Moxa EDR-810 User Manual

Browse online or download User Manual for Routers Moxa EDR-810. Moxa EDR-810 [en]

  • Download
  • Add to my manuals
  • Print
  • Page
    / 129
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
Industrial Secure Router User’s Manual
Second Edition, August 2013
www.moxa.com/product
© 2013 Moxa Inc. All rights reserved.
Reproduction without permission is prohibited.
Page view 0
1 2 3 4 5 6 ... 128 129

Summary of Contents

Page 1 - Second Edition, August 2013

Industrial Secure Router User’s Manual Second Edition, August 2013 www.moxa.com/product © 2013 Moxa Inc. All rights reserved. Reproduction without pe

Page 2 - Disclaimer

Industrial Secure Router User's Manual Getting Started 2-4 the form 192.168.xxx.xxx. On the other hand, if your PC host’s subnet mask is 255.25

Page 3 - Table of Contents

Industrial Secure Router User's Manual Firewall 8-2 Policy Concept A firewall device is commonly used to provide secure traffic control over an

Page 4

Industrial Secure Router User's Manual Firewall 8-3 Enable Setting Description Factory Default Enable or Disable Enable or disable the sele

Page 5 - Introduction

Industrial Secure Router User's Manual Firewall 8-4 Destination IP Setting Description Factory Default All (IP Address) This Firewall Policy

Page 6 - Features

Industrial Secure Router User's Manual Firewall 8-5 detailed description EtherType Setting Description Factory Default 0x0600 to 0xFFFF When

Page 7 - Getting Started

Industrial Secure Router User's Manual Firewall 8-6 Quick Automation Profile Ethernet Fieldbus protocols are popular in industrial automation a

Page 8 - 1, VT100)

Industrial Secure Router User's Manual Firewall 8-7 Modbus TCP/IP (TCP) 502 Modbus TCP/IP (UDP) 502 PROFInet RT Unicast (TCP) 34962 PROFInet

Page 9 - Router’s Console

Industrial Secure Router User's Manual Firewall 8-8 Policy Check The Industrial Secure Router supports a PolicyCheck function for maintainin

Page 10 - Secure Router

Industrial Secure Router User's Manual Firewall 8-9 Include: Policy [X] is included in Policy [Y] The Source/Destination IP range or Source/Des

Page 11

Industrial Secure Router User's Manual Firewall 8-10 Modbus TCP Policy Modbus TCP is a Modbus protocol used for communications over TCP/IP netw

Page 12

Industrial Secure Router User's Manual Firewall 8-11 Enable/Disable Modbus Policy Setting Description Factory Default Enable or Disable Enab

Page 13 - Quick Setting Profile

Industrial Secure Router User's Manual Getting Started 2-5 2. The web login page will open. Select the login account (Admin or User) and enter

Page 14

Industrial Secure Router User's Manual Firewall 8-12 Destination IP Setting Description Factory Default All (IP Address) This Modbus policy

Page 15 - Step 4: Enable services

Industrial Secure Router User's Manual Firewall 8-13 Denial of Service (DoS) Defense The Industrial Secure Router provides 9 different DoS func

Page 16 - System Information

Industrial Secure Router User's Manual Firewall 8-14

Page 17 - User Account

9 9. Virtual Private Network (VPN) The following topics are covered in this chapter:  Overview  IPSec Configuration  Global Settings  IPSec

Page 18 - Delete Existing Account

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-2 Overview In this section we describe how to use the Industrial Secure

Page 19 - Date and Time

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-3 All IPSec Connection Users can Enable or Disable all VPN services with

Page 20 - Warning Notification

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-4 Name of VPN Tunnel Setting Description Factory Default Max. of 16 ch

Page 21 - System Event Settings

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-5 ID ID for indentifying the VPN tunnel connection. The Local ID must

Page 22 - Email Settings

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-6 MD5 SHA1 SHA256 DH Group Setting Description Factory Default DH1(m

Page 23 - Relay Warning Status

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-7 AES-128 AES-192 AES-256 Hash Algorithm Setting Description Facto

Page 24 - SettingCheck

3 3. EDR-810 Series Features and Functions In this chapter, we explain how to access the Industrial Secure Router’s configuration options, perform m

Page 25

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-8 1. Root Certificate generation. Both EDR-G903(A) and EDR-G903(B) need

Page 26

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-9 NOTE The default setting for Certificate Day is 0, which means that th

Page 27 - Port Settings

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-10 Remote Certificate Upload Upload the .crt Remote certificate on this

Page 28

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-11 Login User Name Setting Description Factory Default Max. to xx char

Page 29 - The Port Trunking Concept

Industrial Secure Router User's Manual Virtual Private Network (VPN) 9-12 L2TP for Remote User Maintenance The following example shows how a Ro

Page 30 - Port Mirror

10 10. Diagnosis The Industrial Secure Router provides Ping tools and LLDP for administrators to diagnose network systems. The following topics are

Page 31 - Using Virtual LAN

Industrial Secure Router User's Manual Diagnosis 10-2 Ping The Ping function uses the ping command to give users a simple but powerful tool fo

Page 32 - Configuring Virtual LAN

Industrial Secure Router User's Manual Diagnosis 10-3 LLDT Table Port: The port number that connects to the neighbor device. Neighbor ID: A uni

Page 33 - Quick Setting Panel

A A. MIB Groups The Industrial Secure Router comes with built-in SNMP (Simple Network Management Protocol) agent software that supports cold start t

Page 34 - Multicast

Industrial Secure Router User's Manual MIB Groups A-2 The Industrial Secure Router also provides a MIB file, located in the file “Moxa-EDRG903-

Page 35 - Multicast Filtering

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-2 Quick Setting Profile The EDR-810 series supports WAN Routing

Page 36 - Enabling Multicast Filtering

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-3 Step 3: Configure the WAN port type Configure the WAN port typ

Page 37 - IGMP Table

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-4 Static IP PPPoE Step 4: Enable services Check Enable DHCP Se

Page 38 - Stream Table

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-5 Step 5: Activate the settings Click the Activate button. NOTE

Page 39 - QoS and Rate Control

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-6 User Account The Moxa industrial secure router supports the ma

Page 40 - CoS Mapping

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-7 Create New Account Input the user name, password and assign th

Page 41 - Rate Limiting

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-8 Date and Time The Moxa industrial secure router has a time cal

Page 42 - MAC Address Table

Industrial Secure Router User’s Manual The software described in this manual is furnished under a license agreement and may be used only in accordance

Page 43 - Interface

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-9 Start Date Setting Description Factory Default User-specifie

Page 44

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-10 System Event Settings System Events are related to the overal

Page 45

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-11 Port Event Settings Port Events are related to the activity o

Page 46 - Network Service

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-12 Max. of 30 characters You can set up to 4 email addresses to

Page 47 - DHCP Server

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-13 When relay warning triggered by either system or port events,

Page 48 - Static DHCP

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-14 If the user enables the SettingCheck function with the Access

Page 49 - IP-Port Binding

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-15 TFTP Server IP/Name Setting Description Factory Default IP

Page 50 - SNMP Settings

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-16 Upgrade Firmware To import a firmware file into the Industria

Page 51

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-17 Enable Setting Description Factory Default Checked Allows

Page 52 - Dynamic DNS

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-18 Link Aggregation Link aggregation involves grouping links int

Page 53 - Security

Table of Contents 1. Introduction ...

Page 54 - Trusted Access

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-19 Step 1: Select the desired Trunk Group Step 2: Select the de

Page 55 - Monitor

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-20 Port Mirroring Settings Setting Description Monitored Port

Page 56 - Port Statistics

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-21 Benefits of VLANs The main benefit of VLANs is that they pro

Page 57 - Event Log

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-22 802.1Q VLAN Settings Management VLAN ID Setting Description

Page 58

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-23 Input multi port numbers in the “Port” column, and Port Type

Page 59 - Functions

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-24 • It makes efficient use of network bandwidth and scales wel

Page 60

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-25 Snooping Mode Snooping Mode allows your industrial secure rou

Page 61 - Configuring Basic Settings

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-26 IGMP Snooping IGMP Snooping provides the ability to prune mul

Page 62 - Accessible IP

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-27 The information shown in the table includes: • Auto Learned

Page 63 - Password

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-28 Join Port Setting Description Factory Default Select/Desele

Page 64

SettingCheck ... 4-8 System

Page 65

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-29 inspecting 802.1p CoS tags in the MAC frame to determine the

Page 66

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-30 ToS/DSCP Mapping ToS (DSCP) Value and Priority Queues Settin

Page 67

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-31 Limit Broadcast, Multicast, Flooded Unicast Limit Broadcast,

Page 68 - Configuration File

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-32 Interface WAN VLAN ID Moxa Industrial Secure Router’s WAN in

Page 69

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-33 User Name Setting Description Factory Default Max. 30 Chara

Page 70 - Network Settings

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-34 Detailed Explanation of Static IP Type Address Information I

Page 71 - WAN1 Configuration

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-35 Host Name Setting Description Factory Default Max. 30 chara

Page 72

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-36 DHCP Server The Industrial Secure Router provides a DHCP (Dyn

Page 73

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-37 NOTE 1. The DHCP Server is only available for LAN interfaces.

Page 74

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-38 DNS Server Setting Description Factory Default IP Address

Page 75

1 1. Introduction Welcome to the Moxa Industrial Secure Router series, the EDR-G902, EDR-G902, and EDR-810. The all-in-one Firewall/NAT/VPN secure r

Page 76

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-39 ≥ 5min. The lease time of the connected device None Default

Page 77 - LAN Interface

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-40 SNMP Versions Setting Description Factory Default Disable

Page 78 - Communication Redundancy

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-41 Access Control Setting Description Factory Default Read/Wri

Page 79 - WAN Backup Configuration

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-42 Security User Interface Management Enable MOXA Utility Setti

Page 80

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-43 Authentication Certificate SSL Certificate Re-generate Setti

Page 81 - System Log

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-44 • Grant access to one host with a specific IP address For ex

Page 82

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-45 Port Statistics Access the Monitor by selecting Monitor from

Page 83 - Routing

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-46 Event Log The Event Log Table displays the following inform

Page 84 - Unicast Routing

Industrial Secure Router User's Manual EDR-810 Series Features and Functions 3-47 NOTE The following events will be recorded into the Moxa indu

Page 85

4 4. EDR-G902/G903 Series Features and Functions  Overview  Configuring Basic Settings  System Identification  Accessible IP  Password 

Page 86 - Routing Table

Industrial Secure Router User's Manual Introduction 1-2 Overview As the world’s network and information technology becomes more mature, the tre

Page 87 - Network Redundancy

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-2 Overview The Overview page is divided into three major p

Page 88 - Configuring STP/RSTP

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-3 Click More… at the top of the Recent 10 Event Log table

Page 89

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-4 Maintainer Contact Info Setting Description Factory De

Page 90 - Configuring Turbo Ring V2

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-5 Allowable Hosts Input Format Ay host Disable 192.168.1

Page 91

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-6 Account Setting Description Factory Default Admin “ad

Page 92 - Layer 3 Redundant Protocols

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-7 Current Time Setting Description Factory Default User

Page 93 - Network Address Translation

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-8 SettingCheck SettingCheck is a safety function for indu

Page 94 - 1-to-1 NAT

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-9 If the new configuration does not block the connection

Page 95

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-10 System File Update—by Remote TFTP The EtherDevice Route

Page 96 - N-to-1 NAT

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-11 Log File Click Export to export the Log file of the Eth

Page 97 - Port Forward

2 2. Getting Started This chapter explains how to access the Industrial Secure Router for the first time. There are three ways to access the router:

Page 98

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-12 Network Settings Mode Configuration Network Mode EtherD

Page 99 - Firewall

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-13 WAN1 Configuration Connection Note that there are thre

Page 100 - Policy Configuration

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-14 Example: Suppose a remote user (IP: 10.10.10.10) wants

Page 101

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-15 Gateway Setting Description Factory Default IP Addres

Page 102 - EDR-G902/G903)

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-16 Connection Type Setting Description Factory Default S

Page 103

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-17 DNS (Doman Name Server; optional setting for Dynamic I

Page 104 - Quick Automation Profile

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-18 Subnet Mask Setting Description Factory Default IP Ad

Page 105

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-19 Using DMZ Mode A DMZ (demilitarized zone) is an isolate

Page 106 - Policy Check

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-20 LAN IP Configuration IP Address Setting Description F

Page 107

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-21 WAN Backup Configuration Select Backup for the WAN2/DM

Page 108 - Modbus TCP Policy

Industrial Secure Router User's Manual Getting Started 2-2 RS-232 Console Configuration (115200, None, 8, 1, VT100) NOTE Connection Caution! We

Page 109

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-22 Monitor You can monitor statistics in real time from th

Page 110

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-23 System Log The industrial secure router provides EventL

Page 111

Industrial Secure Router User's Manual EDR-G902/G903 Series Features and Functions 4-24 DI transition (Off -> On) DI transition (On ->

Page 112

5 5. Routing The following topics are covered in this chapter:  Unicast Routing  Static Routing  RIP (Routing Information Protocol)  Routing

Page 113

Industrial Secure Router User's Manual Routing 5-2 Unicast Routing The Industrial Secure Router supports two routing methods: static routing an

Page 114 - IPSec Configuration

Industrial Secure Router User's Manual Routing 5-3 Clickable Buttons Add For adding an entry to the Static Routing Table. Delete For removing s

Page 115 - IPSec Settings

Industrial Secure Router User's Manual Routing 5-4 RIP Interface Table (EDR-810 series only) Setting Description Factory Default Enable/Disab

Page 116

6 6. Network Redundancy The following topics are covered in this chapter:  Layer 2 Redundant Protocols (EDR-810 series only)  Configuring STP/RS

Page 117 - Key Exchange (IPSec phase I)

Industrial Secure Router User's Manual Network Redundancy 6-2 Layer 2 Redundant Protocols (EDR-810 series only) Configuring STP/RSTP The follow

Page 118

Industrial Secure Router User's Manual Network Redundancy 6-3 Hello time (sec.) Setting Description Factory Default Numerical value input by

Page 119 - X.509 Certificate

Industrial Secure Router User's Manual Getting Started 2-3 4. Click the Terminal tab, select VT100 for Terminal Type, and then click OK to con

Page 120 - Certificate Generation

Industrial Secure Router User's Manual Network Redundancy 6-4 Configuring Turbo Ring V2 NOTE When using the Dual-Ring architecture, users must

Page 121 - Local Certificate Upload

Industrial Secure Router User's Manual Network Redundancy 6-5 Explanation of “Settings” Items Redundancy Protocol Setting Description Factory

Page 122 - L2TP Configuration

Industrial Secure Router User's Manual Network Redundancy 6-6 Layer 3 Redundant Protocols VRRP Settings Virtual Router Redundancy Protocol (VR

Page 123 - VPN Plan

7 7. Network Address Translation The following topics are covered in this chapter:  Network Address Translation (NAT)  NAT Concept  1-to-1 NAT

Page 124

Industrial Secure Router User's Manual Network Address Translation 7-2 Network Address Translation (NAT) NAT Concept NAT (Network Address Trans

Page 125 - Diagnosis

Industrial Secure Router User's Manual Network Address Translation 7-3 1-to-1 NAT Setting for EDR-G903 in Production Line 1 1-to-1 NAT Settin

Page 126 - LLDP Setting

Industrial Secure Router User's Manual Network Address Translation 7-4 IP Address Select the Internal IP address in LAN/DMZ network area None

Page 127 - LLDT Table

Industrial Secure Router User's Manual Network Address Translation 7-5 Interface (N-1 mode) Setting Description Factory Default Auto WAN1 WAN

Page 128 - MIB Groups

Industrial Secure Router User's Manual Network Address Translation 7-6 Enable/Disable NAT policy Setting Description Factory Default Enable

Page 129

8 8. Firewall The following topics are covered in this chapter:  Policy Concept  Policy Overview  Policy Configuration  Layer 2 Policy Setup

Comments to this Manuals

No comments