WLR-4002B
TABLE OF CONTENTS INTRODUCTION 7 1 KEY FEATURES 8 2 PACKAGE CONTENTS 9 3 CAUTIONS 10 3.1 USAGE CAUTIONS 3.2 POWER 3.3 REPAIR 3.4 DISPOSING OF THE ROUTER 3.
11 CONFIGURATION WIZARD 30 12 WIRELESS SETTINGS 32 WIRELESS FUNCTION BASIC SETTINGS ADVANCED SETTINGS SECURITY ACL WPS 32 33 34 36 42 43 13 FIREWALL SETTINGS 45 DMZ DENIAL OF SERVICE (DOS) ACCESS URL BLOCK 46 47 48 50 14 ADVANCED SETTINGS 51 PORT FORWARDING VIRTUAL SERVER SPECIAL APPLICATIONS APPLICATION LAYER GATEWAY UPNP QOS 52 54 56 58 59 60 15 VPN 62 STATUS 62 USING THE WIZARD TO CONFIGURE THE WLR-4002B FOR A PPTP VPN TUNNEL.
PROFILE SETTING PPTP L2TP IPSEC L2TP OVER IPSEC USER SETTING EXAMPLE OF CONFIGURING IPSEC SITE TO SITE ARCHITECTURE 97 100 101 102 106 107 108 16 TOOLBOX 112 SITECOM CLOUD SECURITY PASSWORD CHANGE OPTIONS TIME ZONE REMOTE MANAGEMENT FIRMWARE UPGRADE BACKUP SETTINGS RESET DDNS 112 117 118 119 120 121 122 123
125 Revision 2.0 © Sitecom Europe BV 2012 Note: All the information contained in this manual was correct at the time of publication. However, as our engineers are always updating and improving the product, your device’s software may have a slightly different appearance or modified functionality than presented in this manual.
Introduction Congratulations on your purchase of the WLR-4002B Wireless Gigabit VPN Router 300N. The WLR-4002B is compliant with 802.11n and up to 6 times faster than standard 802.11g based routers while still being compatible with 802.11g & 802.11b devices. The WLR-4002B is not only a Wireless Access Point, but also doubles as a 7-port full-duplex Gigabit switch that connects your wired-Ethernet devices together at 10/100/1000 Mbps speeds.
1 Key Features Features Advantages Incredible Data Rate up to Heavy data payloads such as 300Mbps* MPEG video streaming IEEE 802.11n Compliant and Fully Interoperable with IEEE backwards compatible with 802.11b / IEEE802.11g 802.11b/g compliant devices with legacy protection Seven 10/100/1000 Mbps gigabit Scalability, extend your network.
2 Package Contents Open the package carefully, and make sure that none of the items listed below are missing. Do not discard the packing materials, in case of return; the unit must be shipped back in its original package. 1. The WLR-4002B Router 2. A 110V~240V to 12V 1A Switching Power Adapter 3. A Quick Install Guide 4. A CD (User’s Manual) 5. A Warranty card 6. An UTP cable 7.
3 Cautions This router’s design and manufacturer has your safety in mind. In order to safely and effectively use this router, please read the following before usage. 3.1 Usage Cautions The user should not modify this router. The environmental temperature should be within +5 ~ +35 degrees Celsius. 3.2 Power The router’s power voltage is DC 12V 1A. When using this router, please connect the supplied AC adapter or AC adapter cable to the router’s power jack.
4 Product Layout Port Description Power connector Connect the 12V DC adapter to this port LAN (1~7) Connect your PC’s or network devices to this port WAN Connect your ADSL/Cable modem to this port 11
Backlabel The backlabel describes the IP address, login details, SSID, security code and WPS button functionality. Button Description Press 1-5 seconds for OPS mode Press 10-15 seconds to reset the router OPS BUTTON Press 15+ Seconds to reset the router to factory defaults.
LED Definition From left to right. Port Description LAN (Blue) Shows the cable is connected. LAN (Blue) Shows the cable is connected. LAN (Blue) Shows the cable is connected. LAN (Blue) Shows the cable is connected. WAN (Blue) Shows the cable is connected. WiFi (Blue) Shows WiFi activity. Power (Red) Shows the device is turned on. OPS (White) Shows OPS activity.
5 Network + System Requirements To begin using the WLR-4002B, make sure you meet the following as minimum requirements: • PC/Notebook. • Operating System – Microsoft Windows XP/Vista/Seven • 1 Free Ethernet port. • WiFi card/USB dongle (802.11 b/g/n) – optional. • External xDSL (ADSL) or Cable modem with an Ethernet port (RJ-45). • PC with a Web-Browser (Internet Explorer, Safari, Firefox, Opera) • Ethernet compatible CAT5e cables.
7 Setup LAN, WAN WAN connection: 15
LAN connection: 16
8 PC Network Adapter setup Windows XP • Enter [Start Menu] select [Control panel] select [Network].
• Select [Internet Protocol (TCP/IP)] =>Click [Properties]. • Select the [General] tab. The router supports [DHCP] function, please select both [Obtain an IP address automatically] and [Obtain DNS server address automatically].
Windows Vista/Seven • Enter [Start Menu] select [Control panel] select [View network status and tasks] -> select [Manage network connections].
• Select [Internet Protocol Version 4 (TCP/IPv4)] =>Click [Properties]. • Select the [General] tab. The router supports [DHCP] function, please select both [Obtain an IP address automatically] and [Obtain DNS server address automatically].
9 Bringing up the WLR-4002B Connect the supplied power-adapter to the power inlet port and connect it to a wall outlet. Switch on the power via the switch on the back of the device. The WLR-4002B automatically enters the self-test phase. During self-test phase, the Power LED will be lit continuously to indicate that this product is in normal operation. 10 Initial Setup WLR-4002B LOGIN procedure 1. OPEN your browser (e.g. Internet Explorer). 2. Type http://192.168.0.
3. Type user name and password (default username is ‘admin’, the password can be found on the back of he router). 4. Click OK. 5. You will see the home page of the WLR-4002B. The System status section allows you to monitor the current status of your router the UP time, hardware information, serial number as well as firmware version information is displayed here.
LAN settings The LAN tab gives you the opportunity to change the IP settings of the WLR4002B. Click at the bottom of this screen to save any changes. IP address 192.168.0.1. It is the router’s LAN IP address (Your LAN clients default gateway IP address). IP Subnet Mask 255.255.255.0 Specify a Subnet Mask for your LAN segment. 802.1d Spanning Tree is Disabled by default. If the 802.1d Spanning Tree function is enabled, this router will use the spanning tree protocol to prevent network loops.
Lease Time Forever. In the Lease Time setting you can specify the time period that the DHCP lends an IP address to your LAN clients. The DHCP will change your LAN client’s IP address when this time threshold period is reached. IP Address Pool You can select a particular IP address range for your DHCP server to issue IP addresses to your LAN Clients. Note: default IP range is 192.168.0.100 ~ 192.168.0.200.
Device Status View the Broadband router’s current configuration settings. Device Status displays the configuration settings you’ve configured in the Wizard / Basic Settings / Wireless Settings section.
Internet Status This page displays whether the WAN port is connected to a Cable/DSL connection. It also displays the router’s WAN IP address, Subnet Mask, and ISP Gateway as well as MAC address, the Primary DNS. Press the Renew button to renew your WAN IP address.
DHCP Client Status This page shows all DHCP clients (LAN PCs) currently connected to your network. The table shows the assigned IP address, MAC address and expiration time for each DHCP leased client. Use the Refresh button to update the available information. You can check Enable Static DHCP IP. It is possible to add more static DHCP IPs. They are listed in the table Current Static DHCP Table. IP can be deleted at will from the table. Click apply button to save the changed configuration.
WLR-4002B Log View the operation log. This page shows the current system log of the Broadband router. It displays any event occurred after system start up. At the bottom of the page, the system log can be saved to a local file for further processing or the system log can be cleared or it can be refreshed to get the most updated information. When the system is powered down, the system log will disappear if not saved to a local file.
Statistics Shows the counters of packets sent and received on WAN, LAN & WLAN.
11 Configuration Wizard Click Wizard to configure the router. The Setup wizard will now be displayed; check that the modem is connected and click Next. Select your country from the Country list. Select your internet provider. Click Next.
Depending on the chosen provider, you may need to enter your user name and password, MAC address or hostname in the following window. After you have entered the correct information, click Next. Click APPLY to complete the configuration.
12 Wireless Settings You can set parameters that are used for the wireless stations to connect to this router. The parameters include Mode, ESSID, Channel Number and Associated Client. Wireless Function Enable or Disable Wireless function here. Click Apply and wait for module to be ready & loaded.
Basic Settings Mode Allows you to set AP or WDS mode. Band Allows you to set the AP fixed at 802.11b or 802.11g mode. You can also select B+G mode to allow 80211b and 802.11g clients at the same time. Enable SSID # Allows you to enable up to four SSIDs for this router. SSID This is the name of the wireless signal which is broadcasted. All the devices in the same wireless LAN should have the same ESSID. Channel The channel used by the wireless LAN.
Advanced Settings This tab allows you to set the advanced wireless options. The options included are Authentication Type, Fragment Threshold, RTS Threshold, Beacon Interval, and Preamble Type. You should not change these parameters unless you know what effect the changes will have on the router. Authentication Type There are two authentication types: "Open System" and "Shared Key". When you select "Open System", wireless stations can associate with this wireless router without WEP encryption.
Beacon Interval is the interval of time that this wireless router broadcasts a beacon. A Beacon is used to synchronize the wireless network. Data Rate The “Data Rate” is the rate that this access point uses to transmit data packets. The access point will use the highest possible selected transmission rate to transmit the data packets. N Data Rate The “Data Rate” is the rate that this access point uses to transmit data packets for N compliant wireless nodes. Highest to lowest data rate can be fixed.
Security This Access Point provides complete wireless LAN security functions, included are WEP, IEEE 802.11x, IEEE 802.11x with WEP, WPA with pre-shared key and WPA with RADIUS. With these security functions, you can prevent your wireless LAN from illegal access. Please make sure your wireless stations use the same security function, and are setup with the same security key. SSID Selection Here you choose the SSID for which you wish to set the security.
Disable When you choose to disable encryption, it is very insecure to operate the router.
Enable 802.1x Auth IEEE 802.1x is an authentication protocol. Every user must use a valid account to login to this Access Point before accessing the wireless LAN. The authentication is processed by a RADIUS server. This mode only authenticates users by IEEE 802.1x, but it does not encrypt the data during communication.
WEP When you select 64-bit or 128-bit WEP key, you have to enter WEP keys to encrypt data. You can generate the key by yourself and enter it. You can enter four WEP keys and select one of them as a default key. Then the router can receive any packets encrypted by one of the four keys. Key Length You can select the WEP key length for encryption, 64-bit or 128bit. The larger the key will be the higher level of security is used, but the throughput will be lower.
Click “Apply” at the bottom of the screen to save the above configurations. You can now configure other sections by choosing Continue, or choose Apply to apply the settings and reboot the device. WPA Pre-shared Key Wi-Fi Protected Access (WPA) is an advanced security standard. You can use a pre-shared key to authenticate wireless stations and encrypt data during communication. It uses TKIP or CCMP (AES) to change the encryption key frequently.
WPA-Radius Wi-Fi Protected Access (WPA) is an advanced security standard. You can use an external RADIUS server to authenticate wireless stations and provide the session key to encrypt data during communication. It uses TKIP or CCMP (AES) to change the encryption key frequently. Press Apply button when you are done.
ACL This wireless router supports MAC Address Control, which prevents unauthorized clients from accessing your wireless network. Enable wireless access control Enables the wireless access control function Adding an address into the list Enter the "MAC Address" and "Comment" of the wireless station to be added and then click "Add". The wireless station will now be added into the "Current Access Control List" below.
WPS Wi-Fi Protected Setup (WPS) is the simplest way to establish a connection between the wireless clients and the wireless router. You don’t have to select the encryption mode and fill in a long encryption passphrase every time when you try to setup a wireless connection. You only need to press a button on both wireless client and wireless router, and WPS will do the rest for you. The wireless router supports two types of WPS: WPS via Push Button and WPS via PIN code.
WPS Check the box to enable WPS function and uncheck it to disable the WPS function. WPS Current Status If the wireless security (encryption) function of this wireless router is properly set, you’ll see a ‘Configured’ message here. Otherwise, you’ll see ‘UnConfigured’. Self Pin Code This is the WPS PIN code of the wireless router. You may need this information when connecting to other WPS-enabled wireless devices. SSID This is the network broadcast name (SSID) of the router.
13 Firewall Settings The Broadband router provides extensive firewall protection by restricting connection parameters, thus limiting the risk of hacker attacks, and defending against a wide array of common Internet attacks. However, for applications that require unrestricted access to the Internet, you can configure a specific client/server as a Demilitarized Zone (DMZ).
DMZ If you have a client PC that cannot run an Internet application (e.g. Games) properly from behind the NAT firewall, then you can open up the firewall restrictions to unrestricted two-way Internet access by defining a DMZ Host. The DMZ function allows you to re-direct all packets going to your WAN port IP address to a particular IP address in your LAN. The difference between the virtual server and the DMZ function is that the virtual server re-directs a particular service/Internet application (e.g.
Denial of Service (DoS) The Broadband router's firewall can block common hacker attacks, including Denial of Service, Ping of Death, Port Scan and Sync Flood. If Internet attacks occur the router can log the events. Ping of Death Protections from Ping of Death attack Discard Ping From WAN The router’s WAN port will not respond to any Ping requests Port Scan Protects the router from Port Scans. Sync Flood Protects the router from Sync Flood attack.
Access You can restrict users from accessing certain Internet applications/services (e.g. Internet websites, email, FTP etc.), Access Control allows users to define the traffic type permitted in your LAN. You can control which PC client can have access to these services. Deny If you select “Deny” then all clients will be allowed to access Internet accept for the clients in the list below. Allow If you select “Allow” then all clients will be denied to access Internet accept for the PCs in the list below.
Selected". If you want to remove all PCs from the table, just click the "Delete All" button. Filter client PC by MAC Check “Enable MAC Filtering” to enable MAC Filtering. Add PC Fill in “Client PC MAC Address” and “Comment” of the PC that is allowed to access the Internet, and then click “Add”. If you find any typo before adding it and want to retype again, just click "Reset" and the fields will be cleared.
URL block You can block access to some Web sites from particular PCs by entering a full URL address or just keywords of the Web site. Enable URL Blocking Enable/disable URL Blocking Add URL Keyword Fill in “URL/Keyword” and then click “Add”. You can enter the full URL address or the keyword of the web site you want to block.
14 Advanced Settings Network Address Translation (NAT) allows multiple users at your local site to access the Internet through a single Public IP Address or multiple Public IP Addresses. NAT provides Firewall protection from hacker attacks and has the flexibility to allow you to map Private IP Addresses to Public IP Addresses for key services such as Websites and FTP. Select Disable to disable the NAT function.
Port Forwarding Port Forwarding allows you to re-direct a particular range of service port numbers (from the Internet/WAN Port) to a particular LAN IP address. It helps you to host servers behind the router NAT firewall. Enable Port Forwarding Enable Port Forwarding Private IP This is the private IP of the server behind the NAT firewall. Type This is the protocol type to be forwarded. You can choose to forward “TCP” or “UDP” packets only, or select “both” to forward both “TCP” and “UDP” packets.
Remove Port Forwarding If you want to remove a Port Forwarding setting from the "Current Port Forwarding Table", select the Port Forwarding setting that you want to remove in the table and then click "Delete Selected". If you want to remove all Port Forwarding settings from the table, just click "Delete All" button. Click "Reset" will clear your current selections.
Virtual Server Use the Virtual Server function when you want different servers/clients in your LAN to handle different service/Internet application type (e.g. Email, FTP, Web server etc.) from the Internet. Computers use numbers called port numbers to recognize a particular service/Internet application type. The Virtual Server allows you to re-direct a particular service port number (from the Internet/WAN Port) to a particular LAN private IP address and its service port number.
Comment The description of this setting. Add Virtual Server Fill in the "Private IP", "Private Port", "Type", “Public Port” and "Comment" of the setting to be added and then click "Add". Then this Virtual Server setting will be added into the "Current Virtual Server Table" below. Remove Virtual Server If you want to remove Virtual Server settings from the "Current Virtual Server Table", select the Virtual Server settings you want to remove in the table and then click "Delete Selected".
Special Applications Some applications require multiple connections, such as Internet games, video Conferencing, Internet telephony and others. In this section you can configure the router to support multiple connections for these types of applications. Enable Trigger Port Enable the Special Application function. Trigger Port This is the out going (Outbound) range of port numbers for this particular application. Trigger Type Select whether the outbound port protocol is “TCP”, “UDP” or both.
Popular applications This section lists the more popular applications that require multiple connections. Select an application from the Popular Applications selection. Once you have selected an application, select a location (1-10) in the Copy to selection box and then click the Copy to button. This will automatically list the Public Ports required for this popular application in the location (1-10) you specified.
Application Layer Gateway In the context of computer networking, an application-level gateway (also known as ALG or application layer gateway) consists of a security component that augments a firewall or NAT employed in a computer network. It allows customized NAT traversal filters to be plugged into the gateway to support address and port translation for certain application layer "control/data" protocols such as FTP, BitTorrent, SIP, RTSP, file transfer in IM applications etc.
UPnP With UPnP, all PCs in you Intranet will discover this router automatically, so you don’t have to configure your PC and it can easily access the Internet through this router. UPnP Feature You can enable or Disable the UPnP feature here. After you enable the UPnP feature, all client systems that support UPnP, like Windows XP, can discover this router automatically and access the Internet through this router without having to configure anything.
QoS QoS can let you classify Internet application traffic by source/destination IP address and port number. You can assign priority for each type of application and reserve bandwidth for it. The packets of applications with higher priority will always go first. Lower priority applications will get bandwidth after higher priority applications get enough bandwidth. This can let you have a better experience in using critical real time services like Internet phone, video conference …etc.
Edit a QoS rule Select the rule you want to edit and click “Edit”, then enter the detail form of the QoS rule. Click “Apply” after editing the form and the rule will be saved. Adjust QoS rule priority You can select the rule and click “Move Up” to make its priority higher. You also can select the rule and click “Move Down” to make its priority lower.
15 VPN A Virtual Private Network (VPN) provides a secure connection between two or more computers or protected networks over the public Internet. It provides authentication to ensure that the information is going to and from the correct parties and security to protect the information from viewing or tampering en route. The WLR-4002B supports IPSec (Site to Site, Remote to Site) and L2TP over IPSec methods to establish VPN connections and the maximum VPN session number is up to 5.
Using the Wizard to Configure the WLR-4002B for a PPTP VPN tunnel. 1. 2. 3. In the Top Menu on the right side, click VPN. In the submenu, click Wizard to add a VPN profile. Click Next to create a VPN profile. 4. In the Name field, enter a name for the PPTP VPN tunnel. This name is for reference purposes. Click Next to continue.
5. Click PPTP and click NEXT to continue. 6. Complete the following fields : Enter a name for authentication. Enter a password for authentication. Enter any private IP address on a different subnet than the LAN IP address of the computer connected behind the WLR-4002B.(When WLR4002 is on default settings, the LAN IP address is 192.168.0.100. In this case you can select any private IP address other than 192.168.0.x, for example 192.168.3.x).
8. Enable the VPN policy, and then click Apply to save the VPN profile.
Using the Wizard to Configure the WLR-4002B for L2TP over IPSec VPN tunnel. 1. 2. 3. In the Top Menu on the right side, click VPN. In the submenu, click Wizard to add a VPN profile. Click Next to create a VPN profile. 4. In the Name field, enter a name for the L2TP VPN tunnel. This name is for reference purposes. Click Next to continue. 5. Click L2TP and click NEXT to continue.
6. Complete the following fields: Enter a name for authentication. Enter a password for authentication. Enter any IP address on a different subnet than the LAN IP address of the computer connected behind the WLR-4002B.(When WLR4002 is on default settings, the LAN IP address is 192.168.0.100. In this case you can select any IP address other than 192.168.0.x).
8. Enable the VPN policy, and then click Apply to save the VPN profile.
In the following examples it is assumed that the WLR-4002B is placed behind a bridged modem. This means that the Router will receive a public IP address on the WAN side. The WAN/Internet IP address can be found on the Internet status page of the WLR-4002B. If the WAN IP address of the WLR-4002B is not a public IP address but a local IP address (for example any IP address in the following ranges: 10.X.X.X, 172.16.X.X or 192.168.X.X) In this situation your WLR-4002B is placed behind a NAT enabled modem.
Configuring a Microsoft Windows 7 VPN Client 1. Click the Start button and open the Control Panel. 2. From the Control Panel, select Network and Internet.
3. From Network and internet, select Network and Sharing center . 4. Under Network and Sharing Center, select Setup a new connection or network.
5. Click Connect to a workplace, and click Use my internet connection (VPN).
6. Complete the following fields: Internet Address Enter the WLR-4002B WAN IP address. Destination name Enter a name for the VPN client. We recommend to select: Don’t connect now. Just set it up so I can connect later. Click next to continue. 7. Complete the following fields: User name Enter the username used to log onto the VPN tunnel. Password Enter the password used to log onto the VPN tunnel. Click Create to continue.
8. When the following screen appears, click the Close button to close the VPN connection setting. 9. Select Change adapter settings on the left side of the window.
10. Select the VPN connection you just set, right-click VPN Connection, and select Properties. 11. Go to the Security tab and configure the following settings : Under the Type of VPN, select the Protocol that has been set in the WLR4002B, Point to point tunneling protocol(PPTP) or Layer 2 Tunneling Protocol with IPsec (L2TP-IPSec) . Check Check Check unencrypted password (PAP). Challenge Handshake Authentication Protocol (PPTP). Microsoft CHAP Version 2 (MS-CHAP v2).
12. Go to Network and Sharing Center on the bottom-right of the windows. Under VPN Connection click Connect.
Configuring a Microsoft Windows XP VPN Client 1. Click the Start button and open the Control Panel. 2. From the Control Panel, Click on Network Connections.
3. Click on Create a network from the left side of the window. 4. Click Next to continue to setup the VPN client.
5. Select Connect to the network at my workplace and click Next to continue. 6. Select Virtual Private network connection and click Next to continue.
7. Enter a Company name, this name is only for reference purposes. 8. Enter the Hostname , this should be the WLR-4002B WAN IP address and click Next to continue.
9. Click Finish to continue, you may choose to add a shortcut for this connection on the Desktop by clicking the checkbox before you click Finish. 10. Click on Properties.
11. Click on the Security Tab from the top in the window and select Advanced, click Settings to continue.
12. Configure the following settings: Under Data encryption, select Optional encryption (connect even if no encryption) Check Check Uncheck Check Unencrypted password (PAP) Challenge Handshake Authentication Protocol (SPAP) Microsoft CHAP (MS-CHAP) Microsoft CHAP Version 2 (MS-CHAP v2) Click OK to continue. 13. Click Yes to continue. If the VPN type you have configured in the WLR4002B is PPTP you can skip step 14.
14a. If the VPN Type of the tunnel you have set up in the WLR-4002B is L2TP over IPSec You have also entered a Shared key in the WLR-4002B(see step 7 of chapter Using the Wizard to Configure the WLR-4002B for L2TP over IPSec for reference). Click on IPSec Settings… 14b. Check Use pre-shared key for authentication. Key, Enter the shared key you have entered in the WLR-4002B.
Configuring a MacOS VPN Client 1. Select System Preferences. 2. On the System preferences panel, Click Network.
3. Click on the + sign on the bottom left. 4. Select the VPN interface.
5. Under the VPN Type dropdown, select the option that corresponds to the VPN Type you have configured in the WLR-4002B. Enter a name for this profile (this name is for reference purpose only) 6. Complete the following fields: Server address Account Name Enter the WAN IP address of the WLR-4002B. Enter the name used to log onto the VPN tunnel (this must be one of the users you have set in the VPN user table of the WLR-4002B) Click Authentication Settings to continue.
7. Complete the following fields: Enter the password that belongs to the Account name which you have entered in step 6 of this Guide. Shared Key If the VPN Type of the VPN tunnel you have set up in the WLR-4002B is L2TP over IPSec You have also entered a Shared key in the WLR-4002B(see step 7 of chapter Using the Wizard to Configure the WLR-4002B for L2TP over IPSec for reference) Enter the same key in this field. Password Click OK to continue. 8. Click on Advanced in the network panel to continue.
9. Select the checkbox Send all traffic over VPN connection. Click OK to continue. 10. If the VPN tunnel is already connected, click Disconnect and Connect again for the changes made in step 9 to take effect.
Configuring a VPN client on iOS 1. Click Settings on the Springboard. 2. Select General on from the panel of the left side and Click on Network.
3. Click on VPN. 4.
3. Select the VPN Type that corresponds to the VPN Type you have configured in the WLR-4002B. Complete the following fields: Description Server Account Password Enter a name for your VPN connection, this name is for reference purposes only. Enter the WLR-4002B WAN IP address Enter Enter the name used to log onto the VPN tunnel(this must be one of the users you have set in the VPN user table of the WLR-4002B) Enter the Password used to log onto the VPN tunnel.
4. Set the Switch to ON to connect to the VPN Network.
Configuring a VPN client on Android 1. Click on Settings. 2. click on More.. from the Settings menu on the upper left. Then Click on VPN.
2. Click on Add VPN Network. 3. Select the VPN Type that corresponds to the VPN Type you have configured in the WLR-4002B. Complete the following fields: Description Server Account Password Enter a name for your VPN connection, this name is for reference purposes only. Enter the WLR-4002B WAN IP address Enter the name used to log onto the VPN tunnel (this must be one of the users you have set in the VPN user table of the WLR-4002B) Enter the Password used to log onto the VPN tunnel.
4. Click on the VPN network you have just created to connect.
Profile Setting This page allows you to Add, Edit and Delete VPN profiles. Add click here if you wish to manually add a new VPN profile. Edit to edit an existing profile, select one from the list by selecting the corresponding radio button and click ‘Edit’. Click “Apply” to save the settings and apply the changes.
Add Users to an existing Profile Click on Profile Setting. Select the Profile for which you wish to modify user settings and click on Edit. Then Click on the protocol name you selected to edit.
From here all current users that you have created will be shown. In the Available box existing users are be displayed that do not have access to this VPN Tunnel yet. The Member box displays users that already have access to this VPN Tunnel. To Add or remove users to the VPN Tunnel, click the on the username you wish you Add or Remove and press the ´<<’, ‘>>’ buttons to the desired box. Click Apply Click “Apply” to save the settings and apply the changes.
PPTP The Point-to-Point Tunneling Protocol (PPTP) is a method for implementing virtual private networks. PPTP uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets. The PPTP specification does not describe encryption or authentication features and relies on the PPP protocol being tunneled to implement security functionality.
L2TP In computer networking, Layer 2 Tunneling Protocol (L2TP) is a tunneling protocol used to support virtual private networks (VPNs). It does not provide any encryption or confidentiality by itself; it relies on an encryption protocol that it passes within the tunnel to provide privacy. General This page allows you to configure the general VPN settings. Name Connection Type Enter a name for your VPN policy Supports IPSec and L2TP over IPSec methods to establish VPN connection.
IPSec IPSec (Internet Protocol Security) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session. IPSec also includes protocols for establishing mutual authentication between agents at the beginning of the session and negotiation of cryptographic keys to be used during the session. IPSec is an end-to-end security scheme operating in the Internet Layer of the Internet Protocol Suite.
SA (Security Association) A Security Association (SA) is the establishment of shared security attributes between two network entities to support secure communication. An SA may include attributes such as: cryptographic algorithm and mode; traffic encryption key; and parameters for the network data to be passed over the connection. Establishment of an SA is described in RFC 2408, the Internet Security Association and Key Management Protocol. This page allows you to configure SA.
IPSec (Phase 2) Proposal Protocol Select ESP (Encapsulating Security Payload) or AH (Authentication Header) for traffic through the VPN. • AH (Authentication Header) to provide connectionless integrity and data origin authentication for IP datagrams and to provide protection against replay attacks.
Advanced This page allows you to configure advanced VPN settings. Nat Traversal Enabling NAT Traversal allow IPSec traffic from this endpoint to traverse through the translation process during NAT. The remote VPN endpoint must also support this feature and it must be enabled to function properly over the VPN. Dead Peer Detection Enable DPD (Dead Peer Detection) to delete the VPN tunnel if there is no traffic detected. The VPN will re-establish once traffic is again sent through the tunnel.
L2TP over IPSec L2TP over IPSec VPNs enable a business to transport data over the Internet, while still maintaining a high level of security to protect data. You can use this type of secure connection for small or remote office clients that need access to the corporate network. You can also use L2TP over IPSec VPNs for routers at remote sites by using the local ISP and creating a demand-dial connection into corporate headquarters.
User Setting This page allows you to maintain VPN users. Add a user Enter the desired name and password, for verification the password has to be entered twice. Click ‘Add’ to add the user to the current VPN user table Reset This button will clear all values from the input boxes. Current VPN user table shows all existing VPN users. Delete Selected Select a user from the table and Click Delete Selected to delete this user. Delete ALL This deletes all current VPN user from the current table.
Example of configuring IPSec Site to Site architecture In this guide we give an example how to set up a IPSec Site to Site architecture. The values in this example are only to give an impression of how to do the configuration.
Configuring Location B 1. Click on VPN in the top menu then click Wizard in the submenu. Click Next to continue. 2. In the Name field, enter a name for the IPSec VPN tunnel. This name is for reference purposes. Click Next to continue. 3. Click IPSec and click NEXT to continue. 4. Click Site to Site and click NEXT to continue.
5. Complete the following fields : Security Gateway Type Choose the type of Security Gateway you wish to use(In this example we use IP address. Security Gateway Enter the WAN IP address of the remote VPN Server( In our example this is the WAN IP address of the WLR-4002B in Location A, 77.193.12.20) Remote Address Enter an IP address that is on the same Subnet as the Local LAN of the remote VPN server (In our example the WLR-4002B in location A has a local IP of 192.168.2.
7. Enable the VPN policy, and then click Apply to save the VPN profile. 8. Repeat these steps 1~7 for the other VPN server. 9. Once Both VPN routers have been completely set up. Click on Status in the submenu of the VPN menu and click Connect to establish the IPSec Site to Site connection.
16 TOOLBOX Sitecom Cloud Security Antivirus software alone is not safe enough. You can now benefit from additional built-in security in your modem or router. Protect all devices in your home network against cybercrime while browsing. Activated automatically, your network and devices are better secured than ever before. Your Sitecom device comes with a 6 month free Sitecom cloud security subscription. After you have set up your Sitecom device for internet access, open the web browser and enter http://www.
The Sitecom Cloud Security service offers the following protection options: 1 2 3 4 Anti-Malware Anti-Phishing Protection against unsafe websites Advertisement blocking With the protection of unsafe websites activated the Sitecom Cloud Security will always check if a website is safe. If it is not safe it will inform you that is not safe to enter. If you still wish to visit this webpage click on ‘proceed anyway’. Alternatively click ‘Back to Safety’ so that your security will not be breached.
If you wish to change your security options or to extend your subscription at any time, open http://www.sitecomcloudsecurity.com from your web browser. You will be asked for a username and password. These can be found on the backlabel on the bottom of your Sitecom router or modem. If the login succeeded you can click on ‘Settings’ to change your security options.
Or click ‘License’ to renew your subscription.
If you wish to disable Sitecom Cloud Security at any time, open the webpage of your Sitecom product and log in with the supplied credentials (these can be found on the back label on the bottom of your Sitecom device). Go to Toolbox and select “Sitecom Cloud Security”. Click the “Disable” radio button and click ‘Apply’ for the settings to take effect.
Password change options You can change the password required to log into the broadband router's system web-based management. Passwords can contain 0 to 12 alphanumeric characters, and are case sensitive. Current Password Fill in the current password to allow changing to a new password. New Password Enter your new password. Confirmed Password Enter your new password again for verification purposes.
Time Zone The Time Zone allows your router to base its time on the settings configured here, which will affect functions such as Log entries and Firewall settings. Set Time Zone Select the time zone of the country you are currently in. The router will set its time based on your selection. Time Server Address You can set an NTP server address. Enable Daylight Savings The router can also take Daylight savings into account.
Remote Management The remote management function allows you to designate a host in the Internet the ability to configure the Broadband router from a remote site. Enter the designated host IP Address in the Host IP Address field. Host Address This is the IP address of the host in the Internet that will have management/configuration access to the Broadband router from a remote site. If the Host Address is left 0.0.0.
Firmware Upgrade This page allows you to upgrade the router’s firmware. Enable automatic firmware update When enabled the router will periodically check if a new firmware is available, I a new firmware is detected the router will give a notification. Firmware Upgrade This tool allows you to upgrade the Broadband router’s system firmware.
Backup Settings The Backup screen allows you to save (Backup) the router’s current configuration settings. When you save the configuration setting (Backup) you can re-load the saved configuration into the router through the Restore selection. If extreme problems occur you can use the Restore to Factory Defaults selection, this will set all configurations to its original default settings (e.g. when you first purchased the router).
Reset You can reset the router’s system should any problem exist. The reset function essentially re-boots your router’s system.
DDNS DDNS allows you to map the static domain name to a dynamic IP address. You must get an account, password and your static domain name from the DDNS service providers. This router supports DynDNS, TZO and other common DDNS service providers. Enable/Disable Enable or disable the DDNS function of this router Provider Select a DDNS service provider Domain name Fill in your static domain name that uses DDNS Account/E-mail The account that your DDNS service provider assigned to you.
Parts of the firmware of the WLR-4002B Wireless VPN Gigabit Router are subject to the GNU general public license. Appendix A: Licensing Information This product includes third-party software licensed under the terms of the GNU General Public License.. You can modify or redistribute this free software under the terms of the GNU General Public License. Please see Appendix B for the exact terms and conditions of this license.
No Warranty The free software included in this product is distributed in the hope that it will be useful, but WITHOUT ANY LIABILITY OF OR ANY WARRANTY FROM THE LICENSOR. Appendix B: GNU GENERAL PUBLIC LICENSE Version 2, June 1991 Copyright (C) 1989, 1991 Free Software Foundation, Inc. 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice and disclaimer of warranty; keep intact all the notices that refer to this License and to the absence of any warranty; and give any other recipients of the Program a copy of this License along with the Program. You may charge a fee for the physical act of transferring a copy, and you may at your option offer warranty protection in exchange for a fee. 2.
grants you permission to modify or distribute the Program or its derivative works. These actions are prohibited by law if you do not accept this License. Therefore, by modifying or distributing the Program (or any work based on the Program), you indicate your acceptance of this License to do so, and all its terms and conditions for copying, distributing or modifying the Program or works based on it. 6.
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 12.