vpn setup for multiple oncell g3150-hsdpa to one edr-g903

27
VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Upload: timothy-daniels

Post on 26-Mar-2015

241 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Page 2: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Confidential

Setup Diagram

192.168.126.15192.168.126.254

192.168.126.0/24MASK: 255.255.255.0Default Gateway: 192.168.126.254

Static Public IP

192.168.127.0/24MASK: 255.255.255.0Default Gateway: 192.168.127.254

192.168.127.15 192.168.127.254

Floating Public/Private IP

OnCell G31X0 Series/OnCell 5000 Series

EDR-G903

192.168.128.0/24MASK: 255.255.255.0Default Gateway: 192.168.128.254

192.168.128.15 192.168.128.254

Floating Public/Private IP

OnCell G31X0 Series/OnCell 5000 Series

2What Can You Do With More Than 128 OnCells or Need Load Balance?

Get More Than ONE Public IP and EDR-G903!

Page 3: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Confidential3

System Requirments

OnCell G3150_V2 FW: ocg3100_V2_2.3_10122215.rom

SIM card with Public/Private Floating IP

OnCell G3150-HSDPA FW: ocg3100-hsdpa_1.4_Build_11051315.rom

SIM card with Public/Private Floating IP

EDR-G903 FW: EDR_G903_V2.1.rom

WAN is connected to a Static Public IP

3Confidential

Page 4: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Confidential4

OnCell G3150_V2/G3150-HSDPA

Reset to factory default

IP1: 192.168.127.254 Submask: 255.255.255.0

IP2: 192.168.128.254 Submask: 255.255.255.0

Insert SIM and configure the PIN and APN

Enable the system log

Set system time correctly

Setup VPN (See the following page)

4Confidential

Page 5: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA

Page 6: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (Firmware Ver.)

Page 7: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (IP)

Page 8: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (CellularSettings)

Page 9: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (VPN Settings-1)

Page 10: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (VPN Settings-2)

Page 11: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA (System Log Settings)

Page 12: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Repeat Slide 9-14 To Configure Other OnCell G3150

Page 13: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Confidential13

EDR-G903 Up to FWR_DEVICE_EDR_G903_V2.2.4_Build_12061815.rom

Reset to factory default

IP: 192.168.126.254 Submask: 255.255.255.0

Set WAN with a Static IP

Make sure firewall is not blocking anything

Untick the “Enable the accessible IP list” option to allow all IP connections

Under VPN > IPSec > Global Setting, Enable “All IPSec Connection”

Setup VPN (See the following page)

Please make sure “NAT” enable or disable depend on your requirement.

13Confidential

Page 14: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (Firmware Ver.)

FWR_DEVICE_EDR_G903_V2.2.4_Build_12061815.rom

Page 15: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (LAN IP)

Page 16: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (WAN IP)

Page 17: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (VPN-IPSEC-Global Setting)

Page 18: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (VPN-IPSEC Setting-1)

Page 19: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (VPN-IPSEC Setting-2)

Page 20: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Confidential20

To be able to communicate between two laptops, make sure both laptops’ network interfaces have their “Default Gateway” configured correctly (OnCell or EDR-G903).

Make sure there is only one Default Gateway on each laptop (this might happen if there are multiple network cards).

Once everything is ready, both laptops should be able to ping each other.

Once both sides are configured

20Confidential

Page 21: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA-1 (System Log)

VPN Connection works

Page 22: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

OnCell G3150-HSDPA-2 (System Log)

VPN Connection works

Page 23: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

EDR-G903 (IPSEC Status)

Page 24: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Ping Device on EDR-G903 From Both Laptops Connected to OnCell G3150-HSDPA

Page 25: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

First G3150

Page 26: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Second G3150

Page 27: VPN Setup For Multiple OnCell G3150-HSDPA to One EDR-G903

Troubleshooting In the current design, EDR-G903 is acting as the responder (server)

and OnCell is acting as the initiator (client).• EDR-G903

• It has a public IP and you can ping it from the OnCell Device• If it is behind a firewall, make sure port UDP:500 and UDP:4500 (if NAT-T is

enabled) are not blocked• OnCell

• If OnCell is behind a firewall, make sure port UDP:500 and UDP:4500 (if NAT-T is enabled) are not blocked

• Make sure the above two ports are not blocked by the SIM card Operator

If VPN tunnel is not established after your configuration• Enable OnCell System Log and check which phase it failed on• Double check the failed phase• Capture Wireshark packets from the EDR-G903• Export configuration files from both EDR-G903 and OnCell• Send Moxa TS the capture Wireshark log, configuration files, system log

2727Confidential