Eurogard ServiceRouter V2 Manuel utilisateur

Brief description eurogard ServiceRouter V2 1/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
eurogard ServiceRouter V2
Configuration Guide
Version 4.0
eurogard GmbH, January 2011

Brief description eurogard ServiceRouter V2 2/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Hardware ServiceRouter V2
Connection and control elements
The ServiceRouter is designed for installation in a switch cabinet using the mounting rail on
the back cover.
Supply voltage is 18-30VDC/6-18W. The two input terminals for the ± Potential are isolated
by means of diodes. This allows for a redundant voltage supply to the Router, as long as the
ground potential of the sources is at the same level. The +24V LED signalizes adequate
supply to the device.
The Reset button restores the
factory settings of the device. If
required, please press and hold for
at least 3 seconds.
The Setup button copies the last
restore point to the configuration
level. Before use, a restore point has
to be saved in the Router.
The Status LED signalizes the VPN
status.
OFF: VPN terminated
FLASHING: VPN initializing
ON: VPN connection established
The Error LED signalizes the status
of the processor.
ON: Error
FLASHING: Router initializing
OFF: Router in operation
UMTS P Modem module supplied
with voltage
UMTS L Modem module logged into
mobile network
ServiceRouter V2: Technical specifications
- Platform: AMD-Geode 500MHz 256 MB RAM
- 2 GB Flash-Disk, expandable on demand
- Battery backed real-time clock, hardware-Watchdog
- 1 x WAN, 2 x LAN switched, each Ethernet 10/100
- 2 x USB for USB-disk, WEB-Cam and customer add-ons
- miniPCI-slot internal for 54 Mbit WLAN-Option
- Version with UMTS/HSDPA modem available
- Version with 4 digital inputs, 2 outputs available
- Voltage supply 12-30 VDC, 8W (basic version) 18W full version
- Ambient temperature 5-50°C, non-condensing
- DIN-rail mounting
- Dimensions: H:156 W:59 D:160 mm

Brief description eurogard ServiceRouter V2 3/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Ensure accessibility –Target network and DynDNS
Integration into target network (End customer LAN)
Operation as Server in the target network
The ServiceRouterV2 has to be integrated by forwarding the ports described below.
Additionally it has to accessible via DynDNS through updating of its IP.
The port numbers listed below are available.
UDP 1194: For the tunnelled connection to the PLC network (VPN)
OPTIONAL:
TCP 443: for access to the configuration interface(SSL)
Only provisionally: TCP 22 for emergency support through manufacturer
eurogard.
Ports 443 and 22 in the Router can be blocked after first start-up and do
not have to be forwarded after this point.
Since the public IP of our customers is normally dynamic, the public IP of
the ServiceRouters is also dynamic.
For external access to the ServiceRouter, the local IP must be updated
through the provider DynDNS.com.
In order to do this, the Router must be able to communicate via Port 80.
The Router requires access to an NTP server in order to update its system
clock. If an internal NTP is not available, Port 123 outgoing has to be open
for accessing an Internet NTP.
The battery-backed real-time clock of the ServiceRouter bridges offline-
times and allows the Router to be accessed without interruption.
Operation as Client in the target network
If the ServiceRouter V2 is operated as client in the target network, port forwarding
does not apply –along with many a discussion with local IP administrators.
The ServiceRouter V2 only requires an IP in the network and access to the Internet,
just as with any other PC in this network.
Access to an NTP server is required.
DynDNS is only required once at the central server.

Brief description eurogard ServiceRouter V2 4/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Creating a DynDNS account
If the ServiceRouter is to be operated as VPN server, its current IP has to be
traceable for the client wishing to connect. This issue is resolved via the Internet
service DynDNS.com.
At www.dyndns.com an account has to be created for every ServiceRouter–
Server which cannot be accessed via a static IP in the Internet.
Account -> My Services
opens the page shown on
the left. The screen is self-
explanatory and allows for
two free entries.
Access data saved
here subsequently
has to be entered into
the Router.
In case you want to
use the proxy
functions for
visualization purposes, the wildcard function is required, available with the
commercial DynDNS-Pro-Version.
Router configuration: dDNS –Settings of the DynDNS service
Activate the DynDNS-
service at the Router and
enter username and
password of your account
created for this Router.
The Router domain
registered with DynDNS is
entered in the menu item
‘Grundeinstellungen/LAN’
(Basic settings).

Brief description eurogard ServiceRouter V2 5/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Software requirements for the operator without VPN access
Requirements for the operator only allowed access to the web-based operating
interfaces configured in the PLC network are:
Microsoft Internet Explorer or Firefox browser
Animation platform envisaged for the web interface: usually Java TM
In the case of Saia-S-Web: the Java Runtime environment:
http://www.java.com/de/download/manual.jsp
Software requirements for the VPN programming access
In addition to the Explorer, the user with VPN (programming)-access requires:
OpenVPN Client installation. An executable version with Default-Client is included as
part of the scope of delivery. Updates can be downloaded via:
http://openvpn.net/howto.html
The key generated by the Router along with the certificate has to be saved in the
directory „config“ of the OpenVPN installation. For an example, please refer to the
appendix.
The eurogard TeleService Software SRconnect
eurogard provides the VPN-connection tool „ServiceRouter-Connect“, free of charge.
This database oriented
openVPN-Client
administers your
certificates, registers
connection times and, per
mouse-click, sets up a
connection to all
ServiceRouters operated
as servers.
Connections are initiated
from a clearly arranged list and shown in a separate window.
Prior to this, the key files
generated by the
ServiceRouter in the format:
vpn.tar, have to be loaded
into the program.
SRconnect unpacks the
*.tar-file and allows for
additional entries.
For further information
please refer to the
program description.

Brief description eurogard ServiceRouter V2 6/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Functions for users
User-Login
Before the user can access the operating sides of the PLC network, the Router has
to be configurated by the administrator and an account has to be set up in the user
area.
If the Proxy functionality is to be used, at least one webserver in the PLC network
should be created in the Proxy server list, under „Geräte-Webweiterleitung“.
As a standard, communication with the WAN side of the Router takes place via a
secure SSL connection, chosen in the browser by entering https://.
This is followed either by an IP-number
(e.g. 192.168.10.100 as local WAN-IP) or
the DynDNS name, under which the
Router can be accessed in the Internet.
After connection set up, the user
interface of the Router is displayed.
In order to select a menu item, user login
is required.
Menu items for the user: Info-System
The info area provides
information about the
Router itself, eg the
size of the internal disk
and available disk
space is displayed
here, as well as the
temperatures
measured on the
board.

Brief description eurogard ServiceRouter V2 7/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
User –File system
When the user account is created in the admin area, a personal folder for this user is
set up at the same time on the flash drive of the Router.
This user folder is envisaged for storing machine-related data such as PLC projects
or maintenance reports, with password protection. Furthermore, the *.tar-file of the
VPN system is stored here by the Router.
This personalized folder can be accessed via FTP with the user access data at the
LAN-IP of the Router. In the User Area Shared
Documents, all registered
users can share documents.
Set up and use a Proxy Server
Before the user can use the proxy, it has to be set up by the
administrator in the admin area.
The menu item
Geräte (Devices) \
Webweiterleitungen
(Web forwarding)
takes you to the
device list of the
proxy. Here, all
required network
subscribers in the
LAN of the Router
should be entered which are to be accessed at a later point in time.
Click HTML-Cache in order to use the Cache memory in the Router, where you can
store web pages via FTP in order to save PLC memory, and load the web pages into
the Router via FTP at a later point in time. After installation, this
allows a user to view
and utilize these
pages via the web
interface of the
Router without being
granted access to
the PLC network.

Brief description eurogard ServiceRouter V2 8/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Administration of the ServiceRouter
Establishing first contact
The ServiceRouter is connected to the PC via a LAN port. Default IP for accessing
the web interface is: 192.168.155.1.
Local settings
Allow the Router to assign an IP address. Click
Adminlogin in order to change to the
administration area and enter „eurogard“
(default) as user name and password. Go
through the configuration menu in in the order
described below. Please change the password
(see Access –Creating User and Admin
accounts) at a later point in time!
The following parameters are set as default on initial power-up:
WAN / Internet: Connection Ethernet,
DHCP-Client, waiting for IP from the customer network.
LAN: DHCP-Server on: As soon as you connect
a PC to the LAN side via ETHERNET, the
Router attempts to allocate an IP to this PC via
DHCP protocol.
DynDNS: no connection allocated
WLAN: deactivated
Accounts: the device is delivered with the following Administrator / User accounts:
Admin: User: eurogard
Password: eurogard
Settings: Name: Servicerouter
Domain: dyndns.org
Language: German
VPN: No certificates generated, either for the Router or for the user.

Brief description eurogard ServiceRouter V2 9/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
The administration area
Login for the administrator is located in the upper right-hand corner of the initial
screen. At password prompt enter:
User name: eurogard
Password: eurogard
Obviously these accounts should be deleted in
the course of the configuration process and
replaced by creating your own specific user and
administrator accounts.
As a general rule, the following applies for any data
entered in the http interface of the Router:
1. enter parameter
2. press button „Speichern“(Save)
3. then start page functions, eg, Zertifikat „generieren“
(generate certificate).
Some functions, eg the generation of the Router certificate, will take up to 10
minutes! Please do not enter any data during this process and wait for the ready-
message on the user interface!
Please make sure to work through the configuration process from left to right, starting
with the LAN side, then WAN etc, since some functions require parameters from the
preceding menus.

Brief description eurogard ServiceRouter V2 10/23
eurogard GmbH Kaiserstraße 100 D-52134 Herzogenrath T.: +49/2407/9516-0 F: +49/2407/9516-23 www.eurogard.de
Router configuration: LAN side of the Router
Here, the LAN settings of the local PLC network are entered.
LAN address of the ServiceRouter with subnet mask
DHCP area for the users connected on the LAN side
DHCP area for users connected via VPN
Change of HTTPS port and entry of location for easier identification of the
Router are optional.
The Server is given the host
name and the domain name
as registered at dynDNS. This
entry is also required for the
generation of the certificates.
If the Router is supposed to
allocate IP addresses in your
PLC network, please activate
the DCP server of the Router.
In this case, please enter the
available IP number range. It
must not overlap with the
number range of the VPN
network!
Router configuration: WAN side of the Router
The ServiceRouter can be connected to the Internet in different ways.
Select:
DHCP –where the Router receives all necessary information from the DHCP server
of the host network.
Static Configuration - and connect the Router to the host network manually, entering
the data displayed.
Autres manuels Eurogard Porte
Manuels Porte populaires d'autres marques

LST
LST M500RFE-AS Manuel utilisateur

Kinnex
Kinnex Media Gateway Manuel utilisateur

2N Telekomunikace
2N Telekomunikace 2N StarGate Manuel utilisateur

Mitsubishi Heavy Industries
Mitsubishi Heavy Industries Superlink SC-WBGW256 Manuel utilisateur

ZyXEL Communications
ZyXEL Communications ZYWALL2 ET 2WE Manuel utilisateur

Telsey
Telsey CPVA 500 - SIP Manuel utilisateur












