key (an
MD5
key has 128 bits while an

SHA1
key has 160 bits).

The
encryption key starts with

enckey=


and a hexadecimal key (with a length of 190
bits). Separate every 32 bits in the hex key with

_

.



Import key: import a complete key file. Import the key from a file
instead

of filling it
on the web pate. After you import the key, you can see the imported key on the web
page. We suggest that you close IPSec before importing the key file (by unchecking
Enable IPSec on the main configuration page and clicking Save). Or you may fail to
import the key.


The dynamic configuration key wizard page is as follows:

CCU VPN EDGE

Router User Manual

Chapter 3
Router Configuration



50






IPSec

Tun
nel name: fill in the
IPSec

channel name with English characters, digits,
-

or _.
Do n
ot use the

space
symbol
.



Use
: select to build the IPSec on the PPP connection or through L2TP channel or
LAN



Peer

IP: to build the IPSec on the wireless PPP dialing connection, fill in the IP
address of the peer end gateway



L2TP Tu
nnel name: to build the

IPSec on a designated L2TP channel, fill in the name
of the L2TP channel (L2TP user name)



Authorization
: use the pre
-
share key or RSA digit signature mode



Enable: enable or disable the IPSec channel



Advanced: open the advanced options



ID
: fill in the IDs
of the router and peer. ID must be an FQDN starting with
@
, such as
@xyz.example.com



Subnet: fill in the local subnet and peer subnet that can communicate with each
other only after IPSec processing



Perfect Forward Secrecy (PFS) of main key



IKE

survival ti
me: fillin the survival time of the
IKE

key channel in the unit of

s

(second),
m

(minute), and
h

(hour). The largest value is
8

hours



Key renegotiated
: select whether to automatically re
-
negotiate and generate the key
(recommended). Fill in the survival t
ime for the key in the unit of

s

(second), m
(minute), h (hour) or d (day). Fill in the
re
-
negotiation key time before the key expires
in the unit of s (second), m (minute), or h (hour). T
h
e latter value must be smaller
than the former one.



Connecting Ret
ry
: the attempts to establish the
IPSec

Tu
nnel. The value of 0 means
endless att
e
mpt.

CCU VPN EDGE

Router User Manual

Chapter 3
Router Configuration



51




Back: cancel this configuration and return to the main page for IPSec configuration



Next: save the configuration and access the IPSec key management page



Cancel: cancel
the unsaved configuration on this page. All the configuration items
restore to the values before modification

The key management page for dynamic configuration is as follows:





Tu
nnel name: display the name of this IPSec channel



Tu
nnel type: show if the I
PSec channel is a manual configuration key channel or a
dynamic configuration one



Authorization
: use the pre
-
share key or RSA digit signature mode



View key: display the content of uploaded key file



Key file: select a file with key. A key file must contain
a key for ID check. There are
two ID check modes with different formats. To use the RAS digit signature check, the
key file starts with

rsasig=


and the RSA public key of the peer gateway. To use the
pre
-
share key, the key file starts with

secret=


and p
re
-
share key character string.
T
h
e characters that form a key must be in the same row.



Import key: import a complete key file. Import the key from a file
instead

of filling it
on the web pate. After you import the key, you can see the imported key on the

web
page.


Special note:

Only specific hardware versions support
IPSec
.



CCU VPN EDGE

Router User Manual

Chapter 3
Router Configuration



52


VRRP

Configuration


VRRP

is an active/standby work mode designed to remove the network breakdown due to
failure of the default router in the static default route environment. In
this way, the inside
and outside data communication is not affected and the parameters of the internal
network need not to be modified during
handover

of routing equipment.
VRRP needs to
have the IP backup and priority route selection features.

Click
VRRP

Configura
t
ion

on the
Route Parameter Configuration

menu. T
h
e
following interface appears.



VRRP

router group:


Select the homing group of the
VRRP

router.
It
supports
2 groups only;

VRID
:





The ID of the virtual router, ranging from
1
-
255
;

VRRP

route
r priority:

The priority of the VRRP router in this group. The value
ranges from
1

to
254
;

VRRP

Ad
vertisement

interval:


The interval at which the main status router sends
VRRP advertisement. The value ranges from

1

to
254
;

Virtual router IP

Address
:


The

IP address of the virtual router;

Bind

to:


Specify the interface for
VRRP

detection.
You can
select the VPN dialing interface;

Use

preemption

Mode
:


Select to enable the preemption mode.



Special note:

Except the priority, all the parameters in the sa
me group must be the same.


CCU VPN EDGE

Router User Manual

Chapter 3
Router Configuration



53


3.2.6
Logoff

Click "Start"
-
>"Logoff" menu to exit router configuration & management pages.

You may be required to enter correct user name and password when you re
-
login.

3.3
System Upgrade

CCU VPN EDGE

router can be continuously improved

based on the actual application
situations. You can upgrade the software system to meet specific needs from the
customer and improve equipment performance.
The router can be

up
grade
d

by a special
update tool.

For t
he update tool
instructions
,

refer

to Ap
pendix
1
.


CCU VPN EDGE

Router User Manual

Chapter 4
Operation Instruction



54


Chapter 4
Operation Instruction

This chapter
introduces

router operation
introductions
.

1.

Panel

Indication

2.

Operation

3.

Trouble Shooting



4.1
Panel Indication

There are four LEDs at the

router front panel; it indicates the router and
network

operation
status.


L
ED

Status

Description

10M

Blinking (data detected)

Connected
10BaseT

device

and data transmission
detected


Lights off

Connected
100BaseT

device

LINK

Lights up

Ethernet connected

NET

Lights up
/
Blinking

Depends network & radio
module

(*)

RUN

Lights up

Router self test and initializing

Quick b
linking (
about
1/
4

second)

Router dialing

Blinking (
about
1
/2

second)

Router working


(
*
)

NET

indication

will

depend

on
the type of radio module and

network
. Click


Start

-
>

Online Help


at
router menu, and the
n click

Online Help

-
>

FAQ


at the help
page for details.

4.2
Operation

The
router is
an embedded hardware and software
platform
.
N
ormally, it is working without
any manual operation. It provides a
reliable

and flexible data channel for industrial
application
s.

The
router should be installed at place with good radio signal receiving.
For the

cabinet
and
basement

environment
, we recommend to extend the antenna.



For outdoor use, lightning should be considered. We propose to install an arrester
between antenna

and the ANT interface.


CCU VPN EDGE

Router User Manual

Chapter 4
Operation Instruction



55



4.3
T
rouble
S
hooting

Problem 1:
All LEDs are not lights
-
up
.

Check all cables that
are

connected to the router
.

C
heck the power supply adapter output voltage.

If the power is cor
r
ect and there is no LED lights
-
up, the router may be fa
iled.
C
ontact the
re
seller for repairing.

Problem 2:

Router works not stable after long time

of

operation.

Check router cabinet temperature, if it is overheating, place the router at the place with
good
ventilation
.

Problem 3: Router does not run se
l
f
-
tes
t when it is powered on.

Check the power adapter.

Problem
4
: Update failed

System boot system and application program are stored at different memory allocation;
failed update will not affect the router rebooting.
R
e
-
update the firmware
until

it is working.

Problem 5: time out when ping the router.

Pinging 192.168.8.1 with 32 bytes of date:

Request timed out.

It indicates that is something wrong during the installation, check
following

items:



Check the Ethernet connection between your
PC

and
the
router.

(
Not
e:
The
router

s
LINK

and PC

s
Link

should light up if there

is connection
)
.



Check your
TCP/IP

setting.

(
Note: If the
router LAN
IP

is
192.168.8.1
, your PC local connection IP address
should be
192.168.8.xxx)
.

For more checking, type

ipconfig


command at D
OS prompt.




(
Type


ipconfig ?


Command
for its help
)

CCU VPN EDGE

Router User Manual

A
ppendix

1: Firmware Update Tool



56


A
ppendix

1
:
Software

Upgrade Guide

This appendix introduces how to upgrade the software of the router:



Update

Tool and Operation Steps

The router is a product designe
d t
hrough the platform technology,
y
ou can upgrade the
software
by
the
update

tool
.

The
update

tool does not need installation
.

After you install the tool, double click to run the
tool:




Local upgrade:

First, view the system informa
tion in the System T
ools of the
router. Check
the information
against the description in the downloaded Upgrade Software to see if the upgrade
requirements are met.

Conne
ct your PC to the
router based on the related description in
Section 3.1 of

this
manual, and then:



Doub
le click the
update

tool



Ent
er the IP address of the
router you want to upgrade, for example:
192.168.8.1

CCU VPN EDGE

Router User Manual

A
ppendix

1: Firmware Update Tool



57




Click
Browse

to search for the
software

you want to download and upgrade, and
then check
Upgrade

as you like



Click

Start
to start
software

upgrade; th
e following process bar shows the upgrade
progress:

The upgrade
process
may take 5 minutes to complete. After upgrade, the system
displays an
Upgrade succeeds

prompt message. Restart the router to finish upgrade.

Warning
:


1
.

During software upgrade, do
not
switch

off the power or disconnect the PC from the router;

2
.

If upgrade fails, reset the router for another try.



Remote upgrade:

If you already know the IP address of the router in a mobile network, you can remotely
upgrade the router.

You also ne
ed to view the system information in the System Tools of the router. Check the
information against the description in the downloaded Upgrade Software to see if the
upgrade requirements are met.



Double click the
uptools

upgrade tool



Enter the mobile n
etwor
k IP address of the
router you want to upgrade, for example:
220.192.xxx.xxx
. You can query the IP address in the communication data center.



Click
Browse

to search for the
software

you want to download and upgrade, and
then check
Upgrade

as you like



Click

Start

to start
software

upgrade; the following process bar shows the upgrade
progress:

Normally, the upgrade process may take 18 minutes to complete (depending on the
transmission bandwidth of the mobile network). After upgrade, the system displays an
Upg
rade succeeds

prompt message. Restart the router to finish upgrade.


Warning:

1
.

During software upgrade, do not
switch

off the power or disconnect the PC from the router;

2
.

There are risks in remote upgrade. During upgrade, you may fail to access the m
obile network. T
h
e
system may reboot, causing failure to upgrade. Normally, we
recommend

you not to use this upgrade
method;

3
.

Remote upgrade is applicable to the
CDMA 1X

router only;

4
.

If upgrade fails, you may not b
e able to connect to the remote
route
r.