Speedtouch 600 Series
Speedtouch 600 Series
600Series
Business DSL Routers
Orientation Guide
Release R4.2
600
SERIES
SpeedTouch™610
Business DSL Router
Orientation Guide
Release R4.2
Status Released
Change Note PeckelbeenS
Short Title AppNote ST610 Orientation Guide R4.2 (en)
Copyright © 2003 THOMSON. All rights reserved. Passing on, and copying of this document, use and
communication of its contents is not permitted without written authorization from
THOMSON. The content of this document is furnished for informational use only, may be
subject to change without notice, and should not be construed as a commitment by
THOMSON. THOMSON assumes no responsibility or liability for any errors or inaccuracies
that may appear in this document.
Contents
E-SIT-CTC-20030306-0004 v2.0
1
4 SpeedTouch™610 Advanced Concepts ..................... 61
4.1 Native Command Line Interface Access......................................................... 62
5 Troubleshooting ........................................................... 69
E-SIT-CTC-20030306-0004 v2.0
2
1 SpeedTouch™610 Installation
1 SpeedTouch™610 Installation
Introduction Thank you for purchasing the SpeedTouch™610 Business DSL router!
Specially designed for Small/Medium Enterprises (SMEs) and Small Office/Home Office
(SOHO), the SpeedTouch™610 Business Digital Subscriber Line (DSL) router offers
plenty of capabilities. With an easy installation, embedded firewall, embedded IPSec
based IP Virtual Private Networking (VPN) and remote management tools, the Speed-
Touch™610 is a highly secure device.
Beyond the small business market, the SpeedTouch™610 is the ideal solution for
connecting regional and branch offices back to corporate headquarters.
In this Orientation Guide This Orientation Guide will assist you in getting acquainted with the SpeedTouch™610
Business DSL router and its broad range of service capabilities.
UPnP The SpeedTouch™610 is a Universal Plug and Play (UPnP) certified product. This
feature enables your computer to discover and control UPnP devices on the network.
If you are running Microsoft Windows XP, you can add the Universal Plug and Play
(UPnP) component to your system.
When adding this component, you may need the Windows XP CD-ROM.
For more information see Windows XP Help.
Documentation and The SpeedTouch™610 products continue to evolve as extra and new functionalities are
software updates made available.
For more information on the latest technological innovations, software upgrades, and
documents, please visit the SpeedTouch™ web site at:
www.speedtouch.com
E-SIT-CTC-20030306-0004 v2.0
3
1 SpeedTouch™610 Installation
Delivery check Check your SpeedTouch™610 box for the following items:
• The SpeedTouch™610/610i/610s/610v
• One power adapter
• One Cat.5 straight-through Ethernet cable (RJ45/RJ45)
• One DSL cable (RJ11/RJ11, RJ14/RJ14)
• Optionally, one or more cable filter(s)
• The SpeedTouch™610 Quick Installation Guide (eight languages)
• The SpeedTouch™610 Orientation Guide (English only)
• The SpeedTouch™ Setup CD-ROM
In the event of damaged or missing items, contact your product dealer for further
instructions.
Other materials The SpeedTouch™610 box may also include other materials.
E-SIT-CTC-20030306-0004 v2.0
4
1 SpeedTouch™610 Installation
Front and back panel The SpeedTouch™610 is presented in a slim line housing:
layout
Depending on the SpeedTouch™610 model you purchased, the device can be equipped
with:
• One single 10/100Base-T Half-/Full-duplex MDI-X Ethernet port (optionally with
one 25.6Mb/s ATM-Forum port):
Power Switch 25.6Mb/s Dip Switches Serial Console DSL Line Port
ATM-Forum port
E-SIT-CTC-20030306-0004 v2.0
5
1 SpeedTouch™610 Installation
Front panel LEDs The SpeedTouch™610 is equipped with five LEDs on its front panel, indicating the state
of the device during normal operation:
Indicator Description
Ethernet port(s) LEDs Each Ethernet port on the rear panel has two LEDs:
10MB/100MB LED Link Integrity/Activity LED
10/100Base -T
Indicator Description
E-SIT-CTC-20030306-0004 v2.0
6
1 SpeedTouch™610 Installation
DSL variants Four DSL variants of the SpeedTouch™610 Business DSL routers exist:
• The SpeedTouch™610:
The ADSL/POTS variant connecting to an analog POTS(*) line.
• The SpeedTouch™610i:
The ADSL/ISDN variant connecting to a digital ISDN(**) line.
• The SpeedTouch™610s:
The SHDSL variant connecting to a dedicated SHDSL(***) line.
• The SpeedTouch™610v:
The SHDSL variant connecting to a dedicated VDSL(****) line.
Use only the SpeedTouch™610 variant which is appropriate for the DSL service deliv-
ered to your local premises.
Check at your Service Provider whether your SpeedTouch™610 variant meets the DSL
service requirements.
(*) Plain Old Telephone Service (POTS)
(**) Integrated Services Digital Network (ISDN)
(***) Symmetrical High speed Digital Subscriber Line (SHDSL)
(***) Very high speed Digital Subscriber Line (VDSL)
DSL Port
ADSL 3/4
VDSL 3/4
2/5
DSL service The appropriate DSL service must be available at your local premises:
• ADSL, SHDSL or VDSL service must be enabled on your phone line
• In case of ADSL, both POTS or ISDN and ADSL service are simultaneously avail-
able from the same copper pair. Therefore, you need a central splitter or distrib-
uted filters for decoupling ADSL and telephone signals
Always contact your Service Provider for splitter/filter installation!
Public telephone lines carry voltages that can cause electric shock. Only install splitter/
filters yourself if these are qualified for that purpose. Other splitter/filters may only be
installed by qualified service personnel.
E-SIT-CTC-20030306-0004 v2.0
7
1 SpeedTouch™610 Installation
Ethernet Cables In the SpeedTouch™610 box, a full wired Cat.5 straight-through RJ45/RJ45 Ethernet
cable, further referred to as LAN cable is included.
You can use LAN cables other than the one provided in the box. However make sure to
use correct connection cables.
More information on For more information, see the application note “The SpeedTouch™ and Ethernet
Ethernet wiring Connectivity”.
Single PC wiring Once all connections are made the result should look similar as below:
E-SIT-CTC-20030306-0004 v2.0
8
1 SpeedTouch™610 Installation
LAN wiring Using the SpeedTouch™610 switch (if equipped) and/or an external hub you can
connect multiple PCs to your SpeedTouch™610:
Powering Once all previous steps are completed, you can turn the SpeedTouch™610 on (I) with
the power switch.
E-SIT-CTC-20030306-0004 v2.0
9
1 SpeedTouch™610 Installation
What you need from You must have a user account with an Internet Service Provider (ISP) for Internet
your SP access. For this user account, it will provide you with:
• A user name (logon ID).
• A password.
Other information might be required, depending on the ISP’s specific requirements.
SpeedTouch™ The method for configuring the SpeedTouch™610 via the Setup configuration files
configuration options depends on the Operating System (OS) of your computer system.
In case your computer system runs:
• A Microsoft Windows OS
The SpeedTouch™ Embedded Easy Setup wizard, accessible from the Speed-
Touch™ web pages, will automatically guide you through the configuration of the
SpeedTouch™610.
E-SIT-CTC-20030306-0004 v2.0
10
1 SpeedTouch™610 Installation
Microsoft Windows One of the following operating systems must be installed on your PC(s):
• Windows 98
• Windows 98SE
• Windows ME
• Windows NT4.0 SP6
• Windows 2000
• Windows XP
The SpeedTouch™ The SpeedTouch™ Setup wizard procedure consists of two major parts:
Setup Wizard • The detection procedure
• The configuration procedure
E-SIT-CTC-20030306-0004 v2.0
11
1 SpeedTouch™610 Installation
E-SIT-CTC-20030306-0004 v2.0
12
1 SpeedTouch™610 Installation
E-SIT-CTC-20030306-0004 v2.0
13
1 SpeedTouch™610 Installation
7 The Setup wizard will continue to search for the SpeedTouch™610 on the net-
work. The following window shows the detection progress:
8 The setup wizard should find your SpeedTouch™610 device on the local network.
This is indicated by following window:
In case more than one SpeedTouch™ device is found, a listing is provided from
which you can select your SpeedTouch™610.
Note If the wizard does not find a SpeedTouch™610 on the network, an
error window appears. In this case check:
• Whether the SpeedTouch™610 is turned on and fully initialized.
• Whether your PC is correctly connected to the Speed-
Touch™610.
• Whether no dedicated firewall device or a router is placed
between your PC and the SpeedTouch™610 and whether no
personal firewall software is running on your PC.
• Whether TCP/IP is correctly installed on your PC, and whether
your PC is configured with a valid IP address as DHCP client, or
via automatic IP configuration.
To repeat search for the SpeedTouch™610, click Back and proceed
with step 7 of this procedure.
9 To continue with the configuration of your SpeedTouch™610 and your PC, pro-
ceed with the configuration procedure described below.
E-SIT-CTC-20030306-0004 v2.0
14
1 SpeedTouch™610 Installation
E-SIT-CTC-20030306-0004 v2.0
15
1 SpeedTouch™610 Installation
5 After restarting your PC, the SpeedTouch™ Setup wizard will appear again to
announce that the configuration has been successful:
E-SIT-CTC-20030306-0004 v2.0
16
1 SpeedTouch™610 Installation
Supported Operating As the SpeedTouch™610 is OS-independent, this configuration setup can be used by
Systems any computer system.
Note The following procedure may equally be used on MS Windows OSs.
TCP/IP Ensure that your operating system has a valid TCP/IP configuration.
Configure your computer with a static Net10 private IP address, e.g. 10.0.0.1, 10.0.0.2,
etc. Ensure, however, that you do NOT use the 10.0.0.138 IP address as this is the
default IP address of the SpeedTouch™610.
To ensure that IP connectivity exists, you can ping the SpeedTouch™610.
E-SIT-CTC-20030306-0004 v2.0
17
1 SpeedTouch™610 Installation
4 The following window invites you to select the appropriate connection profile for
your internet connectivity:
E-SIT-CTC-20030306-0004 v2.0
18
1 SpeedTouch™610 Installation
7 The SpeedTouch™ Setup Wizard appears again to announce that the configura-
tion has been successfully completed:
E-SIT-CTC-20030306-0004 v2.0
19
1 SpeedTouch™610 Installation
Introduction The Dr. SpeedTouch™ application allows you to diagnose and troubleshoot your
SpeedTouch™610.
With the Dr. SpeedTouch™ application you can do the following:
• View the status and performance of the SpeedTouch™ device
• Run a Diagnostics program to locate a connectivity problem
• Run a Troubleshooter to help you solve a connectivity problem.
Supported Operating Installing and using Dr. SpeedTouch™ is only supported for following Microsoft
Systems Windows Operating Systems:
• Windows 98
• Windows 98SE
• Windows ME
• Windows NT4.0 SP6
• Windows 2000
• Windows XP
E-SIT-CTC-20030306-0004 v2.0
20
1 SpeedTouch™610 Installation
Using Dr. SpeedTouch™ By default Dr. SpeedTouch™ is started automatically at boot of your system and runs in
the background, i.e. minimized in the status area.
To pop up Dr. SpeedTouch™:
1 Double-click in the status area.
2 Dr. SpeedTouch™ searches your network for SpeedTouch™ devices. If more than
one device is found, a list of available devices will be provided. If this is the case,
select the SpeedTouch™ of your choice and click OK.
3 The Dr. SpeedTouch™ window appears:
• View activity between your computer, the SpeedTouch™610 and the Internet:
E-SIT-CTC-20030306-0004 v2.0
21
1 SpeedTouch™610 Installation
• Test and troubleshoot the connectivity of your computer and the Speed-
Touch™610 device to your ISP and the Internet via the Diagnostics wizard.
Note For more information on Dr. SpeedTouch™ please click Help in the applica-
tion or press F1 context sensitive help.
E-SIT-CTC-20030306-0004 v2.0
22
2 SpeedTouch™610 Internet Connectivity
Introduction This chapter provides information on how to access the Internet and how to configure
your SpeedTouch™ according to your preferences.
Surfing the Internet As soon as the SpeedTouch™610 and the computer(s) have been configured as outlined
in “1.3 SpeedTouch™610 Configuration Setup” on page 10, you can connect to the
Internet.
Connection Services The SpeedTouch™610 supports various scenarios to establish end-to-end connectivity
and Packet Services with the BroadBand Remote Access Server (BBRAS) and the Internet.
For more information, see the application note “SpeedTouch™ Connection and Packet
Services”.
The scenario to use depends on the configuration profile/file you used to configure the
SpeedTouch™610 and the Service Provider's requirements.
Direct Access In case the SpeedTouch™610 is configured for direct access (always-on or dial-on-
demand) you can immediately surf the internet.
Note In some cases however, e.g. in case of Transparent Bridging, the remote
organization still might ask for a user name and password on an Internet
welcome page for authentication.
Dial-in access In case the SpeedTouch™610 is configured for dial-in access, you can manually start and
terminate the PPP session. On the following pages, we explain how to start/terminate a
PPP session via:
• UPnP.
See “2.1.1 Internet Sessions via Windows XP’s UPnP” on page 25
• The SpeedTouch™610 web pages.
See “2.1.2 Internet Sessions via the SpeedTouch™ Web Pages (all OSs)” on
page 26.
E-SIT-CTC-20030306-0004 v2.0
23
2 SpeedTouch™610 Internet Connectivity
Introduction The SpeedTouch™ supports both two most popular connection methods: Routed PPP
over ATM (PPPoA) and PPP over Ethernet (PPPoE).
The connection method to use depends on the preferences of your ISP, hence the
connection profile you must apply to the SpeedTouch™ via the SpeedTouch™ Setup
wizard or its embedded Easy Setup wizard.
Note To use the embedded Routed PPPoA (PPPoE) dial-in client, the
SpeedTouch™ needs to be configured for Routed PPPoA (PPPoE) via the
SpeedTouch™ Setup wizard or the embedded Easy Setup wizard.
E-SIT-CTC-20030306-0004 v2.0
24
2 SpeedTouch™610 Internet Connectivity
Starting an Internet To connect to the internet via Windows XP’s Internet Connection icon proceed as
session via Windows follows:
XP’s UPnP
1 Click Control Panel on the Start menu.
2 The Control Panel window appears. Double-click Network Connections.
3 The Network Connections window appears:
E-SIT-CTC-20030306-0004 v2.0
25
2 SpeedTouch™610 Internet Connectivity
E-SIT-CTC-20030306-0004 v2.0
26
3 The SpeedTouch™610 Web Interface
Preconditions Prior to access the SpeedTouch™610 web pages make sure that either:
• Your Web browser is not using a proxy server.
• The SpeedTouch™610 IP address is not submitted to a proxy server.
For more information on how to disable your web browser's proxying, please consult
your web browser's user’s guide.
Use of the In most cases the SpeedTouch™610 is correctly configured for your Internet connec-
SpeedTouch™ web tivity via the appropriate configuration profile/file and no further configuration on the
interface web interface is needed.
Only for using the advanced SpeedTouch™610 features, access to the web pages is
required.
This chapter aims to give a brief overview of the SpeedTouch™610 web pages and their
respective functionality.
For more profound Information, see the relevant application notes.
E-SIT-CTC-20030306-0004 v2.0
27
3 The SpeedTouch™610 Web Interface
Access to the If your computer is Universal Plug and Play (UPnP) enabled, you can access the Speed-
SpeedTouch™610 web Touch™ web pages as follows:
interface via UPnP
1 Double-click My Network Places on your desktop.
2 The following window appears:
E-SIT-CTC-20030306-0004 v2.0
28
3 The SpeedTouch™610 Web Interface
From now on the SpeedTouch™610 acts as a web server sending HTML pages/forms at
your request. You can fill out these pages/forms and submit them to the Speed-
Touch™610. The latter scans the pages and performs the appropriate configurations.
Topic menu and links On the left of each of the SpeedTouch™610 web pages a topics menu is provided. This
menu navigates you via links through all configurational aspects of the Speed-
Touch™610.
For your convenience the links are sorted in six expandable topics menus: Quick, IP
Router, Connections, LAN Services, System Config, and Advanced. Each of these offers
you a set of specific links, leading you to a configuration aspect of the Speed-
Touch™610.
The following table lists all Quick Tasks Links:
E-SIT-CTC-20030306-0004 v2.0
29
3 The SpeedTouch™610 Web Interface
E-SIT-CTC-20030306-0004 v2.0
30
3 The SpeedTouch™610 Web Interface
Save All The Save All link on the tasks menu allows you to save the SpeedTouch™610 settings to
memory.
It is advised to back-up your saved configuration on a regular basis. This can be done via
the Upgrade link in the System Config Tasks Links.
Help The Help link in the topics menu header allows you to browse the SpeedTouch™610
online Help.
For more information on a specific topic you can click the context-related Help links
located at the topic’s web pages.
E-SIT-CTC-20030306-0004 v2.0
31
3 The SpeedTouch™610 Web Interface
Easy Setup Click this link to start the SpeedTouch™ Easy Setup wizard.
See “1.3.2 Configuration Setup for other Operating Systems” on page 17 for more
information.
System Information Click this link to display the System Information page. This page is also the Speed-
Touch™610 home page.
The System Information page consists of four sections:
• Click the Diagnostics tab to view the results of the System Self Test, LAN Connec-
tivity and DSL synchronization test:
• Click the Service Info tab to view the current physical status of the ADSL line:
E-SIT-CTC-20030306-0004 v2.0
32
3 The SpeedTouch™610 Web Interface
• Click the System tab to view some important system information of the Speed-
Touch™:
See “2.1.2 Internet Sessions via the SpeedTouch™ Web Pages (all OSs)” on page 26 for
more information on how to use the Connections table.
For more information on the configuration and use of PPP connections, see the applica-
tion notes “The SpeedTouch™ Routed PPPoA Packet Service” and “The SpeedTouch™
Routed PPPoE Packet Service”.
E-SIT-CTC-20030306-0004 v2.0
33
3 The SpeedTouch™610 Web Interface
• Expand the Wan section. To view the current DSL state and connection informa-
tion, expand the DSL and connections sections:
E-SIT-CTC-20030306-0004 v2.0
34
3 The SpeedTouch™610 Web Interface
This page refreshes every 30 seconds. Via the CLI you can configure additional
syslog events to be notified by syslog messages in addition to the standard set of
syslog events.
• Configure a computer IP address to send syslog messages to. This allows basic
remote monitoring of the SpeedTouch™610:
For more information on Syslog, see the application notes “SpeedTouch™610 Opera-
tion and Maintenance” and “SpeedTouch™610 Remote Management”.
E-SIT-CTC-20030306-0004 v2.0
35
3 The SpeedTouch™610 Web Interface
When adding an IP address, all essential IP routes will be automatically be added to the
SpeedTouch™610 IP routing table. The eth0 interface allows you to assign an IP address
to the SpeedTouch™ Ethernet interface.
E-SIT-CTC-20030306-0004 v2.0
36
3 The SpeedTouch™610 Web Interface
RIP Click this link to display the Routing Information Protocol (RIP) page.
This page allows you to:
• View or configure the SpeedTouch™610's general RIP configuration:
Via the RIP Settings tab you can enable/disable the master RIP daemon and specify
which RIP version should be used. Additionally you can set the default metric and
some RIP timer settings.
• View or configure the RIP configuration per interface:
Do not forget to save your changes to persistent memory by clicking Save All.
E-SIT-CTC-20030306-0004 v2.0
37
3 The SpeedTouch™610 Web Interface
NAPT Click this link to display the Network Address and Port Translation (NAPT) page.
This page allows you to:
• View or add/delete specific static NAPT entries:
E-SIT-CTC-20030306-0004 v2.0
38
3 The SpeedTouch™610 Web Interface
E-SIT-CTC-20030306-0004 v2.0
39
3 The SpeedTouch™610 Web Interface
IPSEC Policy To use the IP Security and IPSEC enabled VPN features of the SpeedTouch™610, the
IPSec VPN software key must be installed. See the topic Add-On in the System Config
Tasks Links for more information, or check the application note “SpeedTouch™610
Operation and Maintenance”.
In case IPSec VPN is enabled, clicking this link will display IPSEC Policy Configuration
page.
This page allows you to:
• View the IP VPN configuration setup for the VPN connection:
This window allows you to configure the local and remote VPN peer identities,
select the key distribution mechanism, and specify in case of a preshared secret,
the secret string.
• View the VPN connection configuration and start/stop VPN connection sessions:
For more information, see the application notes “SpeedTouch™ IPSec Quick Start
Guide” and “SpeedTouch™ IPSec Configuration Guide”.
E-SIT-CTC-20030306-0004 v2.0
40
3 The SpeedTouch™610 Web Interface
IPSEC Certificates Click this link to display the IPSEC Certificates Configuration page.
In case certificates are used for authentication, this page allows you to view/configure
the certificate configuration:
E-SIT-CTC-20030306-0004 v2.0
41
3 The SpeedTouch™610 Web Interface
For more information, see the application note “SpeedTouch™ Connection and Packet
Services”.
Routed Ethernet Click this link to display the Routed Ethernet Configuration page. Routed Ethernet is
often referred to as MAC Encapsulated Routing or MER.
This page allows you to view/configure the SpeedTouch™610 Routed Ethernet connec-
tion entries:
For more information, see the application note “The SpeedTouch™ Routed Ethernet
Packet Service”.
E-SIT-CTC-20030306-0004 v2.0
42
3 The SpeedTouch™610 Web Interface
Routed PPPoE Click this link to display the Routed Point-to-Point Protocol over Ethernet (PPPoE)
page.
This page allows you to view/configure the SpeedTouch™610 Routed PPPoE connec-
tion entries
Per selected Routed PPPoE you can:
• Configure some advanced settings, if applicable:
E-SIT-CTC-20030306-0004 v2.0
43
3 The SpeedTouch™610 Web Interface
• View some session statistics while a session is running on the selected Routed
PPPoE entry:
For more information, see the application notes “The SpeedTouch™ Routed PPPoE”
and “The SpeedTouch™ PPPoE Relay”.
E-SIT-CTC-20030306-0004 v2.0
44
3 The SpeedTouch™610 Web Interface
Routed PPPoA Click this link to display the Routed Point-to-Point Protocol over ATM (PPPoA).
This page allows you to:
• View/configure the SpeedTouch™610 Routed PPPoA connection entries:
For more information, see Routed PPPoE and the application note “The SpeedTouch™
Routed PPPoA”.
Routed IPoA Click this link to display the Routed IP over ATM (IPoA) page.
This page allows you to:
• View/configure the SpeedTouch™610 Routed IPoA connection entries:
E-SIT-CTC-20030306-0004 v2.0
45
3 The SpeedTouch™610 Web Interface
Classical IP Click this link to display Classical IP (CIP) over ATM page.
This page allows you to:
• View/configure the SpeedTouch™610 IP interface connection entries:
Bridged Ethernet Click this link to display the Bridged Ethernet page. Bridged Ethernet is commonly
known as IEEE802.1D Transparent Bridging or RFC1483/Bridged.
The Bridged Ethernet Packet Service is also used for the Bridged PPP over Ethernet
(PPPoE) Packet Service.
This page allows you to:
• View/configure the SpeedTouch™610 Bridged Ethernet connection entries:
For more information, see the application notes “The SpeedTouch™ Bridged Ethernet
Packet Service” and “The SpeedTouch™ Bridged PPPoE Packet Service”.
Relayed PPPoA Click this link to display the Relayed PPPoA page. Relayed PPPoA is often referred to as
PPPoA-to-PPTP Relaying or PPPoA/Point-to-Point Tunnelling Protocol (PPPoA/PPTP).
This page allows you to:
• View the current active SpeedTouch™610 Relayed PPPoA connection sessions:
E-SIT-CTC-20030306-0004 v2.0
46
3 The SpeedTouch™610 Web Interface
DHCP Click this link to display the Dynamic Host Configuration Protocol (DHCP) page.
In this page you can:
• Click the DHCP Server tab to access the DHCP server pages. This page is subdi-
vided into three parts:
• Click the Server Config tab to enable/disable the SpeedTouch™610
(Auto)DHCP server:
If needed, you can also manually add static DHCP leases for specific hosts or
make dynamically assigned leases static by clicking Lock.
E-SIT-CTC-20030306-0004 v2.0
47
3 The SpeedTouch™610 Web Interface
The SpeedTouch™610 DHCP server (if enabled) will use the address pools
listed in this table to provide IP addresses to requesting DHCP clients. If
needed, you can add/delete DHCP address pools manually.
• Click the DHCP Relay tab to view the DHCP Relay pages. This page is subdivided
into two parts:
• Click the Relay Config tab to view the current SpeedTouch™610 DHCP
relay status:
Via this table you can also manually add static SpeedTouch™610 DHCP relay
entries for specific interfaces, if applicable.
• Click the Relay Interfaces tab to view the SpeedTouch™610 DHCP relay
interfaces:
E-SIT-CTC-20030306-0004 v2.0
48
3 The SpeedTouch™610 Web Interface
• Click the DHCP client tab to view the current SpeedTouch™610 DHCP client
status:
Via this table you can also manually add static SpeedTouch™610 DHCP client
entries for specific interfaces, if applicable.
DNS Click this link to display the Dynamic Name System (DNS) page.
This page allows you to:
• View the current SpeedTouch™610 DNS server hostname leases:
Via this table you can also add static DNS hostname entries.
This may be useful for devices which do not support DNS, e.g. a printer. By adding
a name for your network printer, identified by its IP address, you will be able to
contact this printer by name rather than by IP address.
• View and/or supply the SpeedTouch™610 DNS domain name and to enable/
disable the SpeedTouch™610 DNS server:
E-SIT-CTC-20030306-0004 v2.0
49
3 The SpeedTouch™610 Web Interface
SIP Click this link to display the Session Initiation Protocol (SIP) Proxy Server page.
This page allows you to view/configure
The SpeedTouch™610's integrated SIP multimedia PBX web page offers five tabs,
allowing you to:
• Configure the general SIP Settings of the SpeedTouch™610's SIP PBX.
• Overview and add/delete SIP Users allowed to be involved in SIP communications.
• Overview the Location Information for SIP users (i.e. Contact IP address).
• Overview Call information.
• Create outgoing and incoming Black Lists for users.
Note To use the SIP features of the SpeedTouch™610, the SIP software key must
be enabled. See Add-On for more information.
For more information, see the application note “The SpeedTouch™ SIP multi-media
PBX”.
E-SIT-CTC-20030306-0004 v2.0
50
3 The SpeedTouch™610 Web Interface
System Password Click this link to display the System Setup page.
This page allows you to configure a System password to restrict access to the Speed-
Touch™610:
Upgrade Click this link to display the Software- and Configuration Upgrade page.
This page allows you to:
• Upgrade the SpeedTouch™610 system software:
E-SIT-CTC-20030306-0004 v2.0
51
3 The SpeedTouch™610 Web Interface
To backup the current configuration, click Backup and follow the instructions.
E-SIT-CTC-20030306-0004 v2.0
52
3 The SpeedTouch™610 Web Interface
Add-On Click this link to display the Software Activation Key page.
Next to the SpeedTouch™610 standard functionality additional software modules can
be activated via this page.
This page allows to:
• View the current Software module Status:
Note The key is unique for each SpeedTouch™610 device, and can not
be copied from/to other SpeedTouch™ devices.
4 Click Add to process the software activation key.
5 Restart the SpeedTouch™610. After restart the activated software module
can be used.
E-SIT-CTC-20030306-0004 v2.0
53
3 The SpeedTouch™610 Web Interface
SNTP Click this link to display the Simple Network Time Protocol (SNTP) page.
This page allows you to:
• Configure an NTP server on the Internet to which the SpeedTouch™610 is able
to synchronize its internal clock:
You can check on the Internet for available NTP time servers.
• View and/or set the time manually, in case external synchronization is not used:
For more information, see the application note “SpeedTouch™610 Operation and
Maintenance”.
E-SIT-CTC-20030306-0004 v2.0
54
3 The SpeedTouch™610 Web Interface
CLI Click this link to display the SpeedTouch™ Command Line Interface (CLI) page:
The CLI is meant for in depth configuration of the SpeedTouch™610, giving full control
on all configurational aspects of the device.
The web based CLI provides the same functionality as the native Command Line Inter-
face, available through a Telnet session to the SpeedTouch™610, or via the serial
Console interface.
All CLI groups and commands are placed in a menu. You can open a group by clicking
the mark next to a group name, or clicking the group name.
Clicking on a command name will execute it. Commands without parameters are indi-
cated with and are executed immediately. Commands which require additional
parameters are indicated with . After you configured all parameters, simply click
Apply to execute the command.
For more information, see “4.1 Native Command Line Interface Access” on page 62.
Note To access the web based CLI pages:
• You need at least Microsoft's Internet Explorer 4.0, or at least
Netscape's Communicator 4.06, or equivalent, both supporting Javas-
cript.
• You need to install Microsoft Virtual Machine if your computer runs
Microsoft Windows XP.
For more information, see the application note “The SpeedTouch™ Operation and
Maintenance”.
E-SIT-CTC-20030306-0004 v2.0
55
3 The SpeedTouch™610 Web Interface
• Upload new template files, e.g. from the SpeedTouch™ Setup CD-ROM (usually
template files have the extension .tpl):
By uploading templates you can extend the number of services listed in the Easy
Setup wizard.
For more information, see the application note “The SpeedTouch™ Operation and
Maintenance”.
For more information, see the application note “The SpeedTouch™ Operation and
Maintenance”.
E-SIT-CTC-20030306-0004 v2.0
56
3 The SpeedTouch™610 Web Interface
Introduction The SpeedTouch™ NAPT Manager allows you to add static NAT entries for specific
applications.
Using SpeedTouch™ To add a static NAT entry using SpeedTouch™ NAPT Manager:
NAPT Manager
1 Insert the SpeedTouch™ Setup CD-ROM in your computer’s CD-ROM drive. The
SpeedTouch™ CD Browser will start automatically. Select your language in the
Choose Language window and go to Configuration > Configure NAT Settings.
Note If the SpeedTouch™ CD Browser window does not appear automati-
cally, click Run on the Start menu and enter the following path:
D:\Menu.exe where D stands for the drive letter of your CD-ROM
drive.
2 The following windows will guide you through the detection process of the Speed-
Touch™610 as used by the SpeedTouch™ Setup wizard (see “1.3.1 Configuration
Setup for Microsoft Windows Operating Systems” on page 11).
3 The following page lists the current application hosts.
E-SIT-CTC-20030306-0004 v2.0
57
3 The SpeedTouch™610 Web Interface
By default, the IP address of the PC from where you are running NAPT
Manager will be taken as host IP address. To add a NAPT entry for another
PC you have to change the proposed IP address.
• Manually add a static NAPT entry, click the Advanced tab. Select a protocol
in the Protocol list and enter Port and Host IP address in the appropriate
fields.
By default, the IP address of the PC from where you are running NAPT
Manager will be taken as host IP address. To add a NAPT entry for another
PC you have to change the proposed IP address.
• Specify a default server IP address, click the Default inbound host tab. Enter
the new IP address in the Host IP address field.
E-SIT-CTC-20030306-0004 v2.0
58
3 The SpeedTouch™610 Web Interface
E-SIT-CTC-20030306-0004 v2.0
59
3 The SpeedTouch™610 Web Interface
E-SIT-CTC-20030306-0004 v2.0
60
4 SpeedTouch™610 Advanced Concepts
Introduction This chapter is intended to introduce some advanced features the SpeedTouch™610
supports.
E-SIT-CTC-20030306-0004 v2.0
61
4 SpeedTouch™610 Advanced Concepts
Accessing the The SpeedTouch™610 provides two methods for accessing its Command Line Inter-
Command Line face:
Interface
• Via a TCP/IP Telnet session
• Via the serial “Console” interface.
Note For both access methods, authentication is required in case the Speed-
Touch™610 is protected by a system password.
Basic CLI Once authentication has been passed (if required), the following banner appears:
For your convenience, the CLI commands are structured in CLI command groups, e.g.
“dhcp”. To find out which CLI command groups and/or commands are available, you can
execute 'help' from each command group level prompt.
For a syntax description of a CLI command, simply enter 'help' followed by the CLI
command and press Enter.
You can enter a level by executing its name. From each level you can execute '..' to go
one level up.
Executing a command is done by entering the name of the command and subsequently
providing the parameters, whenever asked for. In case the parameter provides preset
values, you can go through these via the arrow keys.
Note Do not forget to save your changes by executing 'saveall' (from any CLI
prompt).
E-SIT-CTC-20030306-0004 v2.0
62
4 SpeedTouch™610 Advanced Concepts
Semi-graphical CLI To use the semi-graphical Command Line Interface, execute 'menu' from the prompt:
The semi-graphical CLI offers you an attractive and easy-to-use configuration environ-
ment for the CLI.
You can browse through the CLI command groups via the arrow keys. Pressing Enter
executes your selection. From each level you can execute '..' to go one level up.
Use the Tab key to change from the CLI command menu to the control menu and vice
versa.
To setup a CLI command, simply press Enter on its name. You can configure and over-
view its various parameters at one time. In case the parameter provides preset values,
you can go through these via the arrow keys.. If you are satisfied, use the Tab key to go
to the 'OK' field and press Enter.
Note Do not forget to save your changes by executing 'saveall' (from any CLI
prompt).
CLI Reference Guide For a complete description of the SpeedTouch™610 Command Line Interface, see the
“SpeedTouch™610 CLI Reference Guide”.
E-SIT-CTC-20030306-0004 v2.0
63
4 SpeedTouch™610 Advanced Concepts
Introduction The Simple Network Management Protocol (SNMP) is a standard way to retrieve
counters, status variables and other diagnostic information of the SpeedTouch™610.
SpeedTouch™610 The SpeedTouch™610 Firewall is configured to count the SNMP packets by default. To
Firewall configuration allow SNMP traffic to migrate to a remote SNMP manager, you will have to allow it
explicitly by adding the appropriate firewall rules.
For more information, see the application note “The SpeedTouch™ Remote Manage-
ment”
SpeedTouch™610 Based on a client /server concept, the SNMP server (the SNMP manager) gets or sets
MIBs the values of objects defined in a Management Information Base (MIB) kept by the
SNMP client (the SNMP agent). In addition the SNMP agent is also able to autono-
mously initiate an action by sending a trap to the SNMP manager.
The SpeedTouch™610 supports following SNMP MIBs:
• RFC1213 MIB-II
• RFC1215 Traps MIB
• RFC2863 IF-MIB
• RFC2665 Ethernet-like MIB
• RFC1493 Bridge MIB
• RFC2668 MAU MIB
• RFC2515 ATM MIB and RFC2514 ATM-TC-MIB
• RFC2662 ADSL MIB
• RFC3276 SHDSL MIB
• IANAifType MIB
• HDSL2-SHDSL-LINE-MIB_v1 MIB
• System MIB (Enterprise specific branch MIB)
• IPSec MIB (SpeedTouch™610 product specific MIB).
For more information, see the application note “SpeedTouch™610 Remote Manage-
ment”.
E-SIT-CTC-20030306-0004 v2.0
64
4 SpeedTouch™610 Advanced Concepts
Introduction A firewall is a security gateway that controls access between a private LAN domain,
often referred to as Intranet (even for one computer), and the public Internet.
It secures the entry points to the network in such way that access is only allowed to
authorized traffic. Therefore, to effectively control the flow of data, firewall protection
should be placed at each point where the network connects to the WAN.
One point at least, and most probably the most important connection point to the
WAN is the SpeedTouch™610.
SpeedTouch™610 The SpeedTouch™610 packet firewall is a set of related programs that protects the
packet firewall resources of your local network from users from other networks.
Basically, a firewall examines each network packet to determine whether to forward it
towards its destination, or not. Firewalls work in most cases closely together with a
forwarding or proxy server that makes network requests on behalf of your local
network users.
For the SpeedTouch™610 firewall the SpeedTouch™610 DSL router acts as well as
network gateway and proxy server to contact the outside world via the DSL line.
How the packet firewall The SpeedTouch™610 is in fact a packet firewall: inside and outside nodes are visible to
works each other in the IP layer, but the firewall filters out, i.e. blocks the passage of certain
packets, based on their header information.
The packets are intercepted at certain Packet Interception Points (PIP) called hooks in
the SpeedTouch™610 IP router. At these points, they are matched against a chain,
which comprises a hierarchical set of rules (at least one). These rules determine the
type of control implemented on the packets.
Incoming and outgoing traffic is validated by comparing certain values in the packets
with configured firewall parameters. The parameters in a rule (See the CLI command
":firewall rule help create" for a full parameter description) can be divided according to
the protocol to which they belong: a first group validates traffic on the interface level, a
second group on IP level, and a third group on protocol level.
E-SIT-CTC-20030306-0004 v2.0
65
4 SpeedTouch™610 Advanced Concepts
• Source
The point of all traffic sourced by the SpeedTouch™ IP router, i.e. at this point it
can be determined whether a packet is allowed to leave the local IP host.
• Output
The point of all outgoing traffic, i.e. at this point it can be determined whether a
packet is allowed to leave the SpeedTouch™610 IP router or local IP host.
Through the hooks defined above, following traffic can run:
• Input-to-Sink
The flow of packets destined exclusively for the SpeedTouch™610.
• Source-to-Output
The flow of packets sourced exclusively by the SpeedTouch™610 itself.
• Input-through-Forward-to-Output
The flow of packets sourced by the WAN, forwarded by the SpeedTouch™610
towards the local network, or vice versa.
SpeedTouch™610 At every hook a separate access list (chain), containing an ordered list of rules will
Packet Firewall and operated on each processed packet, resulting in a specific treatment of this packet. (See
Packet Treatments the CLI command ":firewall rule help create" for a full parameter description)
E-SIT-CTC-20030306-0004 v2.0
66
4 SpeedTouch™610 Advanced Concepts
Firewall treatments Once a packet is intercepted in a hook, and a (first) rule is found to be applicable (i.e.
matches against at least one of the criteria defined in this rule), the SpeedTouch™610
firewall is able to:
• Accept the packet
I.e. submit it to the next processing stage without further action.
• Deny the packet
I.e. no submission is done and a message is sent to the sender that the packet
could not be delivered.
• Drop the packet
I.e. no submission is done; the packet is silently discarded
• Count the packet for statistical use (no further action is done on the packet)
Link the packet to another chain of hooks, i.e. for parsing another defined chain, if the
specific rule applies.
E-SIT-CTC-20030306-0004 v2.0
67
4 SpeedTouch™610 Advanced Concepts
E-SIT-CTC-20030306-0004 v2.0
68
5 Troubleshooting
5 Troubleshooting
Introduction This chapter provides information on how to identify and correct some common prob-
lems you may encounter when using and configuring the SpeedTouch™610.
If the following troubleshooting tips have not resolved the problem contact the
company from which you purchased the SpeedTouch™610 for assistance.
Configuration problems In case you encounter DSL connectivity problems due to misconfiguration you might
consider a hardware reset to factory defaults as described in this chapter.
However, please note that resetting the SpeedTouch™610 to its factory settings will
revoke all the changes you made to the configuration.
Dr. SpeedTouch™ Dr. SpeedTouch™ enables you to test your computer and SpeedTouch™ connectivity
via its Diagnostics wizard. The SpeedTouch™ Troubleshoot will report what is wrong
with your connection.
For more information on Dr. SpeedTouch™, see “1.4 Dr. SpeedTouch™ Installation” on
page 20.
Trouble solving table Following table may help you determine the nature of the problem, and provides some
plausible solutions:
Problem Solution
E-SIT-CTC-20030306-0004 v2.0
69
5 Troubleshooting
Problem Solution
E-SIT-CTC-20030306-0004 v2.0
70
5 Troubleshooting
Config Console
E-SIT-CTC-20030306-0004 v2.0
71
5 Troubleshooting
E-SIT-CTC-20030306-0004 v2.0
72
© 2003 THOMSON. All rights reserved. E-SIT-CTC-20030306-0004 v2.0 TCM3572299A
SERIES
600
www.speedtouch.com