: 255.255.255.0

DHCP Server:

√ DHCP server is enabled.
√ Start IP Address: 192.168.1.100
√ IP pool counts: 100

CHAPTER 4: DEVICE CONFIGURATION

Login to your Device

Open your web browser, enter the IP address of your router, which by default is 192.168.1.254, and click "Go", a user name and password window prompt appears.

The default username and password is "admin" and "admin" respectively for the Administrator.

For the User account, default username and password is "user" and "user".

NOTE: This username / password may vary by different Internet Service Providers.

Windows Security The server 192.168.1.254 is asking for your user name and password. The server reports that it is from MX-200. Warning: Your user name and password will be sent using basic authentication on a connection that isn't secure. User name Password Remember my credentials OK Cancel

Congratulations! You have successfully logged on to your MX-200A ODU

Once you have logged on to your MX-200A ODU via your web browser, you can begin to set it up according to your requirements. On the configuration homepage, the left navigation pane links you directly to the setup pages, which includes:

SectionStatusQuick Start (Wizard Setup)Configuration
Sub-ItemsDevice InfoInterface Setup- Internet- LAN- LoopbackDual WAN- General Setting- Outbound Load Balance- Protocol BindingAdvanced Setup- Firewall- Routing- Dynamic Routing- NAT- VRRP- Static DNS- QoS- Time Schedule- Mail AlertVPN- IPSec- PPTP Server- PPTP Client- L2TP- GRE- OpenVPN Server- OpenVPN ClientAccess Management- Device Management- SNMP- Syslog- Universal Plug & Play- Dynamic DNS- Access Control- Packet Filter- CWMP (TR-069)- Parental Control- BECentral ManagementMaintenance- User Management- Certificate Management- Time Zone- Firmware & Configuration- System Restart- Auto Reboot- Diagnostic Tool
System Status
System Log
3G/4G-LTE Status
Statistics
DHCP Table
IPSEC Status
PPTP Status
L2TP Status
GRE Status
OpenVPN Status
ARP Table
VRRP Status

Please see the relevant sections of this manual for detailed instructions on how to configure your MX-200A ODU device.

Status

Device Info

It provides brief status summary of the device.

Device Information
Model NameMX-200
Firmware Version1.02.1.10
MAC Address00:04:ed:98:76:54
Date-TimeFri Jan 2 01:59:11 UTC 1970
System Up Time1 day 1 hour 59 mins
Physical Port Status
4G LTE -1×
EWAN×
Ethernet
WAN
InterfaceProtocolConnectionIP AddressDefault Gateway
4G LTE -1 ▼Dynamic IPNot Connected/
IP AddressSubnet Mask/Prefix LengthDHCP Server
192.168.1.254255.255.255.0Enable / 192.168.1.100~192.168.1.199Enable / Stateless

Device Information

Model Name: Name of the router for identification purpose.

Firmware Version: Software version currently loaded in the router

MAC Address: A unique number that identifies the router

Data Time: Setup correct time on the MX-200A ODU with your PC. Check on Time Zone section for more configuration information.

System Uptime: Display how long the MX-200A ODU has been powered on.

Physical Port Status

Physical Port Status : Display available connection interfaces, WAN (3G/4G-LTE, EWAN) and LAN (Ethernet) are supported in the MX-200A ODU.

WAN

Interface: List current available WAN connections.

Protocol: Display selected WAN connection protocol

Connection: The current connection status.

IP Address: WAN port IP address.

Default Gateway: The IP address of the default gateway.

LAN

IP Address: LAN port IPv4 address.

Subnet Mask/Prefix Length: Display LAN port IP subnet mask of IPv4 and/or Prefix length of IPv6.

DHCP Server: Display LAN DHCP status of IPv4 and IPv6.

▶ Enable / 192.168.1.100\~199: DHCPv4 server status on or off / DHCP IP range
▶ Enable / Stateless: DHCPv6 server status on or off / DHCPv6 server Type

System Status

Display device CPU and memory usage information

System Status
CPU
Usage1%
Memory
Total60520 kB
Free32196 kB
Cached9948 kB
Refresh

CPU

Usage: Display the amount of CPU's processing capacity is being used in percentage (%). Higher the % rate may result in slow Internet loading, experiencing video lags, etc. To reduce high CPU consumption by resetting the device, power off and on, an easiest way to regain the service.

Memory

Total / Free / Cached (in Kbyte): Display the memory consumptions in kilobytes (kB).

System Log

In system log, you can check the operations status and any glitches to the router.

Jan 1 00:00:31 syslogd started: BusyBox v1.00 (2015.12.28-02:11+0000) Jan 1 00:00:33 pptpd[1492]: MGR: Manager process started Jan 1 00:00:33 pptpd[1492]: MGR: Maximum of 100 connections available Jan 1 00:00:39 PPOELOGIN: bind service port Jan 1 00:00:39 PPOELOGIN: begin service loop Jan 1 00:00:39…

Refresh: Press this button to refresh the statistics.

Backup: Press to save the System log, log.cfg, to your computer / notebook.

3G/4G-LTE Status

It contains 3G/4G-LTE connection information.

4G/LTE Status Status Up Signal Strength -62.00dbm Signal Information RSRP:-92.50 , RSRQ:-13.80 , SINR:11.90 Network Name "Chunghwa Telecom" Cell ID 81023501 Card IMEI Card IMSI Network Mode LTE Network Band B3 Usage Allowance Amount used 0Hours of 720Hours Billing period的日:6 Clean Save Refresh

Status: The current status of the 3G/4G-LTE connection.

Signal Strength: The signal strength bar and dBm value indicates the current 3G/4G-LTE signal strength. The front panel 3G/4G-LTE Signal Strength LED indicates the signal strength as well.

Signal Information: Shows important LTE signal parameters such as RSRP (Reference Signal Receiving Power), RSRQ (Reference Signal Receiving Quality), SINR (Signal to Interference plus Noise Ratio).

  • RSRP (Reference Signal Receiving Power): is the average power of all resource elements which carry cell-specified reference signals over the entire bandwidth.
  • RSRQ (Reference Signal Receiving Quality): measures the signal strength and is calculated based on both RSRP and RSSI.
  • RSSI (Received Signal Strength Indicator): parameter which provides information about total received wide-band power (measure in all symbols) including all interference and thermal noise. Please refer to the Device Description for details.
  • SINR (Signal to Interference plus Noise Ratio): is also a measure of signal quality as well. It is widely used by the operators as it provides a clear relationship between RF conditions and throughput.

NOTE: Some LTE modules do not provide this information.

Network Name: The name of the LTE network the router is connecting to.

Cell ID: The ID of base station that the device is connected to.

Physical Cell ID: Display the actual PCI (Physical Cell ID) that device is attached and to transfer the data.

Card IMEI: The unique identification number that is used to identify the 3G/4G-LTE module.

Card IMSI: The international mobile subscriber identity used to uniquely identify the 3G/4G-LTE

module.

Network Mode / Band: Show the using network mode and LTE band.

Usage Allowance
Usage Allowance Amount used 0Hours of 720Hours Billing period Day:15 Clean Save

Amount Used: Display the amount of mobile data used and remaining in current billing cycle.

Billing Cycle: Display the start date and number of days remaining in current billing cycle

Clean: Reset current saved mobile usage

Save: Click to save current mobile status to ROM

Refresh: Click to refresh the page.

Statistics

4G/LTE

Take 4G/LTE as an example to describe the following connection transmission information.

Statistics
Traffic Statistics
Interface3G/4G-LTE Status EWAN(LAN1) Ethernet
Transmit Statistics
Transmit Frames of Current Connection0
Transmit Bytes of Current Connection0
Transmit Total Frames0
Transmit Total Bytes0
Receive Statistics
Receive Frames of Current Connection0
Receive Bytes of Current Connection0
Receive Total Frames0
Receive Total Bytes0
Refresh

Traffic Statistics

Interface: List all available network interfaces in the router. You are currently checking on the physical status of 3G or 4G/LTE interface.

Transmit Statistics

Transmit Frames of Current Connection: Display the total number of 3G/4G/LTE frames transmitted until the latest second for the current connection.

Transmit Bytes of Current Connection: Display the total bytes transmitted till the latest second for the current connection for the current connection.

Transmit Total Frames: Display the total number of frames transmitted till the latest second since system is up.

Transmit Total Bytes: Display the total number of bytes transmitted until the latest second since system is up.

Receive Statistics

Receive Frames of Current Connection: Display the number of frames received until the latest second for the current connection.

Receive Bytes of Current Connection: Display the total bytes received till the latest second for the current connection.

Receive Total Frames: Display the total number of frames received until the latest second since system is up.

Receive Total Bytes: Display the total frames received till the latest second since system is up.

Refresh: Click to refresh the page.

EWAN (LAN1)

Statistics
Traffic Statistics
Interface3G/4G-LTE Status EWAN(LAN1) Ethernet
Transmit Statistics
Transmit Frames0
Transmit Multicast Frames0
Transmit Total Bytes0
Transmit Collision0
Transmit Error Frames0
Receive Statistics
Receive Frames0
Receive Multicast Frame0
Receive Total Bytes0
Receive CRC Errors0
Receive Under-size Frames0
Refresh

Traffic Statistics

Interface: List all available network interfaces in the router. You are currently checking on the physical status of the EWAN (Ethernet #1) port.

Transmit Statistics

Transmit Frames: Display the number of frames transmitted until the latest second.

Transmit Multicast Frames: Display the number of multicast frames transmitted until the latest second.

Transmit Total Bytes: Display the number of bytes transmitted until the latest second.

Transmit Collision: Numbers of collisions have occurred on this port.

Transmit Error Frames: Display the number of error packets on this port.

Receive Statistics

Receive Frames: Display the number of frames received until the latest second.

Receive Multicast Frames: Display the number of multicast frames received until the latest second.

Receive Total Bytes: Display the number of bytes received until the latest second.

Receive CRC Errors: Display the number of error packets on this port.

Receive Under-size Frames: Display the number of under-size frames received until the latest second.

Refresh: Click to refresh the page.

Ethernet

Statistics
Traffic Statistics
Interface○ 3G/4G-LTE Status ● EWAN(LAN1) ○ Ethernet
Transmit Statistics
Transmit Frames0
Transmit Multicast Frames0
Transmit Total Bytes0
Transmit Collision0
Transmit Error Frames0
Receive Statistics
Receive Frames0
Receive Multicast Frame0
Receive Total Bytes0
Receive CRC Errors0
Receive Under-size Frames0
Refresh

Traffic Statistics

Interface: List all available network interfaces in the router. You are currently checking on the physical status of the Ethernet port.

Transmit Statistics

Transmit Frames: Display the number of frames transmitted until the latest second.

Transmit Multicast Frames: Display the number of multicast frames transmitted until the latest second.

Transmit Total Bytes: Display the number of bytes transmitted until the latest second.

Transmit Collision: Numbers of collisions have occurred on this port.

Transmit Error Frames: Display the number of error packets on this port.

Receive Statistics

Receive Frames: Display the number of frames received until the latest second.

Receive Multicast Frames: Display the number of multicast frames received until the latest second.

Receive Total Bytes: Display the number of bytes received until the latest second.

Receive CRC Errors: Display the number of error packets on this port.

Receive Under-size Frames: Display the number of under-size frames received until the latest second.

Refresh: Click to refresh the page.

DHCP Table

DHCP table displays the devices connected to the router with clear information.

DHCP Table
IndexHost NameIP AddressMAC AddressExpire Time
1Billion-HC-ee192.168.1.10100:C0:9F:D1:E1:CA0days 23:36:1

Index #: The numeric indicator for devices using dynamic IP addresses.

Host Name: Display the hostname of the PC.

IP Address: The IP allocated to the device.

MAC Address: The MAC of the connected device.

Expire Time: The total remaining interval since the IP assignment to the PC.

IPSec Status

IPSec Status Index Action Connection Name Active Connection State Statistics Remote Gateway Remote Network Local Network 0 Connect H-to-B Yes Phase1 Established 191408/43308 69.121.1.30 192.168.0.0/24 192.168.1.0/24 Drop Refresh

Index #: The numeric IPSec VPN tunnel/ rule.

Action: Display Connect or Drop the connection.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Connection State: Display statuses of IPSec phase 1 and phase 2 connections.

Statistics: Display upstream/downstream traffic per session in KB. The value clears when session disconnects.

Remote Gateway: Display remote gateway IP address.

Remote Network: Display remote local IP address and Netmask.

Local Network: Display local IP address and Netmask.

Refresh: Click to refresh the page.

PPTP Status

PPTP Server

PPTP Server
IndexConnection NameActiveConnection StateConnection TypeAssigned IP AddressRemote Network
1HS-LLYesYesLan to Lan192.168.1.2192.168.0.0 / 255.255.255.0
PPTP Client
IndexConnection NameActiveConnection StateConnection TypeServer IP AddressRemote Network
Refresh

Index #: The numeric PPTP VPN tunnel/ rule.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Connection State: Display the VPN connection status.

Connection Type: Display if VPN connection is for single PC use (Remote Access) or multi-user use (LAN to LAN).

Assigned IP Address: Display the IP address assigned to the client by the PPTP Server.

Remote Network: Display the remote network and subnet mask in LAN to LAN PPTP connection.

Refresh: Click to refresh the page.

PPTP Client

PPTP Server
IndexConnection NameActiveConnection StateConnection TypeAssigned IP AddressRemote Network
PPTP Client
IndexConnection NameActiveConnection StateConnection TypeServer IP AddressRemote Network
1BC-LLYesYesLan to Lan69.121.1.33192.168.1.0 / 255.255.255.0
Refresh

Index #: The numeric PPTP VPN tunnel/ rule.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Connection State: Display Yes/No to indicate the VPN connection status.

Connection Type: Display if VPN connection is for single PC use (Remote Access) or multi-user use (LAN to LAN).

Server IP Address: Display the WAN IP address of remote PPTP Server.

Remote Network: Display the remote network address and subnet mask in LAN to LAN PPTP connection.

Refresh: Click to refresh the page.

L2TP Status

IndexConnection NameActiveConnection StateConnection ModeConnection TypeTunnel Remote IP Address
1HS-LLYesConnectedDial inLan to Lan192.168.1.200
Refresh

Index #: The numeric L2TP VPN tunnel/rule indicator.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Connection State: Display Yes/No to indicate the VPN connection status.

Connection Mode: Display if L2TP mode is a dial-in or dial-out.

Connection Type: Display if VPN connection is for single PC use (Remote Access) or multi-user use (LAN to LAN).

Tunnel Remote IP Address: Display the remote tunnel IP address.

Refresh: Click to refresh the page.

GRE Status

GRE Status
IndexConnection NameActiveConnection StateRemote Gateway IPRemote Network
1GRE-0YesConnected69.121.1.30192.168.0.0/255.255.255.0

Index #: The numerical GRE tunnel/rule indication.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Connection State: Display Yes/No to indicate the VPN connection status.

Remote Gateway IP: Display the remote gateway IP address.

Remote Network: Display the remote local network IP address / Netmask.

OpenVPN Status

OpenVPN Server

OpenVPN Status
OpenVPN Server
IndexConnection NameActiveService PortTunnel NetworkStatus
1OpenVPN1Yes1194 /udp192.168.100.0/255.255.255.0Ready
OpenVPN Client
IndexConnection NameActiveRemote ServerStatusDetail Info
Refresh

Index #: The numeric OpenVPN tunnel/ rule.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Service Port: Display the port/protocol (1194/udp) used for OpenVPN connection.

Tunnel Network: Display the virtual tunnel IP address and Netmask of the OpenVPN server.

Status: Display the status of the profile/rule

Refresh: Click to refresh the page.

OpenVPN Client

OpenVPN Status
OpenVPN Server
IndexConnection NameActiveService PortTunnel NetworkStatus
OpenVPN Client
IndexConnection NameActiveRemote ServerStatusDetail Info
1OpenVPN1Yes69.121.10.5:1194 /udpConnectedAssigned IP: 192.168.100.2Route: 192.168.100.0/255.255.255.0192.168.5.0/255.255.255.0
Refresh

Index #: The numeric OpenVPN tunnel/ rule.

Connection Name: The profile name of the VPN connection/tunnel.

Active: Display Yes or No to indicate the profile is enabled or disabled.

Remote Server: Display the remote server public IP address and used port/protocol for this connection.

Status: Display the status of the profile/rule

Detailed Info: Display detailed IP assignment and routing information of this VPN connection.

Refresh: Click to refresh the page.

ARP Table

ARP (Address Resolution Protocol) table displays a mapping IP address with a PC's MAC address.

#IPMAC Address
1192.168.1.11f0:de:f1:31:68:77

: The numeric table list indicator.

IP Address: It is the internal/local IP address to access to the network.

MAC Address: The MAC address of a device, e.g. PC, notebook, printer, etc., that is corresponded with the IP address.

VRRP Status

VRRP Status
Current StatusN/A
Current MasterN/A

Current Status: Display current VRRP status, Master or Backup.

Current Master: Display the IP address of the Master

Quick Start

This is a useful and easy utility to help you to setup the router quickly and to connect to your ISP (Internet Service Provider) with only a few steps. It will guide you step by step to setup password, time zone, and WAN settings of your device. The Quick Start Wizard is a helpful guide for the first-time users to the device.

Quick Start The 'Quick Start' wizard will guide you to configure the device to connect to your ISP(Internet Service Provider). Please follow the 'Quick Start' wizard step by step to configure the device. It will allow you to have Internet access within minutes. Run Wizard

For detailed instructions on configuring WAN settings, see refer to the Interface Setup section.

Quick Start The Wizard will guide you through these five quick steps. Begin by clicking on NEXT. Step 1. Set your new password Step 2. Choose your time zone Step 3. Set your internet connection Step 4. Confirm the configuration and save it Next

Click NEXT to move on to Step 1.

Step 1 – Password

Set new password of the "admin" account to access for router management. The default is "admin". Once changed, please use this new password next time when accessing to the router. Click NEXT to continue.

Quick Start - Password You may change the admin account password by entering in a new password. Click NEXT to continue. New Password Confirm Password Back Next

Step 2 – Time Zone

Choose your time zone. Click NEXT to continue.

Quick Start - Time Zone Select the appropriate time zone for your location and click NEXT to continue. Time Zone (GMT-06:00) Central Time (US & Canada), Maxico City, Saskatchewan ▼ Back Next

Step 3 – ISP Connection Type

Set up your Internet connection.

3.1 Select an appropriate WAN connection protocol then click NEXT to continue.

Quick Start - ISP Connection Type Select the WAN Interface and Internet Connection Type to connect to your ISP. Click NEXT to continue. WAN Interface 4G/LTE Back Next

3.2(1) If selected 4G/LTE

Input all relevant 3G/4G/LTE parameters from your cellular provider.

Click Next to continue.

Quick Start - 4G/LTE Enter the 3G information provided to you by your ISP. Click NEXT to continue. TEL No. *99***1# APN internet PDN Type IPv4 IPv4/IPv6 IPv6 Authentication Protocol Disable ▼ Username Password PIN **** Keep Alive Yes No MTU 1428 (0 means use default:1500) Back Next

3.2(2) If selected EWAN (LAN1) / Static IP or PPPoE, enter the static IP address or PPPoE account information provided by your ISP.

Click NEXT to continue.

Quick Start - ISP Connection Type Select the WAN Interface and Internet Connection Type to connect to your ISP. Click NEXT to continue. WAN Interface EWAN(LAN1) ISP Dynamic IP Address ( Select the WAN Interface and Internet Connection Type to connect to your ISP. Click NEXT to continue. ) Static IP…

Step 4 – Quick Start Completed

The Setup Wizard has completed. Click on BACK to make changes or correct mistakes. Click NEXT to save the current settings and complete the Quick Start setups.

Quick Start - Quick Start Completed Quick Start Completed!! The Setup Wizard has completed. Click on BACK to modify changes or mistakes. Click NEXT to exit the Setup Wizard. Back Next

▼Quick Start - Quick Start Completed !!

Quick Start Completed!!

Saved Changes.

Go back to the Status > Device Info to view the status.

Device Configuration

Interface Setup

Here are the features under Interface Setup: Internet, LAN and Loopback

Internet

4G/LTE

Internet WAN Interface 4G/LTE Status ● Activated ○ Deactivated Usage Allowance► □ Enable IP Pass-Through Mode □ Enable LTE Antenna Diversity ► Enabled Network Mode Automatic PLMN Selection Operator Numeric RAT Scan TEL No. *99***1# Dual APN Single APN APN internet PDN Type ● IPv4 ○ IPv4/IPv6 ○ IPv6…

WAN Interface: List all available WAN interfaces. (In this section, you have selected to use 4G/LTE)

Status: Choose Activated to enable the 4G/LTE connection.

Usage Allowance: Enable and click "Usage Allowance" for further setting configuration of your 4G/LTE data usage.

Usage Allowance

Usage Allowance (Cont.)

Usage Allowance Parameters Volume-based Only Downlod MB data volume per month included Mode Time-based 720 hours per month included The billing period always begins on day1 of a month. Over usage allowance action None Save the statistics to ROM Disable Save Back

Mode: Include Volume-based and Time-based control.

Volume-based include "only Download", "only Upload", and "Download and Upload" to limit the flow.
Time-based control the flow by providing specific hours per month.

The billing period begins on: the beginning day of billing each month.

Over usage allowance action: Here are actions to perform when mobile data usage, defined in Mode, reached to its maximum.

▶ None: No action taken
▶ Disconnect: Disconnect mobile connection
▶ Email Alert: Send an e-mail alert and keep the mobile connection alive.

- Email Alert and Disconnect: Disconnect mobile connection after an alert e-mail is being sent.

Save the statistics to ROM:

- Every one hour: Activate the 3G/4G-LTE statistics on data usage and this info will get updated and saved to the internal memory (ROM) in every hour.

Once the feature is turned on, you can see the amount of data used and how many days left before next billing cycle starts. Go to Status >> 3G/4G-LTE Status page for details.

Usage Allowance Amount used 0Hours of 720Hours Billing period Day:15 Clean Save

NOTE: This statistic information will get deleted after a factory reset.

▶ Disable: No action taken

LTE Mode*: Display current selected LTE frequency band. To change the band, please click "LTE Mode" link to access to the band selection page.

LTE Band

LTE Band: A list of available LTE bands to choose from.

LTE Mode Parameters LTE Band B12 ***Please save config and restart to activate the setting. Please make sure device had get WAN IP, then config this feature. Apply Save Config & Restart

LTE Antenna Diversity *: When enabled, the auxiliary antenna will be activated. With disabled, only the primary antenna is receiving and transmitting data. To change it, please click “LTE Antenna Diversity” link to access to the selection page.

LTE Antenna Diversity

To enable or disable the LTE antenna diversity feature.

LTE Mode Parameters LTE Antenna Diversity ***Please save config and restart to activate the setting. Please make sure device had get WAN IP, then config this feature. Apply Save Config & Restart

* Feature is available with specific cellular module

IP Pass-through Mode: When enabled, MX-200A ODU is in bridge mode that it does not obtain a WAN IP address; features such as routing capabilities, NAT, firewall, etc., are being disabled. The client router that is behind the MX-200A ODU now obtains a WAN IP address. When disabled, MX-200A ODU is in router mode that it handles a WAN IP address and all features become available.

Network Mode: There are 8 options of service standards: "Automatic", "UMTS 3G only", "GSM 2G Only", "UMTS 3G Preferred", "GSM 2G Preferred", "GSM and UMTS Only", "LTE Only", and "GSM, UMTS, LTE". If you are not sure which mode to use, you may select Automatic to auto detect the best mode for you.

PLMN (Public Land Mobile Network) Selection: Either manually enter the information or click Scan button to scanning all closest base stations in the area.TEL No.: The dial string to make a GPRS / 3G/4G-LTE user internetworking call. It may provide by your mobile service provider.

Dual APN*: Unit can support up to two (2) APNs. Select Single / Dual or a different LTE/3G APN.

APN (3G): If select LTE/3G with different APN, enter the APN here.

* Feature is available with specific cellular module

APN: An APN is similar to a URL on the WWW, it is what the unit makes a GPRS / UMTS call. The service provider is able to attach anything to an APN to create a data connection, requirements for APNs varies between different service providers. Most service providers have an internet portal which they use to connect to a DHCP Server, thus giving you access to the internet i.e. some 3G operators use the APN 'internet' for their portal. The default value is "internet".

PDN Type: The IP type for PDN connections. Available types are IPv4, IPv6, and IPv4v6.

Authentication Protocol: Manually specify CHAP (Challenge Handshake Authentication Protocol) or PAP (Password Authentication Protocol). When using PAP, the password is sent unencrypted, while CHAP encrypts the password before sending, and also allows for challenges at different periods to ensure that an intruder has not replaced the client.

Username/Password: Enter the username and password provided by your service provider. The username and password are case sensitive.

PIN: PIN stands for Personal Identification Number. A PIN code is a numeric value used in certain systems as a password to gain access, and authenticate. In mobile phones a PIN code locks the SIM

card until you enter the correct code. If you enter the PIN code incorrectly into the phone 3 times in a row, then the SIM card will be blocked and you will require a PUK code from your network/service provider.

Connection: Default set to Always on to keep an always-on 3G/4G-LTE connection.

Keep Alive / IP: Select Yes to keep the 3G/4G-LTE connection always on. Manually enter the Keep Alive IP Address to be used for ping operation to check if the connection is still on.

Default Route: Select Yes to use this interface as default route interface.

NAT: Select this option to Disabled/Enable the NAT (Network Address Translation) function. Enable NAT to grant multiples devices in LAN to access to the Internet through a single WAN IP.

When router's Internet configuration is finished successfully, you can go to the Status to check connection information.

MTU: Maximum Transmission Unit. The size of the largest datagram (excluding media-specific headers) an IP attempts to send through the interface. 0 means to use default MTU size, 1500byte.

Click Save to apply settings.

EWAN (LAN 1)

Internet
WAN InterfaceEWAN(LAN1)✓
Status○ Activated ● Deactivated
IPv4/IPv6
IP Version○ IPv4 ● IPv4/IPv6 ○ IPv6
ISP Connection Type
ISP○ Dynamic IP Address ○ Static IP Address ● PPPoE
802.1q Options
802.1q○ Activated ● Deactivated
VLAN ID0 (range: 0~4095)
PPPoE
Username
Password
Bridge Interface for PPPoE○ Activated ● Deactivated
Connection Setting
Connection● Always On (Recommended) ○ Connect Manually
TCP MSS OptionTCP MSS 0 bytes(0 means use default)
IP Options
IP Common Options
Default Route● Yes ○ No
TCP MTU OptionTCP MTU 0 bytes(0 means use default:1492)
IPv4 Options
Get IP Address○ Static ● Dynamic
Static IP Address0.0.0.0
IP Subnet Mask0.0.0.0
Gateway0.0.0.0
NATEnable✓
Dynamic RouteRIP1 ✓ Direction None ✓
IGMP Proxy○ Enable ● Disable
IPv6 Options
IPv6 Address
Obtain IPv6 DNS● Enable ○ Disable
Primary DNS
Secondary DNS
MLD Proxy○ Enable ● Disable

Status: Select to enable/activate or disable/deactivated the service.

IPv4/IPv6

IP Version: Choose IPv4, IPv4/IPv6, IPv6 based on your environment. If you don't know which one to choose from, please choose IPv4/IPv6 instead.

ISP Connection Type:

ISP: Select the encapsulation type your ISP uses.

▶ Dynamic IP: Select this option if your ISP provides you an IP address automatically.
▶ Static IP: Select this option to set static IP information. You will need to enter in the Connection type, IP address, subnet mask, and gateway address, provided to you by your ISP. Each IP address entered in the fields must be in the appropriate IP form. IP address from by four IP octets separated by a dot (xx.xx.xx.xx). The Router will not accept the IP address if it is not in this format.
▶ PPPoE: Select this option if your ISP requires you to use a PPPoE connection.
Bridge: Select this mode if you want to use this device as an OSI Layer 2 device like a switch.

802.1q Options

802.1q: When activated, please enter a VLAN ID.

VLAN ID: It is a parameter to specify the VLAN which the frame belongs. Enter the VLAN ID identification, tagged: 0-4095.

PPPoE (If selected PPPoE as WAN Connection Type; otherwise, skip this part)

Username: Enter the user name provided by your ISP.

Password: Enter the password provided by your ISP.

Bridge Interface for PPPoE: When “Activated”, the device will gain WAN IP from your ISP with the PPPoE account. But if your PC is connected to the router working as a DHCP client, in this mode, the device acts as a NAT router; while if you dial up with the account within your PC, the device will then work as a bridge forwarding the PPPoE information to the PPPoE server and send the response to your PC, thus your PC gets a WAN IP working in the internet.

Connection Setting

Connection:

▶ Always On: Click on Always On to establish a PPPoE session during start up and to automatically re-establish the PPPoE session when disconnected by the ISP.
- Connect Manually: Select Connect Manually when you don't want the connection up all the time.

TCP MSS Option: Enter the maximum size of the data that TCP can send in a segment. Maximum Segment Size (MSS).

IP Options

IP Options IP Common Options Default Route Yes No TCP MTU Option TCP MTU 0 bytes(0 means use default:1492) IPv4 Options Get IP Address Static Dynamic Static IP Address 0.0.0.0 IP Subnet Mask 0.0.0.0 Gateway 0.0.0.0 NAT Enable ▼ Dynamic Route RIP1 Direction None ▼ IGMP Proxy Enable Disable IPv6 Optio…

IP Common Options

Default Route: Select Yes to use this interface as default route interface.

TCP MTU Option: Enter the maximum packet that can be transmitted. Default MTU 0 means it is set to 1492 bytes.

IPv4 Options

Get IP Address: Choose Static or Dynamic

Static IP Address: If Static is selected in the above field, please enter the specific IP address you get from ISP and the following IP subnet mask and gateway address.

IP Subnet Mask: The default is 0.0.0.0. User can change it to other such as 255.255.255.0. Type the subnet mask assigned to you by your ISP (if given).

Gateway: Enter the specific gateway IP address you get from ISP.

NAT: Enable to allow MX-200A ODU to assign private network IPs to all devices in the network for get Internet access.

Dynamic Route:

▶ RIP Version: (Routing Information protocol) Select this option to specify the RIP version, including RIP-1, RIP-2.
▶ RIP Direction: Select this option to specify the RIP direction.

  • None is for disabling the RIP function.
  • Both means the router will periodically send routing information and accept routing information then incorporate into routing table.
  • IN only means the router will only accept but will not send RIP packet.
  • OUT only means the router will only send but will not accept RIP packet.

IGMP Proxy: IGMP (Internet Group Multicast Protocol) is a network-layer protocol used to establish membership in a Multicast group. Choose whether enable IGMP proxy.

IPv6 options (only when choose IPv4/IPv6 or just IPv6 in IP version field above):

IPv6 Address: Type the WAN IPv6 address from your ISP.

Obtain IPv6 DNS: Choose if you want to obtain DNS automatically.

Primary/Secondary: if you choose Disable in the Obtain IPv6 DNS field, please type the exactly primary and secondary DNS.

MLD Proxy: MLD (Multicast Listener Discovery Protocol) is to IPv6 just as IGMP to IPv4. It is a Multicast Management protocol for IPv6 multicast packets.

When router's Internet configuration is finished successfully, you can go to status to get the connection information.

Click Save to apply settings.

LAN

A Local Area Network (LAN) is a shared communication system to which many computers are attached and is limited to the immediate area, usually the same building or floor of a building.

LAN IPv4 Parameters IP Address 192.168.1.254 IP Subnet Mask 255.255.255.0 Alias IP Address 0.0.0.0 (0.0.0.0 means to close the alias ip) Alias IP Subnet Mask 0.0.0.0 Snooping ○ Activated ● Deactivated Dynamic Route RIP1 √ Direction None √ DHCPv4 Server DHCPv4 Server ○ Disabled ● Enabled ○ Relay Star…

Fixed Host List
IndexIPMACDrop

IPv4 Parameters

IP Address: Enter the IP address of Router in dotted decimal notation, for example, 192.168.1.254 (factory default).

IP Subnet Mask: The default is 255.255.255.0. User can change it to other such as 255.255.255.128.

Alias IP Address: This is for local networks virtual IP interface. Specify an IP address on this virtual interface.

Alias IP Subnet Mask: Specify a subnet mask on this virtual interface.

IGMP Snooping: Select Activated to enable IGMP Snooping function. Without the IGMP snooping, multicast traffic is treated in the same manner as broadcast traffic to be forwarded to all ports. With IGMP snooping, multicast traffic of a group is only forwarded to ports that have members of that group.

Dynamic Route: Select the RIP version from RIP1 or RIP2.

DHCPv4 Server

DHCP (Dynamic Host Configuration Protocol) allows individual clients to obtain TCP/IP configuration at start-up from a server.

DHCPv4 Server Disabled Enabled Relay Start IP 192 168.1.100 IP Pool Count 100 Lease Time 86400 seconds (0 sets to default value of 259200) Physical Ports ✓ LAN1 ✓ LAN2 DNS Relay ● Automatically ○ Manually Primary DNS Secondary DNS Option 66 Option 160

DHCPv4 Server: If set to Enabled, your MX-200A ODU can assign IP addresses, default gateway and DNS servers to the DHCP client.

▶ If set to Disabled, the DHCP server will be disabled.
If set to Relay, the MX-200A ODU acts as a surrogate DHCP server and relays DHCP requests and responses between the remote server and the clients. Enter the IP address of the actual, remote DHCP server in the Remote DHCP Server field in this case.
- When DHCP is used, the following items need to be set.

Start IP: This field specifies the first of the contiguous addresses in the IP address pool.

IP Pool Count: This field specifies the count of the IP address pool.

Lease Time: The current lease time of client.

Physical Ports: Select to determine if the DHCPv4 server is applicable to the specific port or ports. By default, all ports can obtain local IP from the DHCPv4 server.

DNS Relay:

▶ Select Automatic detection or
▶ Manually specific Primary and Secondary DNS IP addresses

Primary / Secondary DNS Server: Enter the IP addresses of the DNS servers. The DNS servers are passed to the DHCP clients along with the IP address and the subnet mask.

Option 66: Set the IP or hostname of the TFTP server for devices, like IPTV Set Box, to get configuration settings from the TFTP server.

Option 160: Set the IP or hostname of the TFTP server for devices, like IPTV Set Box, to get configuration settings from the TFTP server. (The option 160 is an extended feature in DHCP option, similar to option 66, but using http or https protocols.)

Fixed Host

In this field, users can map the specific IP (must in the DHCP IP pool) for some specific MAC, and this information can be listed in the following table.

Fixed Host IP Address MAC Address

IP Address: Enter the specific IP. For example: 192.168.1.110.

MAC Address: Enter the responding MAC. For example: 00:0A:F7:45:6D:ED

When added, you can see the ones listed as showed below:

Fixed Host Listing
IndexIP AddressMAC AddressDelete
1192.168.1.11000:04:ED:01:01:10

IPv6 Parameters

The IPv6 address composes of two parts, thus, the prefix and the interface ID.

Interface Address/Prefix Length /

Interface Address / Prefix Length: Enter a static LAN IPv6 address. If you are not sure what to do with this field, please leave it empty as if contains false information it could result in LAN devices not being able to access other IPv6 device. Router will take the same WAN's prefix to LAN side if the field is empty.

DHCPv6 Server

DHCPv6 Server Disable Enable DHCPv6 Server Type ● Stateless ○ Stateful Start Interface ID End Interface ID Lease Time seconds(0 sets to default value of 4800) Router Advertisements ○ Disable ● Enable

There are two methods to dynamically configure IPv6 address on hosts, Stateless and Stateful.

Stateless auto-configuration requires no manual configuration of hosts, minimal (if any) configuration of routers, and no additional servers. The stateless mechanism allows a host to generate its own addresses using a combination of locally available information (MAC address) and information (prefix) advertised by routers. Routers advertise prefixes that identify the subnet(s) associated with a link, while hosts generate an "interface identifier" that uniquely identifies an interface on a subnet. An address is formed by combining the two. When using stateless configuration, you needn't configure anything on the client.

Stateful configuration, for example using DHCPv6 (which resembles its counterpart DHCP in IPv4.) In the stateful auto configuration model, hosts obtain interface addresses and/or configuration information and parameters from a DHCPv6 server. The Server maintains a database that keeps track of which addresses have been assigned to which hosts.

DHCPv6 Server: Check whether to enable DHCPv6 server.

DHCPv6 Server Type: Select Stateless or Stateful. When DHCPv6 is enabled, this parameter is

available.

▶ Stateless: If selected, the PCs in LAN are configured through RA mode, thus, the PCs in LAN are configured through RA mode, to obtain the prefix message and generate an address using a combination of locally available information (MAC address) and information (prefix) advertised by routers, but they can obtain such information like DNS from DHCPv6 Server.
▶ Stateful: If selected, the PCs in LAN will be configured like in IPv4 mode, thus obtain addresses and DNS information from DHCPv6 server.

Start interface ID: enter the start interface ID. The IPv6 address composed of two parts, thus, the prefix and the interface ID. Interface is like the Host ID compared to IPv4.

End interface ID: enter the end interface ID.

Leased Time (seconds): the leased time, similar to leased time in DHCPv4, is a time limit assigned to clients, when expires, the assigned ID will be recycled and reassigned.

Router Advertisement: Check to Enable or Disable the Issue Router Advertisement feature. This feature is to send Router Advertisement messages periodically which would multicast the IPv6 Prefix information (similar to v4 network number 192.168.1.0) to all LAN devices if the field is enabled. We suggest enabling this field.

Click Save to apply settings.

Loopback

Loopback interface is a widely known virtual interface, not the physical interface, on router and is highly robust and always up. The loopback interface has its own IP and subnet mask, often used for router management as Telnet management IP and involved in BGP as BGP Update-Source and OSPF as Router ID.

Loopback Loopback interface ○ Activated ● Deactivated IP Address 127.0.0.1 IP Subnet Mask 255.0.0.0 Save

IP Address: Enter a dedicated IP address for the loopback interface.

IP Subnet Mask: Enter the subnet mask for the loopback interface.

Click Save to apply settings.

Dual WAN

Dual WAN, is a feature to have two independent Internet connection connected concurrently, offers a reliable Internet connectivity and maximize bandwidth utilization for critical applications delivery.

General Setting

BEC TECHNOLOGIES 4G LTE M2M Router Status Quick Start Configuration Interface Setup Dual WAN General Setting Outbound Load Balance Protocol Binding Advanced Setup VPN Access Management Maintenance Configuration General Setting Dual WAN Mode Mode Disable Save Copyright @ BEC Technologies Inc All righ…

Mode: Select a mode then click Save to proceed.

Failover & Failback

Auto failover/failback ensures always-online network connectivity. When primary WAN link (WAN1) fails, all traffic will switch over to the backup WAN (WAN2) seamlessly.

Again, when the primary link is restored, traffic will be handled over from WAN2 to WAN1.

General Setting Dual WAN Mode Mode Failover & Failback WAN Port Service Detection Policy WAN1 4G/LTE WAN2 EWAN(LAN1) Keep Backup Interface Connected Disable Minimun RSRP/RSSI -105 / -90 dbm(-111~ -5 , 0:disable) Connectivity Decision Auto failover takes place after straight 3 consecutive failure in…

WAN Port Service Detection Policy

WAN1 (Primary): Choose a desired WAN as the primary WAN Link from the list.

WAN2 (Backup): Choose a desired WAN as the backup WAN Link from the list.

Keep Backup Interface Connected: Select the following option whether to keep the backup WAN (WAN2) interface connected to the Internet.

▶ Disable: Inactivate this feature.
▶ Always: Keep the backup WAN (WAN2) interface always connected to the Internet
By Signal Strength: Enable and initiate automatic backup WAN to connect to the Internet at all time until the RSRP / RSSI of primary WAN is greater than the Minimum RSRP / RSSI.
■ Minimum RSRP / RSSI: Set a minimum requirement for RSRP and RSSI for the primary WAN. Value range from -111 \~ -5. 0 means don't care/no need to check this value.

NOTE: Both the RSRP and RSSI cannot be 0 at the same time.

Connectivity Decision & Probe Cycle: Set a number of times and time in seconds to determine when to switch to the backup link (WAN2) when primary link (WAN1) fails and vice versa.

Example, Auto failover takes place after straight 3 consecutive failures in every 30 seconds meaning all traffic will hand over to backup link (WAN2) after primary link fails to response in total of 90 seconds, 30 seconds for 3 consecutive failures.

Note: Failover and Failback follow the same Connectivity Decision & Probe Cycle rule to failover from WAN1 to WAN2 or fallback from WAN2 to WAN1.

Failover/Fallback Rule Decisions:

  1. Probe by Ping: Enable Ping to the gateway or an IP address

▶ Gateway: Internal system will wait for responses to the pings from the gateway of the WAN.
▶ Host: Internal system will wait for responses to the pings from a fixed IP address.

  1. Probe by Signal Strength: Enable to measure the LTE signal strength

▶ Minimum RSRP / RSSI: Set a minimum requirement for RSRP and RSSI for initiating automatic WAN failback or failover procedures.

The valid range is from -111 \~ -5. 0 means don't care/no need to check this value.

NOTE: Both the RSRP and RSSI cannot be 0 at the same time.

Click Save to apply settings.

Load Balance

Load balance aggregates the bandwidth of the two WAN links to optimize traffic distribution.

When primary link, WAN1, goes down, all traffic will be redirected to the backup, WAN2, to ensure service continuity.

General Setting Dual WAN Mode ModeLoad Balance WAN Port Service Detection Policy WAN14G/LTE WAN2EWAN(LAN1) Service Detection● Enable ○ Disable Connectivity DecisionAuto failover takes place after straight 3 consecutive failure in every 30 seconds. Probe WAN1○ Gateway ● Host 8.8.8.8 Timeout 3 √ secon…

WAN Port Service Detection Policy

WAN1 (Primary): Choose a desired WAN as the primary WAN Link from the list.

WAN2 (Backup): Choose a desired WAN as the backup WAN Link from the list.

Service Detection: Enable to detect WAN connectivity automatically.

Connectivity Decision & Probe Cycle: Set a number of times and time in seconds to determine when to turn-off the Load Balancing service.

Example, Disable Load Balance after straight 3 consecutive failures in every 30 seconds meaning all traffic will hand over to backup link (WAN2) after primary link fails to response in total of 90 seconds, 30 seconds for 3 consecutive failures.

Deactivate Load Balance Decision:

Probe Ping on WAN 1 / WAN2: Enable Ping to the gateway or an IP address

▶ Gateway: Internal system will wait for responses to the pings from the gateway of the WAN.
▶ Host: Internal system will wait for responses to the pings from a fixed IP address.

Click Save to apply settings

Outbound Load Balance

The connections are distributed over WAN1 and WAN2 so that it can utilize bandwidth of both WAN ports. With Outbound load balance, traffic may be routed to a faster link when one of the WAN links is slower or congested so that user gains better throughput and less delay.

Outbound Load Balance Outbound Load Balance Based on Session Mechanism Balance by Session (Round Robin) Balance by Session weight : Based on IP Hash Mechanism Balance by weight : Save

User can distribute outbound traffic based on Session Mechanism or IP Hash Mechanism.

Base on Session Mechanism:

Balance by Session (Round Robin): Automatically assign requests/traffics to each WAN interface based on real-time WAN traffic-handling capacity.

OR

Balance by Session weight: Manually Balance session traffic based on a weight ratio.

Example: Session weight by 3:1 meaning forward 3 requests to WAN1 and 1 request to WAN2.

Base on IP Hash Mechanism:

Balance by weight: Use an IP hash to balance traffic based on a ratio. It is to guarantee requests from the same IP address get forward to the same WAN interface.

Click Save to apply settings

Protocol Binding

Protocol Binding lets you direct specific traffic to go out from a specific WAN port. Policies determine how specific types of internet traffic are routed, for example, traffic from a specific IP address is granted access to only one WAN port rather than using both of the WAN ports as with load balancing.

Rule Index1✓
Active●Yes ○ No
Bind InterfaceWAN1 ✓ (Current WAN1 Mode: 4G/LTE, Current WAN2 Mode: EWAN)
Source IP Address0.0.0.0(0.0.0.0 means Don't care)
Subnet Mask0.0.0.0
Port Number0(0 means Don't care)
Destination IP Address0.0.0.0(0.0.0.0 means Don't care)
Subnet Mask0.0.0.0
Port Number0(0 means Don't care)
DSCP0(Value Range:0~64, 64 means Don't care)
ProtocolTCP✓
Save Delete
Protocol Binding List
#ActiveInterfaceSource IP Address/MaskDestination IP Address/MaskSource PortDestination PortDSCPProtocol

Rule Index: The numeric rule indicator. The maximum entry is up to 16.

Active: Click YES to activate the rule

Bind Interface: The dedicated WAN interface that guarantees to handle this traffic request.

Source IP Address: Enter the local network, known as source, IP address of the origin of a traffic/packet. 0.0.0.0 means any IP address in the network.

Subnet Mask: Enter the subnet of the source network.

Port Number: Enter the port number which defines the application.

Destination IP Address: Enter the destination / remote WAN IP address where the traffic/packet is going to. Enter 0.0.0.0 if no need to route to a specific IP address

Subnet Mask: Enter the subnet of the designation network.

Port Number: Enter the port number which defines the application.

DSCP: The DSCP value. Value Range from 0\~64; 64 means any value/unspecified

Protocol: Select a protocol, TCP, UDP, ICMP, to use for this traffic.

Click Save to apply settings

Example:

All traffics from IP 192.168.1.100/255.255.255.0 with port 8080 will go through WAN1 interface.

The only time it would go through WAN2 interface is when WAN1 has no Internet connection.

Protocol Binding List
#ActiveInterfaceSource IP Address/MaskDestination IP Address/MaskSource PortDestination PortDSCPProtocol
1YesWAN1192.168.1.100/255.255.255.00.0.0.0/0.0.0.0808000TCP

Advanced Setup

Advanced configuration features provides advanced features, including Firewall, Routing, Dynamic Routing, NAT, VRRP, Static DNS, Time Schedule and Mail Alert, for advanced users.

Firewall

Your router includes a firewall for helping to prevent attacks from hackers. In addition to this, when using NAT (Network Address Translation) the router acts as a “natural” Internet firewall, since all PCs on your LAN use private IP addresses that cannot be directly accessed from the Internet.

Firewall Firewall Enabled Disabled SPI Enabled Disabled (WARNING: If You enabled SPI, all traffics initiated from WAN would be blocked, including DMZ, Virtual Server, and ACL WAN side.) Save

Firewall: To automatically detect and block Denial of Service (DoS) attacks, such as Ping of Death, SYN Flood, Port Scan and Land Attack.

▶ Enabled: Activate your firewall function.
▶ Disabled: Deactivate the firewall function.

SPI: If you enabled SPI, all traffics initiated from WAN would be blocked, including DMZ, Virtual Server, and ACL WAN side.

▶ Enabled: Activate your SPI function.
▶ Disabled: Deactivate the SPI function.

Click Save to apply settings

Routing

This is static route feature. You are equipped with the capability to control the routing of all the traffic across your network. With each routing rule created, user can specifically assign the destination where the traffic will be routed to.

IndexDestination IP AddressSubnet MaskGateway IP AddressMetricInterfaceEditDrop
0100.87.150.196255.255.255.2520.0.0.00ppp12
1100.72.1.208255.255.255.2480.0.0.00ppp11
2192.168.1.0255.255.255.00.0.0.00br0
3127.0.0.0255.255.0.00.0.0.00lo
4239.0.0.0255.0.0.00.0.0.00br0
50.0.0.00.0.0.0100.72.1.2090ppp11

Index #: The numeric route indicator.

Destination IP Address: IP address of the destination network

Subnet Mask: The subnet mask of destination network.

Gateway IP Address: IP address of the gateway or existing interface that this route uses.

Metric: It represents the cost of transmission for routing purposes. The number need not be precise, but it must be between 1 and 15.

Interface: Media/channel selected to append the route.

Edit: Edit the route; this icon is not shown for system default route.

Drop: Drop the route; this icon is not shown for system default route.

Add Route

Static Route Destination IP Address 0.0.0.0 Destination Subnet Mask 0.0.0.0 Gateway IP Address / Interface ○ 0.0.0.0 ● 4G/LTE √ Metric 1 Save Back

Destination IP Address: This is the destination subnet IP address.

Destination Subnet Mask: The subnet mask of destination network.

Gateway IP Address or Interface: This is the gateway IP address or existing interface to which packets are to be forwarded.

Metric: It represents the cost of transmission for routing purposes. The number need not be precise, but it must be between 1 and 15.

Click Save to add this route

Dynamic Routing

The NAT (Network Address Translation) feature transforms a private IP into a public IP, allowing multiple users to access the internet through a single IP account, sharing the single IP address. NAT break the originally envisioned model of IP end-to-end connectivity across the internet so NAT can cause problems where IPSec/ PPTP encryption is applied or some application layer protocols such as SIP phones are located behind a NAT. And NAT makes it difficult for systems behind a NAT to accept incoming communications.

Open Shortest Path First (OSPF)

OSPF OSPF Enable Rule Index 0 Interface EWAN(LAN1) Area ID Save Delete OSPF Listing Index Interface Area ID

OSPF: Enable to activate OSPF routing.

Rule Index: The numeric route indicator. The maximum entry is up to 10, ranging from 0 to 9.

Interface: Set the interface which runs the OSPF process (involved in OSPF routing). It can be WAN interfaces or established GRE tunnels.

Area ID: The OSPF area identifier. It is a decimal number in the range of 0-4294967295. Enter the area ID in which the interface belongs to. The area with area-id="0" is the backbone area.

If the router has networks in more than one area, then an area with area-id="0" (the backbone) must always be present. All other areas are connected to it. The backbone is responsible for distributing routing information between non-backbone areas. The backbone must be contiguous, i.e. there must be no disconnected segments. However, area border routers do not need to be physically connected to the backbone - connection to it may be simulated using a virtual link.

Border Gateway Protocol (BGP)

A standardized exterior gateway protocol (an uniquely TCP based inter-Autonomous System routing protocol) designed to allow setting up an inter-domain dynamic routing system that automatically updates routing tables of devices running BGP in case of network topology changes.

BGP BGP Enable As Number Rule Index 1 ▼ Neighbor IP Neighbor As Number Allowas-in Enable Next-Hop-Self Enable Save Delete BGP Listing Index Neighbor IP Neighbor As Number Allowas-in

BGP: Enable to activate BGP routing.

AS Number: Designate the AS number of local router. The AS number is used to identify the IBGP or EBGP your neighbor is running. The same AS number means the IBGP, and the different means EBGP.

Rule Index: The numeric route indicator. The maximum entry is up to 10, ranging from 0 to 9.

Neighbor IP: Enter the neighbor IP address.

Neighbor AS Number: Enter the neighbor AS number.

Allowas-in: Enable to allow inter-communication between devices in the same AS. If the local and neighbor AS number are the same, thus, an inter-AS communication, please enable the allowas-in. Otherwise, the router only support EBGP routing between different domains.

Next-Hop-Self: Enable to use the router's own loopback address as the next-hop address.

NAT

The NAT (Network Address Translation) feature transforms a private IP into a public IP, allowing multiple users to access the internet through a single IP account, sharing the single IP address. NAT break the originally envisioned model of IP end-to-end connectivity across the internet so NAT can cause problems where IPSec/ PPTP encryption is applied or some application layer protocols such as SIP phones are located behind a NAT. And NAT makes it difficult for systems behind a NAT to accept incoming communications.

NAT NAT Status Enable ALG VPN Passthrough Enabled Disabled SIP ALG Enabled Disabled DMZ / Virtual Server Interface 4G/LTE DMZ Edit Virtual Server Edit

NAT Status: Enabled. (Disabled if WAN connection is in BRIDGE mode)

ALG

VPN Passthrough: VPN pass-through is a feature of routers which allows VPN client on a private network to establish outbound VPNs unhindered.

SIP ALG: Enable the SIP ALG when SIP phone needs ALG to pass through the NAT. Disable the SIP ALG when SIP phone includes NAT-Traversal algorithm.

DMZ / Virtual Server

Interface: Select a WAN interface connection to allow external access to your internal network.

Service Index: Associated to EWAN interface marking each EWAN service (0-7), to select which EWAN service the DMZ and Virtual server are applied to.

Click DMZ Edit or Virtual Server Edit to move on to set the DMZ or Virtual Server parameters, which are represented in the following scenario.

DMZ

NOTE: This feature disables automatically if WAN connection is in BRIDGE mode or NAT is being turned OFF.

The DMZ Host is a local computer which has all UDP and TCP ports exposed to the Internet. When setting an internal IP address as the DMZ Host, all incoming packets will be forwarded to this local host device. Packet filter or virtual server entries will take priority over forwarding internet packets to the DMZ host.

DMZ DMZ for Single IPs Account/ EWAN(LAN1) DMZ Enabled Disabled DMZ Host IP Address 0.0.0.0 Save Back Except Ports Port Protocol TCP Description Add DMZ Export Ports Listing Index Description Protocol Port Edit Delete 1 N/A N/A N/A 2 N/A N/A N/A 3 N/A N/A N/A 4 N/A N/A N/A 5 N/A N/A N/A 6 N/A N/A N/…

DMZ for (via a WAN Interface): Allows outside network to connect in and communicate with internal LAN devices via a specific WAN interface.

DMZ:

▶ Enabled: Activate the DMZ function.
▶ Disabled: Deactivate the DMZ function.

DMZ Host IP Address: Give a static IP address to the DMZ Host when Enabled radio button is checked. Be aware that this IP will be exposed to the WAN/Internet.

Click Save to apply settings

Except Ports

Except Ports: Bypass UDP or/and TCP ports, in the list, being forwarded to the DMZ host.

Port: Enter port to be monitored.

Protocol: Enter the protocol to be monitored.

Description: Enter a description to this rule.

Example: Skip port 80 (UDP/TCP) in the list. All Incoming request to access to port 80 (Web GUI) will be forwarded to the embedded HTTP server of MX-200A ODU instead of the DMZ host.

Click Add to add an entry to the Except Listing.

Virtual Server

NOTE: This feature disables automatically if WAN connection is in BRIDGE mode or NAT is being turned OFF.

Virtual Server is also known as Port Forwarding that allows MX-200A ODU to direct incoming traffic to a specific device in the network.

Configure a virtual rule in MX-200A ODU for remote users accessing services such as Web or FTP services via the public (WAN) IP address that can be automatically redirected to local servers in the LAN network. Depending on the requested service (TCP/UDP port number), the device redirects the external service request to the appropriate server within the LAN network.

Virtual Server
RuleProtocolStart PortEnd portLocal IP AddressStart Port LocalEnd Port LocalEditDrop
0TCP2121192.168.1.1102121
1N/AN/AN/AN/AN/AN/A
2N/AN/AN/AN/AN/AN/A
3N/AN/AN/AN/AN/AN/A
4N/AN/AN/AN/AN/AN/A
5N/AN/AN/AN/AN/AN/A
6N/AN/AN/AN/AN/AN/A
7N/AN/AN/AN/AN/AN/A
8N/AN/AN/AN/AN/AN/A
9N/AN/AN/AN/AN/AN/A
10N/AN/AN/AN/AN/AN/A

Virtual Server for: Indicate the related WAN interface to allow outside network to communicate with the internal LAN device.

Protocol: Choose the application protocol.

Start / End Port Number: Enter a port or port range you want to forward.

(Example: Start / End: 1000 or Start: 1000 & End: 2000).

The starting port must be greater than zero (0). The end port must be greater than or equal to the start port.

Local IP Address: Enter the server IP address in the network to receive the traffic/packets.

Start / End Port Number (Local): Enter the start / end port number of the local application (service).

Examples of well-known and registered port numbers are shown below. For further information, please see IANA's website at http://www.iana.org/assignments/port-numbers

Well-known and Registered Ports

Port NumberProtocolDescription
21TCPFTP Control
22TCP & UDPSSH Remote Login Protocol
23TCPTelnet
25TCPSMTP (Simple Mail Transfer Protocol)
53TCP & UDPDNS (Domain Name Server)
69UDPTFTP (Trivial File Transfer Protocol)
80TCPWorld Wide Web HTTP
110TCPPOP3 (Post Office Protocol Version 3)
443TCP & UDPHTTPS
1503TCPT.120
1720TCPH.323
7070UDPRealAudio

BEC Technologies MX-200A ODU - Virtual Server - 1

Attention

Using port forwarding does have security implications, as outside users will be able to connect to PCs on your network. For this reason you are advised to use specific Virtual Server entries just for the ports your application requires, instead of using DMZ. As doing so will result in all connections from the WAN attempt to access to your public IP of the DMZ PC specified.

If you have disabled the NAT option in the WAN-ISP section, the Virtual Server function will hence be invalid.

If the DHCP server option is enabled, you have to be very careful in assigning the IP addresses of the virtual servers in order to avoid conflicts. The easiest way of configuring Virtual Servers is to manually assign static IP address to each virtual server PC, with an address that does not fall into the range of IP addresses that are to be issued by the DHCP server. You can configure the virtual server IP address manually, but it must still be in the same subnet as the router.

Example: How to setup Port Forwarding for port 21 (FTP server)

If you have a FTP server in your LAN network and want others to access it through WAN.

Step 1: Assign a static IP to your local computer that is hosting the FTP server.

Step 2: Login to the Gateway and go to Configuration / Advanced Setup / NAT / Virtual Server.

FTP server uses TCP protocol with port 21.

Enter "21" to Start and End Port Number. The MX-200A ODU will accept port 21 requests from WAN side.

Enter the static IP assigned to the local PC that is hosting the FTP server. Ex: 192.168.1.102

Enter "21" to Local Start and End Port number. The MX-200A ODU will forward port 21 request from WAN to the specific LAN PC (Example: 192.168.1.102) in the network.

Step 3: Click Save to save settings.

Virtual Server
RuleProtocolStart PortEnd portLocal IP AddressStart Port LocalEnd Port LocalEditDrop
0TCP2121192.168.1.1102121
1N/AN/AN/AN/AN/AN/A
2N/AN/AN/AN/AN/AN/A
3N/AN/AN/AN/AN/AN/A
4N/AN/AN/AN/AN/AN/A
5N/AN/AN/AN/AN/AN/A
6N/AN/AN/AN/AN/AN/A
7N/AN/AN/AN/AN/AN/A
8N/AN/AN/AN/AN/AN/A
9N/AN/AN/AN/AN/AN/A
10N/AN/AN/AN/AN/AN/A

VRRP

VRRP is designed to eliminate the single point of failure inherent in the static default routed environment. VRRP specifies an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers in a LAN. The VRRP router controlling the IP address associated with a virtual router is called the Master, and forwards packets sent to these IP addresses. The election process provides dynamic fail-over in the forwarding responsibility should the Master become unavailable. Any of the virtual router's IP addresses in a LAN can then be used as the default first hop router by end-hosts. The advantage gained from using VRRP is a higher availability default path without requiring configuration of dynamic routing or router discovery protocols on every end-host.

VRRP VRRP ○ Activated ○ Deactivated VRID 1 (1~255) Priority 100 (1~254) Preempt Mode ○ Activated ○ Deactivated VRIP 192.168.1.253 Advertisement Period 1 (1~2147483647) Save

VRRP: Click to activate the feature.

VRID: Virtual Router Identifier, range from 1-255 (decimal). A master or backup router running the VRRP protocol may participate in one VRID instance.

Priority: Specifies the sending VRRP router's priority for the virtual router. Higher values equal higher priority. The priority value for the VRRP router that owns the IP address associated with the virtual router MUST be 255. VRRP routers backing up a virtual router MUST use priority values between 1 and 254. The default priority value for VRRP routers backing up a virtual router is 100. The priority value zero (0) has special meaning indicating that the current Master has stopped participating in VRRP. This is used to trigger Backup routers to quickly transition to Master without having to wait for the current Master to timeout.

Preempt Mode: When preempt mode is activated, a backup router always takes over the responsibility of the master router. When deactivated, the lower priority backup is left in the master state.

VRIP: An IP address which is associated with the virtual router.

Advertisement period: Indicates the time interval in seconds between advertisements. Default in 1 second.

Click Save to apply settings.

Static DNS

The Domain Name System (DNS) is a hierarchical naming system built on a distributed database for computers, services, or any resource connected to the Internet or a private network associates various information with domain names assigned to each of the participating entities. Most importantly, it translates domain names meaningful to humans into the numerical identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide.

An often-used analogy to explain the Domain Name System is that it serves as the phone book for the Internet by translating human-friendly computer hostnames into IP addresses. For example, the domain name www.example.com can be translated into the addresses 192.0.32.10 (IPv4).

Static DNS IP Address Domain Name Save Static DNS Listing Index IP Address Domain Name Edit Delete

IP Address: The IP address you are going to give a specific domain name.

Domain Name: The friendly domain name for the IP address.

Click Save to apply settings.

QoS

QoS helps you control the upload traffic of each application from LAN (Ethernet and/or Wireless) to WAN (Internet).

It facilitates you the features to control the quality of throughput for each application. This is useful when there on certain types of data you want giver higher priority to, such as voice data packets given higher priority than web data packets.

QoS helps you control the upload traffic of each application from LAN (Ethernet and/or Wireless) to WAN (Internet).

It facilitates you the features to control the quality of throughput for each application. This is useful when there on certain types of data you want giver higher priority to, such as voice data packets given higher priority than web data packets.

Quality of Service SW QoS ○ Activated ○ Deactivated Bandwidth LAN to WAN Bandwidth 100000 Kbps WAN to LAN EWAN(LAN2) Bandwidth 100000 Kbps 4G/LTE Bandwidth 100000 Kbps Bandwidth Save Rule Index 1 ▼ Wan Interfae EWAN(LAN2) ▼ Application Direction LAN to WAN ▼ Protocol Any ▼ DSCP Marking Disable ▼ Rat…

SW QoS: Select Activate to enable the QoS

LAN to WAN (Bandwidth): You want to control the traffic from local network to the outside (Upstream). You can assign the priority for the application or you can limit the rate of the application.

E.g.: you have an FTP server inside the local network, and you want to have a limited control by the QoS policy and so you need to add a policy with LAN to WAN direction setting.

WAN to LAN (Bandwidth): Control traffic from WAN to LAN (Downstream).

Click Bandwidth Save to save settings.

Rule Index: Index marking for each rule up to maximum of 16.

- WAN Interface: Select a WAN interface connection to allow external access to your internal

network.

▶ Application: Assign a name that identifies the new QoS application rule. Select from the list box for quick setup.

Direction: Shows the direction mode of the QoS application

▶ Protocol: Select a protocol from the drop-down list

▶ DSCP Marking: Differentiated Services Code Point (DSCP), it is the first 6 bits in the ToS byte. DSCP Marking allows users to classify the traffic of the application to be executed according to the DSCP value.

Rate Type: Choose Limited (Maximum) or Guaranteed (Minimum) to specify the date rate is allowed for this policy.

▶ Rate: Specify the date rate in Kbps.

▶ Priority: Set the priority given to each policy/application. Specify the priority for the use of bandwidth. You can specify which application can have higher priority to acquire the bandwidth. Its default setting is set to High. You may adjust this setting to fit your policy / application.

Internal IP Address: The IP address values for Local LAN devices you want to give control.

▶ Internal Port: The Port number on the LAN side, it is used to identify an application.

External IP Address: The IP address on remote / WAN side.

▶ External Port: The Port number on the remote / WAN side.

Click Save to apply settings.

To Remove a Policy: Simply select the Index then hit the Delete button to remove from the list.

Time Schedule

The Time Schedule supports up to 16 timeslots which helps you to manage your Internet connection. In each time profile, you may schedule specific day(s) i.e. Monday through Sunday to restrict or allowing the usage of the Internet by users or applications.

This Time Schedule correlates closely with router's time, since router does not have a real time clock on board; it uses the Simple Network Time Protocol (SNTP) to get the current time from an SNTP server from the Internet.

Time Schedule Rule Index 0 ▼ Rule Name TimeSlot1 Mon. Tues. Wed. Thur. Fri. Sat. Sun. Day of Week □ □ □ □ □ □ Start Time 00:00 00:00 00:00 00:00 00:00 00:00 End Time 00:00 00:00 00:00 00:00 00:00 00:00 Save

Time Index: The rule indicator (0-15) for identifying each timeslot.

Name: User-defined identification for each time period.

Day of Week: Mon. to Sun. Specify the time interval for each timeslot from "Day of Week".

Start Time: The starting point of the interval for the timeslot, anytime in 00:00 – 24:00.

End Time: The ending point of the interval for the timeslot, anytime in 00:00 – 24:00.

Click Save to apply your settings.

Example, you can add a timeslot named "TimeSlot1" which features a period from 9:00 of Monday to 18:00 of Tuesday.

Time Schedule Rule Index 0 ▼ Rule Name TimeSlot1 Mon Tues Wed Thur Fri Sat Sun Day of Week ✓ ✓ □ □ □ □ Start Time 09:00 00:00 00:00 00:00 00:00 00:00 End Time 24:00 18:00 00:00 00:00 00:00 00:00 Save

Another TimeSlot2 spanning from 09:00 to 18:00 of Wednesday

Time Schedule Rule Index 1 ▼ Rule Name TimeSlot2 Mon. Tues. Wed. Thur. Fri. Sat. Sun. Day of Week □ □ ✓ □ □ □ Start Time 00:00 00:00 09:00 00:00 00:00 00:00 00:00 End Time 00:00 00:00 18:00 00:00 00:00 00:00 00:00 Save

Mail Alert

Mail alert is designed to keep system administrator or other relevant personnel alerted of any unexpected events that might have occurred to the network computers or server for monitoring efficiency. With this alert system, appropriate solutions may be tackled to fix problems that may have arisen so that the server can be properly maintained.

Mail Alert Server Information SMTP Server Username Password (Must be XXX@yyy.zzz) Sender's E-mail SSL/TLS Enable Port 25 (1~65535) Account Test WAN IP Change Alert Recipient's E-mail (Must be XXX@yyy.zzz) 4G/LTE Usage Allowance Recipient's E-mail (Must be XXX@yyy.zzz) Apply

Server Information

SMTP Server: Enter the SMTP server that you would like to use for sending emails.

Username: Enter the username of your email account to be used by the SMTP server.

Password: Enter the password of your email account.

Sender's Email: Enter your email address.

SSL/TLS: Check to whether to enable SSL encryption feature.

Port: the port, default is 25.

Account Test: Click the button to test the connectivity and feasibility to your sender's e-mail.

WAN IP Change Alert

Recipient's Email (WAN IP Change Alert): Enter a valid e-mail address to receive an alert message when WAN IP change has been detected.

Recipient's Email (3G/4G-LTE Usage Allowance): Enter a valid e-mail address to receive an alert message when the 3G or 4G/LTE over Usage Allowance occurs.

Click Apply button to save settings

VPN

A Virtual Private Network (VPN) is a private network that interconnects remote (and often geographically separate) networks through primarily public communication infrastructures such as the Internet. VPNs provide security through tunneling protocols and security procedures such as encryption. For example, a VPN could be used to securely connect the branch offices of an organization to a Headquarter office network through the public Internet.

MX-200A ODU supports IPSec, PPTP, L2TP, GRE, and OpenVPN.

IPSec

Internet Protocol Security (IPSec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session. IPSec also includes protocols for establishing mutual authentication between agents at the beginning of the session and negotiation of cryptographic keys to be used during the session.

IPSec is an end-to-end security scheme operating in the Internet Layer of the Internet Protocol Suite. It can be used in protecting data flows between a pair of security gateways (network-to-network), or between a security gateway and a host (network-to-host).

A total of 8 IPSec tunnels can be added.

IPSec IPSec Listing Index Connection Name Active Interface Remote Gateway IP Remote Network Edit Delete Add New Connection

Click Add New Connection to create a new IPSec profile.

IPSec Connection Setting

IPSec
Connection Name
ActiveYes No
InterfaceAuto ▼
Remote Gateway IP(0.0.0.0 means any)
Local Access RangeSubnet ▼Local IP Address0.0.0.0IP Subnetmask0.0.0.0
Remote Access RangeSubnet ▼Remote IP Address0.0.0.0IP Subnetmask0.0.0.0
IKE ModeMain ▼Pre-Shared Key
Local ID TypeDefault (Local WAN IP) ▼IDContent*
Remote ID TypeDefault (Remote Gateway IP) ▼IDContent*
IKE ProposalEncryption AlgorithmDES ▼Authentication AlgorithmMD5 ▼
Diffie-Hellman GroupMODP1024(DH2) ▼
IPSec ProposalESPAH
Encryption AlgorithmDES ▼Authentication AlgorithmMD5 ▼
Perfect Forward SecrecyNone ▼
SA LifetimePhase 1 (IKE)480 min(s)Phase 2 (IPSec)60 min(s)
KeepaliveNone ▼PING to the IP(0.0.0.0:NEVER)0.0.0.0Interval10 seconds
Disconnection Time after No Traffic180 seconds (180 at least)
Reconnection Time3 min(s) (3 at least)
Note * : FQDN with @ as first character means don't resolve domain name.
Note ** : (0-3600, 0 means NEVER)
Save Back

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate the connection.

Interface: Select a WAN interface to establish a tunnel with the remote VPN device. Auto allows system to automatically initiate a connection via current connected WAN interface.

Remote Gateway IP: The WAN IP address of the remote VPN device. Enter 0.0.0.0 for unknown remote WAN IP address – only the peer can initiate the tunnel connection.

Local Access Range: Set the IP address or subnet of the local network.

▶ Single IP: The IP address of the local host, for establishing an IPSec connection between a security gateway and a host (network-to-host).
- Subnet: The subnet of the local network, for establishing an IPSec tunnel between a pair of security gateways (network-to-network)

Remote Access Range: Set the IP address or subnet of the remote network.

▶ Single IP: The IP address of the local host, for establishing an IPSec connection between a security gateway and a host (network-to-host). If the remote peer is a host, select Single Address.
Subnet: The subnet of the local network, for establishing an IPSec tunnel between a pair of security gateways (network-to-network), if the remote peer is a network, select Subnet.

IPSec Phase 1(IKE)

IKE Mode Main Pre-Shared Key Local ID Type Default (Local WAN IP) IDContent * Remote ID Type Default (Remote Gateway IP) IDContent * IKE Proposal Encryption Algorithm DES Authentication Algorithm MD5 Diffie-Hellman Group MODP1024(DH2)

IKE Mode: IKE, Internet Key Exchange, is the mechanism to negotiate and exchange parameters and keys between IPSec peers to establish security associations (SA). Select Main or Aggressive mode.

Pre-Shared Key: This is for the Internet Key Exchange (IKE) protocol, a string from 4 to 128 characters. Both sides should use the same key. IKE is used to establish a shared security policy and authenticated keys for services (such as IPSec) that require a key. Before any IPSec traffic can be passed, each router must be able to verify the identity of its peer. This can be done by manually entering the pre-shared key into both sides (router or hosts).

Local ID Type / Remote ID Type: When the mode of IKE is aggressive, Local and Remote peers can be identified by other IDs.

IDContent: Enter IDContent the name you want to identify when the Local and Remote Type are Domain Name; Enter IDContent IP address you want to identify when the Local and Remote Type are IP addresses (IPv4 and IPv6 supported).

IKE Proposal & Encryption Algorithm: Select the encryption algorithm from the drop-down menu. There are several options: DES and AES (128, 192 and 256). 3DES and AES are more powerful but increase latency.

▶ DES: Stands for Data Encryption Standard, it uses 56 bits as an encryption method.
3DES: Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits as an encryption method.
▶ AES: Stands for Advanced Encryption Standards, you can use 128, 192 or 256 bits as encryption method.

Authentication Algorithm: Authentication establishes the integrity of the datagram and ensures it is not tampered with in transmission. There are 3 options: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA1, SHA256). SHA1 is more resistant to brute-force attacks than MD5. However, it is slower.

MD5: A one-way hashing algorithm that produces a 128-bit hash.
▶ SHA1: A one-way hashing algorithm that produces a 160-bit hash.

Diffie-Hellman Group: It is a public-key cryptography protocol that allows two parties to establish a shared secret over an unsecured communication channel (i.e. over the Internet). MODP stands for Modular Exponentiation Groups.

IPSec Phase 2(IPSec)

IPSec ProposalESPAH
Encryption AlgorithmDESAuthentication AlgorithmMD5
Perfect Forward SecrecyNone

IPSec Proposal: Select the IPSec security method. There are two methods of verifying the authentication information, AH (Authentication Header) and ESP (Encapsulating Security Payload).

Use ESP for greater security so that data will be encrypted and the data origin be authenticated but using AH data origin will only be authenticated but not encrypted.

Encryption Algorithm: Select the encryption algorithm from the drop-down menu. There are several options: DES and AES (128, 192 and 256). 3DES and AES are more powerful but increase latency.

▶ DES: Stands for Data Encryption Standard, it uses 56 bits as an encryption method.
3DES: Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits as an encryption method.
▶ AES: Stands for Advanced Encryption Standards, you can use 128, 192 or 256 bits as encryption method.

Authentication Algorithm: Authentication establishes the integrity of the datagram and ensures it is not tampered with in transmission. There are 3 options: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA1, SHA256). SHA1 is more resistant to brute-force attacks than MD5. However, it is slower.

MD5: A one-way hashing algorithm that produces a 128-bit hash.
▶ SHA1: A one-way hashing algorithm that produces a 160-bit hash.

Perfect Forward Secrecy: It is a public-key cryptography protocol that allows two parties to establish a shared secret over an unsecured communication channel (i.e. over the Internet). MODP stands for Modular Exponentiation Groups.

IPSec SA Lifetime

Phase 1 (IKE)SA Lifetime

480

min(s)

Phase 2 (IPSec)

60

min(s)

SA Lifetime: Specify the number of minutes that a Security Association (SA) will stay active before new encryption and authentication key will be exchanged. There are two kinds of SAs, IKE and IPSec. IKE negotiates and establishes SA on behalf of IPSec, and IKE SA is used by IKE.

▶ Phase 1 (IKE): To issue an initial connection request for a new VPN tunnel. The range can be from 5 to 15,000 minutes, and the default is 480 minutes.
- Phase 2 (IPSec): To negotiate and establish secure authentication. The range can be from 5 to 15,000 minutes, and the default is 60 minutes. A short SA time increases security by forcing the two parties to update the keys. However, every time the VPN tunnel re-negotiates, access through the tunnel will be temporarily disconnected.

IPSec Connection Keep Alive

KeepaliveNone ▼PING to the IP(0.0.0.0:NEVER)0.0.0.0Interval10 seconds **
Disconnection Time after No Traffic180 seconds (180 at least)
Reconnection Time3 min(s) (3 at least)

Keep Alive:

None: Disable. The system will not detect remote IPSec peer is still alive or lost. The remote peer will get disconnected after the interval, in seconds, is up.
▶ PING: This mode will detect the remote IPSec peer has lost or not by pinging specify IP address.
▶ DPD: Dead peer detection (DPD) is a keeping alive mechanism that enables the router to be

detected lively when the connection between the router and a remote IPSec peer has lost. Please be noted, it must be enabled on the both sites.

PING to the IP: It is able to IP Ping the remote PC with the specified IP address and alert when the connection fails. Once alter message is received, Router will drop this tunnel connection. Reestablish of this connection is required. Default setting is 0.0.0.0 which disables the function

Interval: This sets the time interval between Pings to the IP function to monitor the connection status. Default interval setting is 10 seconds. Time interval can be set from 0 to 3600 second, 0 second disables the function.

Ping to the IPInterval (sec)Ping to the IP Action
0.0.0.00No
0.0.0.02000No
xxx.xxx.xxx.xxx (A valid IP Address)0No
xxx.xxx.xxx.xxx(A valid IP Address)2000Yes, activate it in every 2000 second.

Disconnection Time after No Traffic: It is the NO Response time clock. When no traffic stage time is beyond the Disconnection time set, Router will automatically halt the tunnel connection and re-establish it base on the Reconnection Time set. 180 seconds is minimum time interval for this function.

Reconnection Time: It is the reconnecting time interval after NO TRAFFIC is initiated. 3 minutes is minimum time interval for this function.

Click Save to apply settings.

Examples: IPSec – Network (LAN) to Network (LAN)

Two of the MX-200A ODU devices want to setup a secure IPSec VPN tunnel

NOTE: The IPSec Settings shall be consistent between the two routers.

graph LR A["Branch Office"] -->|192.168.0.254| B["Router"] C["Public IP 69.121.1.30"] --> B D["Public IP 69.121.1.3"] --> B E["192.168.0.0/24"] --> B B <--> F["Internet"] F <--> G["Router"] H["Head Office"] -->|192.168.1.0/24| I["Computer"] J["Computer"] --> K["Computer"] L["Computer"] --> M["Comput…

Headquarter office Side:

Configuration SettingsDescription
Connection NameH-to-BAssigned name to this tunnel/profile
Remote Secure Gateway69.121.1.30IP address of the Branch office gateway
Access Network
Local Access RangeSubnetHeadquarter office network
Local Network IP Address192.168.1.0
Local Network Netmask255.255.255.0
Remote Access RangeSubnetBranch office network
Remote Network IP Address192.168.0.0
Remote Network Netmask255.255.255.0
IPSec Proposal
IKE ModeMainSecurity Plan
Pre-Shared Key1234567890
Phase 1 EncryptionAES-128
Phase 1 AuthenticationSHA1
Phase 1 Diffie-Hellman GroupMODP 1024(group2)
Phase 2 ProposalESP
Phase 2 AuthenticationSHA1
Phase 2 Encryption3DES
Prefer Forward SecurityMODP 1024(group2)

IPSec

Connection NameH-to-B
ActiveYes No
InterfaceAuto
Remote Gateway IP69.121.1.30 (0.0.0.0 means any)
Local Access RangeSubnetLocal IP Address192.168.1.0IP Subnetmask255.255.255.0
Remote Access RangeSubnetRemote IP Address192.168.0.0IP Subnetmask255.255.255.0
IKE ModeMainPre-Shared Key1234567890
Local ID TypeDefault Wan IPIDContent*
Remote ID TypeDefault Wan IPIDContent*
Encryption AlgorithmAES-128Authentication AlgorithmSHA1Diffie-Hellman GroupMODP1024(DH2)
IPSec ProposalESPAH
Authentication AlgorithmSHA1Encryption Algorithm3DES
Perfect Forward SecrecyMODP1024(DH2)
Phase 1 (IKE)SA Lifetime480 min(s)Phase 2 (IPSec)60 min(s)
KeepaliveNonePING to the IP(0.0.0.0:NEVER)0.0.0.0Interval10 seconds **
Disconnection Time after No Traffic180 seconds (180 at least)
Reconnection Time3 min(s) (3 at least)
Note*: FQDN with @ as first character means don't resolve domain name.
Note**: (0-3600, 0 means NEVER)
Save Back

Branch Office Side:

Configuration SettingsDescription
Connection NameB-to-HAssigned name to this tunnel/profile
Remote Secure Gateway69.121.1.3IP address of the Branch office gateway
Access Network
Local Access RangeSubnetHeadquarter office network
Local Network IP Address192.168.0.0
Local Network Netmask255.255.255.0
Remote Access RangeSubnetBranch office network
Remote Network IP Address192.168.1.0
Remote Network Netmask255.255.255.0
IPSec Proposal
IKE ModeMainSecurity Plan
Pre-Shared Key1234567890
Phase 1 EncryptionAES-128
Phase 1 AuthenticationSHA1
Phase 1 Diffie-Hellman GroupMODP 1024(group2)
Phase 2 ProposalESP
Phase 2 AuthenticationSHA1
Phase 2 Encryption3DES
Prefer Forward SecurityMODP 1024(group2)

IPSec

Connection NameB-to-H
ActiveYes No
InterfaceAuto
Remote Gateway IP69.121.1.3 (0.0.0.0 means any)
Local Access RangeSubnet ▼Local IP Address192.168.0.0IP Subnetmask255.255.255.0
Remote Access RangeSubnet ▼Remote IP Address192.168.1.0IP Subnetmask255.255.255.0
IKE ModeMain ▼Pre-Shared Key1234567890
Local ID TypeDefault Wan IP ▼IDContent*
Remote ID TypeDefault Wan IP ▼IDContent*
Encryption AlgorithmAES-128 ▼Authentication AlgorithmSHA1 ▼Diffie-Hellman GroupMODP1024(DH2) ▼
IPSec ProposalESPAH
Authentication AlgorithmSHA1 ▼Encryption Algorithm3DES ▼
Perfect Forward SecrecyMODP1024(DH2) ▼
Phase 1 (IKE)SA Lifetime480 min(s)Phase 2 (IPSec)60 min(s)
KeepaliveNone ▼PING to the IP(0.0.0.0:NEVER)0.0.0.0Interval10 seconds **
Disconnection Time after No Traffic180 seconds (180 at least)
Reconnection Time3 min(s) (3 at least)
Note*: FQDN with @ as first character means don't resolve domain name.
Note**: (0-3600, 0 means NEVER)
Save Back

Examples: IPSec – Remote Employee to MX-200A ODU Connection

Router servers as VPN server, and host should install the IPSec client to connect to Headquarter office through IPSec VPN.

graph LR A["Remote Worker"] -->|IPsec| B["Internet"] C["Public IP 69.121.1.30"] -->|IPvN Connection| B D["Public IP 69.121.1.3"] -->|IPvN Connection| B E["Router"] -->|IPvN Connection| B F["Office LAN"] --> G["Computer 192.168.1.0/24"] F --> H["Computer 192.168.1.0/24"] F --> I["Computer 192.168.1.0…

Headquarter office Side:

Configuration SettingsDescription
Connection NameH-to-HAssigned name to this tunnel/profile
Remote Secure Gateway69.121.1.30IP address of the Branch office gateway
Access Network
Local Access RangeSubnetHeadquarter office LAN network information
Local Network IP Address192.168.1.0
Local Network Netmask255.255.255.0
Remote Access RangeSignal IPRemote worker IP address
Remote Network IP Address69.121.1.30
Remote Network Netmask255.255.255.255
IPSec Proposal
IKE ModeMainSecurity Plan
Pre-Shared Key1234567890
Phase 1 EncryptionAES-128
Phase 1 AuthenticationSHA1
Phase 1 Diffie-Hellman GroupMODP 1024(group2)
Phase 2 ProposalESP
Phase 2 AuthenticationSHA1
Phase 2 Encryption3DES
Prefer Forward SecurityMODP 1024(group2)

IPSec

Connection Name H-to-H Active Yes No Interface Auto Remote Gateway IP 69.121.1.30 (0.0.0.0 means any) Local Access Range Subnet Local IP Address 192.168.1.0 IP Subnetmask 255.255.255.0 Remote Access Range Single IP Remote IP Address 69.121.1.30 IP Subnetmask 255.255.255.255 IKE Mode Main Pre-Shared…

PPTP Server

The Point-to-Point Tunneling Protocol (PPTP) is a Layer2 tunneling protocol for implementing virtual private networks through IP network.

In the Microsoft implementation, the tunneled PPP traffic can be authenticated with PAP, CHAP, and Microsoft CHAP V1/V2. The PPP payload is encrypted using Microsoft Point-to-Point Encryption (MPPE) when using MSCHAPv1/v2.

NOTE: 4 sessions for Client and 4 sessions for Server respectively.

PPTP Server PPTP Server ○ Actived ○ Deactivated Authentication Type Chap/Pap ▼ Encryption Key Length Auto ▼ Encryption Mode Allow Stateless and Statefull ▼ CCP ○ Yes ○ No MS-DNS 192.168.1.254 Rule Index 1 ▼ Connection Name Active ○ Yes ○ No Username Password **** Connection Type Remote Access ▼ Priv…

PPTP Server: Select Activate / Deactivate to enable or disable the PPTP Server.

Authentication Type: Pick an authentication type from the drop-down list. When using PAP, the password is sent unencrypted, whilst CHAP encrypts the password before sending, and also allows for challenges at different periods to ensure that an intruder has not replaced the client. When passed the authentication with MS-CHAPv2, the MPPE encryption is supported.

Encryption Key Length: Auto, data encryption and key length, with 40-bit or 128-bit, is automatically negotiated when establish a connection. 128-bit keys provide strong stronger encryption than 40-bit keys.

Encryption Mode: The encryption key will be changed every 256 packets with Stateful mode. With Stateless mode, the key will be changed in each packet.

CCP (Compression Control Protocol): Enable to compress data to save bandwidth and increase data transfer speed.

MS-DNS: Assign a DNS server or use router default IP address to be the MS-DNS server IP address.

Rule Index: The numeric rule indicator for PPTP server. The maximum entry is up to 4.

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate the account. PPTP server is waiting for the client to connect to this account.

Username / Password: Enter the username / password for this profile.

Connection Type: Select Remote Access for single user, Select LAN to LAN for remote gateway.

Private IP Address Assigned to Dial-in User: Specify the private IP address to be assigned to dial-in clients, and the IP should be in the same subnet as local LAN, but not occupied.

Remote Network IP Address: Enter the subnet IP of the remote LAN network.

Remote Network Netmask: Enter the Netmask of the remote LAN network.

Click Save to apply settings.

PPTP Client

Establish a PPTP tunnel over Internet to connect with a PPTP server.

A total of 4 PPTP Client sessions can be created.

PPTP Client Rule Index 1 ▼ Connection Name Active ○ Yes ○ No Authentication Type Chap/Pap ▼ Encryption Key Length Auto ▼ Encryption Mode Allow Stateless or Statefull ▼ CCP ○ Yes ○ No Username Password **** Connection Type Remote Access ▼ Server IP Address Remote Network IP Address Remote Network Net…

Rule Index: The numeric rule indicator for PPTP client. The maximum entry is up to 4.

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate the account. PPTP server is waiting for the client to connect to this account.

Authentication Type: Pick an authentication type from the drop-down list. When using PAP, the password is sent unencrypted, whilst CHAP encrypts the password before sending, and also allows for challenges at different periods to ensure that an intruder has not replaced the client. When passed the authentication with MS-CHAPv2, the MPPE encryption is supported.

Encryption Key Length: Auto, data encryption and key length, with 40-bit or 128-bit, is automatically negotiated when establish a connection. 128-bit keys provide strong stronger encryption than 40-bit keys.

Encryption Mode: The encryption key will be changed every 256 packets with Stateful mode. With Stateless mode, the key will be changed in each packet.

CCP (Compression Control Protocol): Enable to compress data to save bandwidth and increase data transfer speed.

Username / Password: Enter the username / password provided by the PPTP server/host.

Connection Type: Select Remote Access for single user, Select LAN to LAN for remote gateway.

Server Address: Enter the WAN IP address of the PPTP server.

Remote Network IP Address: Enter the subnet IP of the server/host LAN network.

Remote Network Netmask: Enter the Netmask of the server/host LAN network.

Click Save to apply settings.

Example: PPTP – Remote Employee Dial-in to MX-200A ODU
graph LR A["Remote Worker"] <--> B["Internet"] B <--> C["Router"] C <--> D["Office LAN"] E["PPTP Client"] <--> F["PPTP Server"] G["VPN Connection"] --> F H["192.168.1.0/24"] --> I["Computer 1"] H --> J["Computer 2"] H --> K["Computer 3"] H --> L["Computer 4"] style A fill:#f9f,stroke:#333 style B fi…

The input IP address 192.168.1.2 will be assigned to the remote worker. Please make sure this IP is not used in the Office LAN.

Configuration SettingsDescription
Connection NameHS-RAAssigned name to this tunnel/profile
Authentication TypeMS-CHAPv2Authentication type
UsernametestCredential created from the device to a PPTP client to dial-in to the network.
Passwordtest
Connection TypeRemote AccessRemote access for a dial-in
Assigned IP192.168.1.2Local IP assigned to the dial-in client

PPTP Server PPTP Server ● Actived ○ Deactivated Authentication Type MS-CHAPv2 Encryption Key Length Auto Encryption Mode Allow Stateless and Statefull CCP ● Yes ○ No MS-DNS 192.168.1.254 Rule Index 1 Connection Name HS-RA Active ● Yes ○ No Username Nuest Password ●●●● Connection Type Remote Access P…

Example: PPTP – Remote Employee Dial-out to MX-200A ODU

A company's office establishes a PPTP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers.

graph LR A["Server"] -->|61.121.1.33| B["Internet"] B <--> C["Router"] C <--> D["Office LAN"] B <-->|Encryption Data| E["PPTP Server"] E <--> F["PPTP Client"] F <--> G["192.168.1.0/24"] style A fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style C fill:#cfc,stroke:#333 style D fill:#fcc,stroke…

PPTP Server WAN IP address is 61.121.1.33 of the Headquarter office.

Configuration SettingsDescription
Connection NameHS-RAAssigned name to this tunnel/profile
Authentication TypeMS-CHAPv2Authentication type
UsernametestCredential assigned from the PPTP server for PPP client to dial-in to its network.
Passwordtest
Connection TypeRemote AccessRemote access for a dial-in
Server IP61.121.1.33VPN server WAN IP address

PPTP Client Rule Index 1 Connection Name HS-RA Active ● Yes ○ No Authentication Type MS-CHAPv2 Encryption Key Length Auto Encryption Mode Allow Stateless or Statefull CCP ● Yes ○ No Username Grid Password ●●●●● Connection Type Remote Access Server IP Address 69.121 1.33 Remote Network IP Address 192…

Example: PPTP – Network (LAN) to Network (LAN) Connection

The branch office establishes a PPTP VPN tunnel with Headquarter office to connect two private networks over the Internet. The routers are installed in the Headquarter office and branch offices accordingly.

NOTE: Both office LAN networks must be in different subnets with the LAN-LAN application.

graph LR A["Branch Office"] -->|192.168.0.254| B["Router"] C["Head Office"] -->|192.168.1.0/24| D["Router"] B <--> E["Internet"] D <--> E E <--> F["PPTP Server"] G["PPTP Client"] -->|Encryption Data| E style A fill:#f9f,stroke:#333 style C fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style D…

Configuring PPTP Server in the Headquarter office

The IP address 192.168.1.2 will be assigned to the router located in the branch office. Please make sure this IP is not used in the Headquarter office LAN.

Configuration SettingsDescription
Connection NameHS-LLAssigned name to this tunnel/profile
Authentication TypeMS-CHAPv2Authentication type
UsernametestCredential created for a PPTP client to dial-in to its local network.
Passwordtest
Connection TypeLAN to LANLAN to LAN connection
Assigned IP192.168.1.2Local IP assigned to the dial-in client
Remote Network IP129.168.0.0Remote, Branch office, LAN network IP address and Netmask
Remote Network Netmask255.255.255.0

PPTP Server PPTP Server Activated Deactivated Authentication Type MS-CHAPv2 Encryption Key Length Auto Encryption Mode Allow Staleless and Statefull CCP Yes No MS-DNS 192.168.1.254 Rule Index 1 Connection Name HS-LL Active Yes No Username test Password ***** Connection Type LAN to LAN Private IP Add…

Configuring PPTP Client in the Branch office

The IP address 69.1.121.33 is the Public IP address of the router located in Headquarter office.

Configuration SettingsDescription
Connection NameBC-LLAssigned name to this tunnel/profile
Authentication TypeMS-CHAPv2Authentication type
UsernametestCredential assigned from the Headquarter Server to dial-in.
Passwordtest
Connection TypeLAN to LANLAN to LAN connection
Server IP69.121.1.33Headquarter Serve WAN IP address
Remote Network IP129.168.1.0Remote, Headquarter office, LAN network IP address and Netmask
Remote Network Netmask255.255.255.0
PPTP Client
Rule Index1✓
Connection NameBC-LL
Active● Yes ○ No
Authentication TypeMS-CHAPv2✓
Encryption Key LengthAuto✓
Encryption ModeAllow Stateless or Statefull✓
CCP● Yes ○ No
Usernametest
Password●●●●
Connection TypeLAN to LAN✓
Server IP Address69.121.1.33
Remote Network IP Address192.168.1.0
Remote Network Netmask255.255.255.0
Active as Default Route□ Enable
Save Delete
PPTP Client Listing
IndexConnection NameActiveUsernameConnection TypeServer IP Address
1BC-LLYestestLan to Lan69.121.1.33

L2TP

L2TP, Layer 2 Tunneling Protocol is a tunneling protocol used to support virtual private networks (VPNs). It does not provide any encryption or confidentiality by itself; it relies on an encryption protocol that it passes within the tunnel to provide.

NOTE: 4 sessions for dial-in connections and 4 sessions for dial-out connections

L2TP Rule Index 1 ▼ Connection Name Active ● Yes ○ No Connection Mode Dial in ▼ Authentication Type Chap/Pap ▼ Username Password Private IP Address assigned to Dial-in User Connection Type Remote Access ▼ Tunnel Authentication □ Enable Secret Password Local Host Name Remote Host Name Active as Defau…

Rule Index: The numeric rule indicator for L2TP. The maximum entry is up to 8 (4 dial-in and 4 dial-out profiles).

Connection Name: Enter a description for this connection/profile.

Active: To enable or disable this profile.

Connection Mode (Dial in)

Connection Mode Dial in ▼ Authentication Type Chap/Pap ▼ Username Password Private IP Address assigned to Dial-in User

Connection Mode: Select Dial In to operate as a L2TP server.

Authentication Type: Default in Chap/Pap (CHAP, Challenge Handshake Authentication Protocol. PAP, Password Authentication Protocol). If you want the router to determine the authentication type to use, or else manually specify PAP if you know which type the server is using (when acting as a client), or else the authentication type you want clients connecting to you to use (when acting as a server).

Username / Password (Server/Host): Enter the username / password for this profile.

Private IP Address Assigned to Dial-in User: The private IP to be assigned to dial-in user by L2TP

server. The IP should be in the same subnet as local LAN, and should not be occupied.

Connection Mode (Dial out)

Connection Mode Dial out ▼ Server IP Address Authentication Type Chap/Pap ▼ Username Password

Connection Mode: Choose Dial Out if you want your router to operate as a client (connecting to a remote L2TP Server, e.g., your office server).

Server IP Address: Enter the IP address of your VPN Server.

Authentication Type: Default is Chap/Pap (CHAP, Challenge Handshake Authentication Protocol. PAP, Password Authentication Protocol). If you want the router to determine the authentication type to use, or else manually specify PAP if you know which type the server is using (when acting as a client), or else the authentication type you want clients connecting to you to use (when acting as a server).

Username / Password (Client): Enter the username / password provide by the Server/Host.

Connection Type

▶ Remote Access: From a single user.
▶ LAN to LAN: Enter the peer network information, such as network address and Netmask.

Tunnel Authentication and Active

Tunnel Authentication Enable Secret Password Local Host Name Remote Host Name Active as Default Route Enable

Tunnel Authentication: This enables router to authenticate both the L2TP remote and L2TP host. This is only valid when L2TP remote supports this feature.

Secret Password: The secure password length should be 16 characters which may include numbers and characters.

Local Host Name: Enter hostname of Local VPN device that is connected / established a VPN tunnel.

Remote Host Name: Enter hostname of remote VPN device. It is a tunnel identifier from the Remote VPN device matches with the Remote hostname provided. If remote hostname matches, tunnel will be connected; otherwise, it will be dropped.

Active as Default Route: Enabled to let the tunnel to be the default route for traffic, under this circumstance, all packets will be forwarded to this tunnel and routed to the next hop.

Click Save to apply settings.

Example: L2TP VPN – Remote Employee Dial-in to MX-200A ODU

A remote worker establishes a L2TP VPN connection with the Headquarter office using Microsoft's VPN Adapter The router is installed in the Headquarter office, connected to a couple of PCs and Servers.

graph LR A["Remote Worker"] <--> B["Internet"] B <--> C["Router"] D["Public IP 61.56.158.112"] --> B E["192.168.1.254"] --> C F["L2TP Client"] <--> G["L2TP Server"] H["VPN Connection"] --> G I["Office LAN"] --> J["Computer 1"] I --> K["Computer 2"] I --> L["Computer 3"] I --> M["Office LAN 192.168.1…

The input IP address 192.168.1.200 will be assigned to the remote worker. Please make sure this IP is not used in the Office LAN.

Configuration SettingsDescription
Connection NameHS-RAAssigned name to this tunnel/profile
Connection ModeDial inOperate as L2TP server
Authentication TypeChap/PapAuthentication type
UsernametestCredential from the device for remote client to dial-in to the network.
Passwordtest
Assigned IP192.168.1.200An IP assigned to the dial in client
Connection TypeRemote AccessRemote access for dial in

L2TP Rule Index 1 ▼ Connection Name HS-RA Active ● Yes ○ No Connection Mode Dial in ▼ Authentication Type Chap/Pap ▼ Usernamealed funds Password **** Private IP Address assigned to Dial-in User 192.168.1.200 Connection Type Remote Access ▼ Tunnel Authentication □ Enable Secret Password Local Host Na…

Example: L2TP VPN – MX-200A ODU Dial-out to a Server

A company's office establishes a L2TP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers.

graph LR A["Server"] -->|Public IP 61.121.1.33| B["Internet"] B <--> C["Router"] C <--> D["Office LAN"] B <-->|Encryption Data| E["L2TP Server"] E <--> F["L2TP Client"] F <--> G["VPN Connection"] G --> H["L2TP - Remote Access (Dial-out)"]

ItemDescription
Connection NameHC-RAAssigned name to this tunnel/profile
Connection ModeDial outOperate as L2TP client
Server IP69.121.1.33VPN server WAN IP address
Authentication TypeChap/PapAuthentication type
UsernametestCredential from the VPN Server for remote clients to dial-in to the network.
Passwordtest
Connection TypeRemote AccessRemote access for dial out

L2TP Rule Index 1 ▼ Connection Name HC-RA Active ● Yes ○ No Connection Mode Dial out ▼ Server IP Address 69.121.1.33 Authentication Type Chap/Pap ▼ Usernamealedtest Password **** Connection Type Remote Access ▼ Tunnel Authentication □ Enable Secret Password Local Host Name Remote Host Name Active as…

Example: L2TP VPN – Network (LAN) to Network (LAN) Connection

The branch office establishes a L2TP VPN tunnel with Headquarter office to connect two private networks over the Internet. The routers are installed in the Headquarter office and branch office accordingly.

NOTE: Both office LAN networks must be in different subnets with the LAN-LAN application.

graph LR A["Branch Office"] -->|192.168.0.254| B["Router"] C["Head Office"] -->|192.168.1.0/24| D["Router"] B <--> E["Internet"] D <--> E E <--> F["L2TP Client"] E <--> G["L2TP Server"] H["Public IP 69.121.1.33"] --> E I["Encryption Data"] --> E J["Vpn Connection"] --> E style A fill:#f9f,stroke:#33…

Configuring L2TP VPN Dial-in in the Headquarter office

The IP address 192.168.1.200 will be assigned to the router located in the branch office.

ItemDescription
Connection NameHS-LLAssigned name to this tunnel/profile
Connection ModeDial inOperate as L2TP server
Authentication TypeChap/PapAuthentication type
UsernameTestCredential for a PPTP client to dial-in to the network.
PasswordTest
Assigned IP192.168.1.200An IP assigned to the dial in client
Connection TypeLAN to LANLAN to LAN for dial in
Remote Network IP129.168.0.0Remote, Branch office, LAN network IP address and Netmask
Remote Network Netmask255.255.255.0

L2TP

Rule Index1 ▼
Connection NameHS-LL
ActiveYes No
Connection ModeDial in ▼
Authentication TypeChap/Pap ▼
Usernametest
Password......
Private IP Address assigned to Dial-in User192.168.1.200
Connection TypeLan to Lan ▼
Remote Network IP Address192.168.0.0
Remote Network Netmask255.255.255.0
Tunnel AuthenticationEnable
Secret Password
Local Host Name
Remote Host Name
Active as Default RouteEnable

L2TP Listing

IndexConnection NameActiveConnection ModeConnection Type
1HS-LLYesDial inLan to Lan

Configuring L2TP VPN Dial-out in the Branch office

The IP address 69.1.121.33 is the Public IP address of the router located in Headquarter office.

ItemDescription
Connection NameBC-LLAssigned name to this tunnel/profile
Connection ModeDial outOperate as L2TP client
Server IP69.121.1.33Dialed server IP
Authentication TypeChap/PapAuthentication type
UsernametestCredential from the PPTP server to dial-in to the network
Passwordtest
Connection TypeLAN to LANLAN to LAN for dial out
Remote Network IP129.168.1.0Remote, Headquarter office, LAN network IP address and Netmask
Remote Network Netmask255.255.255.0

L2TP

Rule Index1 ▼
Connection NameBC-LL
ActiveYes No
Connection ModeDial out ▼
Server IP Address69.121.1.33
Authentication TypeChap/Pap ▼
Usernametest
Password----
Connection TypeLan to Lan ▼
Remote Network IP Address192.168.1.0
Remote Network Netmask255.255.255.0
Tunnel AuthenticationEnable
Secret Password
Local Host Name
Remote Host Name
Active as Default RouteEnable

L2TP Listing

IndexConnection NameActiveConnection ModeConnection Type
1BC-LLYesDial outLan to Lan

GRE Tunnel

Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate a wide variety of network layer protocol packets inside virtual point-to-point links over an IP network.

NOTE: Up to 8 GRE tunnels supported.

GRE Rule Index 1 Connection Name Active ○ Yes ● No Interface EWAN(LAN1) Remote Gateway IP 0.0.0.0 Tunnel Local IP Address (Virtual Interface) 0.0.0.0 Tunnel Network Netmask (Virtual Interface) 0.0.0.0 Tunnel Remote IP Address (Virtual Interface) 0.0.0.0 Remote Network IP Address 0.0.0.0 Remote Netwo…

Rule Index: The numeric rule indicator for GRE. The maximum entry is up to 8.

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate this GRE profile.

Interface: Select a WAN interface to establish a tunnel with the remote VPN device.

Remote Gateway: Enter the remote GRE WAN IP address.

Tunnel Local IP Address & Remote IP address (Virtual Interface): Enter a virtual IP address for the local and peer network.

Tunnel Network Netmask (Virtual Interface): Enter the Netmask for this virtual interface.

NOTE: The virtual Local and Remote IP addresses must in same subnet and cannot be existed or used in both networks.

Remote Network IP Address Netmask: Enter remote LAN network IP address.

Remote Network Netmask: Enter remote LAN network Netmask.

Enable Keep-alive: Check the box to enable the keep-alive. The system will detect remote peer is still alive or lost. If no responses from the remote peer after certain times, #-of-retry-time x interval, the connection will get dropped.

Keep-alive Retry Times: Set the keep-alive retry times, default is 3.

Keep-alive Interval: Set the keep-alive Interval, unit in seconds. Default is 5 seconds.

Example: Keepalive retry time (3) x keepalive interval (5) = 15 seconds. If no responses for 15

seconds, GRE connection will get aborted.

MTU: Maximum Transmission Unit in byte. The size of the largest datagram (excluding media-specific headers) an IP attempts to send through the interface.

Active as Default Route: Select if to set the GRE tunnel as the default route.

IPSec: Click the checkbox to enable GRE tunnel over IPSec.

IPSec Enable IKE Mode Main IKE(IPSec) Local ID Default (Local WAN IP) IKE(IPSec) Remote ID Default (Remote Gateway IP) IKE(IPSec) Pre-Shared Key

IKE Mode: IKE, Internet Key Exchange, is the mechanism to negotiate and exchange parameters and keys between IPSec peers to establish security associations (SA). Select Main or Aggressive mode.

IKE (IPSec) Local ID Type and Remote ID Type: When the mode of IKE is aggressive, Local and Remote peers can be identified by other IDs.

IKE (IPSec) Pre-Shared Key: This is for the Internet Key Exchange (IKE) protocol, a string from 4 to 128 characters. Both sides should use the same key. IKE is used to establish a shared security policy and authenticated keys for services (such as IPSec) that require a key. Before any IPSec traffic can be passed, each router must be able to verify the identity of its peer. This can be done by manually entering the pre-shared key into both sides (router or hosts).

Click Save to apply settings.

Example: GRE VPN – Network (LAN) to Network (LAN) Connection

The branch office establishes a GRE VPN tunnel with Headquarter office to connect two private networks over the Internet. The routers are installed in the Headquarter office and branch office accordingly.

NOTE: Both office LAN networks must be in different subnets with the GRE VPN connection.

graph LR A["Branch Office"] -->|192.168.0.254| B["Router"] C["Public IP 69.121.1.30"] --> B D["Public IP 69.121.1.3"] --> B E["Public IP 69.121.1.3"] --> B F["Public IP 69.121.1.3"] --> B G["Public IP 69.121.1.3"] --> B H["Head Office"] -->|192.168.1.0/24| I["Router"] J["Virtual IP 192.168.100.10"]…

Configuring GRE connection in the Headquarter office

The IP address 69.1.121.30 is the Public IP address of the router located in branch office.

ItemDescription
Connection NameHS-LLAssigned name to this tunnel/profile
Remote Gateway IP69.121.1.30WAN IP address of Branch office
Tunnel Local IP Address (Virtual Interface)192.168.100.11Local and remote virtual interface IP address must be in same Netmask.
Tunnel Remote IP Address (Virtual Interface)192.168.100.10
Tunnel Network Netmask (Virtual Interface)255.255.255.0Network Netmask of this virtual interface.
Remote Network IP/ Netmask192.168.0.0/ 255.255.255.0The remote, branch office, LAN network IP and Netmask.

GRE Rule Index 1 ▼ Connection Name HS-LL Active ● Yes ○ No Interface 4G/LTE ▼ Remote Gateway IP 69.121.1.30 Tunnel Local IP Address (Virtual Interface) 192.168.100.11 Tunnel Network Netmask (Virtual Interface) 255.255.255.0 Tunnel Remote IP Address (Virtual Interface) 192.168.100.10 Remote Network I…

Configuring GRE connection in the Branch office

The IP address 69.1.121.3 is the Public IP address of the router located in Headquarter office.

ItemDescription
Connection NameBC-LLAssigned name to this tunnel/profile
Remote Gateway IP69.121.1.3WAN IP address of Headquarter office
Tunnel Local IP Address (Virtual Interface)192.168.100.10Local and remote virtual interface IP address must be in same Netmask.
Tunnel Remote IP Address (Virtual Interface)192.168.100.11
Tunnel Network Netmask (Virtual Interface)255.255.255.0Network Netmask of this virtual interface.
Remote Network IP/ Netmask192.168.1.0/ 255.255.255.0The remote, Headquarter office, LAN network IP and Netmask.

GRE Rule Index 1 ▼ Connection Name BC-LL Active ● Yes ○ No Interface 4G/LTE ▼ Remote Gateway IP 69.121.1.3 Tunnel Local IP Address (Virtual Interface) 192.168.100.10 Tunnel Network Netmask (Virtual Interface) 255.255.255.0 Tunnel Remote IP Address (Virtual Interface) 192.168.100.11 Remote Network IP…

OpenVPN

OpenVPN is an open source software application that implements virtual private network (VPN) techniques for creating secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It uses a custom security protocol that utilizes SSL/TLS for key exchange. OpenVPN can run over User Datagram Protocol (UDP) or Transmission Control Protocol (TCP) transports, multiplexing created SSL tunnels on a single TCP/UDP port. It is capable of traversing network address translation (NAT) and firewalls.

OpenVPN allows peers to authenticate each other using a pre-shared secret key, certificates, or username/password. Preshared secret key is the easiest, with certificate based being the most robust and feature-rich. It uses the OpenSSL encryption library extensively, allowing OpenVPN to use all the ciphers available in the OpenSSL package, as well as the SSLv3/TLSv1 protocol, and contains many security and control features.

It has integrated with OpenVPN package, allowing users to run OpenVPN in server or client mode from their network routers.

OpenVPN Server

NOTE: Up to 1 profile.

OpenVPN Server Rule Index 1 Connection Name Active ○ Yes ● No Local Service Port 1194 Tunnel Network (Virtual Interface) IP Address Local Access Range IP Address Protocol UDP Local Certificate Index Default Trusted CA Index Default Cryptographic Suite Cipher Default Hash Default Compression Adaptive…

Rule Index: The numeric rule indicator for OpenVPN.

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate this profile.

Local Service Port: Port 1194 is the default assigned port for OpenVPN

Tunnel Network (virtual Interface)

IP Address / Netmask: Enter a virtual IP address and Netmask for this tunnel.

NOTE: The virtual IP addresses cannot be existed or used in both networks.

Local Access Range

IP Address / Netmask: Enter local LAN network IP address and Netmask.

Protocol: OpenVPN can run over either UDP or TCP transports. Select the protocol.

Local Certificate / Trusted CA Index: OpenVPN mutually authenticate the server and client based on certificates and CA. Select a certificate and CA.

To import certificates and CAs, go to Maintenance >> Certificate Management to upload files. Otherwise, select Default certificate and CA.

Cryptographic Suite

Cipher: OpenVPN uses all the ciphers available in the OpenSSL package to encrypt both the data and channels. Select an encryption method.

Hash: To establish the integrity of the datagram and ensures it is not tampered with in transmission. There are options: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA1, SHA256). SHA1 is more resistant to brute-force attacks than MD5. However, it is slower.

Compression: Choose adaptive to use the LZO compression library to compress the data stream.

Keepalive: Check the box to enable the keep-alive. The system will automatic send ping packet to remote peer to keep the tunnel active.

Interval: Set the keep-alive Interval, unit in seconds. Default is 10 seconds. Valid interval range is from 0 to 3600 seconds.

Timeout: Re-establish tunnel if no responses from peer network after timeout period expires. Default is 120 seconds.

Click Save to apply settings.

OpenVPN Client

OpenVPN client must match the VPN information / settings with the OpenVPN Server.

NOTE: Up to 4 tunnels supported.

OpenVPN Client Rule Index 1 ▼ Connection Name Active ○ Yes ○ No Server IP Address or Domain Name Port Number 1194 Active as Default Route ○ Yes ○ No Remote Subnet IP Address Netmask 255.255.255.0 Protocol UDP ▼ Local Certificate Index Default ▼ Trusted CA Index Default ▼ Cryptographic Suite Cipher D…

Rule Index: The numeric rule indicator for OpenVPN. Maximum up to 4 profile/tunnels

Connection Name: Enter a description for this connection/profile.

Active: Yes to activate this profile.

Server IP Address or Domain Name: Enter OpenVPN Server's WAN IP address or Domain name.

Service Port: Port 1194 is the official assigned port number for OpenVPN

Active as Default Route: Choose Yes to let the OpenVPN tunnel/connection be the default route for traffic, under this circumstance, all outgoing packets will be forwarded to this tunnel and routed to the next hop.

Remote Subnet

IP Address / Netmask: Enter the LAN network IP address and Netmask of the OpenVPN Server.

Protocol: OpenVPN can run over either UDP or TCP transports. Select the protocol.

Local Certificate / Trusted CA Index: OpenVPN mutually authenticate the server and client based on certificates and CA. Select a certificate and CA.

To import certificates and CAs, go to Maintenance >> Certificate Management to upload files. Otherwise, select Default certificate and CA.

Cryptographic Suite

Cipher: OpenVPN uses all the ciphers available in the OpenSSL package to encrypt both the data and channels. Select an encryption method.

Hash: To establish the integrity of the datagram and ensures it is not tampered with in transmission. There are options: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA1, SHA256). SHA1 is more resistant to brute-force attacks than MD5. However, it is slower.

Compression: Choose adaptive to use the LZO compression library to compress the data stream.

Keepalive: Check the box to enable the keep-alive. The system will automatic send ping packet to remote peer to keep the tunnel active.

Interval: Set the keep-alive Interval, unit in seconds. Default is 10 seconds. Valid interval range is from 0 to 3600 seconds.

Timeout: Re-establish tunnel if no responses from peer network after timeout period expires. Default is 120 seconds.

Click Save to apply settings.

Example: OpenVPN – Network (LAN) to Network (LAN) Connection

The Branch office establishes a tunnel with Headquarter office to connect two private networks over the OpenVPN.

NOTE: Both office LAN networks must be in different subnets with the GRE VPN connection.

graph LR A["Branch Office"] -->|192.168.0.254| B["Router"] C["Public IP 69.121.1.30"] --> B D["Public IP 69.121.1.3"] --> B E["Head Office"] -->|192.168.1.254| F["Router"] G["Virtual Interface 192.168.100.0/24"] -->|Encryption Data| H["OpenVPN"] I["Virtual Interface 192.168.100.0/24"] --> H B <--> H…

Configuring OpenVPN server in Headquarter office

The IP address 69.1.121.30 is the WAN IP address of the router located in the Branch office.

The OpenVPN tunnel network virtual interface is set to 192.168.100.0/24.

ItemDescription
Connection NameHS-LLAssigned name to this tunnel/profile
Tunnel Network (Virtual Interface)192.168.100.0/255.255.255.0IP address & Netmask of the virtual tunnel.
Local Access Range192.168.0.0/255.255.255.0OpenVPN Server's local LAN network.

OpenVPN Server

Rule Index

BEC Technologies MX-200A ODU - OpenVPN Server - 1

Connection Name

HS-LL

Active

BEC Technologies MX-200A ODU - OpenVPN Server - 2

BEC Technologies MX-200A ODU - OpenVPN Server - 3

BEC Technologies MX-200A ODU - OpenVPN Server - 4

Local Service Port

BEC Technologies MX-200A ODU - OpenVPN Server - 5

Tunnel Network (Virtual interface)

IP Address

192.168.100.0

Netmask

255.255.255.0

Local Access Range

IP Address

192.168.0.0

Netmask

255.255.255.0

Protocol

BEC Technologies MX-200A ODU - Local Access Range - 1

Local Certificate Index

BEC Technologies MX-200A ODU - Local Access Range - 2

Trusted CA Index

BEC Technologies MX-200A ODU - Local Access Range - 3

Cryptographic Suite

Cipher

Default

BEC Technologies MX-200A ODU - Cryptographic Suite - 1

Hash

Default

Compression

BEC Technologies MX-200A ODU - Cryptographic Suite - 2

Keepalive

BEC Technologies MX-200A ODU - Cryptographic Suite - 3

Enable

Interval

10

second(s)

Timeout

120

second(s)

Save

Delete

Configuring OpenVPN client in Branch office

The IP address 69.1.121.3 is the WAN IP address of the router located in Headquarter office.

ItemDescription
Connection NameBC-LLAssigned name to this tunnel/profile
Server IP Address69.121.1.3The WAN IP address of OpenVPN server.
Remote Subnet192.168.0.0/255.255.255.0Local LAN IP & Netmask of the Branch office

OpenVPN Client Rule Index 1 ▼ Connection Name BC-LL Active ● Yes ○ No Server IP Address or Domain Name 69.121.1.3 Port Number 1194 Active as Default Route ○ Yes ● No Remote Subnet IP Address 192.168.0.0 Netmask 255.255.255.0 Protocol UDP ▼ Local Certificate Index ClientLCA1 ▼ Trusted CA Index Client…

Access Management

Device Management

Device Management Device Host Name Host Name home.gateway Save Embedded Web Server HTTP Port 80 (The default HTTP port number is 80.) HTTPS Port 443 (The default HTTPS port number is 443.) HTTPS Server Certificate Index Default ▼ Save

Device Host Name

Host Name: Enter the host name of the router. Default is home.gateway

Embedded Web Server

HTTP Port: It is the embedded web server (Web GUI) accessing port, default is 80. It can be changed other port other than port 80, e.g. port 8080.

HTTPS Port: Similar to HTTP which is an unencrypted communication using port 80. HTTPS is encrypted by SSL using port 443 instead.

HTTPS Server Certificate Index: HTTPS known as HTTP-over-SSL tunnel protocol. Select a certificate to identify the system web server. When accessing to the web server (Web GUI), the browser will issue a warning page.

To import certificates, go to Maintenance >> Certificate Management to upload files. Otherwise, select Default certificate and CA.

Click Save to apply settings.

SNMP

Simple Network Management Protocol (SNMP) is a protocol used for exchanging management information between network devices. The MX-200A ODU serves as a SNMP agent that allows a manager station to manage and monitor the router through the network.

SNMP SNMP ○ Activated ● Deactivated Get Community Set Community Trap Manager IP 0.0.0.0 System Name System Location System Contact SNMPv3 SNMPv3 ○ Enable ● Disable Username Access Permissions Read Only ▼ Authentication Protocol MD5 ▼ Authentication Key (8~31 characters) Privacy Protocol DES ▼ Privac…

SNMP: Activate to enable SNMP.

Get Community: Type the Get Community, which is the password for the incoming Get-and-GetNext requests from the management station.

Set Community: Type the Set Community, which is the password for incoming Set requests from the management station.

Trap Manager IP: Enter the IP of the server receiving the trap message (when some exception occurs) sent by this SNMP agent.

System Name / Location / Contact: String descriptions of the SNMP agent.

SNMPv3

SNMPv3: Enable to activate the SNMPv3.

User Name: Enter the name allowed to access the SNMP agent.

Access Permissions: Set the access permissions for the user; RO--read only and RW--read and writer.

Authentication Protocol: Select the authentication protocol, MD5 and SHA. SNMP agent can communicate with the manager station through authentication and encryption to secure the message exchange. Set the authentication and encryption information here and below.

Authentication Key: Set the authentication key, 8-31 characters.

Privacy Protocol: Select the privacy mode, DES and AES.

Privacy Key: Set the privacy key, 8-31 characters.

Click Save to apply settings.

Syslog

Use the Syslog to collect system event information to a remote log server.

Syslog Remote System Log ○ Activated ● Deactivated Server IP Address 0.0.0.0 Server UDP Port 514 Save

Remote System Log: Select Activated to enable this feature

Server IP Address: Assign the remote log server IP address.

Server UDP Port: Assign the remote log server port, 514 is commonly used.

Click Save to apply settings.

Universal Plug & Play

UPnP offers peer-to-peer network connectivity for PCs and other network devices, along with control and data transfer between devices. UPnP offers many advantages for users running NAT routers through UPnP NAT Traversal, and on supported systems makes tasks such as port forwarding much easier by letting the application control the required settings, removing the need for the user to control advanced configuration of their device.

Both the user's Operating System and the relevant application must support UPnP in addition to the router.

Universal Plug & Play
UPnP○ Activated ○ Deactivated
Auto-configured○ Activated ● Deactivated (by UPnP-enabled Application)
Save

UPnP: Select this checkbox to activate UPnP. Be aware that anyone could use an UPnP application to open the web configuration's login screen without entering the MX-200A ODU's IP address

Auto-configured: Select this check box to allow UPnP-enabled applications to automatically configure the MX-200A ODU so that they can communicate through the MX-200A ODU, for example by using NAT traversal, UPnP applications automatically reserve a NAT forwarding port in order to communicate with another UPnP enabled device; this eliminates the need to manually configure port forwarding for the UPnP enabled application.

Click Save to apply settings.

Dynamic DNS (DDNS)

The Dynamic DNS function allows you to alias a dynamic IP address to a static hostname, allowing users whose ISP does not assign them a static IP address to use a domain name. This is especially useful for hosting servers via your internet connection, so that anyone wishing to connect to you may use your domain name, rather than having to use your dynamic IP address, which changes from time to time. This dynamic IP address is the WAN IP address of the router, which is assigned to you by your ISP.

Here users can register different WAN interfaces with different DNS Providers.

If you do not have a DDNS account, please choose a DDNS Service Provider from the list then go to their website to create an account first.

Dynamic DNS Dynamic DNS ○ Activated ● Deactivated Service Provider www.dyndns.org (dynamic) ▼ My Host Name Username Password Wildcard support ○ Yes ● No Period 25 Day(s) ▼ Save

Dynamic DNS: Select this check box to activate Dynamic DNS.

Service Provider: Select from drop-down menu for the appropriate service provider, for example: www.dyndns.org.

My Host Name: Type the domain name assigned to your MX-200A ODU by your Dynamic DNS provider.

Username / Password: Enter the user name and password of the account you created with this service provider.

Wildcard support: Select this check box to enable DYNDNS Wildcard.

Period: Set the time period on how often the MX-200A ODU will update the DDNS server with your current external IP address.

Click Save to apply settings.

Example: How to register a DDNS account

If you do not have an account with Dynamic DNS, please go to www.dyndns.org to register an account first.

User test1 register a Dynamic Domain Names in DDNS provider http://www.dyndns.org/.

DDNS: www.hometest.com using username/password test/test

Dynamic DNS Dynamic DNS ● Activated ○ Deactivated Service Provider www.dyndns.org (dynamic) ▼ My Host Name=myhome.dyndns.org Username=myhome-123 Password---------------------------- Wildcard support ○ Yes ● No Period 25 Day(s) ▼ Save

Access Control

Access Control Listing allows you to determine which services/protocols can access the MX-200A ODU interface from which computers. It is a management tool aimed to allow IPs (set in secure IP address) to access specified embedded applications (Web, etc., user can set) through some specified interface (LAN, WAN or both). User can have an elaborate understanding in the examples below.

The maximum number of entry is 16.

Access Control
Access Control○ Activated ○ Deactivated
Access Control Editing
Rule Index0 ▼
Active○ Yes ○ No
Secure IP Address0.0.0.0 ~ 0.0.0.0 (0.0.0.0 ~ 0.0.0.0 means all IPs)
ApplicationALL ▼
InterfaceLAN ▼
Save Delete
Access Control Listing
IndexActiveSecure IP AddressApplicationInterface
0Yes0.0.0.0-0.0.0.0ALLLAN
1Yes0.0.0.0-0.0.0.0PingWAN

Access Control: Select whether to make Access Control function available.

Rule Index: The numeric rule indicator.

Active: Yes to activate the rule.

Secure IP Address: The default 0.0.0.0 allows any client to use this service to manage the MX-200A ODU. Type an IP address range to restrict access to the client(s) without a matching IP address.

Application: Choose a service that you want to all access to all the secure IP clients. The drop-down menu lists all the common used applications.

Interface: Select the access interface. Choices are LAN, WAN and Both.

Click Save to apply settings.

By default, the "Access Control" has two default rules.

Default Rule 1: (Index 1), a rule to allow only clients from LAN to have access to all embedded applications (Web, FTP, etc.). Under this situation, clients from WAN cannot access the router even from Ping.

Access Control Access Control Activated Deactivated Access Control Editing Rule Index 1 Active Yes No Secure IP Address 0.0.0.0 ~ 0.0.0.0 (0.0.0.0 ~ 0.0.0.0 means all IPs) Application ALL Interface LAN Save Delete Access Control Listing Index Active Secure IP Address Application Interface 1 Yes 0.0.…

Default Rule 2: (Index 2), an ACL rule to open Ping to WAN side.

Access Control Access Control Activated Deactivated Access Control Editing Rule Index 2 Active Yes No Secure IP Address 0.0.0.0 ~ 0.0.0.0 (0.0.0.0 ~ 0.0.0.0 means all IPs) Application Ping Interface WAN Save Delete Access Control Listing Index Active Secure IP Address Application Interface 1 Yes 0.0…

Packet Filter

You can filter the packages by MAC address, IP address, Protocol, Port number and Application or URL.

Filter Type - IP & MAC Filter

Packet Filter
Packet Filter
Filter TypeIP & MAC Filter ▼
IP & MAC Filter Editing
ActionBlack List ▼
Rule Index1 ▼
Individual Active○ Yes ● No
Interface4G/LTE ▼
DirectionBoth ▼
TypeIPv4 ▼
Source IP Address0.0.0.0 (0.0.0.0 means Don't care)
Source Subnet Mask0.0.0.0 (0 means Don't care)
Source Port Number0 (0 means Don't care) (0.0.0.0 means Don't care) (0.0.0.0 means Don't care) (0 means Don't care) (0 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range:0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 meansDon't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0~64, 64 means Don't care) (Value Range: 0-64, 64 means Don't care) (Value Range: 0-64, 64 means Don't care) (Value Range: 0-64, 64 means Don't care) (Value Range: 0-64, 64 means Don't care) (Value Range: 0-64, 64 means Don't care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-64, 64 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: 0-63, 63 means Don't Care) (Value Range: All or All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/All/Allyways ▼(✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) (✓) ( ✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ) (✓ ),(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )(✓ )\( \left\lbrack {1 - {1.2}}\right\rbrack \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \left\lbrack {1 - {1.2}}\right\rbrack \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot \cdot {\mathrm{N}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} + {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} + {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} + {1.2}}\right) ,\;{\mathrm{N}}^{\prime }\left( {{1.2} + {1.2}}\right) ,\;{\mathrm{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\mathrm{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\textbf{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\textbf{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\textbf{Nf}}^{\prime }\left( {{1.2} - {1.2}}\right) ,\;{\textbf{Nf}}^{\prime }\left(\textbf{N}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left(\textbf{N}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1.2}}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2} - {1}.7}\right)\left( {{1.2}^{*}, * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * **(a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,v,w,v,w,v,u,v,w,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,u,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v,U,v U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,U,V,\mathbf{A}_{i,j,k,l,m,n,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,O,\mathbf{A}_{i,j,k,l,m,n,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,o,\mathbf{A}_{i,j,k,l,m,n:o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.c,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.o.c,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.o.o.o.o.o.c,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.o.o.c,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.o.c,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*b,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.a,b,c,de,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,c,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,d,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,D,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,D,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,D,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,D,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,C,D,e,f,g,h,i,k,l,m,n:o.o.c.*a,b,C,a,b,CD,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,CD,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,A,B,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,A B,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,ABB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,AAB,C,D,E,F,G,H,I,M,ABB,C,D,E,F,G,H,I,M,ABB,C,D,EF,G,H,I,M,ABB,C,D,EF,G,H,I,M,ABB,C,D,EF,G,H,I,M,ABB,C,D,EF,G,H,I,M,ABB,C,D,EF,G,H,I,M,ABB,C,DE F G H I M A C Filter List Index Active Interface Direction Source IP(IPv6) Address/Mask(Prefix) Destination IP(IPv6) Address/Mask(Prefix) Source MAC Filter Source IP(IPv6) Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter Address/Mask(Prefix) Source MAC Filter

IP & MAC Filter Editing

Rule Index: The numeric rule indicator.

Individual Active: Yes to enable the rule.

Action: This is how to deal with the packets matching the rule. Allow please select White List or Black selecting Black List.

Interface: Select to determine which interface the rule will be applied to.

Direction: Select to determine whether the rule applies to outgoing packets, incoming packets or packets of both directions.

Type: Choose type of field you want to specify to monitor. Select "IPv4" for IPv4 address, port number and protocol. Select "IPv6" for IPv6 address, port number and protocol. Select "MAC" for MAC address.

IPv4

Source IP Address 0.0.0.0 (0.0.0.0 means Don't care) Source Subnet Mask 0.0.0.0 Source Port Number 0 (0 means Don't care) Destination IP Address 0.0.0.0 (0.0.0.0 means Don't care) Destination Subnet Mask 0.0.0.0 Destination Port Number 0 (0 means Don't care) DSCP 0 (Value Range:0~64, 64 means Don't…

Source IP Address: The source IP address of packets to be monitored. 0.0.0.0 means "Don't care".

Source Subnet Mask: Enter the subnet mask of the source network.

Source Port Number: The source port number of packets to be monitored. 0 means "Don't care".

Destination IP Address: The destination IP address of packets to be monitored. 0.0.0.0 means "Don't care".

Destination Subnet Mask: Enter the subnet mask of the destination network.

Destination Port Number: This is the Port that defines the application. (E.g. HTTP is port 80.)

DSCP: DSCP: Differentiated Services Code Point, it is recommended that this option be configured by an advanced user or keep 0. (0 means Don't care.)

Protocol: Specify the packet type (TCP, UDP, ICMP, and ICMPv6) that the rule applies to.

IPv6

Source IPv6 Address 0:0:0:0:0:0:0 (0:0:0:0:0:0:0 means Don't care) Source IPv6 Prefix 32 Source Port Number 0 (0 means Don't care) Destination IPv6 Address 0:0:0:0:0:0:0 (0:0:0:0:0:0:0 means Don't care) Destination IPv6 Prefix 32 Destination Port Number 0 (0 means Don't care) DSCP 0 (Value Range:0~6…

Source IP (IPv6) Address/ Prefix: The source IP address or range of packets to be monitored.

Source Port Number: The source port number of packets to be monitored.

Destination IP (IPv6) Address/ Prefix: The destination subnet IP address.

Destination Port Number: This is the Port or Port Ranges that defines the application.

DSCP: show the set DSCP.

Protocol: It is the packet protocol type used by the application. Select either TCP or UDP or

ICMP or ICMPv6

▶ MAC

Type MAC Source MAC Address

Source MAC Address: show the MAC address of the rule applied.

Click Save to apply settings.

Filter Type- URL Filter

Packet Filter Packet Filter Filter Type URL Filter URL Filter Editing URL Filter Activated Deactivated URL Filter Rule Index 1 Individual Active Yes No URL (Host) Save Delete URL Filter Listing Index Active URL

URL Filter: Select Activated to enable URL Filter.

URL Filter Rule Index: The numeric rule indicator.

Individual Active: To give control to the specific URL access individually, for example, you want to prohibit access to www.yahoo.com, please first press Activated in "URL Filter" field, and also Yes in "Individual Active" field; if some time you want to allow access to this URL, you simply select No in individual active field. In a word, the command serves as a switch to the access of some specific URL with the filter on.

URL (Host): Specified URL which is prohibited from accessing.

Click Save to apply settings.

CWMP (TR-069)

CWMP, short for CPE WAN Management Protocol, also called TR069 is a Broadband Forum technical specification entitled CPE WAN Management Protocol (CWMP). It defines an application layer protocol for remote management of end-user devices. It defines an application layer protocol for remote management of end-user devices.

As a bidirectional SOAP/HTTP based protocol it can provides the communication between customer premises equipment (CPE) and Auto Configuration Server (ACS). It includes both a safe configuration and the control of other CPE management functions within an integrated framework. In the course of the booming broadband market, the number of different internet access possibilities grew as well (e.g. modems, routers, gateways, set-top box, VoIP-phones). At the same time the configuration of this equipment became more complicated –too complicated for end-users. For this reason, TR-069 was developed. It provides the possibility of auto configuration of the access types. Using TR-069 the terminals can get in contact with the Auto Configuration Servers (ACS) and establish the configuration automatically and let ACS configure CPE automatically.

CWMP (TR-069) CWMP ○ Activated ● Deactivated ACS Login Information URL http://cpe.bectechnologies.com/comserver/node1/tr069 Usernamealedtestcpe Password ac5entry Connection Request Information Path Username conexant Password welcome Periodic Inform Config Periodic Inform ○ Activated ○ Deactivated In…

CWMP: Select activated to enable CWMP.

ACS Login Information

URL: Enter the ACS server login URL.

User Name: Specify the ACS User Name for ACS authentication to the connection from CPE.

Password: Enter the ACS server login password.

Connection Request Information

Path: Local path in HTTP URL for an ACS to make a Connection Request notification to the CPE.

Username: Username used to authenticate an ACS making a Connection Request to the CPE.

Password: Password used to authenticate an ACS making a Connection Request to the CPE.

Periodic Inform Config

Periodic Inform: Select Activated to authorize the router to send an Inform message to the ACS automatically.

Interval(s): Specify the inform interval time (sec) which CPE used to periodically send inform message to automatically connect to ACS. When the inform interval time arrives, the CPE will send inform message to automatically connect to ACS.

Bind WAN Interface

Interface: Specify any available or a single WAN interface to handle TR-069 requests.

NATT Config - This is a proprietary feature provided by BEC. May leave them in blank, no configuration is required.

NATT Server: By BEC administrator only.

NATT Period: By BEC administrator only.

Click Save to apply settings.

Parental Control

This feature provides Web content filtering offering safer and more reliable web surfing for users especially for parents to protect network security and control the contents for children at home.

Parental Control Provider www.opendns.com Parental Control ○ Activated ● Deactivated Host Name Username Password **Parental Control provides Web content filtering while surfing the web safer and more reliable. Please get an account and configure at the selected Provider in advance. Save

To activate this feature, please log on to www.opendns.com to get an OpenDNS account first.

Parent Control Provider: Hosted by www.opendns.com

Parent Control: Enable the feature by clicking the Activated

Host Name: It is the domain name of your OpenDNS. If you don't have one, please leave it blink.

Username / Password: Put down your OpenDNS account username and password Click Save to apply settings.

BECentral Management

BECentral is a cloud based device management platform that provides operators with a comprehensive suite of services to manage devices in real-time.

BECentral Management BECentral Management ○ Activated ● Deactivated BECentral Management URL becentral.becloud.io BECentral Management Port 48883 Organization ID DEFAULT Device Report Interval 480 Interface ALL ▼ Save

BECentral Management: Activate to enable the feature.

BECentral Management URL: Access path to the BECentral.

BECentral Management Port: Port listened by the BECentral.

Organization ID: Customer ID

Device Report Interval: Enter the interval time in seconds to send inform message periodically to the BECentral.

Interface: Specify any available or a single WAN interface to handle BECentral requests.

Maintenance

User Management

User Management provides the Administrator with the ability to grant access control and manage GUI login credentials for each user.

There are two access management levels, Administrator and User.

The default root account, Administrator (admin), has full access to all the features listed and ability to create other accounts with features to allow other users to access to. The User account is with limited access (specified by advanced users with admin account) to the GUI.

Total of 8 accounts can be created to grant access to manage the MX-200A ODU via the web page.

Administrator Account

admin/admin is the root/default account username and password.

NOTE: This username / password may vary by different Internet Service Providers.

Login using the Administrator account, you will have the full accessibility to manage & control your gateway device and can also create user accounts for others to control some of the open configuration settings.

User Management User Account Index 1▼ Username hemadmin New Password **** Confirm Password **** Save Delete User Account Listing Index User Name 1 admin 2icer

User Setup

Index: The numeric account indicator. The maximum entry is up to 8 accounts.

User Name: Create account(s) user name for GUI management.

New Password: Enter a new password for this user account.

Confirmed Password: Re-enter the new password again; you must enter the password exactly the same as in the previous field

User Account

user/user is the default user account username and password

NOTE: This username / password may vary by different Internet Service Providers.

User Management User Account Index 2 ▼ Usernameicer New Password **** Confirm Password **** Web GUI Permission Guest Account ○ Enable ○ Disable Interface Setup ○ Enable ○ Disable Advanced Setup ○ Enable ○ Disable VPN Setup ○ Enable ○ Disable Access Management ○ Enable ○ Disable Maintenance ○ Enable…

User Account Setup

Index #: The numeric account indicator. The maximum entry is up to 8.

Username: Create account(s) user name for GUI management.

New Password: Password for the user account.

Confirm Password: Re-enter the password.

Web GUI Permission

Guest Account: Enable to create this new guest account.

Interface Setup / Advanced Setup / VPN Setup / Access Management / Maintenance: Enable to grant this user access to these features.

When someone accesses to the MX-200A ODU using this "user" account, he/she can only manage and configure the features that is pre-selected in Web GUI Permission for this account.

Click Save to apply settings.

Certificate Management

This feature is used for OpenVPN and HTTPS Server authentication of the device using certificate. If the imported certificate doesn't match the authorized certificate with the Server then no access is allowed.

Local Certificate Listing
IndexCertificate NameEditDelete
1
2
Trusted CA Listing
IndexCertificate NameEditDelete
1
2

Edit: Click (Edit) to import a certificate.

Delete: Click (Delete) to remove the certificate from the list.

Local Certificate Listing
Local Certificate Index 1 ▼ Certificate Name PKCS12 Certificate File Choose File No file chosen Upload(Please upload Certificate File. ) Private Key File Choose File No file chosen Upload(Please upload Private Key File. ) Password ...... After clicked "Upload", please wait for 5 seconds and then cli…

Index #: The numeric account indicator. The maximum entry is up to 2.

Certificate Name: Description of the certificate.

PKCS12: Every certificate is accompanied by a private key. Upload both files if PKCS is disabled. Enable PKCS12 to put Certificate & Private Key in the same file, like *.p12, *.pfx.

Certificate File: Browse to locate the target certificate file on PC before uploading it.

Private Key File: Browse to locate the target file on PC before uploading it. If PKCS enabled, please ignore this setting.

Password: Enter the password if any, which is used to protect the private key. Otherwise, leave it empty.

Click Apply to save settings.

Trusted CA Listing

Trusted CA Index 1 ▼ CA Name CA Certificate File Choose File No file chosen Upload (Please upload CA Certificate File. ) After clicked "Upload", please wait for 5 seconds and then click "Apply". Apply Back

Index #: The numeric account indicator. The maximum entry is up to 2.

CA Name: Description of the CA.

CA Certificate File: Browse to locate the target certificate file on PC before uploading it.

Click Apply to save settings.

Time Zone

With default, MX-200A ODU does not contain the correct local time and date.

There are several options to setup, maintain, and configure current local time/date on the MX-200A ODU. If you plan to use Time Schedule feature, it is extremely important you set up the Time Zone correctly.

Time Zone Current Date/Time N/A (Can't find NTP server) Time Synchronization Synchronize time with ● NTP Server ○ PC's Clock ○ Manually Time Zone (GMT-06:00) Central Time (US & Canada), Maxico City, Saskatchewan ▼ Daylight Saving ○ Enabled ● Disabled NTP Server Address 0.0.0.0 (0.0.0.0: Default Valu…

Synchronize time with: Select the methods to synchronize the time.

▶ NTP Server automatically: To synchronize time with the SNTP servers to get the current time from an SNTP server outside your network then choose your local time zone. After a successful connection to the Internet, MX-200A ODU will retrieve the correct local time from the SNTP server this is specified.
PC's Clock: To synchronize time with the PC's clock.
▶ Manually: Select this to enter the SNMP server IP address manually.

◆ Date: Month / Date / Year. Month – 1 \~ 12 (January \~ December).
◆ Time: Hour: Minute: Second

Time Zone: Choose the time zone of your location. This will set the time difference between your time zone and Greenwich Mean Time (GMT).

Daylight Saving: Select this option if you use daylight savings time.

NTP Server Address: Enter the IP address of your time server. Check with your ISP/network administrator if you are unsure of this information.

Click Save to apply settings.

Firmware & Configuration

Firmware is the software that controls the hardware and provides all functionalities which are available in the GUI. This software may be improved and/or modified; your MX-200A ODU provides an easy way to update the code to take advantage of the changes.

To upgrade the firmware of the MX-200A ODU, you should download or copy the firmware to your local environment first. Click “Choose File” to specify the path of the firmware file. Then, click “Upgrade” to start upgrading process. After completing the firmware upgrade, the MX-200A ODU will automatically restart and run the new firmware.

Firmware & Configuraiton Upgrade ● Firmware ○ Configuration System Restart with ● Current Settings ○ Factory Default Settings File Choose File No file chosen Backup Configuration Backup Status It might take several minutes, don't power off it during upgrading. Device will restart after the upgrade.…

Upgrade: Choose Firmware or Configuration you want to update.

System Restart with:

  • Current Settings: Restart the device with the current settings automatically when finishing upgrading.
    ▶ Factory Default Settings: Restart the device with factory default settings automatically when finishing upgrading.

File: Type in the location of the file you want to upload in this field or click Browse to find it.

Choose File: Click "Choose File" to find the configuration file or firmware file you want to upload. Remember that you must extract / decompress / unzip the .zip files before you can upload them.

Backup Configuration: Click Backup button to back up the current running configuration file and save it to your computer in the event that you need this configuration file to be restored back to your MX-200A ODU device when making false configurations and want to restore to the original settings.

Upgrade: Click "Upgrade" to begin the upload process. This process may take up to two minutes.

Firmware Upgrade File upload succeeded, starting flash erasing and programming!! Progress Percent 15 %

BEC Technologies MX-200A ODU - System Restart with: - 2

DO NOT turn off or power cycle the device while firmware upgrading is still in process.

Improper operation could damage your MX-200A ODU.

System Restart

Click System Restart with option Current Settings to reboot your router.

System Restart System Restart with Current Settings Factory Default Settings Restart

If you wish to restart the router using the factory default settings (for example, after a firmware upgrade or if you have saved an incorrect configuration), select Factory Default Settings to restore to factory default settings.

You may also restore your router to factory settings by holding the small Reset pinhole button on the back of your router in about more than 6s seconds whilst the router is turned on.

Auto Reboot

Schedule an automatic reboot for your MX-200A ODU to ensure proper operation and best performance.

This reboot will only reboot with current configuration settings and not overwrite any existing settings.

Auto Reboot Schedule 1. □ Enable □ Mon. □ Tues. □ Wed. □ Thur. □ Fri. □ Sat. □ Sun. Time 00 :00 2. □ Enable □ Mon. □ Tues. □ Wed. □ Thur. □ Fri. □ Sat. □ Sun. Time 00 :00 Save

Click Save to apply settings

Example: Schedule MX-200A ODU to reboot at 10:00pm (22:00) every weekday (Monday thru Friday) and reboot at 9:00am on Saturday and Sunday.

Auto Reboot Schedule 1. ✓ Enable ✓ Mon. ✓ Tues. ✓ Wed. ✓ Thur. ✓ Fri. □ Sat. □ Sun. Time 22 :00 2. ✓ Enable □ Mon. □ Tues. □ Wed. □ Thur. □ Fri. □ Sat. □ Sun. Time 09 :00 Save

Diagnostics Tool

The Diagnostic Test page shows the test results for the connectivity of the physical layer and protocol layer for both LAN and WAN sides.

Ping other IP Address: Click Yes if you wish to ping other IP address rather than google.com

Click START to begin to diagnose the connection.

Diagnostic Tool WAN Interface 4G/LTE Testing Ethernet LAN Connection N/A Ping Primary DNS ( N/A ) N/A Ping www.google.com N/A Ping other IP Address ○ Yes ● No N/A Start

Trace Route is to display how many hops (also view the exact hops) the packet of data has to take to get to the destination.

Click Yes, enter the IP address or domain then Start Trace Route.

Trace Route Yes No IP Address or Domain Max TTL Value 16 [2-30] Start Trace Route

IP Address or Domain: Set the destination host (IP, domain name) to be traced.

Max TTL value: Set the max Time to live (TTL) value.

Shown as we "trace" www.billion.com below.

traceroute to www.billion.com (125.227.205.188), 16 hops max, 60 byte packets 1 172.16.1.254 (172.16.1.254) 0.472 ms 0.488 ms 0.643 ms 2 122.96.153.233 (122.96.153.233) 7.354 ms 7.517 ms 7.704 ms 3 221.6.12.69 (221.6.12.69) 7.921 ms 8.108 ms 8.256 ms 4 221.6.1.253 (221.6.1.253) 8.392 ms 8.544 ms * 5…

LAN

Diagnostic Tool WAN Interface LAN Testing Ethernet LAN Connection PASS Ping other IP Address or Domain Yes No Skipped IP Address or Domain N/A Start

Ping other IP Address: Click Yes to ping any desired IP address or a domain.

Click START to begin to diagnose the connection.

Chapter 5: Troubleshooting

If your MX-200A ODU is not functioning properly, you can refer to this chapter for simple troubleshooting before contacting your service provider support. This can save you time and effort but if symptoms persist, consult your service provider.

Problems with the Router

ProblemSuggested Action
You have forgotten your login username or passwordTry the default username "admin" and password "admin". If this fails, you can restore your router to its factory settings by pressing the reset button on the device rear side.

Problem with LAN Interface

ProblemSuggested Action
Cannot PING any PC on LANCheck the Ethernet LEDs on the front panel. The LED should be on for the port that has a PC connected. If it does not lit, check to see if the cable between your router and the PC is properly connected. Make sure you have first uninstalled your firewall program before troubleshooting.
Verify that the IP address and the subnet mask are consistent for both the router and the workstations.

APPENDIX: PRODUCT SUPPORT & CONTACT

If you come across any problems please contact the dealer from where you have purchased the product.

Contact BEC @ http://www.bectechnologies.net

MAC OS is a registered Trademark of Apple Computer, Inc.

Windows 10/8/7 and Windows Vista are registered Trademarks of Microsoft Corporation

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : BEC Technologies

Model : MX-200A ODU

Category : Router