NB3700 Manual 3.7.0.101
NB3700 Manual 3.7.0.101
1 Welcome to NetModule 3
2 Conformity                                                                                                                                4
  2.1 Safety Instructions . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   4
  2.2 Declaration of Conformity     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   5
  2.3 Waste Disposal . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   5
  2.4 National Restrictions . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   5
      2.4.1 France . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   5
      2.4.2 Italy . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   6
      2.4.3 Latvia . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   6
      2.4.4 Luxembourg . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   6
      2.4.5 Norway . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   6
      2.4.6 Russian Federation      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   6
      2.4.7 Turkey . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   7
3 Specifications                                                                                                                             8
  3.1 Features . . . . . . . . . . . . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
  3.2 Operating Elements . . . . . . . . .              .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    9
  3.3 Interfaces . . . . . . . . . . . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   11
      3.3.1 Overview . . . . . . . . . .                .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   11
      3.3.2 USB 2.0 Host Port . . . . .                 .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
      3.3.3 M12 Ethernet Connectors .                   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
      3.3.4 Power . . . . . . . . . . . .               .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
      3.3.5 Digital Inputs and Outputs                  .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   13
      3.3.6 RS-232 Port . . . . . . . . .               .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   14
4 Installation                                                                                                                              16
  4.1 Environmental Conditions . . . . . . .                    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
  4.2 Installation of the Router . . . . . . .                  .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
  4.3 Installation of the SIM Card . . . . . .                  .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
  4.4 Installation of the WLAN Antennas . .                     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
  4.5 Installation of the Local Area Network                    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
  4.6 Installation of the Power Supply . . . .                  .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
                                                    2
                              NB3700 User Manual 3.7
5 Configuration                                                                                                                                18
  5.1 First Steps . . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    18
      5.1.1 Initial Access . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    19
      5.1.2 Recovery . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    19
  5.2 HOME . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    20
  5.3 INTERFACES . . . . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    22
      5.3.1 WAN . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    22
      5.3.2 Ethernet . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    28
      5.3.3 Mobile . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    34
      5.3.4 WLAN . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    40
      5.3.5 USB . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    48
      5.3.6 Serial Port . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    51
      5.3.7 Digital I/O . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    53
      5.3.8 GNSS . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    54
  5.4 ROUTING . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    56
      5.4.1 Static Routes . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    56
      5.4.2 Extended Routing          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    58
      5.4.3 Multipath Routes .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    60
      5.4.4 Mobile IP . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    61
      5.4.5 Quality Of Service        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    65
  5.5 FIREWALL . . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    67
      5.5.1 Administration . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    67
      5.5.2 Adress Groups . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    67
      5.5.3 Rules . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    67
      5.5.4 NAPT . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    69
  5.6 VPN . . . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    73
      5.6.1 OpenVPN . . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    73
      5.6.2 IPsec . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    78
      5.6.3 PPTP . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    84
      5.6.4 GRE . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    87
      5.6.5 Dial-In . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    88
  5.7 SERVICES . . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    90
      5.7.1 SDK . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    90
      5.7.2 DHCP Server . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   100
      5.7.3 DNS Server . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   103
      5.7.4 NTP Server . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   104
      5.7.5 DynDNS . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   105
      5.7.6 E-Mail . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   107
      5.7.7 Events . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   109
      5.7.8 SMS . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   110
      5.7.9 SSH/Telnet Server         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   113
      5.7.10 SNMP Agent . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   115
                                                      3
         5.7.11 SNMP Configuration .             .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   117
         5.7.12 SNMP Authentication              .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   118
         5.7.13 Web Server . . . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   119
         5.7.14 Redundancy . . . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   120
         5.7.15 Voice Gateway . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   122
   5.8   SYSTEM . . . . . . . . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   124
         5.8.1 System . . . . . . . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   124
         5.8.2 Authentication . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   128
         5.8.3 Software Update . . .             .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   131
         5.8.4 Configuration . . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   133
         5.8.5 Troubleshooting . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   137
         5.8.6 Keys and Certificates .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   140
         5.8.7 Licensing . . . . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   143
   5.9   LOGOUT . . . . . . . . . . .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   144
A Appendix                                                                                                                                       160
  A.1 Abbrevations . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   160
  A.2 System Events . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   162
  A.3 Factory Configuration      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   164
  A.4 SNMP VENDOR MIB            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   165
  A.5 SDK Examples . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   174
                                                         4
                                 NB3700 User Manual 3.7
List of Figures
  5.1    Home . . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   20
  5.2    WAN Links . . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   24
  5.3    WAN Settings . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   25
  5.4    Link Supervision . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   26
  5.5    Ethernet Ports . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   28
  5.6    Ethernet Link Settings . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   29
  5.7    LAN IP Configuration . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   31
  5.8    SIMs . . . . . . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   34
  5.9    WWAN Interfaces . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   37
  5.10   WLAN Management . . . . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   40
  5.11   WLAN Scan . . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   42
  5.12   WLAN Interfaces . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   43
  5.13   WLAN Configuration . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   45
  5.14   WLAN IP Configuration . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   46
  5.15   USB Device Server . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   49
  5.16   Serial Port . . . . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   51
  5.17   Static Routing . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   56
  5.18   Extended Routing . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   58
  5.19   Multipath Routes . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   60
  5.20   Mobile IP . . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   64
  5.21   NAPT Administration . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   69
  5.22   Inbound NAPT . . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   71
  5.23   Outbound NAPT . . . . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   72
  5.24   OpenVPN Administration . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   73
  5.25   OpenVPN Configuration . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   75
  5.26   OpenVPN Client Management           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   77
  5.27   IPsec Administration . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   79
  5.28   IPsec Configuration . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   80
  5.29   PPTP Administration . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   84
  5.30   PPTP Tunnel Configuration .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   85
  5.31   PPTP Client Management . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   86
  5.32   Dial-in Server Settings . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   88
  5.33   SDK Administration . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   94
                                                     5
  5.34   SDK Jobs . . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    96
  5.35   SDK Testing . . . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    98
  5.36   DHCP Leases . . . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   100
  5.37   DHCP Server . . . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   102
  5.38   DNS Server . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   103
  5.39   NTP Server . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   104
  5.40   Dynamic DNS Settings . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   105
  5.41   E-Mail Settings . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   107
  5.42   Event Notification Settings . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   109
  5.43   SMS Configuration . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   111
  5.44   SSH and Telnet Server . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   113
  5.45   SNMP Agent . . . . . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   117
  5.46   Web Server . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   119
  5.47   VRRP Configuration . . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   120
  5.48   Voice Gateway . . . . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   122
  5.49   Voice Client Configuration . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   124
  5.50   System . . . . . . . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   126
  5.51   Regional settings . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   127
  5.52   User Accounts . . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   128
  5.53   Remote Authentication . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   130
  5.54   Manual File Configuration . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   133
  5.55   Automatic File Configuration . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   134
  5.56   Factory Configuration . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   135
  5.57   Log Viewer . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   137
  5.58   Tech Support File . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   138
  5.59   Keys and certificates management        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   140
  5.60   Licensing . . . . . . . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   143
  5.61   Logout . . . . . . . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   144
List of Tables
                                                 6
                              NB3700 User Manual 3.7
                                                7
1. Welcome to NetModule
Thank you for purchasing a NetModule Router. This document should give you an
introduction to the router and its features. The following chapters describe any aspects
of commissioning the device, installation procedure and provide helpful information
towards configuration and maintenance.
                                           8
2. Conformity
This chapter provides general information for putting the router into operation.
                                             9
                               NB3700 User Manual 3.7
more information.
We highly recommended creating a copy of a working system configuration. It can
be downloaded using the Web Manager and easily applied to a newer software release
afterwards as we generally guarantee backward compatibility.
                  NetModule hereby declares that under our own responsibility that the
                  routers comply with the relevant standards following the provisions of
                  the Council Directive 1999/5/EC. The signed version of the Declara-
                  tions of Conformity can be found on the NetModule web page.
2.4.1. France
In case the product is used outdoors, the output power is restricted at some parts of the
band. See the table below or check http://www.art-telecom.fr/ for more details.
                                           10
                               NB3700 User Manual 3.7
2.4.2. Italy
This product meets the national radio interface regulations and requirements specified
in the National Frequency Allocation Table for Italy. Unless operating within the bound-
aries of the owners property, the use of this Wireless LAN product requires a general
authorization. Please check http://www.comunicazioni.it for more details.
2.4.3. Latvia
The outdoor usage within the 2.4-GHz band requires authorization from the Electronic
Communications Office. Please check http://www.esd.lv for more details.
2.4.4. Luxembourg
2.4.5. Norway
Frequency                  Restrictions
2400.0-2483.5 MHz          This band range cannot be operated in any geographical
                           areas within a radius of 20km away from the center of Ny-
                           lesund
                                          11
                      NB3700 User Manual 3.7
2.4.7. Turkey
Frequency          Restrictions
5470-5725 MHz      Not implemented
                                  12
3. Specifications
3.1. Features
There are several different models of NB3700 available:
Note: All UMTS models include support for EDGE/GPRS. All LTE models include
support for UMTS/EDGE/GPRS. The UMTS/LTE models can be equipped with a
supplementary VOICE (-V) or GNSS (-G) option. We also offer models for CDMA
450MHz (-Ca).
All models have following basic functionality in common:
    Galvanically isolated power supply
    5 Ethernet ports (M12)
    1 USB 2.0 host port
    2 digital inputs
    2 digital outputs
    2 SIM card slots
Due to its modular approach, the NB3700 router and its hardware components can be
arbitrarily assembled according to its indented usage or application. Please contact us
in case of special project requirements.
                                          13
                            NB3700 User Manual 3.7
                                        14
                        NB3700 User Manual 3.7
                                   15
                             NB3700 User Manual 3.7
3.3. Interfaces
3.3.1. Overview
                                          16
                                NB3700 User Manual 3.7
     Feature                             Specification
     Speed                               Low, Full & Hi-Speed
     Current                             max. 500 mA
Specification
The five Ethernet ports have the following specification:
     Feature                             Specification
     Isolation                           1500 Vrms
     Speed                               10/100 Mbps
     Mode                                Half- & Full-Duplex
     Crossover                           Automatic MDI/MDI-X
     Connector type                      M12, 4 poles, D-coded female
Pin Assignment
3.3.4. Power
                                           17
                                NB3700 User Manual 3.7
     Feature                             Specification
     Power supply nominal voltages       24 VDC, 36 VDC and 48 VDC according to
                                         EN 50155
     Voltage range                       12 VDC to 60 VDC (15% / +5%)
     Max. power consumption              15 W
     DC isolation                        yes
     Power Interruption Class S2         Sustains interruptions up to 10 ms, there
                                         are no batteries included
     Connector type                      M12, 4 poles, A-coded male
Pin Assignment
Isolated Outputs
The isolated digital output ports have the following specification:
     Feature                             Specification
     Number of output ports              2
     Limiting continuous current         1A
     Maximum switching voltage           60 VDC, 42 VAC ( Vrms)
     Maximum switching capacity          60 W
                                             18
                                  NB3700 User Manual 3.7
Isolated Inputs
The isolated digital input ports have the following specification:
     Feature                               Specification
     Number of inputs                      2
     maximum input voltage                 40 VDC
     Minimum voltage for level 1
     (set)                                 7.2 VDC
     Maximum voltage for level 0
     (not set)                             5.0 VDC
Pin Assignment
     Feature                               Specification
     Protocol                              3-wire RS-232 (TXD, RXD, GND)
                                               19
                              NB3700 User Manual 3.7
    Feature                             Specification
    Baud rate                           300, 1 200, 2 400, 4 800, 9 600, 19 200,
                                        38 400, 57 600, 115 200
    Data bits                           7 bit, 8 bit
    Parity                              none, odd, even
    Stop bits                           1, 2
    Software flow control               None, XON/XOFF
    Hardware flow control               None
    Connector type                      M12, 4 poles, D-coded female
Pin Assignment
                                          20
4. Installation
     Parameter                          Rating
     Input Voltage                      12 VDC to 48 VDC (15% / +20%)
     Operating Temperature Range        25  C to +70  C
     Humidity                           0 to 95% (non-condensing)
     Altitude                           up to 4000m
     Over-Voltage Category              II
     Pollution Degree                   2
     Ingress Protection Rating          IP40 (with SIM and USB covers mounted)
                                             21
                                NB3700 User Manual 3.7
provider upon a certain condition. However, a SIM switch usually takes about 10-20
seconds which can be bypassed (e.g. at bootup) if SIMs are installed reasonably. Using
only a single SIM with one modem, it should be preferably placed into the SIM 1 holder.
For systems which should operate two modems with two SIMs in parallel, we recommend
to assign Mobile 1 to SIM 1 and Mobile 2 to SIM 2.
Further information about SIM configuration can be found in chapter 5.3.3.
                                           22
5. Configuration
The following chapters give information about setting up the router and configuring its
features as provided with system software 3.7.
                                            23
                               NB3700 User Manual 3.7
In factory state you will be prompted for a new administrator password. Please choose
a password which is both, easy to remember but also robust against dictionary attacks
(such as one that contains numbers, letters and punctuation characters). The password
shall have a minimum length of 6 characters. It shall contain a minimum of 2 numbers
and 2 letters.
Please note that the admin password will be also applied for the root user which can be
used to access the device via the serial console, telnet, SSH or to enter the bootloader.
You may also configure additional users which will only be granted to access the summary
page or retrieve status information but not to set any configuration parameters.
A set of services (USB Autorun, CLI-PHP) are by default activated in factory state and
will be disabled as soon as the admin password has been set. They can be enabled again
afterwards in the relevant sections.
5.1.2. Recovery
Following actions might be taken in case the router has been misconfigured and cannot
be reached anymore:
  1. Factory Reset: You can initiate a reset back to factory settings via the Web Man-
     ager, by running the command factory-reset or by pressing the reset button.
     The latter would require a slim needle or paper clip which must be inserted into
     the hole to the left of the LEDs . The button must be hold pressed for up to 5
     seconds until all LEDs flash up.
  2. Serial Console Login: It is also possible to log into the system via the serial port.
     This would require a terminal emulator (such as PuTTY or HyperTerminal) and an
     RS232 connection (115200 8N1) attached to the serial port of your local computer.
  3. Recovery Image: In severe cases we can provide a recovery image on demand which
     can be loaded into RAM via TFTP and executed. It offers a minimal system image
     for running a software update or doing other modifications. You will be provided
     with two files, recovery-image and recovery-dtb, which must be placed in the root
     directory of a TFTP server (connected via LAN1 and address 192.168.1.254). The
     recovery image can be launched from the boot-loader using a serial connection. You
     will have to stop the boot process by pressing s and enter the bootloader. You
     can then issue run recovery to load the image and start the system which can be
     accessed via HTTP/SSH/Telnet and its IP address 192.168.1.1 afterwards. This
     procedure can be also initiated by holding the factory reset button longer than 15
     seconds.
                                           24
                               NB3700 User Manual 3.7
5.2. HOME
This page provides a status overview of enabled features and connections.
Summary
This page offers a short summary about the administrative and operational status of
the routers interfaces.
WAN
This page offers details about any enabled Wide Area Network (WAN) links (such as
the IP addresses, network information, signal strength, etc.) The information about the
amount of downloaded/uploaded data is stored in non-volatile memory, thus survive a
reboot of the system.
The counters can be reset by pressing the Reset button.
WLAN
The WLAN page offers details about the enabled WLAN interfaces when operating in
access-point mode. This includes the SSID, IP and MAC address and the currently used
frequency and transmit power of the interface as well as the list of associated stations.
                                           25
                               NB3700 User Manual 3.7
GNSS
This page displays the position status values, such as latitude/longitude, the satellites
in view and more details about the used satellites.
Ethernet
This page shows information about the Ethernet interfaces and packet statistics infor-
mation.
LAN
This page shows information about the LAN interfaces plus the neighborhood informa-
tion.
DHCP
This page offers details about any activated DHCP service, including a list of issued
DHCP leases.
OpenVPN
This page provides information about the OpenVPN tunnel status.
IPSec
This page provides information about the IPsec tunnel status.
PPTP
This page provides information about the PPTP tunnel status.
GRE
This page provides information about the GRE tunnel status.
MobileIP
This page provides information about Mobile IP connections.
Firewall
This page offers information about any firewall rules and their matching statistics. It
can be used to debug the firewall.
QoS
This page provides information about the used QoS queues.
System Status
The system status page displays various details of your NB3700 router, including system
details, information about mounted modules and software release information.
SDK
This section will list all webpages generated by SDK scripts.
                                           26
                                NB3700 User Manual 3.7
5.3. INTERFACES
5.3.1. WAN
Link Management
Depending on your hardware model, WAN links can be made up of either Wireless
Wide Area Network (WWAN), Wireless LAN (WLAN), Ethernet or PPP over Ethernet
(PPPoE) connections. Please note that each WAN link has to be configured and enabled
in order to appear on this page.
Generally, a link will be only dialed or declared as up if the following prerequisites are
met:
The menu can be used further to prioritize your WAN links. The highest priority link
which has been established successfully will become the so-called hotlink which holds
the default route for outgoing packets.
In case a link goes down, the system will automatically switch over to the next link in
the priority list. You can configure each link to be either established when the switch
occurs or permanently in order to minimize link downtime.
                                           27
                                NB3700 User Manual 3.7
Links are being triggered periodically and put to sleep in case it was not possible to
establish them within a certain amount of time. Hence it might happen that permanent
links will be dialed in background and, as soon as they got established, replace low-
priority links again.
We recommend to use the permanent operation mode for WAN links in general. How-
ever, in case of time-limited mobile tariffs for instance, the switchover mode might be
applicable. By using the distributed mode, it is possible to distribute outgoing traffic
over multiple WAN links based on their weight ratio.
For mobile links, it is further possible to pass-through the WAN address towards a local
host (also called Drop-In). In particular, the first DHCP client will receive the public IP
address. More or less, the system acts like a modem in such case which can be helpful
in case of firewall issues. Once established, the Web Manager can be reached over port
8080 using the public address.
Settings
This page can be used to configure WAN specific settings like the Maximum Segment Size
(MSS). The MSS corresponds to the largest amount of data (in bytes) that the router
can handle in a single, unfragmented TCP segment. In order to avoid any negative side
effects the number of bytes in the data segment and the headers must not add up to
more than the number of bytes in the Maximum Transmission Unit (MTU). The MTU
can be configured per each interface and corresponds to the largest packet size that can
be transmitted.
                                            28
NB3700 User Manual 3.7
         29
NB3700 User Manual 3.7
           30
                              NB3700 User Manual 3.7
Supervision
Network outage detection can be performed by sending pings on each link to some
authoritative hosts. A link will be declared as down in case all trials have failed and
only as up if at least one host can be reached.
                                          31
                        NB3700 User Manual 3.7
                                   32
                               NB3700 User Manual 3.7
5.3.2. Ethernet
NB3700 routers ship with an Ethernet switch (ETH1-ETH5) which can be linked via
M12 connectors.
ETH1 usually forms the LAN1 interface which should be used for LAN purposes. Other
interfaces can be used to connect other LAN segments or for configuring a WAN link.
Port Assignment
This menu can be used to individually assign each Ethernet port to a LAN interface, just
in case you want to have different subnets per port or use one port as WAN interface. You
may assign multiple ports to the same interface. Please note that on systems without
an Ethernet switch, the ports will be bridged by software then and operated by running
the Spanning Tree Protocol (STP).
Link Settings
Link negotiation can be set for each Ethernet port individually. Most devices support
auto-negotiation which will configure the link speed automatically to comply with other
devices in the network. In case of negotiation problems, you may assign the modes
                                           33
    NB3700 User Manual 3.7
                34
                              NB3700 User Manual 3.7
manually but it has to be ensured that all devices in the network utilize the same
settings then.
VLAN Management
NetModule routers support Virtual LAN according to IEEE 802.1Q which can be used
to create virtual interfaces on top of an Ethernet interface. The VLAN protocol inserts
an additional header to Ethernet frames carrying a VLAN Identifier (VLAN ID) which
is used for distributing the packets to the associated virtual interface. Any untagged
packets, as well as packets with an unassigned ID, will be distributed to the native
interface. In order to form a distinctive subnet, the network interface of a remote LAN
host must be configured with the same VLAN ID as defined on the router. Further,
802.1P introduces a priority field which influences packet scheduling in the TCP/IP
stack.
The following priority levels (from lowest to highest) exists:
IP Settings
This page can be used to configure IP addressing for your LAN/WAN Ethernet inter-
faces. In addition to the primary IP address/subnet mask you may define an additional
IP address alias on the interface.
Please keep in mind that the DNS servers can be set globally in the DNS server config-
uration menu. But as soon as a link comes up it will use the interface-specific name-
servers (e.g. the ones being retrieved over DHCP) and update the resolver configuration
accordingly.
                                          35
    NB3700 User Manual 3.7
               36
                               NB3700 User Manual 3.7
When running in LAN mode, the interface may be configured with the following settings:
When running in WAN mode, the interface may be configured with the following settings:
When running as DHCP client, no further configuration is required because all IP-related
settings (address, subnet, gateway, DNS server) will be retrieved from a DHCP server
in the network. You may also define static values but caution has to be taken to assign
an unique IP address as it would otherwise raise IP conflicts in the network.
PPPoE is commonly used when communicating with another WAN access device (like
a DSL modem). The following settings can be applied:
                                          37
                          NB3700 User Manual 3.7
                                      38
                               NB3700 User Manual 3.7
5.3.3. Mobile
SIMs
The SIM page gives an overview about the available SIM cards, their assigned modems
and the current state. Once a SIM card has been inserted, assigned to a modem and
successfully unlocked, the card should remain in state ready and the network registration
status should have turned to registered. If not, please double-check your PIN.
Please keep in mind that registering to a network usually takes some time and depends
on signal strength and possible radio interferences. You may hit the Update button
at any time in order to restart PIN unlocking and trigger another network registration
attempt.
Under some circumstances (e.g. in case the modem flaps between base stations) it
might be necessary to set a specific service type or assign a fixed operator. The list
of operators around can be obtained by initiating a network scan (may take up to 60
seconds). Further details can be retrieved by querying the modem directly, a set of
suitable commands can be provided on request.
                                           39
                              NB3700 User Manual 3.7
Configuration
A SIM card is generally assigned to a default modem but might be switched, for instance
if you set up two WWAN interfaces with one modem but different SIM cards.
Close attention has to be paid when other services (such as SMS or Voice) are operating
on that modem, as a SIM switch will naturally affect their operation.
The following settings can be applied:
Network
This page provides information about the current network status, signal strength and
the Local Area Identifier (LAI) to which the modem has been registered. An LAI is
a globally unique number that identifies the country, network provider and Local Area
Code (LAC, group of base stations) of any given location area. It can be used to force
the modem to register to a particular mobile cell in case of competing stations.
You may further initiate a mobile network scan for getting networks in range and assign
an LAI manually.
                                          40
                             NB3700 User Manual 3.7
Query
This page allows you to send Hayes AT commands to the modem. Besides the 3GPP-
conforming AT command-set further modem-specific commands can be applicable which
we can provide on demand. Some modems also support running Unstructured Supple-
mentary Service Data (USSD) requests, e.g. for querying the available balance of a
prepaid account.
                                       41
                                NB3700 User Manual 3.7
WWAN Interfaces
This page can be used to manage your WWAN interfaces. The resulting link will pop
up automatically as WAN link once an interface has been added. Please refer to chap-
ter 5.3.1 for how to manage them.
The Mobile LED will be blinking during the connection establishment process and goes
on as soon as the connection is up. Refer to section 5.8.5 or consult the system log files
for troubleshooting the problem in case the connection did not come up.
Please note that these settings supersede the general SIM based settings as soon as the
link is being dialed.
                                           42
                              NB3700 User Manual 3.7
Generally, the connection settings are derived automatically as soon as the modem has
registered and the network provider has been found in our database. Otherwise, it will
be required to configure the following settings manually:
                                          43
            NB3700 User Manual 3.7
                      44
                               NB3700 User Manual 3.7
5.3.4. WLAN
WLAN Management
In case your router is shipping with a WLAN (or Wi-Fi) module you can operate it
either as client or access point. As a client it can create an additional WAN link
which for instance can be used as backup link. As access point, it can form another LAN
interface which can be either bridged to an Ethernet-based LAN interface or create a
self-contained IP interface which can be used for routing and to provide services (such
as DHCP/DNS/NTP) in the same way like an Ethernet LAN interface does.
If the administrative status is set to disabled, the module will be powered off in order
to reduce the overall power consumption. Regarding antennas, we generally recommend
using two antennas for better coverage and throughput. A second antenna is definitely
mandatory if you want to achieve higher throughput rates in 802.11n.
A WLAN client will automatically became a WAN link and can be managed as de-
scribed in chapter 5.3.1.
                                          45
                                 NB3700 User Manual 3.7
Running as access point, you can further configure the following settings:
Prior to setting up an access point, it is always a good idea to run a network scan for
getting a list of neighboring WLAN networks and then choose the less interfering channel.
Please note that two adequate channels are required for getting good throughputs with
802.11n and a bandwidth of 40 MHz.
                                           46
                               NB3700 User Manual 3.7
Running in client mode, you can select the network to which you want to connect to
and enter the required authentication settings. You may also perform a WLAN network
scan and pick the settings from the discovered information directly. The credentials can
be obtained by the operator of your WLAN access point.
                                          47
                              NB3700 User Manual 3.7
WLAN Interfaces
An access point can define up to 4 networks being broadcasted. The networks can be
individually bridged to a LAN interface or operate as dedicated interface in routing-
mode.
WLAN Configuration
Running in access point mode you can define up to 4 SSIDs with each running their own
network configuration. This section can be used to configure security-related settings.
                                          48
                           NB3700 User Manual 3.7
Being a shared medium, we strongly advise to secure your WLAN connection using
passwords or even keys/certificates.
                                       49
    NB3700 User Manual 3.7
              50
                              NB3700 User Manual 3.7
WLAN IP Settings
This section lets you configure the TCP/IP settings of your WLAN network.
A client interface can be run over DHCP or with a statically configured address and
default gateway.
The access point networks can be bridged to any LAN interface for letting WLAN clients
and Ethernet hosts operate in the same subnet. However, for multiple SSIDs we strongly
recommend to set up separated interfaces in routing-mode in order to avoid unwanted
access and traffic between the interfaces. The corresponding DHCP server for each
network can be configured in afterwards as described in chapter 5.7.2.
                                         51
                       NB3700 User Manual 3.7
                                 52
                               NB3700 User Manual 3.7
5.3.5. USB
NetModule routers ship with a standard USB host port which can be used to connect a
storage, network or serial USB device. Please contact our support in order to get a list
of supported devices.
USB Administration
If the USB/IP device server has been enabled you can discover the mounted USB devices
and attach them to the USB/IP server. Enabled devices can now be exported to a remote
host. You will need an additional driver on the client for which we provide Windows or
Linux drivers. Further installation instructions can be provided on demand.
Please note that some USB devices behave latency-sensitive which may raise problems
when operating over a slow IP connection. Some devices may generally not work with
the USB/IP driver. Please contact our support in case of compatibility issues.
USB Devices
This page show the currently connected devices and it can be used to enable a specific
device based on its Vendor and Product ID.
Any ID must be specified in hexadecimal notation, wildcards are supported (e.g. AB[0-1][2-3]
or AB*)
USB Autorun
This feature can be used to automatically launch a shell script or perform a software/-
config update as soon as an USB storage stick has been plugged in. For authentication, a
file called autorun.key must exist in the root directory of a FAT16/32 formatted stick.
It can be downloaded from that page and corresponds to the SHA256 Hash of the admin
                                          53
   NB3700 User Manual 3.7
              54
                            NB3700 User Manual 3.7
password. The file can hold multiple hashes which will be processed line-by-line dur-
ing authentication which can be used for setting up more systems with different admin
passwords.
For new devices with an empty password the hash key e3b0c44298fc1c149afbf4c8996fb92427ae41e46
can be used.
Once authentication has succeeded, the system scans for other files in the root directory
which can perform the following actions:
  1. For running a script: autorun.sh
  2. For a configuration update: cfg-<SERIALNO>.zip (e.g. cfg-00112B000815.zip),
     or if not available cfg.zip
  3. For a software update: sw-update.img
                                      55
                               NB3700 User Manual 3.7
This page can be used to manage your serial ports. They can be used for various purposes
on the system. When set to none it will be disabled, when set to login console you
would be able to get a login shell when connecting to the serial port (115200 8N1). You
may also mark them as reserved for SDK scripts.
Furtheron, a device server can be run for each port which can be used to control the
serial device via IP.
It can be configured as follows:
                                          56
                              NB3700 User Manual 3.7
                                         57
                              NB3700 User Manual 3.7
The Digital I/O page displays the current status of the I/O ports and can be used to
turn output ports on or off.
You can apply the following settings:
Besides on and off you may keep the default status as the hardware has initialized it
after power-up.
The digital inputs and outputs can also be monitored and controlled by SDK scripts.
                                         58
                               NB3700 User Manual 3.7
5.3.8. GNSS
Administration
The GPS page lets you enable or disable the GPS modules present in the system and can
be used to configure the daemon that can be used to share access to receivers without
contention or loss of data and to respond to queries with a format that is substantially
easier to parse than the NMEA 0183 emitted directly by the GPS device.
We are currently running the Berlios GPS daemon (version 2.37), please navigate to
http://gpsd.berlios.de for getting more information about how to incorporate it.
The GPS values can also be queried by the CLI and used in SDK scripts.
Information
This pages provides further information about the satellites in view and values derived
from them:
                                          59
                               NB3700 User Manual 3.7
Please note that the values are shown as calculated by the daemon, their accuracy might
be suggestive.
                                           60
                               NB3700 User Manual 3.7
5.4. ROUTING
5.4.1. Static Routes
This menu shows all routing entries of the system. They are typically formed by an
address/netmask couple (represented in IPv4 dotted decimal notation) which specify
the destination of a packet. The packets can be directed to either a gateway or an
interface or both. If interface is set to ANY, the system will choose the route interface
automatically, depending on the best matching network configured for an interface.
In general, host routes precede network routes and network routes precede default routes.
Additionally, a metric can be used to determine the priority of a route, a packet will go
in the direction with the lowest metric in case a destination matches multiple routes.
Netmasks can be specified in CIDR notation (i.e. /24 expands to 255.255.255.0).
                                           61
                              NB3700 User Manual 3.7
Flag                      Description
A                         The route is considered active, it might be inactive if the
                          interface for this route is not yet up.
P                         The route is persistent, which means it is a configured route,
                          otherwise it corresponds to an interface route.
H                         The route is a host route, typically the netmask is set to
                          255.255.255.255.
N                         The route is a network route, consisting of an address and
                          netmask which forms the subnet to be addressed.
D                         The route is a default route, address and netmask are set
                          to 0.0.0.0, thus matching any packet.
                                           62
                              NB3700 User Manual 3.7
Extended routes can be used to perform policy-based routing, they generally precede
static routes.
In contrast to statis routes, extended routes can be made up, not only of a destination
address/netmask, but also a source address/netmask, incoming interface and the type
of service (TOS) of packets.
                                          63
            NB3700 User Manual 3.7
                      64
                              NB3700 User Manual 3.7
Multipath routes will perform weighted IP-session distribution for particular subnets
across multiple interfaces.
                                         65
                               NB3700 User Manual 3.7
5.4.4. Mobile IP
Mobile IP (MIP) can be used to enable seamless switching between different kinds of
WAN links (e.g. WWAN/WLAN). The mobile node hereby remains reachable via the
same IP address (home address) at any time, independently of the WAN link being
used. Effectively, any WAN link switch causes very small outages during switchover
while keeping all IP connections alive.
Moreover, NetModule routers also support NAT-Traversal for mobile nodes running
behind a firewall (performing NAT), which makes mobile nodes even there accessible
from a central office via their home address, and thus, bypassing any complicated VPN
setups.
The home agent accomplishes this by establishing a tunnel (similar to a VPN tunnel)
between itself and the mobile node. WAN link switching works by telling the home
agent that the WAN IP address (called the care-of address in MIP terms) of the
mobile node has changed. The home agent will then encapsulate packets destined to
a mobile nodes home address into a tunnel packet containing the current care-of
address of the mobile node as its destination address.
To prevent problems with firewalls and private IP addressing, the MIP implementation
always employs reverse tunneling, which means that all traffic sent by a mobile node is
relayed via the tunnel to the home agent instead of directly being conveyed to the final
destination. This fact also empowers MIP to be used as a lightweight VPN replacement
(without payload secrecy).
The MIP implementation supports RFCs 3344, 5177, 3024 and 3519. For applications
requiring vast numbers of mobile nodes, interoperability with the Cisco 2900 Series home
agent implementation has been verified. However, since NetModule routers implement
a mobile node as well as a home agent, a MIP network with up to 10 mobile nodes
can be implemented without requiring expensive third party routers.
                                          66
                               NB3700 User Manual 3.7
If MIP is run as a home agent, you will have to set up a home address and network
mask for the home agent first. Then you will need to add the configuration for all mobile
nodes, which is made up of the following settings:
                                           67
                      NB3700 User Manual 3.7
                                68
NB3700 User Manual 3.7
          69
                                NB3700 User Manual 3.7
NetModule routers are able to prioritize and shape certain kinds of IP traffic. This is
currently limited on egress, which means that only outgoing traffic can be stipulated.
The current QoS implementation uses Stochastic Fairness Queueing (SFQ) classes in
combination with Hierarchy Token Bucket (HTB) queuing disciplines. In case of de-
mands for other classes or qdiscs please contact our support team in order to evaluate
the best approach for your application.
QoS Administration
The administration page can be used to enable and disable QoS.
QoS Classification
The classification section can be used to define the WAN interfaces on which QoS should
be active.
When defining limits, you should consider bandwidth limits which are at least possible as
most shaping and queues algorithms will not work correctly if the specified limits cannot
be achieved. In particular, any WWAN interfaces operating in a mobile enviroment are
suffering variable bandwidths, thus rather lower values should be used.
In case an interface has been activated, the system will automatically create the following
queues:
                                            70
                              NB3700 User Manual 3.7
You can now configure and assign any services to each queue. The following parameters
apply:
                                           71
                                NB3700 User Manual 3.7
5.5. FIREWALL
5.5.1. Administration
This menu can be used to form address groups which can be later used for firewall rules
in order to reduce the number of rules for a set of addresses.
5.5.3. Rules
In general, the firewall is set up of a range of rules which control each packets permis-
sion to pass the router. Please note that the rules are processed by order, that means
traversing the list from top to bottom until a matching rule is found. Packets which are
not matching any of the rules configured will be ALLOWED.
                                            72
                             NB3700 User Manual 3.7
The statistics page can be used to figure out if rules have matched any packets and
provides a convenient way to debug your firewall setup.
                                         73
                              NB3700 User Manual 3.7
5.5.4. NAPT
This page can be used to configure Network Address and Port Translation (NAPT) for
packets traversing the system. NAPT hereby modifies IP addresses or/and TCP/UDP
ports in matching IP packets. By tracking those connections, it will also automatically
adjust the returning packets of an IP session.
The administration page lets you specify the interfaces on which outgoing NAT (also
called Masquerading) will be performed. NAT will hereby use the address of the selected
interface and choose a random source port for outgoing connections and thus enables
communication between hosts from a private local area network towards hosts on the
public network.
                                          74
                               NB3700 User Manual 3.7
list from top to bottom until a matching rule is found. If there is no matching rule
found, the packet will pass as is.
                                          75
 NB3700 User Manual 3.7
           76
  NB3700 User Manual 3.7
            77
                              NB3700 User Manual 3.7
5.6. VPN
5.6.1. OpenVPN
OpenVPN Administration
Tunnel Configuration
NetModule routers support one single server tunnel and up to four client tunnels. You
can specify tunnel parameters either in standard configuration or upload an expert mode
file which has been created in advance. Refer to chapter 5.6.1 to learn more about how
to manage clients and generate the files.
                                          78
                                NB3700 User Manual 3.7
If the tunnel is operated in client mode, the following settings can be applied:
Setting up a tunnel server just requires the server port to be set, the settings mentioned
below apply for both, server and client tunnels:
                                           79
                               NB3700 User Manual 3.7
ExpertConfiguration
                                          80
                                NB3700 User Manual 3.7
Please note that you may specify arbitrary file names, however, the configuration file
suffix must be .conf and all files referred in the configuration file must correspond to
relative path names.
OpenVPN Expert Configuration (Server) A server tunnel typically requires the fol-
lowing files:
Keep in mind that a certificate becomes valid once its validity time has been reached,
thus an accurate system has to be set prior to creating certificates and establishing a
tunnel connection. Please ensure that all NTP servers are reachable. Using host names
also requires a working DNS server.
Client Management
Once you have successfully set up an OpenVPN server tunnel, you can manage and
enable clients connecting to your service. Currently connected clients can be seen on
this page, including the connect time and IP address. You may kick connected clients
by disabling them.
In the Networking section you can specify a fixed tunnel endpoint address for each client.
Please note that, if you intend to use a fixed address for a particular client, you would
have to apply fixed addresses to the other ones as well.
You may specify the network behind the clients as well as the routes to be pushed to each
                                            81
                                NB3700 User Manual 3.7
client. This can be useful for routing purposes, e.g. in case you want to redirect traffic
for particular networks towards the server. Routing between the clients is generally not
allowed but you can enable it if desired.
Finally, you can generate and download all expert mode files for enabled clients which
can be used to easily populate each client.
                                           82
                               NB3700 User Manual 3.7
5.6.2. IPsec
Mechanism                  Description
AH                         Authentication Headers (AH) provide connectionless in-
                           tegrity and data origin authentication for IP datagrams and
                           ensure protection against replay attacks.
ESP                        Encapsulating Security Payloads (ESP) provide confiden-
                           tiality, data-origin authentication, connectionless integrity,
                           an anti-replay service and limited traffic-flow confidentiality.
SA                         Security Associations (SA) provide a secure channel and a
                           bundle of algorithms that provide the parameters necessary
                           to operate the AH and/or ESP operations. The Internet
                           Security Association Key Management Protocol (ISAKMP)
                           provides a framework for authenticated key exchange.
Negotating keys for encryption and authentication is generally done by the Internet Key
Exchange protocol (IKE) which consists of two phases:
Phase                      Description
IKE phase 1                IKE authenticates the peer during this phase for setting up
                           an ISAKMP secure association. This can be carried out by
                           either using main or aggressive mode. The main mode ap-
                           proach utilizes the Diffie-Hellman key exchange and authen-
                           tication is always encrypted with the negotiated key.The
                           aggressive mode just uses hashes of the pre-shared key and
                           therefore represents a less-secure mechanism which should
                           generally be avoided as it is prone to dictionary attacks.
IKE phase 2                IKE finally negotiates IPSec SA parameters and keys and
                           sets up matching IPSec SAs in the peers which is required
                           for AH/ESP later on.
                                           83
    NB3700 User Manual 3.7
               84
                               NB3700 User Manual 3.7
Administration
This page can be used to enable/disable IPsec, you may also specify whether NAT-
Traversal should be used.
NAT-Traversal is mainly used for connections which traverse a path where a router
modifies the IP address/port of packets. It encapsulates packets in UDP and therefore
requires a slight overhead which has to be taken into account when running over small-
sized MTU interfaces.
Please note that running NAT-Traversal makes IKE using UDP port 4500 rather than
500 which has to be taken into account when setting up firewall rules.
General
For setting up the tunnel you will have to configure the following parameters first:
                                           85
                               NB3700 User Manual 3.7
IKE Authentication
NetModule routers support IKE authentication through pre-shared keys (PSK) or cer-
tificates within a public key infrastructure.
Using PSK requires the following settings:
When using certificates you would need to specify the operation mode. When run as
PKI client you can create a Certificate Signing Request (CSR) in the certificates section
which needs to be submitted at your Certificate Authority and imported to the router
afterwards. In PKI server mode the router represents the Certificate Authority and
issues the certificates for remote peers.
IKE Proposal
This section can be used to configure the phase 1 settings:
                                           86
                               NB3700 User Manual 3.7
IPsec Proposal
This section can be used to configure the phase 2 settings:
Networks
When creating Security Associations, IPsec will keep track of routed networks within
the tunnel. Packets will be only transmitted when a valid SA with matching source and
destination network is present. Therefore, you may need to specify the networks right
and left of the endpoints by applying the following settings:
                                          87
                        NB3700 User Manual 3.7
                                  88
                                NB3700 User Manual 3.7
5.6.3. PPTP
                                            89
       NB3700 User Manual 3.7
                  90
                              NB3700 User Manual 3.7
PPTP clients for a server tunnel need to be configured here. They are made up of user-
name and password. A fixed IP address can be assigned to them which can be used to
point any routes to a dedicated tunnel.
                                          91
                                NB3700 User Manual 3.7
5.6.4. GRE
The Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate
a wide variety of network layer protocols inside virtual point-to-point links over IP. GRE
is defined in RFC 1701, 1702 and 2784. It does not provide encryption nor authorization
but can be used on an address-basis on top of other VPN techniques (such as IPsec) for
tunneling purposes.
The following parameters are required for setting up a tunnel:
In general, the local tunnel address/netmask should not conflict with any other interface
addresses. The remote network/netmask will result in an additional route entry in order
to control which packets should be encapsulated and transferred over the tunnel.
                                           92
                                NB3700 User Manual 3.7
5.6.5. Dial-In
On this page you can configure the Dial-In server in order to establish a data connection
over GSM calls. Thus, one would generally apply a required service type of 2G-only, so
that the modem registers to GSM only. Naturally, a concurrent use of outgoing WWAN
interfaces and Dial-In connection is not possible.
                                            93
                              NB3700 User Manual 3.7
Besides the admin account you can configure further users in the user accounts section
which shall be allowed to dial-in.
Please note that Dial-In connections are generally discouraged. As they are implemented
as GSM voice calls, they suffer from unreliability and poor bandwidth.
                                          94
                              NB3700 User Manual 3.7
5.7. SERVICES
5.7.1. SDK
NetModule routers are shipping with a Software Development Kit (SDK) which offers
a simple and fast way to implement customer-specific functions and applications. It
consists of:
  1. An SDK host which defines the runtime environment (a so-called sandbox), that
     is, controlling access to system resources (such as memory, storage and CPU) and,
     by doing so, catering for the right scalability
  2. An interpreter language called arena, a light-weight scripting language optimized
     for embedded systems, which uses a syntax similar to ANSI-C but adds support
     for exceptions, automatic memory management and runtime polymorphism on top
     of that
  3. A NetModule-specific Application Programming Interface (API), which ships with
     a comprehensive set of functions for accessing hardware interfaces (e.g. digital IO
     ports, GPS, external storage media, serial ports) but also for retrieving system
     status parameters, sending E-Mail or SMS messages or simply just to configure
     the router
Anyone, reasonably experienced in the C language, will find an environment that is easy
to dig in. However, feel free to contact us via router@support.netmodule.com and we
will happily support you in finding a programming solution to your specific problem.
The Language
The arena scripting language offers a broad range of POSIX functions (like printf
or open) and provides, together with tailor-made API functions, a simple platform for
implementing any sort of applications to interconnect your favourite device or service
with the router.
Here comes a short example:
                                          95
                               NB3700 User Manual 3.7
A set of example scripts can be downloaded directly from the router, you can find a
list of them in the appendix. The manual which can be obtained from the NetModule
support web page gives a detailed introduction of the language, including a description
of all available functions.
The current range of API functions can be used to implement the following features:
  1.   Send/Retrieve SMS
  2.   Send E-mail
  3.   Read/Write from/to serial device
  4.   Control digital input/output ports
  5.   Run TCP/UDP servers
  6.   Run IP/TCP/UDP clients
  7.   Access files of mounted media (e.g. an USB stick)
  8.   Retrieve status information from the system
  9.   Get or set configuration parameters
 10.   Write to syslog
 11.   Transfer files over HTTP/FTP
 12.   Get system events / Reboot system
 13.   Control the LEDs
The SDK API which can be obtained from the NetModule support page provides an
overview but also explains all functions in detail.
                                           96
                                 NB3700 User Manual 3.7
Please note that some functions require the corresponding services (e.g. E-Mail, SMS)
to be properly configured prior to utilizing them in the SDK.
Lets now pay some attention to the very powerful API function nb_status. It can
be used to query the routers status values in the same manner as they can be shown
with the CLI. It returns a structure of variables for a specific section (a list of available
sections can be obtained by running cli status -h).
By using the dump function you can figure out the content of the returned structure:
struct(8): {
  .LOCATION_STREET              =   string[11]:   "Bahnhofquai"
  .LOCATION_CITY                =   string[10]:   "Zurich"
  .LOCATION_COUNTRY_CODE        =   string[2]:    "ch"
  .LOCATION_COUNTRY             =   string[11]:   "Switzerland"
  .LOCATION_POSTCODE            =   string[4]:    "8001"
  .LOCATION_STATE               =   string[6]:    "Zurich"
  .LOCATION_LATITUDE            =   string[9]:    "47.3778058"
  .LOCATION_LONGITUDE           =   string[8]:    "8.5412757"
}
wanlink.0.mode
wanlink.0.name
wanlink.0.prio
wanlink.0.weight
Running the CLI in interactive mode, you will be also able to step through possible
configuration parameters by the help of the TAB key.
                                             97
                                NB3700 User Manual 3.7
Running SDK
In the SDK, we are speaking of scripts and triggers which form jobs.
Any arena script can be uploaded to the router or imported by using dedicated user
configuration packages. You may also edit the script directly at the Web Manager or
select one of our examples. You will further have a testing section on the router which
can be used to check your syntax or doing test runs.
Once uploaded, you will have to specify a trigger, that is, telling the router when the
script is to be executed. This can be either time-based (e.g. each Monday) or triggered by
one of the pre-defined system events (e.g. wan-up) as described in Events chapter 5.7.7.
With both, a script and a trigger, you can finally set up an SDK job now. The test
event usually serves as a good facility to check whether your job is doing well. The
admin section also offers facilities to troubleshoot any issues and control running jobs.
The SDK host (sdkhost) corresponds to the daemon managing the scripts and their
operations and thus avoiding any harm to the system. In terms of resources, it will
limit CPU and memory for running scripts and also provide a pre-defined portion of
the available flash storage. You may, however, extend it by external USB storage or
(depending on your model) SD cards.
Files written to /tmp will be hold in memory and will be cleared upon a restart of the
script. As your scripts operate in the sandbox, you will have no access to tools on the
system (such as ifconfig).
                                           98
    NB3700 User Manual 3.7
              99
                               NB3700 User Manual 3.7
Administration
This page can be used to control the SDK host and apply the following settings:
The status page informs you about the current status of the SDK. It provides an overview
about any finished jobs, you can also stop a running job there and view the script output
in the troubleshooting section where you will also find links for downloading the manuals
and examples.
Job Management
This page can be used to set up scripts, triggers and jobs. It is usually a good idea to
create a trigger first which is made up by the following parameters:
                                          100
NB3700 User Manual 3.7
         101
                                NB3700 User Manual 3.7
You can now add your personal script to the system by applying the following parame-
ters:
You are ready to set up a job afterwards, it can be created by using the following
parameters:
You can trigger each configured job directly which can be helpful for testing purposes.
Pages
Any programmed SDK pages will show up here.
Testing
The testing page offers an editor and an input field for optional arguments which can be
used to perform test runs of your script or test dedicated portions of it. Please note that
you might need to quote arguments as they will otherwise be separated by white-spaces.
                                           102
                                NB3700 User Manual 3.7
/* generates :
 *      argv0 :     scriptname
 *      argv1 :     schnick
 *      argv2 :     schnack
 *      argv3 :     s c h n u c k
 */
In case of syntax errors, arena will usually print error messages as follows (indicating
the line and position where the parsing error occurred):
                                           103
                               NB3700 User Manual 3.7
admin01
status
Command                    Action
status                     Will reply a message to the sender including a short system
                           overview
connect                    Will enable the first WAN link configured on the system
disconnect                 Will disable the first WAN link configured on the system
reboot                     Initiates a reboot of the system
output 1 on                Turns on the first digital output port
output 1 off               Turns off the first digital output port
output 2 on                Turns on the second digital output port
output 2 off               Turns off the second digital output port
                                          104
                              NB3700 User Manual 3.7
This section can be used to individually configure the Dynamic Host Configuration
Protocol (DHCP) service for each LAN interface which will serve dynamic IP addresses
to hosts in the local network. You may also have a look to the leases page where you
can find an overview about negotiated client addresses.
Please note that WLAN interfaces (for each SSID) will pop up here as well in case you
have configured an access point respectively.
The following settings for each interface can be applied then:
                                        105
                    NB3700 User Manual 3.7
                              106
NB3700 User Manual 3.7
          107
                               NB3700 User Manual 3.7
The DNS server can be used to proxy DNS requests towards servers on the net which have
for instance been negotiated during WAN link negotiation. By pointing DNS requests to
the router, one can reduce outbound DNS traffic as it is caching already resolved names
but it can be also used for serving fixed addresses for particular host names.
You may further configure static hosts for serving fixed IP addresses for various host-
names. Please remember to point local hosts to the routers address for resolving them.
                                         108
                               NB3700 User Manual 3.7
This section can be used to individually configure the Network Time Protocol (NTP)
server function.
                                          109
                               NB3700 User Manual 3.7
5.7.5. DynDNS
The dynamic DNS client on this box can be used to tell one or more DynDNS providers
the current WAN address of this system. This address can be either derived from the
current hot-link address or by querying an HTTP service in the Internet for the current
Internet address. The latter might be applicable in NAT scenarios.
                                             110
                              NB3700 User Manual 3.7
Please note that your NetModule router can operate as DynDNS service as well, provided
that you have your hosts pointed to the DNS service of the router.
                                         111
                               NB3700 User Manual 3.7
5.7.6. E-Mail
The E-Mail client can be used to send notifications to a particular E-Mail address upon
certain events or by SDK scripts.
                                          112
            NB3700 User Manual 3.7
                      113
                             NB3700 User Manual 3.7
5.7.7. Events
By using the event manager you can notify one or more recipients by SMS or E-Mail
upon certain system events. The messages will contain a description provided by you
and a short system info.
A list of all system events can be found in the appendix A.2.
                                        114
                              NB3700 User Manual 3.7
5.7.8. SMS
Administration
On NetModule routers it is possible to receive or send short messages (SMS) over each
mounted modem (depending on the assembly options). Messages are received by query-
ing the SIM card over a modem, so prior to that, the required assignment of a SIM card
to a modem needs to be specified on the SIMs page.
Please bear in mind, in case you are running multiple WWAN interfaces sharing the
same SIM, that the system may switch SIMs during operation which will also result in
different settings for SMS communication.
Received messages are pulled from the SIMs and temporarily stored on the router but
get cleared after a system reboot. Please consider to consult an SDK script in case you
want to process or copy them.
Sending messages heavily depends on the registration state of the modem and whether
the provided SMS Center service works and may fail. You may use the sms-report-received
event to figure out whether a message has been successfully sent.
Please do not forget that modems might register roaming to foreign networks where
other fees may apply. You can manually assign a fixed network (by LAI) in the SIMs
section.
The relevant page can be used to enable the SMS service and specify on which it should
operate.
By using SMS routing you can specify outbound rules which will be applied whenever
message are sent. On the one hand, you can forward them to an enabled modem. For
a particular number, you can for instance enforce messages being sent over a dedicated
SIM. Phone numbers can also be specified by regular expressions, here are some exam-
ples:
Number                    Result
+12345678                 Specifies a fixed number
+1*                       Specifies any numbers starting with +1
+1*9                      Specifies any numbers starting with +1 and ending with 9
+[12]*                    Specifies any numbers starting with either +1 or 2
Please note that numbers have to be entered in international format including a valid
                                         115
   NB3700 User Manual 3.7
             116
                               NB3700 User Manual 3.7
prefix.
On the other hand, you can also define rules to drop outgoing messages, for instance,
when you want to avoid using any expensive service or international numbers.
Both types of rules form a list will be processed by order, forwarding outgoing messages
over the specified modem or dropping them. Messages which are not matching any of
the rules below will be dispatched to the first available modem.
Filtering serves a concept of firewalling incoming messages, thus either dropping or
allowing them on a per-modem basis. The created rules are processed by order and in
case of matches will either drop or forward the incoming message before entering the
system. All non-matching messages will be allowed.
Status
The status page can be used to the current modem status and get information about
any sent or received messages. There is a small SMS inbox reader which can be used to
view or delete the messages. Please note that the inbox will be cleared each midnight
in case it exceeds 512 kBytes of flash usage.
Testing
This page can be used to test whether SMS sending in general or filtering/routing rules
works. The maximum length per message part is limited to 160 characters, we also
suggest to exclusively use characters which are supported by the GSM 7-bit alphabet.
                                          117
                                NB3700 User Manual 3.7
Apart from the Web Manager, the SSH and Telnet services can be used to log into the
system. Valid users include root and admin as well as additional users as they can be
created in the User Accounts section. Please note, that a regular system shell will only
be provided for the root user, the CLI will be launched for any other user whereas normal
users will only be able to view status values, the admin user will obtain privileges to
modify the system.
Please note that these services will be accessible from the WAN interface also. In doubt,
please consider to disable or restrict access to them by applying applicable firewall rules.
The following parameters can be applied to the Telnet service:
                                            118
                        NB3700 User Manual 3.7
                                  119
                                    NB3700 User Manual 3.7
NetModule routers are equipped with an SNMP daemon, supporting basic MIB tables
(such as ifTable), plus additional enterprise MIBs to manage multiple systems. Our
VENDOR-MIB is listed in the appendix or can be downloaded directly from the router.
The VENDOR-MIB tables offer some additional information over the system and its
WWAN, GNSS and WLAN interfaces. They can be accessed over the following OIDs:
                                               120
                              NB3700 User Manual 3.7
                                         121
                               NB3700 User Manual 3.7
                                           122
                               NB3700 User Manual 3.7
Once the SNMP agent is enabled, SNMP traps can be generated using SDK scripts.
In general, the admin user can read and write any values. Read access will be granted
to any other system users.
There is no authentication/encryption in SNMPv1/v2c and should not be used to set
any values. However, it is possible to define its communities and authoritive host which
will be granted administrative access.
Attention must be paid to the fact that SNMP passwords have to be more than 8
characters long. Shorter passwords will be doubled for SNMP (e.g. admin01 becomes
admin01admin01).
Please note that the SNMP daemon is also listening on WAN interfaces and it is therefore
suggested to restrict the access with the firewall.
                                          123
                              NB3700 User Manual 3.7
This page can be used to configure different ports for accessing the Web Manager via
HTTP/HTTPS. We strongly recommend to use HTTPS when accessing the web service
via a WAN interface as the communication will be encrypted and thus avoids any misuse
of the system.
In order to enable HTTPS you would need to generate or upload a server certificate in
the section 5.8.6.
                                        124
                               NB3700 User Manual 3.7
5.7.14. Redundancy
This page can be used to set up a redundant pair of NetModule routers (or other systems)
by running the Virtual Router Redundancy Protocol (VRRP) between them. A typical
VRRP scenario defines a first host playing the master and another the backup device,
they both define a virtual gateway IP address which will be distributed by gratuitous
ARP messages for updating the ARP cache of all LAN hosts and thus redirecting the
packets accordingly. A takeover will happen within approximately 3 seconds as soon as
the partner is not reachable anymore (checked via multicast packets). This may happen
when one device is rebooting or the Ethernet link went down. Same applies when the
WAN link goes down.
In case DHCP has been activated, please keep in mind that you will need to reconfigure
the DHCP gateway address offered by the server and let them point to the virtual
gateway address. In order to avoid conflicts you may turn off DHCP on the backup
device or even better, split the DHCP lease range across both routers in order to prevent
any lease duplication.
                                          125
                              NB3700 User Manual 3.7
We assign a priority of 100 to the master and 1 to the backup router. Please adapt the
priority of your third-party device appropriately.
                                         126
                              NB3700 User Manual 3.7
Depending on your hardware, you can set up a voice gateway on the router which can
be connected by any VoIP client from the local network capable of the SIP protocol. It
hereby listens for arriving SIP calls and forwards them as a GSM call on the modem
which has been configured. Due to this nature only one concurrent call is possible.
                                         127
                              NB3700 User Manual 3.7
Please bear in mind, in case you are running multiple WWAN interfaces sharing the
same SIM, that the system may switch SIMs during operation which will also result in
different settings for voice communication.
Client Configuration
The sip client should be configured to use the router as a voice gateway. The easiest
way to achieve this is to configure the router as proxy. The Voice Gateway does not
require authenticationi however it may be necessary to fill in dummy values as user ID,
Domain and Password. Any SIP client with access to the SIP IP Interface can use the
router as a voice gateway.
Sample configuration for the Counter Path X-Lite client (Version 5.0.0 build 67284)
                                         128
                               NB3700 User Manual 3.7
5.8. SYSTEM
5.8.1. System
System Settings
The following system parameters can be set:
                                          129
                               NB3700 User Manual 3.7
Reboot
This page can be used to set up a periodic automatic reboot but also to trigger a manual
reboot which will be issued immediately.
                                          130
NB3700 User Manual 3.7
          131
  NB3700 User Manual 3.7
             132
                                NB3700 User Manual 3.7
5.8.2. Authentication
This pages offers a simple shortcut to only allow secure connections (SSH, HTTPS) for
managing the router.
User Accounts
By using this page you can manage the user accounts on the system. The standard
admin user is a built-in power user that has permission to access the Web Manager and
other administrative services and is used by several services as default user. Keep in
mind that the admin password will be also applied to the root user which is able to
enter a system shell.
Any other user represents a user with lower privileges, for instance it has only permission
to view the status page or retrieve status values when using the CLI.
                                           133
                               NB3700 User Manual 3.7
Remote Authentication
A RADIUS server can be used for authenticating remote users. This applies for the Web
Manager, the WLAN network and other services supporting and incorporating remote
authentication.
It can be configured as follows:
                                           134
     NB3700 User Manual 3.7
               135
                                NB3700 User Manual 3.7
When issuing a software update, the current configuration (including files like keys/cer-
tificates) will be backuped. Any other modifications to the filesystem will be erased.
The configuration is generally backward-compatible. We also apply forward compati-
bility when downgrading to a previous software within the same release line, which is
accomplished by sorting out unknown configuration directives which actually may lead
to loss of settings and features. Therefore, its always a good idea to keep a copy of the
working configuration.
Attention: In case you perform a major downgrade with a previous release line (e.g. 3.7.0
to 3.6.0), please ensure to always use the latest release of that branch (i.e. 3.6.0.X) as
only those tend to be fully forward-compatible. Also keep in mind, that some hardware
features may not work (e.g. if not implemented in that version). In doubt, please consult
our support team.
A software image can be either uploaded via the Web Manager or retrieved from a
specific URL. It will be unpacked and deployed to a spare partition which gets activated
if the update completed successfully. The whole procedure is accompanied by all green
LEDs flashing up, the subsequent system reboot gets denoted by a slowly blinking Status
LED. The backuped configuration will be applied at bootup and the Status LED will
blink faster during this operation. Depending on your configuration, this may take a
while.
                                           136
                                NB3700 User Manual 3.7
Remark: SSL certificates of HTTPS URLs will be only verified if a list of CA root
certificates are provided under 5.8.6.
After the new software has been installed, the latest running configuration will be applied
afterwards during bootup. This is indicated by a faster green blinking of the Status LED.
                                           137
                                 NB3700 User Manual 3.7
5.8.4. Configuration
Configuration via the Web Manager becomes tedious for larger volumes of devices. The
router therefore offers automatic and manual file-based configuration to automate things.
Once you have successfully set up the system you can back up the configuration and
restore the system with it afterwards. You can either upload a single configuration file
(.cfg) or a complete package (.zip) containing the configuration file and a packed version
of other essential files (such as certificates) in the root directory.
This section can be used to download the currently running system configuration (in-
cluding essential files such as certificates). In order to restore a particular configuration
you can upload a configuration previously downloaded. You can choose between missing
configuration directives set to factory defaults or getting ignored, that means, potentially
existing configuration directives will be kept at the system.
                                            138
        NB3700 User Manual 3.7
                   139
                                NB3700 User Manual 3.7
Factory Configuration
This menu can be used to reset the device to factory defaults. Your current configuration
will be lost. This procedure can also be initiated by pressing and holding the Reset
button for at least five seconds. A successfully initiated factory reset can be noticed by
all LEDs having been turned on. The factory reset will set the IP address of the first
Ethernet interface back to 192.168.1.1. You will be able to communicate again with
the device using the default network parameters. You may store the currently running
                                           140
                               NB3700 User Manual 3.7
configuration as factory defaults which will reside active even when a factory reset has
been initiated (e.g. by your service staff).
Please ensure that this corresponds to a working configuration. A real factory reset to
the default settings can be achieved by restoring the original factory configuration and
initiating the factory reset again.
                                          141
                                NB3700 User Manual 3.7
5.8.5. Troubleshooting
Network Debugging
Log Files
You can view the system log here by selection the option Debug log or if you are interested
in the boot log select Boot log.
Another way to see what is going on on the box is opening a SSH or Telnet session as
root and typing tail-log. Furthermore the system log can be redirected to a syslog
server, see section 5.8.1.
Tech Support
You can generate and download a tech support file here. We strongly recommend pro-
viding this file when getting in touch with our support team, either by e-mail or via our
on-line support form, as it would significantly speed up the process of analyzing and
resolving your problem. Log files can be viewed a downloaded and reset here. Please
study them carefully in case of any issues. Various tools reside on this page for further
analysis of potential configuration issues.
                                           142
   NB3700 User Manual 3.7
             143
                                NB3700 User Manual 3.7
It is possible to trace any IP interface and inspect individual packet flows between hosts.
This can be achieved by logging onto the box and start a network packet capture by
using the tool tcdump. We recommend to use the -n switch to bypass name resolution
(e.g. tcpdump -n -i lan0). You may also generate a dump in PCAP format using
the Web Manager, download it to your computer and perform further inspections with
Wireshark (available at www.wireshark.org).
                                           144
                                NB3700 User Manual 3.7
The key and certificate page lets you generate required files for securing your services
(such as the HTTP and SSH server).
Term                       Description
Root CA                    The root Certificate Authority (CA) which issues certifi-
                           cates, its key can be used to certify it at trusted third party
                           on other systems
Certificate                Corresponds to a digital certificate which uses a signature
                           to bind a public key with an identity
Key                        Corresponds to an either public or private key
CSR                        Certificate Signing Request, which can be used to sign a
                           certificate by a third party authority
                                          145
                               NB3700 User Manual 3.7
Term                       Description
P12                        PKCS12 container format which can include certificates and
                           keys protected by passphrase
RSA                        An encryption algorithm based on the fact that factorization
                           of large integers is difficult
DSS/DSA                    An encryption algorithm based on the discrete logarithm
                           problem
Phrase                     A passphrase used for protecting keys
Attribute                  Description
CN                         The certificate owners common name, mainly used to iden-
                           tify a host
C                          The certificate owners country (usually a TLD abbrevia-
                           tion)
ST                         The certificate owners state
L                          The certificate owners location
C                          The certificate owners country
O                          The certificate owners organization
OU                         The name of the organizational unit to which the certificate
                           issuer belongs
E                          The certificate owners email address
Those attributes form a so-called subject name, mainly used for matching a certificate
or when signing certificate requests:
Depending on your configuration, keys and certificates may be used for particular ser-
vices, for instance if OpenVPN uses a certificate-based authentication or if you want to
access the system over HTTPS or SSH.
                                          146
                                NB3700 User Manual 3.7
Keys and certificates can be installed to the system by uploading the corresponding files.
It is also possible to create an own (unsigned) Certificate Authority and issue ready-for-
use client certificates (e.g. for OpenVPN or WLAN clients). Such certificates can be
revoked and invalidated again (for instance if they have been compromised or lost).
Generally, when generating keys and certificates on the box, the systems hostname is
used for subject names and the passphrase corresponds to the current administrators
password.
Please note that an accurate system time is needed prior to creating certificates as it
determines the lifetime of a certificate. The validity period is usually set to 10 years.
The X.509 certificates are encoded in PEM (Privacy Enhanced Mail) format and can be
machined by OpenSSL (see www.openssl.org) or other Secure Sockets Layer tools. The
.p12 files usually contain the CA certificate, the user certificate and the private key and
the .phr files hold the required passphrase.
For curl-based SSL client connections as used by SDK functions or when downloading
configuration/software images, you might upload the corresponding CA root certificates
in order to build a chain of trust. Those can be derived from various browsers (see
http://curl.haxx.se/docs/caextract.html). In case of uploaded CA bundles, all SSL client
connections will abort if CA verification of the remote end fails.
                                           147
                                NB3700 User Manual 3.7
5.8.7. Licensing
Certain features of NetModule routers require a valid license to be present in the system,
some of them also depend on the mounted modules. Please contact us for getting a valid
license for available components and we will provide a license file based on your serial
number which can be installed to the router afterwards.
                                           148
                             NB3700 User Manual 3.7
5.9. LOGOUT
Please use this menu to log out from Web Manager.
                                       149
6. Command Line Interface
The Command Line Interface (CLI) offers a generic control interface to the router and
can be used to get/set configuration parameters, apply updates, restart services or per-
form other system tasks.
It will be started automatically in interactive mode when logging in as admin user or by
running cli -i. However, the same syntax can be used when calling it from the system
shell. A list of available commands can be displayed by running cli -l.
The CLI supports TAB completion, that is expanding entered words or fragments by
hitting the TAB key at any time. This applies to commands but also to some arguments
and generally offers a convenient way for working on the shell.
Please note that each CLI session will perform an automatic logout as soon as a certain
time of inactivity (10 minutes by default) has been reached. It can be turned off by the
command no-autologout.
                                          150
                             NB3700 User Manual 3.7
Please note, that it can be required to apply quotes (") when entering commands with
arguments containing whitespaces.
The following sections are now trying to explain the available commands.
> help
                                           151
                                NB3700 User Manual 3.7
Usage :
            help [<command >]
Available commands :
> get h
Usage :
            get [hsvfc ] <parameter> [<parameter > . . ]
Options :
            s         generate sourceable output
            v         validate config parameter
            f         get factory default rather than current value
            c         show configuration sections
> set h
Usage :
                                         152
                             NB3700 User Manual 3.7
Options :
            v     validate config parameter
> status h
Usage :
        status [hs ] <section>
Options :
            s     generate sourceable output
Available sections :
                                       153
                            NB3700 User Manual 3.7
> scan h
Usage :
        scan [hs ] <interface>
Options :
            s     generate sourceable output
> send h
Name :
        clisend ( Send message or mail )
Usage :
            send [h ] <type> <dest> <msg>
Options :
            <type>      type of message to be sent ( mail , sms ,
            techsupport )
            <dest>      destination of message ( mailaddress or phone
            number )
            <msg>       message to be sent
> update h
Usage :
        update [hrsn ] <software | config | license | sshkeys> <URL>
Options :
            r     reboot after update
                                      154
                             NB3700 User Manual 3.7
Available actions :
You may also run ' update software latest ' to install the latest
version
from our server .
> restart h
Usage :
        restart [h ] <service>
Available services :
                                       155
                             NB3700 User Manual 3.7
> debug h
Usage :
        debug [h ] <target>
         system
         scripts
         configd
         watchdog
         swupdate
         wwanmanager
         ledmanager
         eventmanager
         linkmanager
         wwanmd
         surveyor
         mobilenode
         homeagent
         voiced
         smsd
         sdkhost
         qmid
         ser2net
         qosd
> reset h
                                        156
                               NB3700 User Manual 3.7
Usage :
          reset [h ]
> reboot h
Usage :
        reboot [h ]
> shell h
Usage :
        shell [h ] [<cmd >]
> histor h
Usage :
        history [c ]
6.15. CLI-PHP
CLI-PHP, the HTTP frontend to the CLI application, can be used to configure and
control the router remotely. It is enabled in factory configuration, thus can be used for
deployment purposes, but disabled as soon as the admin account has been set up.
The service can later be turned on/off by setting the cliphp.status configuration
parameter:
                                          157
                             NB3700 User Manual 3.7
This section describes the CLI-PHP interface for Version 2. It accepts POST and GET
requests.
Running with GET requests, the general usage is defined as follows:
Usage :
  http ( s ) : / / cli . php?<key1>=<value1>&<key2>=<value2 >..<keyN>=<valueN>
Available keys :
Notes :
  The commands correspond to CLI commands as seen by ' cli l ' , the
  arguments ( arg0 . . arg31 ) will be directly passed to cli .
cli get " admin . password " " admin . debug " " admin . access "
Response :
  The returned response will always contain a status line in the
  format :
                                       158
                               NB3700 User Manual 3.7
Examples :
  OK : status command successful
  ERROR : authentication failed
Key usage :
  command=status [& arg0=<section >]
Notes :
  Available sections can be retrieved by running
  command=status&arg0=h .
  Please note that the status summary can be displayed without
  authentication .
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=status&arg0=h
Key usage :
  command=get&arg0=<configkey>[&arg1=<configkey > . . ]
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=get&arg0=config . version
Key usage :
  command=set&arg0=<configkey>&arg1=<configvalue>[&arg2=<config
                                          159
                               NB3700 User Manual 3.7
key>&arg3=<configvalue > . . ]
Notes :
  In contrast to the other commands , this command requires a set of
  tuples because of the reserved '= ' char , i . e .
  [ arg0=key0 , arg1=val0 ] , [ arg2=key1 , arg3=val1 ] , [ arg4=key2 , arg5=
  val2 ] , etc
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=set&arg0=snmp . status&arg1=1
Key usage :
  command=restart&arg0=<service>
Notes :
  Available services can be retrieved by running ' command=restart&
  arg0=h '
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=restart&arg0=h
Key usage :
  command=reboot
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=reboot
                                          160
                               NB3700 User Manual 3.7
Key usage :
  command=reset
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=reset
Key usage :
  command=update&arg0=<facility>&arg1=<URL>
Notes :
  Available facilities can be retrieved by running ' command=update&
  arg0=h '
Examples :
  http : / / 1 9 2 . 1 6 8 . 1 . 1 / cli . php ? version=2&output=html&usr=admin&pwd=
  admin01&command=update&arg0=software&arg1=tftp : / / 1 9 2 . 1 6 8 . 1 . 2 5 4 /
  latest
                                          161
7. Technical Support
NetModules mission statement is to provide you with state of the art products, technolo-
gies and services for your embedded applications. This certainly includes a professional
and friendly team of support engineers which will be pleased to offer consultancy, pro-
vide assistance and deliver solutions in case of technical issues. With their broad-based
experience they will be able to narrow down your problem and thus prevent you from
getting too much gray hair.
In case of support requests please use our support form on the NetModule web page and
submit a detailed description of your problem together with a tech-support file which
contains all the necessary information to speed up the process of analyzing and resolving
your problem.
The latest software and documentation material can found in the technical support area
via the NetModule website.
Feedback
Your feedback is highly appreciated; please send comments, suggestions, feature re-
quests, error reports or your personal user experience with this NB3700 router to
router@support.netmodule.com.
                                          162
8. Legal Notice
Copyright
NetModule and NB3700 are trademarks and the logo is a service mark of NetModule
AG, Switzerland.
All other products or company names mentioned herein are used for identification pur-
poses only and may be trademarks or registered trademarks of their respective owners.
The following description of software, hardware or process of NetModule or other third
party provider may be included with your product and will be subject to the software,
hardware or other license agreements.
                                          163
                               NB3700 User Manual 3.7
Contact
                                          164
A. Appendix
A.1. Abbrevations
Parameter           Description
ETHx                Corresponds to Ethernet interfaces (either single or switched
                    ones)
LANx                LAN interfaces which are generally based on Ethernet in-
                    terfaces (including bridges)
WLANx               Refers to a Wireless LAN interface which will be represented
                    as additional LAN interface when configured as access point
WWANx               Refers to a Wireless Wide Area Network (2G/3G/4G) con-
                    nection
TUNx                Specifies an OpenVPN tunnel interface (based on TUN)
TAPx                Specifies an OpenVPN tunnel interface (based on TAP)
PPTPx               Specifies a PPTP tunnel interface
MOBILEIPx           Refers to a Mobile IP tunnel interface
SIMx                Specifies the SIM slot as seen on the front panel
GNSSx               Specifies a Global Navigation Satellite System module
Mobilex             Identifies a WWAN modem
SERIALx             Identifies a serial port
OUTx                Specifies a digital I/O output port (DOx)
INx                 Specifies a digital I/O input port (DIx)
ANY                 Generally includes all options offered by the current section
APN                 Access Point Name
CID                 A Cell ID is a generally unique number used to identify each
                    Base Transceiver Station (BTS).
                                    165
                                NB3700 User Manual 3.7
 Parameter                  Description
 LAC                        The Location Area Code corresponds to an identifier of a
                            set of base stations that are grouped together to optimize
                            signaling
 LAI                        The Location Area Identity is a globally unique number that
                            identifies the country, network provider and location area
 MSS                        Maximum Segment Size
 MTU                        Maximum Transmission Unit
 DNS                        Domain Name System
 NAPT                       Network Address and Port Translation
 DHCP                       Dynamic Host Configuration Protocol
 SDK                        Script Development Kit which can be used to program ap-
                            plications
 CLI                        Command Line Interface, a generic interface to query the
                            router or perform system tasks
 SIM                        Subscriber Identity Module
 SMS                        Short Message Service
 SSID                       Service Set Identifiers, can be used to define multiple WLAN
                            networks on a module
 STP                        Spanning Tree Protocol
 USSD                       Unstructured Supplementary Service Data
 VRRP                       Virtual Router Redundancy Protocol
 VPN                        Virtual Private Network
 WAN                        WAN links include all Wide Area Network interfaces which
                            are currently activated in the system
 FQDN                       Fully qualified domain name
In general, internal interfaces are written lower-case and may have a different naming.
Their index starts from zero, whereas interfaces seen by the user will be written in capital
letters starting from one.
                                            166
                           NB3700 User Manual 3.7
ID              Event                   Description
101             wan-up                  WAN link came up
102             wan-down                WAN link went down
201             dio-in1-on              DIO IN1 turned on
202             dio-in1-off             DIO IN1 turned off
203             dio-in2-on              DIO IN2 turned on
204             dio-in2-off             DIO IN2 turned off
205             dio-out1-on             DIO OUT1 turned on
206             dio-out1-off            DIO OUT1 turned off
207             dio-out2-on             DIO OUT2 turned on
208             dio-out2-off            DIO OUT2 turned off
301             gps-up                  GPS signal is available
302             gps-down                GPS signal is not available
401             openvpn-up              OpenVPN connection came up
402             openvpn-down            OpenVPN connection went down
403             ipsec-up                IPsec connection came up
404             ipsec-down              IPsec connection went down
406             pptp-up                 PPTP connection came up
407             pptp-down               PPTP connection went down
408             dialin-up               Dial-In connection came up
409             dialin-down             Dial-In connection went down
410             mobileip-up             Mobile IP connection came up
411             mobileip-down           Mobile IP connection went down
412             gre-up                  GRE connection came up
413             gre-down                GRE connection went down
501             system-login-failed     User login failed
502             system-login-           User login succeeded
                succeeded
                                      167
              NB3700 User Manual 3.7
ID    Event                  Description
503   system-logout          User logged out
504   system-rebooting       System reboot has been triggered
505   system-startup         System has been started
506   test                   test event
507   sdk-startup            SDK has been started
508   system-time-           System time has been updated
      updated
601   sms-sent               SMS has been sent
602   sms-notsent            SMS has not been sent
603   sms-received           SMS has been received
604   sms-report-received    SMS report has been received
701   call-incoming          A voice call is coming in
702   call-outgoing          Outgoing voice call is being established
801   ddns-update-           Dynamic DNS update succeeded
      succeeded
802   ddns-update-failed     Dynamic DNS update failed
901   usb-storage-added      USB storage device has been added
902   usb-storage-           USB storage device has been removed
      removed
903   usb-eth-added          USB Ethernet device has been added
904   usb-eth-removed        USB Ethernet device has been removed
905   usb-serial-added       USB serial device has been added
906   usb-serial-removed     USB serial device has been removed
                           168
                              NB3700 User Manual 3.7
                                         169
                                                                                 NB3700 User Manual 3.7
--   ****************************************************************************
--   NetModule AG VENDOR MIB
--
--
--   ( c ) COPYRIGHT 2014 by NetModule AG , Switzerland
--   All rights reserved .
--
--
--   ****************************************************************************
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- imports
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
IMPORTS
             MODULE - IDENTITY , OBJECT - TYPE , NOTIFICATION - TYPE ,
             Integer32 , Counter32 , Gauge32 ,
             Counter64 , TimeTicks                          FROM SNMPv2 - SMI
             TEXTUAL - CONVENTION , DisplayString ,
             PhysAddress , TruthValue , RowStatus ,
             TimeStamp , AutonomousType , TestAndIncr       FROM SNMPv2 - TC
             MODULE - COMPLIANCE , OBJECT - GROUP           FROM SNMPv2 - CONF
             snmpTraps                                      FROM SNMPv2 - MIB
             URLString                                      FROM NETWORK - SERVICES - MIB
             enterprises                                    FROM SNMPv2 - SMI ;
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- module definition
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
nb MODULE - IDENTITY
        LAST - UPDATED " 201405091000 Z "
        ORGANIZATION " NetModule AG "
        CONTACT - INFO
              " NetModule AG , Switzerland "
        DESCRIPTION
              " MIB module which defines the NB router specific entities "
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- root anchor
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- table definitions
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- NBAdminTable
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
                                                                                                             170
                                                                                 NB3700 User Manual 3.7
c on f i gU p da t e St a tu s OBJECT - TYPE
       SYNTAX INTEGER {
                           succeeded (1) ,
                           failed (2) ,
                           inprogress (3) ,
                           notstarted (4)
                     }
       MAX - ACCESS read - only
       STATUS current
       DESCRIPTION
              " The status of the last configuration update cycle "
       ::= { admin 12 }
s o f t w a r e U p d a t e S t a t u s OBJECT - TYPE
        SYNTAX INTEGER {
                                succeeded (1) ,
                                failed (2) ,
                                inprogress (3) ,
                                notstarted (4)
                        }
        MAX - ACCESS read - only
        STATUS current
        DESCRIPTION
                " The status of the last software update cycle "
        ::= { admin 14 }
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- NBWwanTable
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
                                                                                                             171
                                                                      NB3700 User Manual 3.7
w w a n R e g i s t r a t i o n S t a t e OBJECT - TYPE
        SYNTAX                  DisplayString
        MAX - ACCESS read - only
        STATUS                  current
        DESCRIPTION
                " The current registration state of the WWAN modem "
        ::= { nbWwanEntry 5 }
w wa n S ig n al S t re n gt h OBJECT - TYPE
       SYNTAX              Integer32
       MAX - ACCESS read - only
       STATUS              current
       DESCRIPTION
              " The current signal strength of the WWAN modem ( -999 means un known ) "
       ::= { nbWwanEntry 6 }
w w a n L o c a l A r e a I d e n t i f i c a t i o n OBJECT - TYPE
        SYNTAX                  DisplayString
                                                                               172
                                                                                 NB3700 User Manual 3.7
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- NBGnssTable
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
                                                                                                             173
                                                                                 NB3700 User Manual 3.7
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- NBWlanTable
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
                                                                                                             174
                                                                                 NB3700 User Manual 3.7
::= { nbWlanEntry 4 }
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- NBDioTable
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
-- trap objects
-- * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
                                                                                                             175
                                                NB3700 User Manual 3.7
                                                         176
                                                 NB3700 User Manual 3.7
                                                          177
                                             NB3700 User Manual 3.7
END
                                                             178
                           NB3700 User Manual 3.7
Event                  Description
config-summary.are     This script shows a summary of the currently running con-
                       figuration.
dio-monitor.are        This script monitors the DIO ports and sends a SMS to the
                       specified phone number.
dio-server.are         This script implements a TCP server which can be used to
                       control the DIO ports.
dio.are                This script can be used to set a digital output port.
dynamic-operator.are   This script will scan Mobile2 and dial the appropriate SIM
                       on Mobile1
email-to-sms.are       This script implements a lightweight SMTP server which is
                       able to receive mail and forward them as SMS to a phone
                       number.
etherwake.are          This script can be used to wake up a sleeping host (WakeOn-
                       Lan)
gps-monitor.are        A script for activating WLAN as soon as GPS position
                       (lat,lon) is within a specified range.
gps-udp-client.are     This script sends the local GPS NMEA stream to a remote
                       UDP server.
gps-upd-client-        This script sends the local GPS NMEA stream to a remote
compat.are             UDP server (incl. device identity).
led.are                This script can be used to set a LED
mount-media.are        This script can be used to mount an USB storage stick.
ping-supervision.are   This script will supervise a specified host.
read-config.are        This script can be used to read a configuration parameter.
scan-mobile.are        This script can be used to switch the Mobile LAI according
                       to available networks
scan-wlan.are          This script can be used to switch the WLAN client network
                       according to availability
send-mail.are          This script will send an E-Mail to the specified address.
send-sms.are           This script will send an SMS to the specified phone number.
                                      179
                            NB3700 User Manual 3.7
Event                   Description
serial-read.are         This script can be used to read messages from the serial
                        port.
serial-readwrite.are    This script will write to and read from the serial port.
serial-tcsetattr.are    This script can be used to set/get the attributes of the serial
                        port.
serial-udp-server.are   This script reads messages coming from the serial port and
                        forwards them via UDP to a remote host (and vice versa).
serial-write.are        This script can be used to write a message to the serial port.
sms-control.are         This script will execute commands received by SMS.
sms-delete-inbox.are    This script can be used to flush the SMS inbox.
sms-read-inbox.are      This script can be used to read the SMS inbox.
sms-to-email.are        This script will forward incoming SMS messages to a given
                        E-mail address.
sms-to-serial.are       This script can be used to write a received SMS to the serial
                        port.
snmp.are                This script can be used to send SNMP traps
status.are              This script can be used to display all status variables
syslog.are              Throw a simple syslog message.
tcpclient.are           This script sends a message to a TCP server.
tcpserver.are           This script implements a TCP server which is able to receive
                        messages.
transfer.are            This scripts stores the latest GNSS positions in a remote
                        FTP file
udp-msg-server.are      This script will run an UDP server which is able to receive
                        messages and forward them as SMS/E-Mail.
udpclient.are           This script sends a message to a remote UDP server.
udpserver.are           This script implements an UDP server which is able to re-
                        ceive messages.
update-config.are       This script can be used to perform a configuration update
webpage.are             This script will generate a page which can be viewed in the
                        Web Manager
                                       180
                      NB3700 User Manual 3.7
Event              Description
write-config.are   This script can be used to set a configuration parameter.
                                 181
SDK API Manual
        Version 1.2
1 Introduction 3
2 API functions                                                                                                                               4
  2.1 Serial . . . . . . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    4
      2.1.1 nb_serial_getattr . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    4
      2.1.2 nb_serial_setattr . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    4
      2.1.3 nb_serial_write . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    4
      2.1.4 nb_serial_read . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    5
  2.2 Media . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    5
      2.2.1 nb_media_mount .             .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    5
      2.2.2 nb_media_umount .            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    5
      2.2.3 nb_media_getmount            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    5
  2.3 SMS . . . . . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    6
      2.3.1 nb_sms_send . . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    6
      2.3.2 nb_sms_list . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    6
      2.3.3 nb_sms_retrieve . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    6
      2.3.4 nb_sms_header . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    6
      2.3.5 nb_sms_body . . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    7
      2.3.6 nb_sms_delete . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    7
  2.4 E-mail . . . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    7
      2.4.1 nb_email_send . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    7
  2.5 Digital I/O . . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
      2.5.1 nb_dio_get . . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
      2.5.2 nb_dio_set . . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
      2.5.3 nb_dio_summary . .           .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
  2.6 Configuration . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
      2.6.1 nb_config_get . . .          .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    8
      2.6.2 nb_config_set . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    9
      2.6.3 nb_config_summary            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    9
  2.7 Status Information . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    9
      2.7.1 nb_status . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .    9
      2.7.2 nb_status_summary            .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   10
  2.8 Network Scanning . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   10
                                                     2
       2.8.1 nb_scan_networks . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   10
2.9    File Transfers . . . . . . . . . . .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   10
       2.9.1 nb_transfer_get . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   10
       2.9.2 nb_transfer_put . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   11
       2.9.3 nb_transfer_post . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   11
       2.9.4 nb_transfer_list . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
       2.9.5 nb_transfer_delete . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
2.10   LED . . . . . . . . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
       2.10.1 nb_led_acquire . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   12
       2.10.2 nb_led_release . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   13
       2.10.3 nb_led_set . . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   13
2.11   Config/Software Update . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   13
       2.11.1 nb_update_status . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   14
       2.11.2 nb_update_config . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   14
       2.11.3 nb_update_software . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   14
       2.11.4 nb_update_sshkeys . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   14
2.12   Web Pages . . . . . . . . . . . . .    .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   15
       2.12.1 nb_page_register . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   15
       2.12.2 nb_page_unregister . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   15
       2.12.3 nb_page_request . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   15
       2.12.4 nb_page_respond . . . .         .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
       2.12.5 nb_page_finish . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
2.13   SNMP functions . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
       2.13.1 nb_snmp_traphost . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   16
       2.13.2 nb_snmp_trap . . . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
2.14   Various network-related functions      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
       2.14.1 nb_gethostbyname . . . .        .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   17
       2.14.2 nb_ifc_address . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   18
       2.14.3 nb_ping . . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   18
       2.14.4 nb_arp_ping . . . . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   18
       2.14.5 nb_arp_gratuitous . . . .       .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   18
       2.14.6 nb_etherwake . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   19
2.15   Other system functions . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   19
       2.15.1 nb_syslog . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   19
       2.15.2 nb_event_get . . . . . . .      .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   19
       2.15.3 nb_reboot . . . . . . . . .     .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   .   19
                                              3
1 Introduction
This manual describes the SDK API functions which provide a range of general-purpose
extensions for the Arena scripting language.
  Version 1.2 ships with the following features:
                                         4
2 API functions
2.1 Serial
2.1.1 nb_serial_getattr
  Returns a struct containing values for baudrate, databit, stopbit, parity, flowctl or
void on error.
2.1.2 nb_serial_setattr
The nb_serial_setattr function can be used to set the attributes of a serial device.
2.1.3 nb_serial_write
                                           5
  The nb_serial_write function can be used to directly write a message to a serial
device.
2.1.4 nb_serial_read
2.2 Media
2.2.1 nb_media_mount
2.2.2 nb_media_umount
2.2.3 nb_media_getmount
                                           6
    string nb_media_getmount ( void )
   The nb_media_getmount function returns all media currently mounted including the
corresponding mountpoint. Returns list of mounted media and its mountpoints line-by-
line (such as "xx on xx/xx"). If nothing is mounted or in case of an error an empty
string will be returned.
2.3 SMS
Please note that the SMS daemon must be properly configured prior to using the func-
tions.
2.3.1 nb_sms_send
  The nb_sms_send function can be used to send a SMS to the specified telephone
number.
2.3.2 nb_sms_list
  The nb_sms_list function can be used to retrieve the messages in the inbox. Returns
an array of message files.
2.3.3 nb_sms_retrieve
2.3.4 nb_sms_header
                                         7
     file     the message file
     tag      a specific header tag ( such as " From ")
Returns header value of specified tag, all headers if omitted or NULL on error.
2.3.5 nb_sms_body
2.3.6 nb_sms_delete
The nb_sms_delete function can be used to delete a message from the inbox.
2.4 E-mail
Please note that the E-Mail client must be properly configured prior to using the func-
tions.
2.4.1 nb_email_send
                                          8
  Returns 0 on success or any error code.
2.5.1 nb_dio_get
2.5.2 nb_dio_set
  The nb_dio_set function can be used to turn on/off the status of a digital output
port.
Returns -1 on error.
2.5.3 nb_dio_summary
  The nb_dio_summary function retrieves the status of all digital I/O ports.
  Returns a string holding the status of all ports or an empty string on error.
2.6 Configuration
2.6.1 nb_config_get
                                            9
  The nb_config_get function returns the currently configured value of a particular
config parameter.
2.6.2 nb_config_set
  The nb_config_set function can be used to set system configuration parameters. Note,
that this function will immediately apply the values to the system.
Returns -1 on error.
2.6.3 nb_config_summary
   The nb_config_summary function will return the current system configuration, that
is, the difference between the factory and the running configuration.
2.7.1 nb_status
  The nb_status function will return various status values, the following sections can
be specified:
                                         10
                   lan              LAN interface status
                   wan              WAN interface status
                   openvpn          OpenVPN connection status
                   ipsec            IPsec connection status
                   dio              Digital IO status
Returns a struct holding the relevant status values (see status.are example).
2.7.2 nb_status_summary
  The nb_status_summary function will return a short summary about the current
system status or NULL on error.
2.8.1 nb_scan_networks
2.9.1 nb_transfer_get
                                            11
  The nb_transfer_get function can be used to get a file from a remote server. The
usr/pwd arguments can be applied in order to perform authentication.
Returns -1 on error.
2.9.2 nb_transfer_put
  The nb_transfer_put function can be used to transfer a file to a remote server. The
usr/pwd arguments can be applied in order to perform authentication.
Returns -1 on error.
2.9.3 nb_transfer_post
Returns -1 on error.
                                         12
2.9.4 nb_transfer_list
  The nb_transfer_list function can be used to retrieve the list of files from a remote
server. The usr/pwd arguments can be applied in order to perform authentication.
  Returns an array of struct describing the directory files. They are made up of:
  name name of the file size file size in bytes mode file mode and permission (see chmod)
user owner username group owner groupname time modification time tm time struct of
modification time
2.9.5 nb_transfer_delete
  The nb_transfer_delete function can be used to delete a file from a remote FTP
server. The usr/pwd arguments can be applied in order to perform authentication.
Returns -1 on error.
2.10 LED
2.10.1 nb_led_acquire
   The nb_led_acquire function will acquire the specified indication LED to be used for
a script. Any associated system indication will stop being signalled until the LED is
released again. The status LED cannot be acquired/set.
                                           13
  Returns -1 on error otherwise zero.
2.10.2 nb_led_release
led the number of the LED to be released or LED_ALL for all LEDs
2.10.3 nb_led_set
The nb_led_set function will set the specified LED to a specific mode.
     led the number of the LED to be released or LED_ALL for all LEDs
     mode      the LED mode to be applied which can be specified by
        OR  ing the following colors and types :
       LED_OFF             turn off LED
       LED_COLOR_GREEN     color is green
       LED_COLOR_RED       color is red
       LED_COLOR_YELLOW color is yellow
       LED_SOLID           type is solid
       LED_BLINK_FAST      type is fast blinking
       LED_BLINK_SLOW      type is slow blinking
     http :// < server >/ < path >      ( retrieve file via    HTTP )
     https :// < server >/ < path >     ( retrieve file via    HTTPS )
     ftp :// < server >/ < path >       ( retrieve file via    FTP )
     tftp :// < server >/ < path >      ( retrieve file via    TFTP )
     file :/// < path >                 ( use local file )
                                          14
  Please bear in mind that calling nb_update_software() will result in a system reboot.
The nb_update_config() call will restart the SDK which will terminate your scripts.
Thus, it is recommended to exit the script after calling this function and check the
result later on via nb_update_status().
2.11.1 nb_update_status
  The nb_update_status function returns the status of the last or currently running
update operation
2.11.2 nb_update_config
 The nb_update_config function will perform a configuration update from the specified
URL.
2.11.3 nb_update_software
 The nb_update_software function will perform a software update from the specified
URL.
2.11.4 nb_update_sshkeys
The nb_update_sshkeys function will perform an update of the SSH authorized keys.
                                          15
  Returns zero on success.
2.12.1 nb_page_register
   The nb_page_register function registeres a new page with the specified identifier and
title (as well as submenu).
     id                 identifier
     title              page title
     submenu            submenu for page
  Returns -1 on error and otherwise a page structure which can be used for further page
functions.
2.12.2 nb_page_unregister
2.12.3 nb_page_request
 Returns void on error, otherwise a request structure which holds possible GET and
POST parameters.
                                          16
2.12.4 nb_page_respond
  The nb_page_responds function can be used to echo back a string to the request and
can be called multiple times until page is to be finished. It supports a fmt string and
additional arguments that are formatted according to the format string. Please refer to
the printf function for more information about format options.
2.12.5 nb_page_finish
  The nb_page_finish function will be used to signal that responding to a request has
been finished and data shall be passed to the client.
2.13.1 nb_snmp_traphost
  The nb_send_traphost function will set the host for sending SNMP traps.
  For an SNMPv1/v2 host the parameters are:
                                          17
  For an SNMPv3 host the parameters are:
Returns -1 on error.
2.13.2 nb_snmp_trap
  The nb_send_trap function will send an SNMP trap with the specified OID to a
remote traphost.
  Please note that a traphost has to be set prior to using this function.
  Returns -1 on error.
2.14.1 nb_gethostbyname
  The nb_gethostbyname function performs a DNS lookup for the given hostname and
returns an array of resolved IP addresses. Please note that a valid DNS is available prior
to using this function.
                                           18
2.14.2 nb_ifc_address
The nb_ifc_address function can be used to obtain the first address of an interface.
2.14.3 nb_ping
 The nb_ping function will send ICMP ping packets to the specified host and returns
whether the host correctly responded or not.
2.14.4 nb_arp_ping
 The nb_arp_ping function will send an ARP request for the specified host and returns
whether the host address has been successfully resolved.
Returns 1 in case the specified host could be resolved, 0 if not and -1 on error.
2.14.5 nb_arp_gratuitous
   The nb_arp_gratuitous function will send an gratuitous ARP advert for the address
of the specified interface (or the host address provided). This can be used to update the
ARP tables of your neighbors.
                                           19
    interface            the interface on which the packet should be send
    host                 the host address to advert
2.14.6 nb_etherwake
  The nb_etherwake function will send a WakeOnLan magic packet to wake up sleeping
hosts.
2.15.1 nb_syslog
  The nb_syslog function creates a message in the system log. Please refer to sprintf
for more information about the format string fmt and additional arguments.
Returns -1 on error.
2.15.2 nb_event_get
Returns received event as string or NULL when the specified timeout has been reached.
2.15.3 nb_reboot
                                          20
  void nb_reboot ( int delay )
21