ETIC SIG Manuale utente

SIG
TLS or IPSec VPN server
_________________
User manual
Document reference : 9017409-01
_________________

The SIG router & VPN server is manufactured by
ETIC TELECOM
13 Chemin du vieux chêne
38240 MEYLAN
FRANCE
TEL : + (33) (0)4-76-04-20-05
FAX : + (33) (0)4-76-04-20-01
web : www.etictelecom.com

CONTENT
SIG Router & VPN server User’s guide ref. 9017409-01 Page 3
PRESENTATION
1TECHNICAL DATA......................................................................................................7
2OVERVIEW..................................................................................................................9
INSTALLATION
1PRODUCT DESCRIPTION........................................................................................10
2INSTALLATION.........................................................................................................11
CONFIGURATION
1CONFIGURING THE SIG ROUTER ..........................................................................13
1.1 Overview.......................................................................................................13
1.2 First configuration .......................................................................................14
1.3 Modifying the configuration........................................................................15
2REBOOTING THE ROUTER AFTER PARAMETERS CHANGES...........................16
3RECOVERING THE IP ADDRESS OF THE ROUTER..............................................16
4RECOVERING THE FACTORY CONFIGURATION.................................................16
5RESTRICTING ACCESS TO THE ADMINISTRATION SERVER.............................17
6ASSIGNING IP ADDRESSES TO THE LAN AND THE WAN INTERFACES ..........18
6.1 Principles of operations..............................................................................18
6.2 LAN interface parameters ...........................................................................19
6.3 WAN interface parameters.........................................................................21
7CREATING VPN CONNECTIONS BETWEEN ROUTERS......................................22
7.1 Principles......................................................................................................22
7.2 IPSec VPN connections...............................................................................24
7.3 TLS VPN connections..................................................................................30
../..

CONTENT
Page 4 User’s guide ref 9017409-01 SIG Router & VPN server
… CONFIGURATION
8ROUTING FUNCTIONS.............................................................................................35
8.1 Basic routing function.................................................................................35
8.2 Static routes .................................................................................................36
8.3 RIP protocol..................................................................................................37
9ADDRESS AND PORT TRANSLATION ...................................................................38
9.1 Port forwarding ............................................................................................38
9.2 Advanced network address and port translation......................................39
10 VRRP REDUNDANCY...............................................................................................44
10.1 Principle........................................................................................................44
10.2 Configuring VRRP on the LAN interface....................................................45
10.3 Configuring VRRP on the WAN interface .................................................46
11 REMOTE USERS CONNECTIONS SERVICE ..........................................................47
12 REMOTE USERS CONNECTIONS...........................................................................48
12.1 Principles......................................................................................................48
12.2 Configuring a TLS connection....................................................................49
12.3 Configuring a PPTP connection.................................................................52
13 USERS LIST...............................................................................................................53
14 FIREWALL.................................................................................................................56
14.1 Overview.......................................................................................................56
14.2 Main filter......................................................................................................58
14.3 Remote users filters.....................................................................................62
../..

CONTENT
SIG Router & VPN server User’s guide ref. 9017409-01 Page 5
… CONFIGURATION
15 ADVANCED FUNCTIONS.........................................................................................67
15.1 Adding a certificate......................................................................................67
15.2 Alarms......................................................................Erreur ! Signet non défini.
15.3 Configuring the web portal.........................................................................68
15.4 Configuring the DNS server........................................................................69
1DIAGNOSTIC.............................................................................................................71
2SAVING THE PARAMETERS TO A FILE.................................................................72
3UPDATING THE FIRMWARE....................................................................................72
1OVERVIEW................................................................................................................77
2FUNCTIONS...............................................................................................................78
3OPERATION..............................................................................................................78
Appendix 1 : Administration html server
Appendix 2 : VPN mechanisms


INSTALLATION
SIG Router & VPN server User’s guide ref. 9017409-01 Page 7
1 Technical data
General characteristics
Dimensions 137 x 48 x 116 mm (h, l, p)
Electrical safety EN 60950- UL 1950
EMC
ESD : EN61000-4-2 : Discharge 6 KV
RF field : EN61000-4-3 : 10V/m < 2 GHz
Fast transient : EN61000-4-4
Surge voltage : EN61000-4-5 : 4KV line / earth
RoHS 2002/95/CE (RoHS)
Supply voltage 110 to 230 VAC - 50/60Hz - 60 W
Operating T° +5°C / + 40°C Humidity 5 - 95 %
Internet connection ( Ethernet 4)
Type Bridge : PPPo Ethernet
IP Router
Ethernet / IP router
Ethernet 10/100 BT
Port Ethernet 1 : LAN conection
Port Ethernet 4 : WAN connection
IP router Remote connections- static routes - RIP V2
Ip address
translation
Source IP @ translation (NAT)
Destination IP @ translation (DNAT)
Port translation (Port forwarding)
DNS
IP address assignment LAN interface : Fixed IP @ or DHCP server
Throughput 30 MB/s

INSTALLATION
Page 8 User’s guide ref 9017409-01 SIG Router & VPN server
VPN and firewall
VPN
• 128 VPN
• IPSec - Client or server - PSK or X509
certificates
• TLS/SSL - Client or server - X509 certificates
• Encryption 3DES
Firewall Stateful packet inspection
Logs Event logs (date and time)
Remote access server (RAS)
User list 25 users
Connection VPN PPTP / L2TP-IPSec / TLS Open VPN
Login & password
Certificate X509
Alarms 3 inputs : emails

INSTALLATION
2 Overview
The SIG is designed to build safe and reliable remote control system
through the internet or private extended networks.
The SIG comes with two 10/100 BT Ethernet interfaces :
The WAN interface (Interface Ethernet 4)
On that interface, the SIG behaves as a VPN server.
The LAN interface (Ethernet 1).
The SIG is at the same time
a VPN server able to manage up to 128 IPSec or TLS tunnels,
an IP router to route IP packets between its two interfaces.
a remote access server (RAS) to give a secure access to the LAN
or to the remote sites for authenticated remote users.
.
SIG Router & VPN server User’s guide ref. 9017409-01 Page 9

INSTALLATION
1 Product description
SIG router
Interface Led Function
Ethernet 1 DATA Blinking quickly : Data activity
LINK Lit : Interface connected
Ethernet 4 DATA Blinking quickly : Data activity
LINK Lit : Interface connected
Power led
Page 10 User’s guide ref 9017409-01 SIG Router & VPN server
Indice
Altri manuali ETIC Server



















