Oxygen User en HDI34201 3.6.2ote
Oxygen User en HDI34201 3.6.2ote
Oxygen User en HDI34201 3.6.2ote
Gateway
VDSL2/ADSL2+ Multiservice Access Device
User’s Guide
v3.6.2ote
November 2018
Product and Publication Details
This guide is designed to assist users in using the Oxygen Multiservice Gateway. Information in this
document has been carefully checked for accuracy; however, Oxygen Broadband s.a. assumes no
responsibility or liability for any errors or inaccuracies that may appear in this document. Information
as well as drawings and specifications contained in this document are subject to change without prior
notice.
Further to the above, some pages, icons, messages, and colors of the information shown in your device
may be different from the information presented in this manual due to customization decided by your
ISP. The same applies to the device default settings, default passwords and the existence or absence
of certain menus, sub-menus or options, which again have been decided in accordance with your
ISP policies. This manual should be used in conjunction with the Quick Installation Guide supplied as a
printed leaflet in the packaging of your device. In the Quick Installation Guide there may be specific
information regarding unique functionalities of the offered services by your ISP (e.g. a service activation
procedure).
Should you have any inquiries, please feel free to contact [email protected]. For latest
product info and features, visit our website at http://www.oxygenbroadband.com .
Declaration of Conformity
Hereby, Oxygen Broadband s.a. declares that this Oxygen Multiservice Gateway device is in compliance
with the essential requirements and other relevant provisions of Directive 1999/5/EC.
Safety Rules
The most careful attention has been devoted to quality standards in the manufacture of the Oxygen
Multiservice Gateway. Safety is a major factor in the design of every set. But, safety is your responsibility
too. For your safety, be sure to read and follow all the safety rules:
• Do not use the product in high-humidity areas or close to water, for example in a WC or in a wet
basement.
• Do not use chemicals, cleaning products or aerosols to clean the device and its accessories.
• Do not place objects on top of the device or cover the device’s ventilation openings. Inadequate
air flow may cause damage to the device.
• Do not touch the power adapter or the device with wet hands or allow liquids to spill on it.
• Do not open the device or power supply unit. If you open or remove the covers you may be
exposed into dangerous high voltage or other risks. ONLY authorized personel with the suitable
knowledge may service or disassemble the device. Contact your supplier for more information.
• Use ONLY the provided power supply or power cable for your device.
• Connect the power supply or cable in the proper mains power supply (e.g. 110V AC in North
America or 230V AC in Europe)
• Do not allow anything to contact on top of the power supply or cable and Do not place the
product at a point where someone may step on it or trip over.
• Do not use the device if the power supply or cable has been damaged. Danger of electrocution
is possible.
• If the power supply or cable has been damaged, remove it carefully from mains supply.
• Do not try to repair the power supply or cable. Contact your supplier and order a new one.
• Do not install, use or perform maintenance during a storm. There is a very small possibility of
electrocution by thunder.
• Do not use the device outdoors. Make sure all connections have been implemented indoors.
There is a very small risk of electrocution by thunder.
• If device is placed on wall, be careful not to cause damage in power transmission, gas or water
lines.
• Keep the device away from household appliances or other electronic devices with strong
electromagnetic fields (e.g. microwave oven, refrigerator or DECT phone).
• Make sure you have connected all cables to the correct sockets.
• Do not power-off or disconnect your device while it is being automatically configured or a firmware
update is in progress.
• Make sure to connect the cables to the correct ports, that the connector matches the port and
that you have positioned the connector correctly in relation to the port. Do NOT force a connector
into a port. If the connector and port don’t join with reasonable ease, they probably don’t match.
• When removing the connector from the port remove it by pulling on the connector, not the cable.
Some types of connectors have a release clip that releases the connection. Failure to release this
clip or abruptly pulling on the cord could cause damage to the connector or the device.
Copyright Declarations
All copyright, intellectual and industrial rights in this document and in the technical knowledge it contains
are owned by Oxygen Broadband s.a. and/or their respective owners. Any rights not expressly granted
herein are reserved.
This product includes copyrighted third-party software licensed under the terms of the GNU General Pub-
lic License (GPL) or the GNU Lesser General Public License (LGPL). Please see the GNU GPL and LGPL for
the exact terms and conditions of these licenses. Source code is available upon request (at cost) and may
also be available at the Oxygen Broadband’s website: http://www.oxygenbroadband.com/downloads/gpl/
for at least three years from the purchase date of this product. Note that we do not offer ANY support
for the distribution and the source code is distributed WITHOUT ANY WARRANTY and is subject to the
copyrights of one or more authors.
This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (
http://www.openssl.org/ )
Artwork was made by or based on artwork by Bosky Cinek ( http://boskastrona.ovh.org ) and Tango
Desktop Project ( http://tango.freedesktop.org ) and placed under the Creative Commons attribution
share-alike License.
Trademarks
All product and corporate names appearing in this document may or not be registered trademarks or
copyrights of their respective companies, and are used only for identification or explanation and to the
owners’ benefit, without intent to infringe.
1 Introduction 21
Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Device Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Using this Document . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Notational Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Typographical Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Special Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Getting Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
8
Oxygen Multiservice Gateway User’s Guide
6 Internet Menu 73
Quick Start . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
ATM PVCs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77
Connections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
802.1q VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
Modem Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
PPP Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
IP Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
IPv4 Address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
IPv6 Address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
IPv6 over IPv4 Tunnel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
IPv4 over IPv6 Tunnel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
L2TP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
DSL Line . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
3G/4G Modem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
Modem Info . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92
Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94
7 Network Menu 97
Interface Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101
Ethernet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
IPv6 Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
DHCP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
Static DHCP Leases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
14 Troubleshooting 217
I Glossary 259
Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 259
15
Oxygen Multiservice Gateway User’s Guide
This User’s Guide will show you how to connect your Oxygen Multiservice Gateway, and how to
customize its configuration to get the most out of your new product.
21
Oxygen Multiservice Gateway User’s Guide
Features
The list below contains the main features of the Oxygen Multiservice Gateway and may be useful to users
with knowledge of networking protocols. If you are not an experienced user, the chapters throughout
this guide will provide you with enough information to get the most out of your device. The features
include:
• Fully flexible LAN access with the option of 4 10/100/1000Base-T ports to provide Internet connec-
tivity to all computers on your LAN.
• 802.11 WiFi router to provide Internet connectivity to all wireless devices on your LAN (WiFi-enabled
devices only).
• Voice over IP (VoIP) functionality with analog and/or ISDN BRI voice interfaces (number and type
of ports depend on model).
• USB host interface for connecting external storage devices (USB sticks, hard disks), USB printers and
USB 3G/4G dongles (optional feature).
• Network Address Translation (NAT) and Firewall functions to provide security for your LAN.
Device Requirements
In order to use the Oxygen Multiservice Gateway, you must have the following:
• Instructions from your Internet Service Provider (ISP) on what type of Internet access you will be
using, and the parameters needed to set up access.
• One or more computers, each containing a wired (Ethernet) or wireless (WiFi) Ethernet card
(WiFi-enabled devices only).
• For system configuration using the embedded web-based configuration tool: Microsoft Internet
Explorer version 5.5 or newer, Mozilla Firefox 1.5 or newer, Google Chrome, Apple Safari version
1.2 or newer.
It is essential that JavaScript is enabled on your Web browser in order to be able to use
the embedded Web Configuration tool of the Oxygen Multiservice Gateway.
WARNING
Notational Conventions
• Acronyms are defined the first time they appear in the text and also in the glossary (Appendix I
on page 259).
• For brevity, the Oxygen Multiservice Gateway is frequently referred to as "Oxygen" or "CPE" or "the
device".
• The term LAN (Local Area Network) refers to a group of Ethernet-connected computers at one
site.
Typographical Conventions
• Italic text is used for items you select from menus and drop-down lists and the names of sections
in this guide.
• Bold text is used for names and parameters of the displayed web pages, and to emphasize
important points.
Special Messages
This document uses the following icons to draw your attention to specific instructions or explanations.
Getting Support
Please visit the web site of Oxygen Broadband ( http://www.oxygenbroadband.com ) in order to get
the most up-to-date information and support for your Oxygen Multiservice Gateway.
Your Oxygen Multiservice Gateway package should arrive containing the following:
If for any reason you do not have any of the items listed above, please contact your
Service Provider as soon as possible.
WARNING
27
Oxygen Multiservice Gateway User’s Guide
Front Panel
The front panel contains a series of lights, called Light Emitting Diodes (LEDs), that indicate the status of
the unit.
Examining the front panel from top to bottom, we can find the LEDs listed in table 2.2.
Light Red
Light Red: During boot sequence.
DSL White On: Showtime (successfully connected to
(optional feature)
(optional feature)
Rear Panel
The rear panel contains the ports for the device’s data, telephony and power connections, the main
On/Off switch and a Restore Defaults pin button.
Examining the rear panel from left to right, we can find the ports listed in table 2.3.
Label Function
PHONE 1-2 Analog ports for connecting the Telephone devices.
(voice-enabled devices only)
WARNING: If you are going to use only one
analog phone, connect it to port 1.
Ext Sync ISDN synchronization port.
Used for connecting and synchronizing with another CPE NT
or an ISDN NTU terminal.
(Please refer to Appendix H on page 255 for details)
Sync Term. Sync port termination switch.
Used for 100-ohm termination of the Sync port S-bus.
BRI ISDN BRI interface.
Used for connecting to your private ISDN PBX, ISDN terminal
or to ISDN NT. This port is configurable and operates
either in Network (NT) or in Terminal (TE) mode. When operating
in NT mode, a straight ISDN cable is used, whereas when set
to operate in TE mode, an ISDN crossover cable is required.
Please refer to Appendix G on page 251 for details about the
pinout of both cables.
BRI Term. BRI port termination switch.
Used for 100-ohm termination of the BRI interface S-bus.
I/O The main switch of the device. Please make sure it is
in the "Off" position before starting the installation
procedure.
DC 12 V This is where you will connect the power adapter.
Please use only the power adapter supplied with
your device.
WARNING: Using a power adapter with a
Side Panel
The right side of Oxygen Multiservice Gateway also contains the WiFi On/Off and WPS activation button
(WiFi-enabled devices only).
Finally it contains a USB host interface for connecting external storage devices (USB sticks, hard disks),
USB printers and USB 3G/4G dongles (optional feature)
In addition to configuring the device, you also need to configure the Internet properties of your
computer(s). For more details, see sections:
This section describes how to connect the device to the power outlet and your personal computer(s) or
network.
Before you begin, turn the power off for all devices. These include your personal
computer(s) and the Oxygen Multiservice Gateway.
WARNING
33
Oxygen Multiservice Gateway User’s Guide
The diagram below illustrates the hardware connections. The layout of the ports on your device may
vary slightly from the layout shown. Refer to the steps that follow for specific instructions.
Connect one end of the provided black phone cable to the port labeled DSL on the rear panel of the
device. Connect the other end to your wall phone port providing the DSL service.
Connect your PC to one of the Ethernet ports of the device via the supplied yellow Ethernet cable.
If you plan to use a Wireless connection between your PC and the Oxygen Multiservice
Gateway (optional feature), please skip this step and move directly to the next one.
Note
All Ethernet ports are Auto-MDIX. Therefore, you can use straight Ethernet cables to
connect to either PCs or switches with no need for a crossover Ethernet cable.
Note
Connect your ISDN PBX to the port(s) labeled BRI. Make sure you use the correct cable and you
terminate the ISDN line appropriately, using the switches below the ISDN port.
Connect your analog telephone-set, DECT base-station, or fax machine to the port(s) labeled PHONE.
You will not be able to make or receive telephone calls until your Voice-over-IP (VoIP)
service has properly been configured. Please refer to Chapter Voice Menu on page 143
WARNING for more information.
Connect the provided AC power adapter to the Power connector on the back of the device and plug
the adapter into a wall outlet or power strip. Turn on the Oxygen Multiservice Gateway.
During the boot-sequence of the Oxygen Multiservice Gateway, the Power LED is Light
Red (either solid or blinking). The device is ready for operation when the LED is solid
Note White.
You may now have to configure the Internet properties on your Ethernet PC. See Configuring Ethernet
PCs on page 225, if using a wired Ethernet connection, or Configuring Wireless PCs on page 226, if
planning to use a wireless one (WiFi-enabled devices only).
Next Step
After setting up the Oxygen Multiservice Gateway and configuring your PC, you can log on to the
device by following the instructions in Getting Started with the Web Pages on page 37. Using the Web
Configuration tool you will be able to setup all the functionality related to your Internet service.
This guide includes also a chapter called Troubleshooting (page 217), which enables you to find
solutions to common problems that hinder your device from working properly.
Some pages, icons, messages, and colors of the information shown in your device may
be different from the information presented in this manual, due to the capabilities of the
exact model you are using and due to customization decided by your ISP. The same
applies to the device default settings, default passwords and the existence or absence
Note of certain menus, sub-menus or options, which again have been decided in accordance
with your ISP policies.
37
Oxygen Multiservice Gateway User’s Guide
1. A laptop or PC connected to the LAN port on the device or through WiFi (WiFi-enabled devices
only).
2. A JavaScript enabled web browser installed on the PC. The minimum browser version requirement
is Microsoft Internet Explorer version 5.5 or newer, Mozilla Firefox 1.5 or newer, Google Chrome,
Apple Safari version 1.2 or newer.
3. Launch your web browser, type http://oxygen.lan or http://192.168.1.1 in the web address (or
location) box, and press [Enter] on your keyboard.
4. An access control window appears. Enter the appropriate username and password.
The default username and password combination can be found printed on the main label on the
bottom of your device.
5. After succesful login, the Home page opens, displaying the system view page with an overview of
the device.
At the top of the page you can see the main top configuration menu, which displays the company’s
logo and all the configuration menu categories. This top configuration menu is constantly visible during
the use of the web configuration tool. It comprises the categories described in the following sections,
with each menu category (except Home) providing different configuration options.
Clicking on the desired menu category icon, leads to a screen with a list of available submenu
entries and a brief description about the functionality of each sub-menu entry.
Selection of a sub-menu entry can be performed by clicking on its title (bold letters) or using the
navigation menu on the left side of the screen (see figure 4.4). The latter is always visible, in order to
assist further navigation through the different configuration options.
Logout
At the bottom of the page see a field containing Oxygen Broadband’s Copyright notice, the firmware
version and the current administration mode (i.e. the username used for login). At any moment you can
logout from the web configuration tool of the Oxygen Multiservice Gateway by pressing on the icon .
Languages
The Oxygen Multiservice Gateway optionally offers localized versions of the web configuration tool. In
this case, the flags of the available languages are displayed in the field at the bottom of the page. At
any moment, you can switch language by clicking on the corresponding flag.
This is by default the page displayed after successful login to the web configuration tool of your device.
It provides an overview of the system and is divided into three main sections:
System Section (right-pane) - displays information about the Wireless (WiFi-enabled devices only),
Voice (voice-enabled devices only), USB Host (optional feature) and other functionality of the device.
The Internet menu allows the configuration and management of the broadband access connections.
• Quick Start for quick configuration of device operation and Internet access (see page 75 ).
• ATM PVCs for modifying existing or adding new ATM virtual circuits (see page 77 ).
• Connections for modifying existing or adding new Internet connections (see page 80 ).
• DSL Line for configuring the DSL line settings (see page 87 ).
• 3G/4G Modem for managing the embedded (optional feature) or connected external (USB)
3G/4G modem (see page 90 ).
• Redundancy for managing the WAN connection backup operation (see page 94 ).
The Network menu provides configuration options for the LAN with the locally connected PCs and other
IP-enabled devices.
• Interface Groups for spliting the local network interfaces into different "Service Groups" (private
VLANs) (see page 99 ).
• VLAN for configuring private and/or 802.1q VLAN operation (see page 101 ).
• Ethernet for modifying the LAN Ethernet interfaces (see page 102 ).
• Addresses for specifying the IP address of each Service Group interface (see page 104 ).
• DHCP for configuring the DHCP server for each Service Group interface (see page 106 ).
• DNS Settings for modifying the local DNS server settings (see page 110 ).
• Static Routes for viewing and configuring static IP routing rules (see page 113 ).
• Dynamic Routing for configuring dynamic IP routing protocols (see page 115 ).
• Wake On LAN for remotely turning on computers on the LAN (see page 116 ).
• Public IPs for configuring on the LAN, IP addresses directly accessible from the Internet (see page
117 ).
The Wireless menu provides configuration options for the Wireless functionality of the Oxygen Multiservice
Gateway (WiFi-enabled devices only).
• Radio for configuration of the wireless LAN radio operation (see page 121 ).
• Configuration for setting up the wireless LAN operation and security parameters (see page 123 ).
• MAC Filtering for enabling wireless access control based on the MAC address of the WiFi client
devices (see page 127 ).
The Firewall menu provides configuration options for the protection of the LAN through the embedded
firewall of the Oxygen Multiservice Gateway.
• Port Forward for allowing selected incoming connections from the Internet towards the LAN, in
order to enable some applications to work behind the firewall (see page 131 ).
• UPnP / NAT-PMP for activation/deactivation of automatic firewall port forwarding using the UPnP
and/or NAT-PMP protocols (see page 133 ).
• IP Filters for precise control of allowed or denied IP connections between the LAN and the Internet
(see page 134 ).
• Web Filters for denying access to web sites based on a configured list of keywords (see page 137
).
• DMZ Filters for configuring a subnet on the internal network that has its hosts selectively exposed
to access from the Internet (see page 139 ).
• Address Mapping for configuring the use of different public (WAN) IPs from different LAN hosts
using Network Address Translation (NAT) (see page 141 ).
The Voice menu lets you configure the parameters necessary for the provision of the voice service over
your broadband connection.
• Phone Lines for configuring the external phone lines (see page 145 ).
• Services for setting-up the telephony supplementary services (see page 148 ).
• Analog Interfaces for configuring the analog voice interfaces (see page 149 ).
The Advanced configuration menu lets you control a series of different advanced services offered by
the Oxygen Multiservice Gateway.
• Dynamic DNS for configuring the Dynamic DNS application (see page 153 ).
• Date and Time for changing date and time protocol settings (see page 154 ).
• SSL VPN for setting-up a secure SSL-based VPN connection using OpenVPN (see page 155 ).
• GRE Tunnel for setting-up a Generic Routing Encapsulation (GRE) tunnel (see page 159 ).
• L2TP Tunnel for setting-up an L2TP and/or IPSec-based VPN tunnel (see page 160 ).
• IPSec Tunnel for setting-up an IPSec VPN tunnel (see page 163 ).
• QoS Policy for defining and configuring Quality of Service classes (see page 165 ).
• File Sharing for activation/deactivation of file sharing through connected USB storage devices
(see page 170 ).
The System menu provides system administration utilities such as firmware upgrade, configuration backup
& restore, and Syslog service configuration.
• SNMP for configuration of the Simple Network Management Protocol (see page 175 ).
• Syslog for controling the system logging service (see page 177 ).
• Remote Admin for allowing remote access to the device for administration and/or support
purposes (see page 178 ).
• Time-plan for managing system Time-of-Day profiles and events (see page 180 ).
• Change Password for modifying the device administration password (see page 182 ).
• Backup / Restore for backing-up the current or restoring a previous configuration of the device
(see page 184 ).
• Device Restart for restarting the device and optionally erasing the entire configuration (factory
defaults) (see page 186 ).
• Firmware Upgrade for performing a local or remote firmware upgrade (see page 187 ).
The Status menu lets you view device messages, the runtime values of device parameters and statistics
about local interfaces and Internet connections.
• About for displaying general information about the device (see page 192 ).
• System Log for viewing system log entries (see page 193 ).
• Interfaces for displaying information for the Ethernet and (optional) USB interfaces (see page 195
).
• DSL Line for displaying status and statistics for the DSL broadband connection (see page 197 ).
• Wireless for a list of the connected WiFi clients and access points (AP) in range (WiFi-enabled
devices only) (see page 199 ).
• Phone Lines for viewing information about the active voice calls and the status of supplementary
services (see page 200 ).
• Call Details for viewing duration and history information for voice calls (see page 203 ).
• ISDN Interfaces for viewing information about the ISDN interfaces (see page 205 ).
• Firewall for displaying the current firewall status (see page 206 ).
• VPN Service for displaying VPN service information (see page 209 ).
• Diagnostics for performing broadband connection and IP diagnostic tests (see page 210 ).
• Healthcheck for quickly checking the service operation status of the device (see page 212 ).
• Net Statistics for information about the LAN- and WAN-side network traffic (see page 214 ).
• IP Network for a list of addresses of IP interfaces, IP routes, DNS servers and active IP connections
(see page 216 ).
The following buttons and icons are used throughout the web pages:
Button Function
Radio buttons - these appear in many configuration pages. You will be asked to select one
radio button from the list of two or more available options. You cannot select more than one
radio button at a time.
This button appears in pages showing lists of configuration items (e.g. Internet connections,
Firewall rules). Click on this button to Edit the corresponding entry.
This button appears in pages showing lists of configuration items (e.g. Internet connections,
Firewall rules). Click on this button to Delete the corresponding entry.
This icon corresponds to the telephony Voice service (if provided by your ISP).
This icon corresponds to the Video service (if provided by your ISP).
This button appears in pages showing lists of configuration items (e.g. Internet connections,
Firewall rules). Click on this button to Add a new entry.
This button appears in pages related to adding or editing a member of a configuration list
(e.g. Internet connection, Firewall rule). Click on this button to Save the entry.
This button appears in most configuration pages. Click on this button to store and Apply the
values of the different parameters appearing in the web page.
This button appears in pages where a file must be uploaded (e.g. Firmware Upgrade). Click
on this button to Browse through your PC and find the desired file.
The following terms are used throughout this guide in association with these buttons:
Click - point the mouse arrow over the button, menu entry or link on the page and click the left
mouse button. This performs an action, such as displaying a new page or performing the action specific
to the button on which the left mouse button is clicked.
Select - usually used when describing which radio button to select from a group of radio buttons, or
which entry to select from a drop-down list. Point the mouse arrow over the entry and left-click to select
it. This does not perform an action - you will also be required to click on a button, menu entry or link in
Upon delivery, the Oxygen Multiservice Gateway is preconfigured with default settings for use in a typical
home or small office network.
The table below lists some of the most important default settings; these and other features are
described fully in the subsequent chapters. If you are familiar with network configuration, review these
settings to verify that they meet the needs of your network. Follow the instructions to change them if
necessary. If you are unfamiliar with these settings, try using the device without modification, or contact
your ISP for assistance.
We strongly recommend that you contact your ISP prior to changing the default
configuration.
WARNING
67
Oxygen Multiservice Gateway User’s Guide
On the upper side of the section. Broadband line synchronization status of the device is displayed
according to the following color-codes:
Icon Status
Orange Training
Green Synchronized
If synchronization has succeeded, the achieved Downstream and Upstream data rates are also
displayed.
Below the broadband line status info, on the same pane, there is also information about the WAN
Connections. All configured WAN connections are listed with an indication of their current status (red
icon: disconnected, green IP: connected, other: status/error messages).
This section displays information about the Local Area Network and the connected IP devices. On the
upper side of the section, there is information about the link status of the Ethernet ports of the Oxygen
Multiservice Gateway. Below the link information, the user can see the private IP addresses assigned
to each of the active Service Interface Groups (private VLANs - one for each service of a multi-service
broadband connection). The icons , , and correspond to the Data, Voice and Video services
respectively. Finally, in the bottom part of the section, a list of the local connected hosts is displayed.
This section displays information about the Wireless LAN (WiFi-enabled devices only), the Voice service
(voice-enabled devices only) and the devices connected to the USB Host port (optional feature). The
information presented includes the Status, SSID (Network Name) and Security Mode for the Wireless LAN,
the Numbers of the active VoIP connections along with their registration status and finally the status of
the USB services.
• Quick Start for quick configuration of device operation and Internet access (see page 75 ).
• ATM PVCs for modifying existing or adding new ATM virtual circuits (see page 77 ).
• Connections for modifying existing or adding new Internet connections (see page 80 ).
• DSL Line for configuring the DSL line settings (see page 87 ).
• 3G/4G Modem for managing the embedded (optional feature) or connected external (USB)
3G/4G modem (see page 90 ).
• Redundancy for managing the WAN connection backup operation (see page 94 ).
73
Oxygen Multiservice Gateway User’s Guide
Quick Start
The Quick Start page is the fast and easy way to configure your device for Internet access and any
other service provided by your ISP over the broadband connection.
The first thing shown when the Quick Start configuration option is selected, is a list of the available
service options.
For configuring the basic parameters related to Internet Access, click on the correponding entry in
the list. The following page appers:
This page contains basic information required in order to configure the broadband Internet access
operation of Oxygen Multiservice Gateway. Please refer to the following sections of chapter Internet
Menu for a detailed description of the parameters.
By clicking the Apply button, the information entered is stored and the connection is dialed.
ATM PVCs
Asynchronous Transfer Mode (ATM) is the underlying technology used for providing IP connectivity over
the ADSL broadband connection. Permanent Virtual Circuits (PVC) over the ATM network serve as
point-to-point links from the DSL access device (the Oxygen Multiservice Gateway) to the core network
of the ISP. WAN ADSL connections are always associated with an ATM PVC. Note that, in certain cases,
multiple WAN connections may share the same ATM PVC.
ATM PVCs are only relevant for your VDSL Oxygen Multiservice Gateway, only when the
device operates in ADSL fallback mode. VDSL operation does not rely on ATM virtual
WARNING circuits, but on the direct transport of Ethernet frames.
Following the ATM PVCs configuration option, a list of the configured PVCs is displayed.
You can Edit and Delete configured PVCs by clicking on the icons and respectively of Action
column.
In order to add a new ATM PVC, press Add New. The following page will appear:
These are the basic parameters used to describe the ATM PVC over the ADSL connection:
1. VPI and VCI are the characteristic numbers defining the PVC. Valid VPI and VCI numbers are
between 0 and 255 and between 0 and 65535 respectively.
2. Protocol defines the type of connection this PVC is going to be used with. Available options
are RFC 1483/2684 bridged (for PPPoE and EoA connections), RFC 1483/2684 routed (for IPoA
connections) and RFC 2364 (for PPPoA connections).
3. Encapsulation is the type of service encapsulation used over the ATM connection. Available
options are LLC (Logical Link Control) and VCMux (VC Multiplexing).
4. Traffic Class, PCR and SCR are the ATM QoS traffic class of the connection, the Peak Cell Rate and
the Sustainable Cell Rate value respectively. Available Traffic Class options are CBR (Constant Bit
Rate), VBR-rt (Variable Bit Rate - real time), VBR-nrt (Variable Bit Rate - non real time) and UBR
(Unspecified Bit Rate).
Please consult your Service Provider about the values that must be used for all the
parameters listed above. If the PVCs configured on your Oxygen Multiservice Gateway
do not have the same type and VPI/VCI values with the ones used by your Service
WARNING Provider, no data communication will be possible.
Connections
Using the Connections configuration option it is possible to configure the WAN connections of the
Oxygen Multiservice Gateway.
Entering the sub-menu, the first thing displayed is a list of all configured WAN connections with their
current status.
You can Edit and Delete configured connections by clicking on the icons and respectively of
Action column. You can also Dial or Disconnect any connection by clicking on the icons and
respectively of the same column.
In order to add a new WAN connection, click Add New and the following page will appear. The
parameters of this page are explained in detail in the following sub-sections.
Connection
1. Name is a name used in order to distinguish between the different connections. Note that
names must be unique among different connections and that, once configured, they cannot be
modified. It should also be noted that connection names cannot contain spaces and selected
special characters.
2. Status is the status of connection. Available options are Enabled and Disabled.
3. Service is the type of service this connection will support. Available options are Data, Voice and
Video (when offered by your ISP).
4. WAN port is the type of port this connection will use. Available options are VDSL, ADSL, Ethernet
(optional feature), L2TP (optional feature) and Modem (optional feature).
5. Type is the protocol used for connecting to your broadband Service Provider. The available
options depend on the selection of the WAN port parameter. Please consult your Service Provider
about the option that must be selected.
The parameters appearing on the rest of the configuration page, depend mainly on the values of
the WAN port and Type parameters.
802.1q VLAN
In case of Ethernet-over-DSL (e.g. PPPoE) or other Ethernet-type connection, the Ethernet frames can
optionally by tagged with a 802.1q VLAN ID. This way, multiple connections can share the same ATM
PVC, VDSL or Ethernet WAN port, separated at the Ethernet level using normal Ethernet VLANs. In
order to activate this functionality for the connection, select the Enabled checkbox and specify the
corresponding VLAN ID. Valid VLAN ID values are 1 to 4094.
Modem Options
This provides the parameters required in the case of broadband access through an embedded 3G/4G
modem or a dongle connected to the USB port of the Oxygen Multiservice Gateway (optional features).
1. Device is the modem used for this connection, or ANY MODEM in order to use the active
first modem detected. Refer to section 3G/4G Modem on page 90 for a description of the
configurations steps required in order to define and activate a 3G/4G modem.
2. Profile is the set of parameters used in case of a 3G/4G modem. Pre-defined sets of parameters
can be selected, whereas CUSTOM allows the user to manually enter the following modem-related
parameters:
• APN is the Access Point Name used to determine how the 3G/4G modem of the Oxygen
Multiservice Gateway communicates via the GSM network to the Service Provider’s network.
• Dial string is the modem dial string.
Please refer to your 3G/4G Service Provider in order to find the correct APN and Dial
string values, in case you do not use one of the pre-defined profiles.
WARNING
PPP Options
These are the PPP authentication parameters required in the case of a PPP connection (e.g. PPPoE):
1. Username is the username used for the PPP negotiation with your Service Provider. Please consult
your Service Provider about the correct value.
2. Password is the password used for the PPP negotiation with your Service Provider. Please consult
your Service Provider about the correct value.
3. Dial On Demand enables or disables the "on-demand" functionality of the PPP session, to be
automatically activated when there is need for data traffic and deactivated when the connection
is idle for a defined interval (configured in seconds).
4. PPPoE passthrough enables or disables the transparent forwarding of PPPoE sessions initiated
from a LAN host (e.g. a PC) towards the WAN in case of Ethernet-over-DSL (e.g. PPPoE) or
other Ethernet-type connections. Proxy value performs a local termination of LAN PPPoE sessions
(optional feature).
IP Options
In case IPv6 functionality is globaly enabled on the Oxygen Multiservice Gateway (please refer to section
IPv6 Addresses on page 104), the Operation drop-down list controls the IPv4 and IPv6 type of operation
of the WAN connection. Available options are:
Under the IP Options heading, it is also possible to set the MTU size (Maximum Transmission Unit) in
bytes of the IP connection interface.
Do not modify the default MTU value, unless instructed so by your Service Provider. Invalid
MTU values can lead to loss of connectivity or degradation of service.
WARNING
IPv4 Address
This category provides the IPv4 address configuration required in the case of non-PPP routed connections.
Available choices are: automatic configuration through DHCP client, and Static IP address configuration.
In the latter case:
3. Gateway is the default gateway, used only if the Default route option described below is either
Yes or Fallback.
IPv6 Address
In case IPv6 functionality for the connection is enabled using the Operation drop-down list described
above, the Method drop-down list controls the mechanism followed for acquiring IPv6 addressing
information. Available options are:
1. Stateless DHCPv6, where the WAN connection uses Router Advertisements (R.A.) for its IPv6
address and DHCPv6 for additional IPv6 patameters (e.g. Prefix Delegation),
2. Stateful DHCPv6, where all IPv6 addressing information is obtained through DHCPv6,
3. SLAAC, which allows for WAN interface to be autoconfigured for an IPv6 prefix through Router
Advertisements (R.A.),
4. Link local only, where the WAN interface obtains only a link-local IPv6 address
This method is a way to support IPv6 operation in the LAN if the ISP broadband network supports only
IPv4 operation. There exist various IPv6 tunneling mechanisms supported by the Oxygen Multiservice
Gateway. In order to configure a tunneling mechanism you need to select the desired tunneling Method
from the provided drop-down list and fill-in the necessary tunnel-specific parameters:
• Tunnelbroker.net: You must first fill in the Tunnel ID, then the remote server’s IPv4 address into
Server IPv4, the Local IPv6 address into the Local IPv6, the /64 IPv6 subnet used for LAN hosts
into IPv6 subnet field, and finally the credentials for the connection in the fields Username and
Password respectively.
• Sixxs.net: Configuration of Sixxs tunnel is done following the same steps as in Tunnelbroker tunneling
mechanism described above.
• 6to4: This method relies on autoconfiguration mechanisms and requires optionally setting only the
link MTU size value.
This category controls the IPv4 over IPv6 tunneling operation, when this option has been selected in the
Operation drop-down list. In order to configure a tunneling mechanism you need to select the desired
tunneling Method from the provided drop-down list and fill-in the necessary tunnel-specific parameters:
• Select the desired tunneling Method i.e. choose LW4o6, DS-lite or MAP-T
• Select Auto or Fixed in the Remote server drop-down list for automatic or manual configuration
of the relevant tunnel operation parameters. In case of manual configuration, fill-in the necessary
tunnel-specific parameters in order to configure the selected tunnel.
L2TP Server
In case of L2TP tunneling connection, the LNS Server parameter contains the IP address of the L2TP
Network Server (LNS).
Routing
The Default route parameter defines if the connection will provide the default route for Internet
connectivity. Available options are Yes, for a connection offering default route, Fallback, for a
connection acting as a backup in case of failure of the default-route connection, and No, for any plain
connection.
Only one connection is allowed to provide default route. Usually, this connection will be
the one providing Internet Data service.
Note
DSL Line
In this configuration sub-menu, it is possible to modify the different parameters controlling the functionality
of the DSL modem embedded into the Oxygen Multiservice Gateway.
• Operation: type of the line syncronization operation. Select between PSTN and ISDN according
to the type of the connected line.
• ADSL: the ADSL line type / operation mode. Off disables ADSL fallback is case of VDSL models.
• Bitswap: swap bits around different frequency channels, in order to adapt to changes of the line
conditions without retraining.
• SRA: Seamless Rate Adaptation of the DSL data rate as a response to changes of the line
conditions in order to avoid dropping a connection.
• Annex M: a variation of the ADSL technology offering increased upload speed (if supported by
your model of the Oxygen Multiservice Gateway and by the ISP’s DSLAM - PSTN connections only).
• Databoost: a special, proprietary, mode of operation offering higher speeds of connection (if
supported by the ISP’s DSLAM).
• EC/FDM Mode: choice between Echo-Cancellation (EC) or Frequency Division Multiplexing (FDM)
mode of operation.
• Coding Gain: the increase in efficiency that the coded signal provides over an uncoded one.
• VDSL profile: the maximum negotiated VDSL profile. Off disables VDSL mode of operation (only
ADSL fallback).
• G.Vector: VDSL2 vectoring operation (if supported by your model of the Oxygen Multiservice
Gateway and by the ISP’s DSLAM).
Do not modify the default DSL configuration values, unless instructed so by your Service
Provider. Invalid values can lead to loss of connectivity or degradation of service.
WARNING
3G/4G Modem
The Oxygen Multiservice Gateway can provide broadband access not only through a fixed line but
also through the mobile network. This is supported either via an embedded 3G/4G modem or through
an external 3G/4G dongle connected to an external USB Host port (optional features). In either case,
control of the corresponding parameters is performed using the 3G/4G Modem sub-menu.
The first thing shown when entering this page is if a 3G/4G modem is available, and if yes information
about its current status. When no modem has been detected, a page like the following appears:
In order to perform a scan for the presence of a connected 3G/4G modem, press New Scan. A
new scan for connected 3G/4G modems is performed and any connected devices are automatically
added to the list of known modems.
When a modem has been detected, a table at the top of the page displays basic information about
it. The most important entry in this table is the Status row, which diplays info about the modem’s current
status. Possible values are:
• PIN needed, the modem SIM is locked and requires a PIN to unlock and get ready for operation,
• Locked, the modem SIM is locked due to multiple wrong PIN inputs and requires the PUK code to
unlock,
Depending on the status of the modem, different Actions can be performed using the corresponding
drop-down list:
2. Disable PIN or Activate PIN, in order to disable or re-enable PIN control on the SIM,
5. Unlock, (visible when the modem is in Locked status) in order to unlock the modem SIM using the
correct PUK code.
When configuring the modem, the most usual task is to set the PIN of the SIM inserted into the modem.
It is also possible to set the following advanced parameters (usually not required to be modified):
1. Radio Status, which enables or disables the operation of the radio transmitter/receiver of the
modem.
2. Mode, which is the preferred mobile data communication standard. There are multiple options
available depending on the modem, the region and provider configurations. Common options
include Auto (default and recommended), LTE / 3G, LTE only, 3G only, 3G preferred, 2G only, 2G
preferred etc.
The last option available in this page, is the control over the activation of WAN Connections using
the 3G/4G modem. Using the Activation drop-down list it is possible to select between Auto or Manual.
With Auto, connectivity to the WAN is activated automatically based only on the Redundancy settings
(please refer to page 94). If, on the other hand, the Manual option is selected, the connection to the
WAN must be manually initiated pressing the Dial button.
The Manual configuration option under the WAN Connections parameter is strongly
advised for users with a fixed volume mobile data plan, in order to avoid unexpected
WARNING charges from their Mobile Service Provider.
Modem Info
By clicking on the More Info button (when availabe) in the top modem-status table, a page like the
following appears:
This page displays detailed information about the modem and its status, including the modem model
details, the IMEI of the device, the current status, SIM information, signal strength, connection and usage
details.
Redundancy
The Redundancy page controls the failover operation between configured WAN connections. This way,
it is possible to have multiple connections defined for the same Service using different broadband access
methods (e.g. DSL and 3G/4G) as primary and backup methods for service provision.
This Redundancy functionality can be divided into two different categories: operation of default-
route and operation of non default-route WAN connections (please refer to the Default route parameter
of section Connections on page 80). The former, which are usually used for supporting the Data Service,
are handled under the Default Route heading. The Oxygen Multiservice Gateway supports two different
methods for the redundancy operation of WAN connections offering default-route connectivity:
• Single Primary / Fallback: this is the simple operation mode. One connection is defined as Primary
(with Default route setting equal to Yes) and another as Fallback (with Default route setting equal
to Fallback). Whenever the Primary connection is down, the Fallback connection is automatically
activated.
• Based on access type: this is the more flexible operation mode. Any connection with Default route
setting equal to Yes or Fallback is treated as a Primary connection. Selection between the list
of different connections is performed based on the type of WAN access they are using and the
corresponding priorities set under the Access priority table.
On the other hand, redundancy operation for non default-route WAN connections is handled under
the Other Connections heading. Also in this case, different methods are offered:
• Per default route: this is the simple operation mode. Non default-route connections are activated
or deactivated based on the default-route connection which uses the same broadband access
type.
• Variable: this is the more flexible operation mode. Using the appropriate drop-down lists, multiple
Primary vs. Fallback relationships can be defined for couples of connections. Note that multiple
entries can be defined for each connection. This way, sequences of different access technologies
can be created for the same Service. If, for example, we want to have multiple Voice connections,
with Voice-DSL as first priority, Voice-Ethernet as second and Voice-3G-4G as third, three different
entries must be used:
Further to the primary / backup relationship between the different WAN connections, under the same
page it is possible to manually set values for the parameters which control the redundancy operation
of PPP connections. Available PPP Options include the LCP Interval (sec), LCP Failures or Maximum
Failures for the primary and the fallback connection, which handle when a PPP session should be
terminated in case of connectivity loss.
Finally, it is possible to enable Multilink operation between PPP connections (when supported by the
provider).
• Interface Groups for spliting the local network interfaces into different "Service Groups" (private
VLANs) (see page 99 ).
• VLAN for configuring private and/or 802.1q VLAN operation (see page 101 ).
• Ethernet for modifying the LAN Ethernet interfaces (see page 102 ).
• Addresses for specifying the IP address of each Service Group interface (see page 104 ).
• DHCP for configuring the DHCP server for each Service Group interface (see page 106 ).
• DNS Settings for modifying the local DNS server settings (see page 110 ).
• Static Routes for viewing and configuring static IP routing rules (see page 113 ).
• Dynamic Routing for configuring dynamic IP routing protocols (see page 115 ).
• Wake On LAN for remotely turning on computers on the LAN (see page 116 ).
• Public IPs for configuring on the LAN, IP addresses directly accessible from the Internet (see page
117 ).
97
Oxygen Multiservice Gateway User’s Guide
Interface Groups
The Oxygen Multiservice Gateway is a full featured device, capable of supporting more than one service
over the broadband access network. In the typical multi-service deployment scenario, it is essential that
the local Ethernet interfaces are divided and assigned to the different broadband services. This way
WAN connections and LAN inetrfaces are organized into Service Groups and traffic is allowed only
between connections and interfaces belonging to the same Service Group.
The Oxygen Multiservice Gateway supports two alternative methods for this division of the LAN
interfaces into different Service Groups:
• Private VLANs: this is the simple approach. Each local Ethernet ports is assigned to a single Service
Group. This is an internal function of the Oxygen Multiservice Gateway and no requirement is
imposed on the clients on the local Ethernet network.
• 802.1q VLANs: this enables the use of 802.1q VLAN tags on Ethernet frames and Ethernet ports are
assigned to one or multiple Service Groups, through the use of different VLAN IDs. This is a more
powerful but also more complex approach, as it normally requires advanced configuration also
for the clients on the local Ethernet network.
Selection between Private VLANs and 802.1q VLANs is performed in the VLAN configuration page
(see page 101).
Regardless of the method selected for splitting the local Ethernet ports, their assignment to different
broadband Service Groups is performed using the Interface Groups web menu.
To this end, this web configuration page provides a list of all physical LAN ports (when using Private
VLANs) or defined LAN 802.1q VLANs (when using 802.1q VLANs). Using the corresponding drop-down
list of supported Services, each Interface (physical port or 802.1q VLAN) can be assigned to the
appropriate Service Group.
The configured broadband connections and the service each of them supports, are also
presented in this page. However, their membership to Service Groups is presented for
information-only purposes and cannot be changed here. It is handled using the Service
Note parameter in the Connections configuration page (see page 80).
The Interface Groups web menu allows also the control of the operation of Internet Group
Management Protocol (IGMP) for multicast traffic. The following parameters can be enabled:
1. IGMP snooping to activate local snooping of WAN multicast traffic based on IGMP messages
from LAN hosts.
2. IGMP proxy to activate the proxying operation for multicast IGMP packets from the LAN towards
the WAN.
VLAN
VLAN (Virtual Local Area Network) is a technology that allows you to partition one physical network into
a set of virtual networks. VLANs are essential for the support of multiple broadband services over the
Local Area Network. The Oxygen Multiservice Gateway supports two alternative methods for this division
of the LAN interfaces into different Service Groups: Private VLANs, and 802.1q VLANs.
Private VLANs is the simpler approach and the default mode of operation for the Oxygen Multiservice
Gateway. The VLAN configuration page allows the activation and control of the more complex mode:
802.1q VLANs. In order to activate the use of 802.1q VLANs on the Oxygen Multiservice Gateway, you
must first select Enabled as 802.1q Status.
The next step is the definition of the list of allowed VLAN-IDs and the assignment of physical Ethernet
ports as well as wireless virtual interfaces (SSIDs) (WiFi-enabled devices only) to them.
1. Enter the VLAN ID. Valid VLAN ID values are between 1 and 4095.
2. Select for each port the type of VLAN membership method you want: ’---’ for no membership,
Access for membership without the use of 802.1q tag, and Tagged for membership with the use
of 802.1q tags.
3. Click Apply.
Only one VLAN-ID can be selected for each port as Access VLAN. If no Access VLAN-ID
has been selected for a switch Ethernet port, this port is automatically set to belong to
Note the Switch native VLAN.
Ethernet
This web configuration page provides to the web administrator the ability to control the operation of
physical Ethernet ports.
By default, each port is configured to set in Auto-negotiation mode. If required to manually set
the Ethernet link characteristics of a specific port, uncheck the corresponding checkbox and select the
desired Speed and Duplex values.
In the same page, it is also possible to select for optional Combo interfaces (Optical and Copper
with one of the two active), the preferred priority between Optical and Copper mode of operation.
Addresses
Each of the Interface Groups supporting the different services has its own private (LAN) IP address. The
Addresses configuration menu allows the modification of this IP address for each Interface Group.
4. Click Apply.
Alternatively, you can use a DHCP client for automatic configuration of the LAN IP address of the
Oxygen Multiservice Gateway. This requires the existence of a DHCP Server in the LAN. Enable/Disable
the DHCP client by selecting/deselecting the corresponding DHCP Client checkbox.
The default LAN IP address for the Data Interface Group is 192.168.1.1.
Note
IPv6 Addresses
Under the Addresses configuration menu, it is also possible to enable or disable the global IPv6 operation
of the Oxygen Multiservice Gateway. This is performed using the respective radio button that appears
under the Global IPv6 Operation title.
When global IPv6 operation is Enabled, it is also possible to control the assignment of IPv6 Unique
Local Addresses (ULA) to each Service Interface Group. Through the Status drop-down list, you can
The Global IPv6 Operation setting affects the presence of various IPv6-related options
in different web pages (e.g. for Internet connections refer to subsection IPv6 Address in
Note page 84).
choose between Off, Auto and Fixed. When option Auto is selected, a ULA address is configured for the
respective interface based on a pseudo-random algorithm that combines NTP time and the so-called
EUI-64 identifier according to RFC 4193. Otherwise, you may choose the Fixed mode of operation, in
order to define your own ULA format by inserting the corresponding values in the Address and Mask
fields. Finally, you can disable ULA addresses by selecting Off option for the respective Interface Group.
DHCP
The embedded DHCP server of the Oxygen Multiservice Gateway allows the automatic network
configuration of all LAN devices on each Interface Group.
1. Enable/Disable the DHCP server by selecting On/Off from the drop-down list of DHCP column. The
status of the DHCP sever is changed accordingly. A third option is Relay, where the local DHCP
server is deactivated and all DHCP requests received on the LAN are forwarded to an external
DHCP server.
2. Specify the IP Address range by entering the Start IP and End IP values. In case of Relay operation,
only the Start IP entry field is active and must contain the IP address of the external DHCP server.
3. Configure the validity period of each assigned IP address under the Lease parameter. The default
lease time value is 86400 seconds (1 day).
4. Click Apply.
By default the DHCP server is activated only for the Data Interface Group with an
address pool 192.168.1.2 - 253.
Note
The embedded DHCP server of the Oxygen Multiservice Gateway assigns IP settings to every device on
each Interface Group using the available addresses from the corresponding address pool in a dynamic
way. In some cases, however (e.g. port forwarding), it is required that a PC or some other network
device will always obtain the same IP address. In this case, the DHCP server is required to assign a fixed
IP address based on the physical (MAC) address of the device. The Static DHCP Leases configuration
page enables this functionality.
At the top of the page, a list of the configured address reservations is displayed. You can Delete
configured reservations by clicking on the icon of Action column.
In order to make a new static DHCP lease, fill in the MAC address of the device along with the
desired IP Address and Hostname (optional). If the host has already got an IP address automatically
through the Oxygen Multiservice Gateway DHCP server, these values can be automatically filled in using
the Host drop-down list.
If required, you can also check Static ARP, in order to add a static IP-to-MAC binding in the Oxygen
Multiservice Gateway MAC address table.
If, on the other hand, a Hostname has been provided, you can also add a correponding DNS entry
in the local list of known hostnames (please refer to section Host Aliases on page 110).
The embedded DHCP server does not provide only IP address to LAN hosts, but also additional settings
via the use of DHCP options. This way LAN hosts obtain the values of the DNS server or the default
gateway IP (which by default are equal to the IP address of the Oxygen Multiservice Gateway itself).
However, it is possible to modify the values of these standard options from their default ones or send
addional options further to the standard ones. This is attainable using the Static DHCP Options page.
Following the corresponding link, a list of already configured options appears. You may delete existing
entries by clicking on the icon of Action column.
To add a new static DHCP option select the Service Group for which the DHCP server will provide
the option (All for all Service Groups) and the type of Option. Enter the corresponding option Value. You
can optionally also enter a Vendor ID value, if you wish the configured DHCP option to be transmitted
only to hosts whose vendor-class matches a specific string (vendor class-specific option). Finally click on
Save.
In case IPv6 functionality is globaly enabled on the Oxygen Multiservice Gateway (please refer to section
IPv6 Addresses on page 104), in the LAN IPv6 addresses section you can specify the method for IPv6
address asignment to the LAN hosts. In particular, for each Service Group there is a possibility of different
options.
1. SLAAC: With Stateless Address Autoconfiguration (SLAAC), Router Advertisements that contain
Prefix and LifeTime information are sent to the LAN hosts that belong to the specific Service Group.
In parallel, RDNSS is enabled, which means that DNS server information is also provided through
Router Advertisements for hosts whose Operating System supports this functionality (e.g. Linux PCs).
2. Stateless DHCPv6: With this option, LAN hosts obtain their IPv6 address via Router Advertisment.
However, the Router Advertisement packets have the so-called Other Configuration Flag set to
on. This way, the LAN host is dictated to start a DHCPv6 request and the Oxygen Multiservice
Gateway provides it with stateless configuration parameters, such as DNS server, NTP, SIP servers,
AFTR server etc. This is the most commom mode of IPv6 operation for LAN hosts.
3. Stateful DHCPv6: With this option, both address and additional information are transmitted over
DHCPv6.
4. Off : With this option, no IPv6 addressing info is provided by the Oxygen Multiservice Gateway to
LAN hosts.
Using any of the IPv6 address assignment methods (except Off ), the Oxygen Multiservice Gateway
assigns a /64 IPv6 prefix to IPv6-enabled hosts in the LAN. Therefore, in parallel to the method used for
IPv6 address assignment, it is essential to select also the source of these assigned IPv6 prefixes. IPv6
prefixes can be either obtained from the WAN through DHCPv6 Prefix Delegation (please refer to the
Stateless DHCPv6 and Stateful DHCPv6 options in section Connections on page 80) or they can be
manually configured. The first option is realized by selecting Auto under the Pool drop-down list, whereas
the latter by selecting Fixed and configuring the appropriate Subnet and Lease time values.
Parameters related to the Router Advertisement operation of the Oxygen Multiservice Gateway can
be controlled using the corresponding fields on the bottom of the configuration page. These include
Maximum RA interval, Preferred and Valid Lifetime (all parameters in seconds). Default values for these
parameters are 600, 14400 and 86400 secs respectively.
DNS Settings
The Oxygen Multiservice Gateway serves as a Domain Name Service (DNS) proxy for all devices on the
LAN towards the DNS servers of the ISP. Normally, the IP addresses of the DNS servers are automatically
configured for every WAN connection (either through PPP or through DHCP), but in certain cases it may
be required to manually configure them.
1. Select between:
• simultaneous use of the DNS servers obtained by every WAN connection (All connections)
• use of the DNS servers obtained only by the Default-route connection, or
• manual configuration of the IP addresses of the DNS servers (Static servers)
2. In case of manual DNS configuration, provide the IP address of the primary and (optional)
secondary DNS servers.
3. Specify if all available DNS servers are queried in parallel (default) or if Sequential queries are sent
to one server after the other.
Host Aliases
The DNS servers configured in the DNS Settings configuration page or automatically obtained through
the WAN connections are queried by the Oxygen Multiservice Gateway for resolving hostnames into
IP addresses. In some cases however, it is required that a manual configuration is performed for some
hostname-to-IP bindings (e.g. for hosts in the LAN). The Host Aliases configuration page enables this
functionality. Following the corresponding link, the following page appears:
At the top of the page, a list of the configured entries is displayed. You can Delete configured
bindings by clicking on the icon of Action column.
In order to make a new static DNS alias, fill in the desired IP Address and Hostname combination.
If the host has already got an IP address automatically through the DHCP server, the IP Address and
Hostname values can be automatically filled in, through the Host drop-down list. Finally click Save.
Forced Lookups
Another special requirement when resolving hostnames via DNS, is to selectively use DNS Servers related
to certain WAN connections for resolving specific domain names. This can be controlled using the Forced
Domain Lookups page, where you can select the use of the DNS servers obtained from a specific WAN
connection or Service Group for resolving hostnames belonging to special domain names.
At the top of the page, a list of the configured entries is displayed. You can Delete entries by clicking
on the icon of Action column.
To add a new forced lookup entry, select the Service / Connection and enter the Domain name to
be resolved through the DNS servers of the selected Service / Connection. Finally click on Save.
Static Routes
In most cases, for Internet traffic it is adequate to specify the correct Default Route WAN connection
(please refer to section Connections on page 80). Using specific methods (e.g. dynamic routing
protocols or DHCP options), it is also possible for the ISP to automatically apply more specific routing
rules on the device. In certain cases, however, manual configuration of routing entries is required. This
functionality is supported through the Static Routes configuration page.
Selecting this entry, the following page appears with a list of the configured static routing entries:
You can Edit and Delete configured route entries by clicking on the icons and respectively of
Action column.
To add a new static routing rule, click Add New and the new Static Route page opens:
2. Enter the Gateway IP address and/or Interface/Connection used for the forwarding of the
packets.
3. Optionally enable the Strict option. When enabled, if the configured Gateway and/or Inter-
face/Connection is not available, traffic towards the configured Destination will not be forwarded
via the default-route entry of the routing table but will instead be dropped.
5. Click Save.
Enter static routing entries with caution! Wrong routing rules can lead to loss of
connectivity or degradation of service.
WARNING
Dynamic Routing
An automatic method of applying routing information on the device, is through the activation of a
dynamic routing protocol, such as RIP. When such a routing protocol is offered by the ISP’s network, use
the Dynamic Routing menu entry to activate the corresponding functionality on the Oxygen Multiservice
Gateway.
1. Select the Enabled radio button under Status for the overall activation of the dynamic routing
service.
2. Activate or deactivate dynamic routing for each individual WAN connection. In Passive mode the
connection only receives, whereas in Active mode it both sends and receives dynamic routing
information.
3. For any connections in Active mode, under Advertised Route enter the routing entries to be sent
towards the network.
4. Click Apply.
Wake On LAN
Most modern PCs have a special capability of being automatically activated while in Off (Standby)
status, when they receive a special Ethernet packet. This capability is called Wake On LAN (WOL) and
can be used for the remote activation of PCs or servers without physical access to their On/Off switch.
In order to activate a host on the LAN using the Wake On LAN service, enter the MAC address of
the host. Alternatively, if the host has already been added to the DHCP server’s list of static leases, the
MAC address can be automatically filled in, through the Host drop-down list. Click Apply and the WOL
process is initiated by the Oxygen Multiservice Gateway.
The support of the Wake On LAN service by the PC or server depends on its BIOS and
Network Interface Card (NIC) settings.
Note
Public IPs
In the majority of installations, each host in the LAN uses a separate private IP address and accesses
the Internet through the automatic transformation by the Oxygen Multiservice Gateway between the
private and one or more public IP addresses (NAT operation). In some cases, however, it is required to
use also public IP addresses in the LAN (usually for Web servers, FTP servers etc.). In order to realize this,
one option is to use a separate DMZ (DeMilitarized Zone) Interface Group, totally separated from the
other LAN hosts (refer to sections Addresses on page 104 and section DMZ Filters on page 139). If it
is required, however, that the hosts with the public IP addresses coexist in the same Ethernet segment
with the other internal hosts using private IP addresses, a second available option is to notify the Oxygen
Multiservice Gateway about the existance of public IPs in the LAN. This is achieved through the Public
IPs configuration menu. In this configuration page, a subnet of public IP addresses can be configured
for each Interface Group. IP addresses belonging to these subnets will be routed directly (without NAT),
and NAT will only be applied to the private IP addresses.
Using the corresponding table entries, for each LAN Interface Group:
1. Enter the public IP Address and Netmask values for the Oxygen Multiservice Gateway. This will be
used by the device as a secondary IP for the LAN Interface Group.
2. Check the Enabled checkbox in order to activate the relevant operation for the specific Interface
Group.
3. Click Apply.
The combination of IP Address and Netmask define the subnet of IPs that will not be treated as
private by the Oxygen Multiservice Gateway and will not be translated via NAT. Out of this network of
Public IPs, addresses can be assigned to hosts in the LAN and for each of these hosts the IP Address
value configured for the Oxygen Multiservice Gateway in step 1 must be set as default gateway.
When global IPv6 operation is enabled, under the Public IPs configuration menu it is also possible to
control the assignment of Global IPv6 Addresses to each Service Interface Group. Through the Status
drop-down list, you can choose between Off, Auto and Fixed. When option Auto is selected, a Global
IPv6 address is configured for the respective interface based on the IPv6 prefix obtained from the WAN
via Prefix Delegation. Otherwise, you may choose the Fixed mode of operation, in order to define your
own global IPv6 values by inserting the corresponding values in the Address and Mask fields. Finally, you
can disable global IPv6 addresses by selecting Off option for the respective Interface Group.
• Radio for configuration of the wireless LAN radio operation (see page 121 ).
• Configuration for setting up the wireless LAN operation and security parameters (see page 123 ).
• MAC Filtering for enabling wireless access control based on the MAC address of the WiFi client
devices (see page 127 ).
119
Oxygen Multiservice Gateway User’s Guide
Radio
This page allows the configuration of all the general parameters controling the operation of your wireless
interface:
1. Enable or Disable the wireless network using the corresponding Status radio button.
2. Select the Number of SSIDs. A value higher than 1 leads into the separation of the wireless
functionality into multiple virtual, independent sub-networks. Each of these independent sub-
networks is identified using a Network name (SSID) and is treated like a totally different wireless
network. For example, each sub-network can have its own encrytpion method (see section
Configuration on page 123) or can be assigned to a different Service / Interface Group (see
section Interface Groups on page 99).
3. Select the used Frequency band channel as Auto or specify a specific channel number.
5. Optionally set the Beacon interval. The default setting of 100 milliseconds should be ideal for most
situations.
6. Select the Mode of operation between any combination of the supported 802.11 profiles.
8. Enable or disable additional capabilities for the wireless operation (e.g. WMM - Wi-Fi Multimedia
Extensions).
When multiple Wireless radio interfaces are present (optional feature), each radio
interface has its own set of parameters. Select between the different radio interfaces
Note using the appropriate tab at the top of the page.
Apart from the wireless operation settings, in this web configuration sub-menu it is possible also to
control the operation of the WiFi and WPS Hardware Buttons. Using the corresponding drop-down list
you wan select which SSID is controlled by the WiFi button and if the WPS button is Enabled or Disabled.
Configuration
This page allows the modification of the wireless network name and the corresponding security settings.
The first task for the operation of each wireless (sub)network (SSID) is the assignment of a network
Name. It is possible also to control if this value is going to be broadcast and visible (On) or hidden (Off )
using the Broadcast radio buttons.
The next task is the encryption of transmitted and received wireless traffic using the desired Security
mode. The available security options are WEP, WPA and WPA2, whereas option Off leaves your wireless
traffic unencrypted. In the following paragraphs we will see more details for the parameters related to
the different security options.
If no encryption is used (Off mode), anyone within the range of the wireless network can
potentially capture your Internet traffic and access your home network.
WARNING
Finally, for each SSID it is also possible to limit the number of connected clients (Maximum clients),
to disallow connectivity between connected clients by checking the Isolate clients option, and (only for
secondary SSIDs) to control the maximum Down and Up Bandwidth limit.
The Wi-Fi Protected Access (WPA) encryption method and WPA2 (which is the upgrade of the initial
WPA standard), are the de-facto standards for securing wireless networks. Selecting WPA or WPA2 as
the encryption method, the following page appears:
When using WPA or WPA2, there are two different modes of Authentication:
• Personal is the simpler and most common method. It uses a fixed security WPA key (PSK -
Pre-Shared Key), 8 to 63 ASCII characters long, shared among the Access-Point and the endpoints
(PCs).
• Enterprise, on the other hand, is a more complex method. It relies on the use of an external Radius
Server for authenticating each endpoint that requests WiFi connectivity (802.1x protocol).
Further to Personal and Enterprise, under Authentication it is also possible to choose between two
different types of encryption:
• TKIP (Temporal Key Integrity Protocol) is the older encryption protocol introduced with WPA. TKIP
is no longer considered secure, and is now deprecated.
• AES (Advanced Encryption Standard) is a more secure encryption protocol introduced with WPA2.
In the 2.4GHz band, selection of TKIP authentication mode forces the device to operate
in 802.11b/g and not in 802.11n mode. Likewise, in the 5GHz band, TKIP forces the device
WARNING to operate in 802.11a and not in 802.11ac mode.
It is STRONGLY recommended to use WPA2-AES. The use of all other options is vulnerable.
WARNING
WEP Encryption
Wired Equivalent Privacy (WEP) is a legacy wireless security method, deprecated because of the
deficiencies found in its encryption algorithm. It is supported by Oxygen Multiservice Gateway for
backwards compatibility with legacy wireless clients not supporting WPA.
4. Click Apply.
WEP keys are some times used in hexadecimal format by wireless PC drivers. For this
reason, when the desired ASCII WEP key is entered, its corresponding hexadecimal
Note representation is displayed as well next to the Hex label.
When WPA2 is the the chosen security mode it is possible to enable and use WPS. With this mode
it is possible to automatically connect a wireless client to your Oxygen Multiservice Gateway without
manually entering the wireless key value. Using WPS, all the necessary encryption information is
automatically exchanged between the Oxygen Multiservice Gateway and the wireless client.
Before using WPS, it must first be enabled. To enable WPS mode for a specific SSID:
2. Click on Apply.
Now WPS is enabled for the selected SSIDs. At any moment you can activate WPS and allow a
wireless client to automatically connect. To this end:
1. Press the WPS button or click on Activate in the Web Configuration tool.
2. WPS activation lasts for a predefined time interval (3 minutes). Within this period connect your WPS-
capable wireless device to the Oxygen Multiservice Gateway (please refer to your client-device
user’s manual for instructions).
WPS is incompatible with MAC filtering. Therefore, MAC filtering is disabled for SSIDs with
enabled WPS operation (please refer to section MAC Filtering on page 127).
Note
WPA2 is the default security policy of the Oxygen Multiservice Gateway. The default
WPA key is printed on the bottom label of the device.
Note
MAC Filtering
Apart from the wireless encryption protocols, another method of limiting wireless access to the Oxygen
Multiservice Gateway (but not encrypting traffic), is through the MAC Filtering sub-menu.
The Default Policy radio buttons set which is the default rule for client access:
After selection of the default policy, add the desired set of MAC Addresses in the provided list and
click Apply.
WPS is incompatible with MAC filtering. Therefore, MAC filtering is disabled for SSIDs with
enabled WPS operation.
Note
• Port Forward for allowing selected incoming connections from the Internet towards the LAN, in
order to enable some applications to work behind the firewall (see page 131 ).
• UPnP / NAT-PMP for activation/deactivation of automatic firewall port forwarding using the UPnP
and/or NAT-PMP protocols (see page 133 ).
• IP Filters for precise control of allowed or denied IP connections between the LAN and the Internet
(see page 134 ).
• Web Filters for denying access to web sites based on a configured list of keywords (see page 137
).
• DMZ Filters for configuring a subnet on the internal network that has its hosts selectively exposed
to access from the Internet (see page 139 ).
• Address Mapping for configuring the use of different public (WAN) IPs from different LAN hosts
using Network Address Translation (NAT) (see page 141 ).
129
Oxygen Multiservice Gateway User’s Guide
Port Forward
The firewall and Network Address Translation (NAT) engine of the Oxygen Multiservice Gateway keeps the
private network (LAN) protected from external threats. It is frequently required, however, to selectively
allow access from the Internet to a host on the local network that runs an application or service.
This selective accessibility of a server on the LAN from the WAN is enabled using the Port Forward
sub-menu. Each forwarding rule tells the Oxygen Multiservice Gateway on which computer a service or
application is running. The service or application is defined by its characteristic TCP/UDP port number(s),
and whenever traffic is received on the external (public) IP address with this specific port number as
destination, this traffic is automatically routed to the specified private IP address.
Selecting the Port Forward option, a list of the configured port forwarding rules is displayed.
You can Edit and Delete configured port forwarding rules by clicking on the icons and
respectively of Action column.
To configure a new port forwarding rule, click Add New and the Port Forward Rule page opens:
2. Select the Protocol that will be forwarded. This can be one of the pre-defined services/applications
appearing in the drop-down list or CUSTOM for explicitly defining the forwarded port.
3. In case of CUSTOM protocol selection, specify the Type of incoming connection (TCP, UDP or
TCP/UDP) and the corresponding Port number (valid ports are 1-65535). Port ranges can also be
specified using the optional up to field.
4. Specify the Internet Connection this new port forwarding rule will apply to. You can select a
specific Internet connection, connections belonging to a specific Service Group or --- WAN --- to
match all Internet connections.
5. Select if incoming connections from all Hosts are going to be forwarded (option ALL) or only
connections from a Restricted host/network. For a single host, enter its IP address, whereas for a
network use the xxx.xxx.xxx.xxx/yy notation (xxx.xxx.xxx.xxx is the network address and yy is the
length of the mask in bits - see Appendix B on page 229).
6. Under the Forward to heading, enter the private (LAN) IP address of the internal server in the Host
entry field. Note that if the desired local network server obtains its IP address from the Oxygen
Multiservice Gateway through DHCP, you can select it from the drop-down list and a static DHCP
lease will also be automatically added .
7. Specify if the port must be forwarded unchanged (normal situations) or if the port of the internal
server is different from the public one. Note that this option is only available if a single port is going
to be forwarded and not in the case of a port range.
UPnP / NAT-PMP
UPnP and NAT-PMP are protocols that enable applications on the LAN to operate automatically through
the NAT and Firewall engine of the Oxygen Multiservice Gateway by transparently applying the required
port-forwarding rules. Through these protocols, the PCs on the LAN notify the Oxygen Multiservice
Gateway about the need for specific port forwarding rules, and the necessary actions are performed
without any user intervention.
2. Click Apply.
IP forwarding rules automatically applied through UPnP and/or NAT-PMP are listed in the
Firewall sub-menu of the Status Menu (see page 206).
Note
IP Filters
The IP filtering service allows the Oxygen Multiservice Gateway to control in a detailed way connection
attempts and IP streams in both the incoming (Internet → LAN) and the outgoing (LAN → Internet)
direction. Different services and applications can be allowed or denied based on the source and/or
destination IP address.
The default policy of the Oxygen Multiservice Gateway is that all outgoing connections
are allowed and all incoming connections denied.
Note
Selecting the IP Filters option, a list of the configured IP filtering rules is displayed.
You can Edit and Delete configured IP filtering rules by clicking on the icons and respectively
of Action column.
To configure a new IP filtering rule, click Add New and the IP Filtering Rule page opens:
2. Enter the type of filter rule in Filter field. Options Drop and Reject both lead to discarded
connection attempts. The difference is that with Drop the connection attempt is rejected silently
whereas Reject sends an ICMP notification packet. Accept on the other hand, leads to an
acceptance of the connection attempt and subsequent IP traffic.
3. Select the Source of the filtered traffic: Using the Service/Connection drop-down list, select a
specific Internet connection or LAN Interface Group (private VLANs), WAN:--Service-- for any WAN
connection belonging to a specific Service, --WAN-- to match all Internet connections or --LAN--
to match the entire LAN (all Interface Groups).
4. Specify if the filtering rule is going to be applied to traffic from any host or only to traffic from a
specific Host or Subnet. In the former case, the relevant input field must be left blank or set to
0.0.0.0/0. For a single host, on the other hand, enter its IP address, whereas for a sub-network use
the xxx.xxx.xxx.xxx/yy notation (xxx.xxx.xxx.xxx is the network address and yy is the length of the
mask in bits - see Appendix B on page 229).
5. Repeat steps 3 to 4 for the selection of the Destination of the filtered traffic.
6. Specify the Application/Service being filtered by choosing any of the pre-defined applications in
the Protocol drop-down list or by choosing CUSTOM followed by the protocol Type (TCP, UDP or
TCP/UDP) and the Port number. Port ranges can also be specified using the optional up to field.
Enter IP filtering rules with caution! Wrong IP filtering rules can lead to loss of connectivity,
degradation of service and even loss of access to the configuration menu of the Oxygen
WARNING Multiservice Gateway.
Web Filters
The Oxygen Multiservice Gateway offers also a web filtering, parental control service, that allows the
selective rejection of outgoing HTTP requests based on keywords found in the requested URL.
1. Enable or Disable the service using the appropriate Status radio button.
• Transparent mode does not require any configuration on the PCs in the local network and
transparently forces all HTTP traffic through the filtering service of the Oxygen Multiservice
Gateway. The disadvantage of this approach is that it operates only for HTTP traffic and not
for HTTPS.
• Proxy mode forces both HTTP and HTTPS traffic to pass through the filtering service of the
Oxygen Multiservice Gateway but it requires the LAN IP address of Oxygen Multiservice
Gateway to be set as LAN proxy on the PCs in the local network.
5. Optionally force all web traffic to pass through an external HTTP proxy server. To this end, check
the Force upstream proxy checkbox, and fill-in the Name or IP and the Port of the proxy server.
6. Optionally specify the IP addres for a list of Unrestricted Local Hosts, for which the web filtering will
not apply.
DMZ Filters
A DMZ (DeMilitarized Zone) is a local subnet that can be accessed from the Internet and is usually used
to host Web servers, FTP servers etc. Being a local subnet, the Ethernet ports that are part of the DMZ
and the IP addressing scheme used for the DMZ subnet are configured, like for every LAN service, using
the relevant configuration options of the Network configuration menu (see page 97). From a security
point of view, however, the DMZ is treated like a semi-external network, usually using public IP addresses
and kept totally separated from the Data, Voice and Video Interface Groups. To be more precise:
1. Connections from the Internet towards the DMZ are filtered through the firewall (see below).
2. Connections from the DMZ towards the Internet are allowed based on the configuration options
(see below).
3. For connections from the DMZ towards the Internet, by default no NAT is applied, since public IP
addresses are usually assigned to the DMZ hosts
4. Connections from the DMZ towards the LAN Interface Groups are filtered through the firewall.
5. Connections from the LAN Interface Groups towards the DMZ are allowed, but NAT is applied
hiding the internal IP addressing scheme.
The DMZ Filters sub-menu, first of all controls item 1 of the list above, through the configuration of the
list of services that are allowed to pass the firewall from the Internet towards the hosts in the DMZ. From
the list of services/protocols displayed, check the ones that should be allowed through the firewall.
Regarding item 2, of the list above, traffic from the DMZ to the Internet is normally only allowed
in response to incoming connection requests. Using, however, the Allow all outgoing connections
checkbox, it is possible to allow any traffic from the DMZ towards the Internet.
Having selected the preferred DMZ operation parameters, click Apply to activate your settings.
The DMZ Filters functionality can be considered as a special case of IP fltering. Therefore,
entries corresponding to all allowed services/applications are automatically added to
the list of IP Filters. The IP Filters sub-menu gives the administrator the freedom to
Note configure more complex cases, whereas the DMZ Filters configuration page presents, in
a simpler form, only Internet → DMZ rules.
Address Mapping
The Network Address Translation (NAT) service of Oxygen Multiservice Gateway allows multiple hosts in
the internal LAN to share the same external (public) IP address. While this is adequate for most users, it
is sometimes required (normally in business environments), to share more than one external IP addresses.
This is the case, for example, when a SOHO/SME has been provided multiple static IP addresses by
the ISP and the administrator wants to use one of these IP addresses for the company’s Web server, a
second for the FTP server, etc.
The Address Mapping configuration sub-menu allows the controlled mapping of external IP addresses
to LAN hosts.
1. Enter the External (WAN) IP address value. Alternatively, from the drop-down list, you can select a
specific WAN connection or a specific Service. In this case, the IP address automatically assigned
to the selected WAN connection(s) will be used for the static address mapping.
2. Specify the LAN host this mapping rule will apply to. Under the Internal (LAN) heading, enter the
LAN IP address of the internal server. Note that, if the desired LAN server obtains its IP address from
the Oxygen Multiservice Gateway through DHCP, you can select it from the drop-down list.
3. Check the Firewall option if IP traffic for the specific mapping should be controlled by the Firewall
of the Oxygen Multiservice Gateway or if it will be freely forwarded.
Repeat the above procedure for all required external IP addresses and corresponding LAN servers.
In case you want to bypass these Address Mapping rules for some hosts, enter the corresponding
entries in the Un-NATed Addresses table and finally click Apply to activate the service.
The Voice configuration menu handles all parameters related to the voice operation of the Oxygen
Multiservice Gateway. You can access the following voice sub-menus:
• Phone Lines for configuring the external phone lines (see page 145 ).
• Services for setting-up the telephony supplementary services (see page 148 ).
• Analog Interfaces for configuring the analog voice interfaces (see page 149 ).
143
Oxygen Multiservice Gateway User’s Guide
Phone Lines
This configuration page allows the control of the phone lines of the Oxygen Multiservice Gateway. The
list of phone lines includes all types of connections to the telephony network: the Voice over IP (VoIP)
service accounts, and, when present, the FXO and External ISDN interfaces (optional features).
For each phone line, select the corresponding tab and configure the relevant parameters.
In the case of VoIP service accounts, the line settings first of all require the selection of Status.
Subsequently, you must insert the SIP credentials Number, Username and Password as well as the mode
of transport of DTMF tones, with available options being RFC 2833, Inband and SIP Info (RFC 2976).
Finally, using the Force Caller-ID drop-down list, it is also possible to configure the Caller-ID presented in
outgoing calls. Available options are:
• Off : present the Caller-ID as it was received from the local voice ports (no change).
• On-Empty: present the line Number as Caller-ID, when no Caller-ID was received from the local
voice ports.
• Validate: present the Caller-ID as it was received from the local voice ports, only if this Caller-ID is
equal to the line Number or one of it MSNs (if available). Otherwise, force the presentation of the
line Number as Caller-ID.
Having configured the line settings, the next step is the configuration of the way Incoming Calls
are handled. The first option is to select the number of right-end digits to be retained for the internal
numbering scheme. This is the number of Significant Digits. If, for example, this parameter is set to 3,
when an incoming call is received for number 2101234500, the called number will be truncated to 500
and afterwards it will be routed to the internal voice interfaces. This is useful, especially in the case of
ranges of consecutive numbers, which are usually directly converted to internal numbers through simple
transformations. The final step for routing incoming calls, is to select to which internal voice interfaces
the call will be directed to. This is possible using the table of voice interfaces under the Incoming Calls
section, by selecting every appropriate interface (e.g. FXS ports and/or ISDN-NT interfaces).
The list of available options in the table of the Incoming Calls section, depends on the
voice interfaces and optional functionality of the Oxygen Multiservice Gateway.
Note
Having performed the above configuration for each available phone line, the final step is the
selection of the phone line / number used by each internal voice interface for placing outgoing calls.
This is performed using the Outgoing tab of this page. When selecting this tab, a table of all available
voice interfaces as well as phone lines / numbers appears. By selecting for each voice interface one
of the available lines / numbers, the selected line / number is going to be used for outgoing calls. Two
additional options are Internal Only for allowing only outgoing calls towards other local voice interfaces
and Blocked for blocking all outgoing calls from the corresponding voice interface.
Two final parameters available for each voice interface are Anonymous and Alarm port. With the
first one it is possible to mark calls from the corresponding voice interface as anonymous (i.e. hiding the
Caller-ID), whereas the second one can be used in order to indicate that this port is connected to an
alarm or some other system that needs to sense the port as non-operational (no on hook-voltage) when
voice calls towards the VoiP network are not possible (e.g. broadband network unavailability) (option
available only for FXS ports).
Services
This page allows the configuration of supplementary services for the voice ports of the Oxygen Multiservice
Gateway.
For each voice port, select the corresponding tab and configure the relevant parameters.
• Caller-ID Restriction: a checkbox indicating if outgoing calls from the specific port will appear as
anonymous.
• Alarm port: this checkbox can be used in order to indicate that this port is connected to an alarm
or some other system that needs to sense the port as non-operational (no on hook-voltage) when
voice calls towards the VoiP network are not possible (e.g. broadband network unavailability)
(option available only for FXS ports).
• Hotline: the corresponding parameters can be used in order to control the operation of the Hotline
supplementary service. When Enabled, the specified Number is automatically called once the
port gets in off-hook position and no digit is dialed for the defined Timeout number of seconds.
Analog Interfaces
Through Analog Interfaces you are able to configure the optional analog voice interfaces (FXS) of the
Oxygen Multiservice Gateway:
• Hook-flash interval: on/off-hook time limits for the detection of a hook-flash event
• Transparent DTMF; direct forwarding of DTMF signals without any local processing by the Oxygen
Multiservice Gateway (required for some alarm systems)
• FAX operation: different profiles of voice-related settings (e.g. gains, jitter buffer) in order to
optimize the operation of different analog FAX devices
• Input and Output gain: voice level gains in the input and output direction
Additionally you can optionally Enable the generation of Advice of Charge (AOC) Metering Pulses
along with the corresponding pulse parameters (optional feature).
Speed Dials
The Speed Dials configuration page allows you to assign destination phone numbers to the list of
speed-dialing patterns of the Oxygen Multiservice Gateway. These speed-dialing patterns are short
codes which are matched with full telephone numbers and, once dialed, the corresponding destination
number is called.
1. In the Destination fields put the phone numbers you wish to be called when the corresponding
speed-dial Pattern is dialed.
2. Click Apply.
The Advanced configuration menu allows the configuration of a series of different advanced services
offered by the Oxygen Multiservice Gateway. It includes the following sub-menus:
• Dynamic DNS for configuring the Dynamic DNS application (see page 153 ).
• Date and Time for changing date and time protocol settings (see page 154 ).
• SSL VPN for setting-up a secure SSL-based VPN connection using OpenVPN (see page 155 ).
• GRE Tunnel for setting-up a Generic Routing Encapsulation (GRE) tunnel (see page 159 ).
• L2TP Tunnel for setting-up an L2TP and/or IPSec-based VPN tunnel (see page 160 ).
• IPSec Tunnel for setting-up an IPSec VPN tunnel (see page 163 ).
• QoS Policy for defining and configuring Quality of Service classes (see page 165 ).
• File Sharing for activation/deactivation of file sharing through connected USB storage devices
(see page 170 ).
151
Oxygen Multiservice Gateway User’s Guide
Dynamic DNS
The Dynamic DNS service allows Internet users with dynamic IP address broadband access to register a
domain name. This way it is possible to access their home network through a fixed hostname, despite
the fact that their IP address changes frequently. The Oxygen Multiservice Gateway supports different
Dynamic DNS service providers.
2. Specify the Service Type, Hostname, Username, Password and optional Token.
3. Click Apply.
You must first create an account at a Dynamic DNS service provider and configure the
corresponding Hostname, Username and Password, before activating the service on
Note the Oxygen Multiservice Gateway.
It may take even a few minutes for a successful activation and/or update of the Dynamic
DNS service.
Note
This sub-menu lets you configure the date and time values of the Oxygen Multiservice Gateway. Usually,
this is performed using the embedded Simple Network Time Protocol (SNTP) client, which allows the
Oxygen Multiservice Gateway to contact a configured Network Time Protocol (NTP) server and obtain
the current date and time values.
5. Click Apply.
Alternatively, you may configure the date and time of the Oxygen Multiservice Gateway using the
date and time values of your PC, provided to the Oxygen Multiservice Gateway via your web browser.
You may do so by clicking on Update from Browser button.
SSL VPN
This sub-menu lets you configure your Oxygen Multiservice Gateway to act either as a server or as a
client for a Secure Sockets Layer (SSL) Virtual Private Network (VPN) tunnel. An SSL VPN is a form of VPN
that uses the SSL protocol for ensuring the security of data transmitted over the Internet. In the Oxygen
Multiservice Gateway, this functionality is based on the widely used opensource OpenVPN project (
http://openvpn.net/ ) and supports both client and server modes of operation.
Client Mode
3. Specify the hostname or IP address of the SSL server in the Host/IP field.
4. Select between Routed (Layer-3 / IP) or Bridged (Layer-2 / Ethernet) Type of VPN tunnel. The
former means that the VPN tunnel is a point-to-point IP connection. Bridged, on the other
hand, means that the VPN connection will operate like an Ethernet bridge between the LANs
behind both the server and the client. For more detailed information about the advantages and
disadvantages of each type, please refer to Appendix E. Please note that you must make the
same sellection for both the server and the client.
5. When using Routed type, select if NAT (Network Address Translation) is going to be enabled for
LAN devices for traffic over the SSL VPN tunnel. In other words, when NAT is enabled, the multiple
devices in the client’s LAN are going to connect to the SSL VPN server using the IP address used
by the client for the VPN tunnel.
6. Select which LAN Service (Interface Group) is going to be bridged or routed over the configured
SSL VPN tunnel.
8. Click Apply.
In order to finish with the secure connection to the SSL VPN server, you will also need to install the
corresponding Certificates. These certificates must be provided to you by the administrator of the SSL
VPN server and can be uploaded by selecting the appropriate file using the Browse key and finally by
clicking the Upload key. The required certificate files and their names are:
It is also possible to install all files in one step, by gathering them in a zip archive, as they are provided by
an Oxygen OpenVPN server.
Server Mode
If, on the other hand, you wish to configure your device to act as an SSL VPN server:
3. As in Client mode, select between Routed (Layer-3 / IP) or Bridged (Layer-2 / Ethernet) Type of
VPN tunnel. Please note that you must make the same sellection for both the server and the client.
4. When using Routed type, specify the Subnet and Netmask values for the subnet used as an IP
address pool for providing addressing information to connected clients.
5. Select which LAN Service (Interface Group) is going to be bridged or routed over the configured
SSL VPN tunnel. When using Bridged type, the DHCP server settings of this Service are going to be
used for the assignment of IP addresses to any DHCP requests from the SSL VPN clients.
7. Optionally check Isolate clients to disable connectivity between the SSL VPN connected clients.
8. Optionally select if logging information should be recorded on external storage drive by checking
USB logging.
9. Click Apply.
The last step required for the operation of the SSL VPN server, is the definition of remote clients and
the generation of the corresponding certificates. To this end, click the Manage key next to the SSL VPN
clients label. The following page appears:
In order to add a new remote client, enter the username under the Add New Client heading and
click the Save key. The new client is added and a message window opens prompting you to save a zip
file. This zip file contains the configuration files and certificates corresponding to the added client. Save
the file and give it to the new remote client. It will be needed in order to connect to the SSL VPN server
running on your Oxygen Multiservice Gateway.
If, on the other hand, you wish to prohibit further access to configured remote clients, Revoke them
by clicking on the corresponding icon of Action column, in the list of the configured clients.
For more detailed information about the configuration of SSL VPN, please refer to
Appendix E.
Note
GRE Tunnel
This sub-menu lets you configure a Generic Routing Encapsulation (GRE) Tunnel between your Oxygen
Multiservice Gateway and another GRE-capable endpoint. GRE is a tunneling mechanism which uses IP
as the transport protocol and can be used for carrying many different passenger protocols.
2. Enter the public IP of the remote endpoint in the Remote Server field.
3. Specify the IP Address and Netmask for the local virtual interface of the GRE tunnel (the remote
endpoint must use compatible values).
4. Select the corresponding Service from the drop-down list. The internal firewall will allow forwarding
of IP traffic between the GRE tunnel and the selected LAN Interface Group (Service).
6. Optionally enter the appropriate numeric Pre-shared key value (the remote endpoint must use
the same key value).
7. Click Apply.
L2TP Tunnel
This sub-menu allows the configuration of an L2TP (Layer-2 Tunneling Protocol) or L2TP/IPSec (Internet
Protocol Security) -based VPN tunnel. L2TP tunnels are used for the transport of other protocols (e.g.
Point-to-Point Protocol - PPP) inside IP/UDP datagrams. Since, however, L2TP does not provide any
encryption or confidentiality by itself, it is frequently combined with an encryption protocol (e.g. IPSec)
which is passed within the tunnel to provide privacy. Your Oxygen Multiservice Gateway can act either
as a server or as a client for L2TP or L2TP/IPSec VPN tunnels.
To configure the L2TP tunnel, first select Enabled as Status. Then, use the Type drop-down list to
select the type of L2TP VPN. Available options are L2TP and L2TP/IPSec for L2TP-only or L2TP over IPSec
operation respectively. Finally, select between Server and Client Mode of operation.
Once the type and mode of operation of L2TP VPN has been selected, the relevant parameters
appear on the web configuration page.
Client Mode
The main required parameter for L2TP client operation, is the public Hostname or IP Address of the
Remote Server. For tunnel authorization purposes, a L2TP Pre-shared key, Username and Password
combination must also be supplied (with same values configured on the remote server).
Having defined the parameters for setting up the L2TP VPN tunnel, under the VPN Tunnel heading it
is possible to configure the operation of the L2TP VPN interface once it is up:
• Check Enable NAT in order to activate NAT (Network Address Translation) for LAN device traffic
over the L2TP VPN tunnel. In other words, when NAT is enabled, the multiple devices in the client’s
LAN are going to connect to the L2TP VPN server using the IP address used by the client for the
VPN tunnel.
• Select which LAN Service (Interface Group) is going to be routed over the configured L2TP VPN
tunnel.
If, on the other hand, IPSec is used for the encryption of the L2TP tunnel (L2TP/IPSec type), some
additional parameters, related to IPSec operation, appear under the IPSec Options heading:
• Key lifetime, used to specify the lifetime of the IPSec tunnel key,
• DPD interval, used for the control of the Dead-Peer-Detection (DPD) functionality (value 0
corresponds to disabled).
Server Mode
In the case of Server mode of operation, the main parameters used for the operation of the tunnel are
the same like in the client mode. The main difference is that, insted of the Remote Server parameter, this
time an IP address pool must be configured for the VPN Tunnel. This is performed using the Subnet and
Netmask parameters, whereas the Enable Access to WAN checkbox controls if clients connected to the
Oxygen Multiservice Gateway L2TP server will be allowed to pass traffic to and from WAN connections
belonging to Service.
Finally, the list of PPP Users along with the PPP authentication method must be configured. In order
to manage the list of PPP Users, press on the Manage button.
In order to add a new PPP user, enter the Username and corresponding Password values and click
on Save. The user will be added to the list of PPP Users. If you want to revoke a user click on its icon
from the Action column.
IPSec Tunnel
This sub-menu allows the configuration of an IPSec-based VPN tunnel. IPsec is a protocol suite for
securing IP communications by authenticating and encrypting each IP packet of a data stream. IPSec
wraps the original packet, encrypts it, adds a new IP header and sends it to the other side of the VPN
tunnel. Your Oxygen Multiservice Gateway can act as a client for an IPSec VPN tunnel connecting to
an IPSec VPN server or another IPSec VPN client.
To configure the IPSec tunnel, first select Enabled as Status and enter the IP Address of the Remote
Server (or remote peer).
Parameters related to IPSec operation, appear under the Options heading. These include:
• DPD interval, used for the control of the Dead-Peer-Detection (DPD) functionality (value 0
corresponds to disabled).
For tunnel authorization purposes, a Pre-shared key value must be supplied (with same value
configured on the remote server).
Finally, it must be selected if the tunnel will operate in Tunnel or Transport mode. In the former case
(Tunnel), the pairs of Local and Remote Subnets must be configured. The IPSec VPN tunnel allows traffic
to pass through, only if it belongs to one of the defined Local and Remote Subnet pairs. If, on the other
hand, no Local and Remote Subnet entries have been defined, the IPSec tunnel is set to operate in
Transport mode.
QoS Policy
This sub-menu lets you configure the Quality of Service (QoS) policy of the Oxygen Multiservice Gateway.
This policy consists of the classification of IP traffic into Priority Classes, the IP DSCP Marking of IP packets
and the use of VLAN CoS Marking on Ethernet frames with 802.1q VLAN tag.
Policy Classes
With Policy Classes, IP traffic is selectively distributed into 3 different priority categories: GOLD (high-
priority), SILVER (medium-priority) and BRONZE (low-priority). This classification scheme is realized with
the use of Classes, with each class representing a different type of traffic (e.g. a different service, an
application, traffic from/to a specific host, etc.).
The first thing displayed when selecting the QoS Policy link is a list of the already configured QoS
classes for IP traffic.
You can Edit and Delete configured QoS classes by clicking on the icons and respectively of
Action column.
To configure a new QoS class, click Add New and the Priority Class page appears.
2. Enter the Name of the new priority class. This name is going to be used in order to distinguish
between the different priority classes. Note that names must be unique among different classes
and that once configured, they cannot be modified.
4. Select the WAN Connection from the drop-down list, for which this class applies.
5. Select the desired traffic classification method under the Filter parameter. The Oxygen Multiservice
Gateway offers the following different methods for the classification of IP Traffic:
(a) DiffServ Value: Based on the TOS/DSCP value of the IP header of the packets. All packets with
a ToS/DSCP value equal to the one configured in the DSCP field, will belong to this Priority
Class.
(b) IP Addresses: Based on the Source or Destination IP address of the IP packets (Direction).
Traffic with IP address belonging to the range of IP addresses defined using the Start IP and
(optional) End IP parameters, will belong to this Priority Class.
(c) Connection Bytes: Traffic streams with data volume that exceeds the Begin after parameter
will belong to this Priority Class, until they exceed the (optionally defined) Stop after parameter.
(d) Application/LAN service: Based on the application or service the IP packets belong to. Traffic
part of a specific Service or application will belong to this Priority Class. This application can
be one of the pre-defined protocols/applications appearing in the drop-down list or CUSTOM
for explicitly defining the characteristics of the service. In the latter case, the Type of IP packets
(TCP, UDP or TCP/UDP) and the corresponding Port numbers (valid ports are 1-65535) must
be configured. Port ranges can also be specified using the optional up to field.
(e) IP Packet Size: Based on the size of the IP packet being transferred. Packets with size at least
equal to Payload from and optionally up To value, will belong to this Priority Class.
(f) LAN Service: Based on the Service Interface Group associated with the packet.
6. Click Save.
IP DSCP Marking
With the IP DSCP Marking functionality, it is possible to set and manage the QoS DSCP values for selected
streams of IP traffic.
Inside the table shown under the IP DSCP Marking heading, a list of the already configured rules
appears. You can Edit and Delete configured QoS DSCP rules by clicking on the icons and
respectively of Action column.
In order to configure a new rule, press on Add New below the table and the QoS IP DSCP Marking
Rule page appears.
2. Select the direction of Traffic stream this rule applies to: Egress (Outgoing), Ingress (Incoming) or
Forwarded.
4. For Ingress or Forwarded streams, select the Source Connection / Service and optionally enter a
Host or Subnet address. Leave blank to allow any host.
5. Similarly, for Egress or Forwarded streams, configure the corresponding Destination values.
6. Set the Application parameters Direction, Protocol, Type and Port range.
7. Click Save.
With the VLAN CoS Marking functionality, it is possible to set and manage the QoS CoS values (802.1q
priority bits) for incoming and outgoing 802.1q VLAN tagged Ethernet frames.
Inside the table shown under the VLAN CoS Marking heading, a list of all configured VLANs appears.
This list contains all WAN connections for which a VLAN ID has been defined (please refer to section
Connections on page 80) as well as all VLANs defined for the LAN (please refer to section VLAN on
page 101).
You can Edit and Delete configured CoS Marking rules by clicking on the icons and respectively
of Action column.
When pressing the Edit icon for a specific VLAN ID value, the QoS VLAN CoS Marking page
appears (Figure 11.14). Using the corresponding drop-down lists, select how CoS values are mapped to
internal system Priority classes for all Incoming tagged frames with the specific VLAN ID. In the same
manner, for the reverse direction, select how internal system Priority classes are mapped to CoS values
for all Outgoing tagged frames with the specific VLAN ID.
If, on the other hand, the Delete icon is pressed for a specific VLAN ID value, all CoS value and
Priority class mappings for this VLAN are cleared.
Bandwidth
Using the Bandwidth tab of the QoS Policy sub-menu, it is possible to manually define the WAN
bandwidth available to the device over a specific WAN access interface type. This is essesntial for the
correct operation of the QoS mechanisms, in cases where the Oxygen Multiservice Gateway cannot
directly detect the available broadband bandwidth value. For example, in case of xDSL broadband
connections, the synchronization speed is usually equal to the available bandwidth. However, when we
have a WAN Ethernet connection, the local Ethernet link speed is not necessarily equal to the available
broadband speed and QoS rules cannot be correctly applied.
In cases like this, it is possible, using the corresponding input fields or the Bandwidth tab, to manually
set the maximum Download and/or Upload speed for the desired WAN Port type. Setting the value to
0 or leaving it empty, corresponds to the default use of the line sync values.
File Sharing
When your Oxygen Multiservice Gateway is equipped with a USB Host port (optional feature), it is possible
to connect an external storage device (USB stick, Hard Disk) to this port. The File Sharing sub-menu lets
you configure the protocols handling the advertising and sharing of a connected external USB storage
device for all computers on the LAN.
To this end, select Enabled for the file-sharing protocols you wish to activate, and click Apply in order
to activate and save your selection. Available options are UPnP (with optional activation of a special
Xbox profile), FTP server (with the option to Allow access from Internet) and SMB/CIFS for Windows PCs.
In the latter case, the Windows Workgroup value can also be configured along with the type of File
access provided: Full or Read-only.
Before unplugging an external storage device from the Oxygen Multiservice Gateway,
make sure you first Disconnect it using the icon under the Devices category of the
Home page or in the Interfaces sub-menu of the Status configuration menu. Removal
WARNING of the device without disconnecting first, may lead to corrupted data on the storage
device!
Printing
When your Oxygen Multiservice Gateway is equipped with a USB Host port (optional feature), it is possible
to connect a USB printer to this port. The Printing sub-menu lets you configure the protocols handling the
advertising and sharing of the connected USB printer for all computers on the LAN.
Select Enabled for the printing protocols you wish to activate, and click Apply in order to activate
and save your selection. Please refer to Appendix Network Printing on page 235 for more information
about the available options and the configuration process for the LAN PCs.
Note that some USB printers may not be supporting this functionality.
Note
The System menu allows the configuration and use of the following administrative utilities:
• SNMP for configuration of the Simple Network Management Protocol (see page 175 ).
• Syslog for controling the system logging service (see page 177 ).
• Remote Admin for allowing remote access to the device for administration and/or support
purposes (see page 178 ).
• Time-plan for managing system Time-of-Day profiles and events (see page 180 ).
• Change Password for modifying the device administration password (see page 182 ).
• Backup / Restore for backing-up the current or restoring a previous configuration of the device
(see page 184 ).
• Device Restart for restarting the device and optionally erasing the entire configuration (factory
defaults) (see page 186 ).
• Firmware Upgrade for performing a local or remote firmware upgrade (see page 187 ).
173
Oxygen Multiservice Gateway User’s Guide
SNMP
The Simple Network Management Protocol (SNMP) is a widely used networking management protocol
for remote management of all ranges of IP-enabled devices, including end-user devices like the Oxygen
Multiservice Gateway.
• Check the LAN checkbox in order to allow access to the SNMP service from hosts in the
local area network.
• Select ALL in order to allow incoming connections from any IP address, or restrict access for
the entered list of hosts or subnets (xxx.xxx.xxx.xxx/yy notation) seperated by comma (,).
6. Optionally enable Traps by sellecting the appropriate Method and set a trap Community and
Host.
7. Click Apply.
Syslog
Syslog is the logging service providing information about the operation of the Oxygen Multiservice
Gateway.
2. Select the desired Log level from the drop-down list. Only events falling into the selected and
above log-levels will be logged.
3. Optionally check Store in USB to store the syslog to an external storage drive.
4. Click Apply.
Using the Web interface of Oxygen Multiservice Gateway, log messages can be viewed in the
System Log page of the Status configuration menu (see page 193).
You can, optionally, also define a remote Syslog server for transmission of the log messages over the
network. To this end check the Remote logging checkbox and define the remote server’s Name or IP
address and the protocol Port (default syslog port is 514).
Finally, it is also possible to log access to specific pages of the Web GUI, by enabling Logging and
selecting the desired Log level.
Remote Admin
This sub-menu controls remote administration access to the Oxygen Multiservice Gateway. This may help
the support department of your Service Provider to configure the device remotely.
1. Select the WAN checkbox for each remote access services you wish to activate. The available
services for remote access are:
2. Optionally select the LAN checkbox for the services for which you want to have access also from
the local network.
3. For each selected access service optionally specify a port different than the well-known one (e.g.
port 8080 instead of 80 for HTTP).
4. Under WAN Interface, select the WAN Connection for remote access. Available options are ALL,
Default route and Selected. In the latter case check the appropriate WAN connection(s) in order
to allow incoming connections.
5. Specify Hosts as ALL in order to allow incoming connections from any IP address, or restrict remote
access for the selected methods for the entered list of hosts or subnets (xxx.xxx.xxx.xxx/yy notation)
seperated by comma (,).
6. Configure the time Interval, during which remote access will be enabled (default 60 min). After
this interval, remote access will be automatically deactivated.
7. Click Apply.
An Interval value equal to 0 will keep remote administration active until the next device
restart, whereas a value of -1 will keep it permanently active.
Note
At any moment, you can see the current remote administration status by clicking on the Support Info
key.
Time-plan
The Time-plan functionality allows the execution of periodic actions based on day and time patterns.
For example, it is possible to activate the WiFi functionality only during specific time periods and leave it
disabled during the rest.
The operation of Time-plan functionality relies on the presence of real-time date and
time information (please refer to section Date and Time on page 154).
Note
For the Time-plan functionality to operate, the first step is to define a Time Profile. A Time Profile
includes all information about the days and time-period when an action will be performed.
In order to add a new Time Profile entry, click Add New under the Time Profile heading and the
following fields will appear:
1. Name is a name used in order to distinguish between the different profiles. Note that names must
be unique among different profiles and that they cannot contain spaces and selected special
characters.
2. Time-plan is the start and end time for the defined profile.
4. Click Save.
Having defined the necessary Time Profile, the next step is to assign one or more Time Events to it. A
Time Event is the action performed at the day and time periods defined by the profile.
In order to add a new Time Event entry, click Add New under the Time Event heading and:
1. Under the Profile drop-down list select the desired Time Profile.
2. Under the Event drop-down list select the desired Time Action. Note that for some actions only the
Start Time applies from the selected Time Profile.
3. Click Save.
You can Delete Time Profile or Time Event entries by clicking on the icon of the corresponding
Action column.
Change Password
This sub-menu lets you change the password for the active user profiles of the Oxygen Multiservice
Gateway.
After changing the password you will have to restart your web browser and login again
using the new password value.
Note
Backup / Restore
This sub-menu allows you to save the current configuration of the Oxygen Multiservice Gateway as a
backup on a PC, and optionally restore it at a later time.
Backup Configuration
1. Click Backup.
A message window opens prompting you to save the file:
2. Specify the path where the file is to be saved and click Save.
It is possible to protect the saved backup file via File Encryption, by entering a Password value
before pressing the Backup button.
There is no way to recover the File Encryption Password if you forget it.
WARNING
Restore Configuration
1. Click Browse or Choose File to specify the path of the saved configuration file.
2. If the backup file has been saved using File Encryption, enter the correct Password value.
3. Click Restore.
The Oxygen Multiservice Gateway will be automatically restarted after the end of the
configuration-restore process.
WARNING
Device Restart
1. Optionally select the Erase Configuration checkbox in order to erase the current configuration
and restore the factory default one.
2. Click Restart.
Firmware Upgrade
This page allows you to upgrade the Oxygen Multiservice Gateway to the latest firmware version. This
can be performed locally, if you have the new firmware file stored on your PC, or optionally through the
Internet, if your ISP has configured a pre-defined server with the latest firmware version.
1. Click Browse or Choose File to specify the path of the firmware file.
2. Click Upgrade.
Use only the appropriate firmware file for the exact model of your Oxygen Multiservice
Gateway.
WARNING
If, on the other hand, your ISP has configured a web server with the latest firmware version, the
Automatic Upgrade heading is visible. Click Check in order to query the server for the latest firmware
release. If a newer compared to the one stored on your device release is available, a notification
message will appear.
Click Download in order to download the new firmware file and perform the upgrade.
The Oxygen Multiservice Gateway will be automatically restarted after the end of the
firmware-upgrade process.
WARNING
The Status menu displays device messages and statistics about local interfaces and internet connections.
It includes the following sub-menus:
• About for displaying general information about the device (see page 192 ).
• System Log for viewing system log entries (see page 193 ).
• Interfaces for displaying information for the Ethernet and (optional) USB interfaces (see page 195
).
• DSL Line for displaying status and statistics for the DSL broadband connection (see page 197 ).
• Wireless for a list of the connected WiFi clients and access points (AP) in range (WiFi-enabled
devices only) (see page 199 ).
• Phone Lines for viewing information about the active voice calls and the status of supplementary
services (see page 200 ).
• Call Details for viewing duration and history information for voice calls (see page 203 ).
• ISDN Interfaces for viewing information about the ISDN interfaces (see page 205 ).
• Firewall for displaying the current firewall status (see page 206 ).
189
Oxygen Multiservice Gateway User’s Guide
• VPN Service for displaying VPN service information (see page 209 ).
• Diagnostics for performing broadband connection and IP diagnostic tests (see page 210 ).
• Healthcheck for quickly checking the service operation status of the device (see page 212 ).
• Net Statistics for information about the LAN- and WAN-side network traffic (see page 214 ).
• IP Network for a list of addresses of IP interfaces, IP routes, DNS servers and active IP connections
(see page 216 ).
About
This page displays basic information about the device, including Model Type, Serial Number and
Firmware Versions.
System Log
The System Log page provides useful information about the operation of your Oxygen Multiservice
Gateway.
In case the Syslog service has not been activated, an error message appears notifying that you
should first activate the logging process (see section Syslog on page 177).
Finally, it is possible to download the current logs locally to your device, by clicking on the Download
button.
Interfaces
Ethernet Switch
This page displays information about the link, speed and duplex status of the LAN Ethernet Ports. It also
displays the service each port is assigned to (Interface Group), using the icons , and for the
Data, Voice and Video services respectively.
USB Devices
On the same page, it is also possible to find information about the status of connected Data Modems
and USB Devices (Storage disks or Printers) on the USB Host port of the Oxygen Multiservice Gateway
(optional feature).
When a data modem is detected, you can get detailed information about its status by clicking on
the Info icon , which appears in the Action column.
When, on the other hand, an external storage device is connected, the storage link appears. Follow
the icon in order to browse through the contents of the external storage device. At the same time,
the icon appears in the Action column. Use this icon to Disconnect the device before physically
unplugging it.
Before unplugging an external storage device from the Oxygen Multiservice Gateway
make sure you first Disconnect it using the icon under the Devices category of the
Home page or in the Interfaces sub-menu of the Status configuration menu. Removal
WARNING of the device without disconnecting first, may lead to corrupted data on the storage
device!
DSL Line
This page displays basic information about the DSL connection of the Oxygen Multiservice Gateway.
Available information includes connection status, type of connection, sync rates, signal quality and
error counters. Optionally you can also restart the DSL training process by clicking on the Retrain button.
Clicking on the Clear Counters button resets the DSL line statistics to 0.
Wireless
This page displays a list of the connected wireless clients, as well as a list of the wireless access points in
range of the Oxygen Multiservice Gateway (WiFi-enabled devices only).
By clicking on the Info icon next to each client entry, you can see more details about the
corresponding connected wireless client.
Phone Lines
This page displays information about the active voice calls and the status of basic supplementary services
for all phone lines. It also displays the relevant service activation and deactivation codes.
To activate for example a supplementary service such as Call Waiting you should press #**43# and
in order to deactivate it #*#43#. In the case of the Call Forward supplementary service, when activating
the service the target number must also be entered. For example, in order to activate Call Forward
Unconditional (CFU):
• then press #
The table below lists the specific codes for the most common supplementary services.
You can also see the codes for other supported supplementary services, by following the View Other
Supplementary Service Codes link, which leads to the following page:
Service Code
You can activate any other supplementary service using the sequence #**Code#,
Note deactivate using #*#Code# or check the current service status using #**#Code#.
Call Details
Specifically, it displays the total call duration for Local (between the local extensions of the Oxygen
Multiservice Gateway), Incoming and Outgoing calls. It also displays the Last Incoming and Last
Outgoing call for each line and finally a list of the Last Calls.
ISDN Interfaces
This page displays information about the status of ISDN interfaces of the Oxygen Multiservice Gateway;
For each ISDN interface, it is possible to see the Status, the Mode of operation (Terminal (TE) vs
Network (NT) and Point-to-Point (PTP) vs Point-to-Multipoint (PTMP)), the Link status of ISDN Layers 1 and
2, and finally the number of Errors and Active B-channels.
In order to debug the ISDN interfaces select the available Debug Capture Interface from the
drop-down list and click on the Start button. Click on Stop to stop the capturing and download the log
locally to your device. Use a program like Wireshark ( http://www.wireshark.org/ ) in order to open and
analyze the file.
Firewall
• Statically Forwarded Ports: which contains all active port forwarding rules (see section Port Forward
on page 131).
• UPnP/NAT-PMP Forwarded Ports: which contains ports forwarded automatically through the
corresponding protocols. (see section UPnP / NAT-PMP on page 133).
• Filtered IP Traffic: which displays the list of IP filtering rules. (see section IP Filters on page 134).
Below the list of the active firewall rules, this page also displays the Connection Tracking timeout
values as well as the maximum and current number of active IP connections. It is also possible to see a
detailed list of the IP connections. To this end you must follow the View Detailed Connection Tracking
link and a page similar to the following will appear:
Clients
This page provides a list of all clients connected to the Oxygen Multiservice Gateway.
By clicking on the Info icon next to each client entry, you can see more details about the
corresponding connected LAN client.
VPN Service
This page displays information about the SSL VPN and/or L2TP and/or IPSec VPN services running on the
Oxygen Multiservice Gateway (optional features).
For each VPN type, the current status of the service as well as details about connected VPN peers is
displayed.
Diagnostics
This page provides you with multiple tools useful to troubleshoot IP connectivity from your Oxygen
Multiservice Gateway.
Connectivity
There are different tests which can be used to test the IP connectivity of Oxygen Multiservice Gateway
to the LAN or WAN. You can perform a Ping test to check plain end-to-end connectivity, a Traceroute
test in order to identify also the intervening nodes or Arping to check connectivity using ARP request
method.
2. In case of Arping, select the appropriate Arping interface from the drop-down list.
3. Click either Ping, Traceroute or Arping in order to perform the corresponding IP connectivity test.
Healthcheck
This page displays health information about the status and connectivity of the Oxygen Multiservice
Gateway.
Net Statistics
This page displays graphs of LAN and Internet traffic statistics. Outbound and Inbound traffic is displayed
as separate lines on the corresponding graph, for both local (LAN) and broadband (Internet) traffic.
By clicking on each graph, a new page appears with more detailed information (Daily, Weekly
profiles).
IP Network
This sub-menu displays information about the IP interfaces and IP-related parameters for the network
operation of the Oxygen Multiservice Gateway.
Selecting one of the IPv4 or IPv6 tabs, there appears a list of the active IP Interfaces, the MAC
address table, the IP routing table (including static and dynamic routes), the IP routing rules and the
active Domain Name Service (DNS) servers.
If, on the other hand, the WAN or Traffic tab is selected, a list of WAN connections or LAN/WAN
interfaces appears along with their status and RX/TX traffic counters.
This chapter suggests solutions for problems you may encounter in installing or using the Oxygen
Multiservice Gateway, and provides instructions for using common IP utilities to diagnose problems.
217
Oxygen Multiservice Gateway User’s Guide
Once you have connected your hardware and configured your PCs, any computer on your LAN should
be able to use the device’s broadband connection to access the Internet. To test the connection, turn
on the device, wait for 60 seconds and then verify that the LEDs are illuminated as follows:
LED Behavior
Light Red during the boot sequence. Solid White
to indicate that the device has finished booting.
Power
If this light is not on, check the power cable
attachment.
Blinking White when a synchronization attempt
DSL is being performed. Solid White upon successful
synchronization.
Blinking White while trying to connect. Solid White
when a valid IP address has been assigned to
Internet
the device by the ISP. Solid Red when an invalid
username/password combination is being used.
Solid White to indicate active link on the corre-
Ethernet sponding Ethernet link. Blinking when the device
is sending or receiving data from the LAN.
Solid White to indicate that the Wireless LAN
Wireless connection is operational. Slow blinking while the
wireless operation is being turned on or off.
(WiFi-enabled devices only)
Solid White to indicate that the USB connection
USB
is operational.
Table 14.1: LED Indicators
If the LEDs illuminate as expected, test your Internet connection from a LAN computer. To do this,
open your web browser, and type the URL of any external website (such as http://www.yahoo.com ).
The device should connect to the site.
If the LEDs do not illuminate as expected, you may need to configure your Internet access settings
using the information provided by your ISP. If the LEDs still do not illuminate as expected or the web page
is not displayed, follow the Troubleshooting Suggestions presented in the next paragraph or contact your
ISP for assistance.
Troubleshooting Suggestions
LEDs
Verify that you are using the power adapter provided with
Power LED does not illuminate af-
the device and that it is securely connected to the Oxygen
ter product is turned on.
Multiservice Gateway and a wall socket/power strip.
Verify that a standard telephone cable (called an RJ-11
cable) like the one provided is securely connected to the
DSL LED does not illuminate after DSL port and your wall phone port. Allow about 60 seconds
phone cable is attached. (depending on the distance between the router and the
telephone exchange and on the quality of the telephone
line) for the device to negotiate a connection with your ISP.
Verify that the Ethernet cable is securely connected to your
PC or LAN switch and to the Oxygen Multiservice Gateway.
Make sure the PC and/or LAN switch is turned on. Verify that
your cable is sufficient for your network requirements. A 1
Ethernet LED does not illuminate
Gbit/sec (1000-BaseT) or 100 Mbit/sec network (100-BaseT)
after Ethernet cable is attached.
should use at least CAT 5 cables (including CAT 5e and CAT
6). Moreover, 1000Base-T requires all four cable pairs for
simultaneous transmission in both directions. A 10 Mbit/sec
network may tolerate lower quality cables.
Internet Access
Run a health check on your device. Use the Ping utility
(discussed in the following section) to check whether your PC
can communicate with the Oxygen Multiservice Gateway’s
LAN IP address (by default 192.168.1.1). If it cannot, check
first the Ethernet cabling. The Ethernet LED corresponding to
the Ethernet port being used must be lit or blinking. If you
statically assigned a private IP address to the computer, (not
a registered public address), verify the following:
My PC cannot access the Inter- • Check that the gateway IP address on the computer is
net Oxygen Multiservice Gateway’s LAN IP address (by default
192.168.1.1). If it is not, correct the address or configure the
PC to receive IP information automatically through DHCP.
Web pages
If you have not changed the password from the default,
try using user as username and the default password that is
printed on the label on the bottom of the device. Otherwise,
you can reset the device to the default configuration by
I forgot/lost my username or pass-
pressing the Reset button on the rear panel of the device
word.
(see Rear Panel on page 29). Then, type the default
username and password shown above.
WARNING: Resetting the device removes any custom
settings and returns all settings to their default values.
Use the Ping utility, discussed in the following section, to
check whether the PC can communicate with the device’s
LAN IP address (by default 192.168.1.1). If it cannot, check
the Ethernet cabling. Verify that you are using Microsoft
I cannot access the web pages Internet Explorer version 5.5 or newer, Mozilla Firefox 1.5 or
from my browser. newer, Google Chrome, Apple Safari version 1.2 or newer,
and that Javascript is enabled. Verify that the PC’s IP
address is configured as being on the same subnet as the IP
address assigned to the LAN port on the Oxygen Multiservice
Gateway.
Ping
Ping is a command you can use to check whether your PC can recognize other computers on your
network and the Internet. A ping command sends a message to the computer you specify. If the
computer receives the message, it sends messages in reply. To use it, you must know the IP address of
the computer with which you are trying to communicate.
On Windows-based computers, you can execute a ping command from the Start menu. Click the
Start button, and then click Run. In the Open text box, type a statement such as the following:
ping 192.168.1.1
Click OK . You can substitute any private IP address on your LAN or a public IP address for an Internet
site, if known.
If the target computer receives the message, a Command Prompt window is displayed:
If the target computer cannot be located, you will receive the message Request timed out.
Using the ping command, you can test whether the path to the Oxygen Multiservice Gateway is
working (using the preconfigured default LAN IP address 192.168.1.1) or another address you assigned.
You can also test whether access to the Internet is working by typing an external address, such as
that for www.yahoo.com as ping target. This way you test both DNS operation and IP connectivity.
From most other IP-enabled operating systems, you can execute the same command at a command
prompt or through a system administration utility.
nslookup
You can use the nslookup command to determine the IP address associated with an Internet site name.
You specify the common name, and the nslookup command looks up the name in on your DNS server
(usually your Oxygen Multiservice Gateway, which forwards requests to the DNS server of your ISP). If
that name is not an entry in your ISP’s DNS table, the request is then referred to another higher-level
server, and so on, until the entry is found. The server then returns the associated IP address.
On Windows-based computers, you can execute the nslookup command from the Start menu. Click
the Start button, and then click Run. In the Open text box, type the following:
nslookup
Click OK . A Command Prompt window is displayed with a bracket prompt (>). At the prompt, type
the name of the Internet address that you are interested in, such as www.microsoft.com.
The window will display the associate IP address, if known, as shown below:
There may be several addresses associated with an Internet name. This is common for web sites that
receive heavy traffic; they use multiple, redundant servers to carry the same information.
To exit from the nslookup utility, type exit and press [Enter] at the command prompt.
By default, the Oxygen Multiservice Gateway automatically assigns the required Internet settings to your
PCs.
• Follow the instructions that correspond to the operating system installed on your PC, in order to
configure it to accept IP addressing information assigned by the Oxygen Multiservice Gateway
(DHCP operation).
• If you want to allow Wireless PCs to access your device, follow the instructions in Configuring
Wireless PCs on page 226.
In some cases however, you may want to assign Internet information to some or all of your PCs
directly (often called "statically"), rather than allowing the Oxygen Multiservice Gateway to assign it. This
option may be desirable (but not required) if:
• You have obtained one or more public IP addresses that you want to always associate with
specific computers (for example, if you are using a computer as a public web server).
225
Oxygen Multiservice Gateway User’s Guide
• You maintain different subnets on your LAN (subnets are described in Appendix B).
Before you begin, you must have the following information available:
• The IP address of the default gateway for your LAN. In most cases, this is the address assigned to
the LAN port on the Oxygen Multiservice Gateway. By default, the LAN port is assigned the IP
address 192.168.1.1. (You can change this number or another number can be assigned by your
ISP.)
On each PC to which you want to assign static information, follow the instructions that correspond to
the operating system installed on your PC for static IP address configuration.
Your PCs must have IP addresses that place them in the same subnet as the Oxygen
Multiservice Gateway’s Data LAN port.
Note
The wireless network cards used determine the maximum distance between your wireless PCs and your
device. Guidelines on positioning the hardware components of your wireless network should be provided
by your network card provider.
Each PC on your wireless LAN must be fitted with a wireless access card. You must also install the
corresponding driver files for your particular wireless card on your PC. You should receive driver files and
instructions on how to install them together with your wireless card.
Before you start configuring your Wireless PC, you must ensure that you have:
The configuration steps below will vary depending on both the operating system and wireless card
installed on the PC. These steps provide a basic outline, however you should refer to the documentation
provided with your wireless access card for specific instructions. To configure Wireless PCs:
Set the adapter to use infrastructure mode. This configures the PCs to access each other and
the Internet via the Oxygen Multiservice Gateway.
Configure the SSID, encryption method and channel to match the corresponding values previ-
ously configured on the device. (see Configuration on page 123). Default values are shown in
Table 4.2 on page 64.
4. Configure TCP/IP setting for the operating system installed on your Wireless enabled PCs using the
same procedure described for Configuring Ethernet PCs on page 225.
Your wireless network can now communicate with the Internet via the device.
on page 123). Default values are shown in Table 4.2 on page 64.
This section refers only to IP addresses for IPv4 (version 4 of the Internet Protocol). IPv6
addresses are not covered. This section assumes basic knowledge of binary numbers,
Note bits and bytes.
IP addresses, the Internet’s version of telephone numbers, are used to identify individual nodes
(computers or devices) on the Internet. Every IP address contains four numbers, each from 0 to 255 and
separated by dots (periods), e.g. 20.56.0.211. These numbers are called, from left to right, field1, field2,
field3, and field4.
This style of writing IP addresses as decimal numbers separated by dots is called dotted decimal
notation. The IP address 20.56.0.211 is read "twenty dot fifty-six dot zero dot two-eleven."
Structure of an IP Address
IP addresses have a hierarchical design similar to that of telephone numbers. For example, a 7-digit
telephone number starts with a 3-digit prefix that identifies a group of thousands of telephone lines, and
ends with four digits that identify one specific line in that group. Similarly, IP addresses contain two kinds
of information:
229
Oxygen Multiservice Gateway User’s Guide
• Network ID
Identifies a particular network within the Internet or intranet
• Host ID
Identifies a particular computer or device on the network
The first part of every IP address contains the network ID, and the rest of the address contains the host
ID. The length of the network ID depends on the network’s class (see following section). The table below
shows the structure of an IP address.
Network Classes
The three commonly used network classes are A, B, and C. (There is also a class D but it has a special
use beyond the scope of this discussion.) These classes have different uses and characteristics.
Class A networks are the Internet’s largest networks, each with room for over 16 million hosts. Up to
126 of these huge networks can exist, for a total of over 2 billion hosts. Because of their huge size, these
networks are used for WANs and by organizations at the infrastructure level of the Internet, such as your
ISP.
Class B networks are smaller but still quite large, each able to hold over 65,000 hosts. There can be up
to 16,384 class B networks in existence. A class B network might be appropriate for a large organization
such as a business or government agency.
Class C networks are the smallest, only able to hold 254 hosts at most, but the total possible number
of class C networks exceeds 2 million (2,097,152 to be exact). LANs connected to the Internet are usually
class C networks.
• A host ID can have any value except all fields set to 0 or all fields set to 255, as those values are
reserved for special uses.
Subnet Masks
A mask looks like a regular IP address, but contains a pattern of bits that tells what parts of an IP address
are the network ID and what parts are the host ID: bits set to 1 mean "this bit is part of the network ID"
and bits set to 0 mean "this bit is part of the host ID".
Subnet masks are used to define subnets (what you get after dividing a network into smaller pieces).
A subnet’s network ID is created by "borrowing" one or more bits from the host ID portion of the address.
The subnet mask identifies these host ID bits.
For example, consider a class C network 192.168.1.0. To split this into two subnets, you would use the
subnet mask:
255.255.255.128
As with any class C address, all of the bits in field1 through field3 are part of the network ID, but note
how the mask specifies that the first bit in field4 is also included. Since this extra bit has only two values (0
and 1), this means there are two subnets. Each subnet uses the remaining 7 bits in field4 for its host IDs,
which range from 1 to 126 hosts (instead of the usual 0 to 255 for a class C address).
Similarly, to split a class C network into four subnets, the mask is:
255.255.255.192 or 11111111.11111111.11111111.11000000
The two extra bits in field4 can have four values (00, 01, 10, 11), so there are four subnets. Each
subnet uses the remaining six bits in field4 for its host IDs, ranging from 1 to 62.
A different way used in order to identify the subnet mask of a network, is using the xxx.xxx.xxx.xxx/yy
notation, where xxx.xxx.xxx.xxx is the network address and yy is the length of the mask in bits. This way,
the network 192.168.1.0 with subnet mask 255.255.255.128, which was described above, can be written
as:
192.168.1.0/25
whereas the same network with subnet mask 255.255.255.192, can be written as:
192.168.1.0/26
Sometimes a subnet mask does not specify any additional network ID bits, and thus no
subnets. Such a mask is called a default subnet mask. These masks are:
Class A:255.0.0.0
Class B:255.255.0.0
Note Class C:255.255.255.0
These are called default because they are used when a network is initially configured, at
which time it has no subnets.
• Wired Equivalent Privacy (WEP): a widely used, but deprecated wireless security method because
of the deficiencies found in its encryption algorithm.
• Wi-Fi Protected Access (WPA): an encryption method that provides superior security compared
to WEP. It has been introduced as an intermediate measure to take the place of WEP until the
preparation of the full IEEE 802.11i standard and implements the majority of the latter.
• Wi-Fi Protected Access 2 (WPA2): the encryption method that implements the mandatory
elements of the IEEE 802.11i standard and replaced WPA.
As mentioned, WEP is a legacy security method which has proven to be vulnerable to external
attacks and for this reason has been replaced by WPA2, with WPA being an intermediate step during
the WEP-to-WPA2 transition (also proven to be vulnerable to external attacks).
In order to be able to use the WPA2 security algorithm, however, one has to make sure that it is supported
by both the Operating System of his PC and the driver of the PC’s wireless card. Unfortunately, there are
233
Oxygen Multiservice Gateway User’s Guide
cases of legacy equipment where there is only support for WEP or there is support for the interim WPA
and not for the final 802.11i (i.e. WPA2) standard.
In the case of Microsoft Windows, WPA and WPA2 support is offered either by default or through an
update according to the following:
• Windows XP with Service Pack 3 (SP3) and newer (e.g. Windows Vista, Windows 7, Windows Server
2008): WPA and WPA2 are supported by default.
• Windows XP SP2: WPA (but not WPA2) is supported by default. In order to add support for WPA2,
one has either to upgrade to SP3 or to install the Wireless Client Update for Windows XP with
Service Pack 2 from Microsoft (see http://support.microsoft.com/kb/917021 ).
• Windows XP SP1: neither WPA nor WPA2 are supported by default. In order to add support for
both WPA and WPA2, one has to upgrade to newer SP versions. Alternatively, WPA (but not
WPA2) support can be added by installing the Windows XP Support Patch for Wi-Fi Protected
Access from Microsoft (see http://support.microsoft.com/kb/815485 ).
Computers with Windows versions older than Windows XP SP1, do not offer WPA and/or WPA2 support
and must be upgraded to newer OS versions in order to do so.
• AppSocket/JetDirect
The user can configure the printing system using the Web configuration pages, under the Printing
sub-menu of the Advanced configuration menu. Additionally, the current status of a connected printer
can be seen in the Interfaces page of the Status configuration menu.
AppSocket / JetDirect
This is the most efficient way to use the printer. With this method, the PC provides the printing data as
soon as they are going to be printed, requiring this way no spooling (and thus no storage space) in the
Oxygen Multiservice Gateway. As a consequence, there is no limit on the size of the submitted print jobs.
1. In the Windows task bar, click the Start button, point to Settings, and then click Printers and Faxes.
235
Oxygen Multiservice Gateway User’s Guide
4. Make sure that the Automatically detect and install my Plug and Play printer option is NOT
selected and click Next.
5. Select Create a new port and Standard TCP/IP Port as Type of port. Click Next.
6. The Add Standard TCP/IP Printer Port Wizard is activated Click Next.
7. Enter 192.168.1.1 in the Printer Name or IP Address field, and click Next.
9. In the Configure Standard TCP/IP Port Monitor window that appears, select the Raw radio button,
verify that the Port Number is 9100, and finally click OK.
10. Click Finish to exit the Add Standard TCP/IP Printer Port Wizard and continue with the installation
process.
11. If prompted to install a driver for the printer, select the printer’s make and model from the displayed
list or click Have disk in order to specify a driver location.
13. Click Finish to exit the wizard and finish the printer installation process.
This method is based on a spooling server, embedded into the Oxygen Multiservice Gateway, which
uses the IPP protocol. This alternative requires the use of local storage space in the Oxygen Multiservice
Gateway, which naturally imposes an upper limit to the size of submitted print jobs. In normal situations,
printing jobs are roughly limited to 40-60 pages.
1. In the Windows task bar, click the Start button, point to Settings, and then click Printers and Faxes.
6. If prompted to install a driver for the printer, select the printer’s make and model from the displayed
list or click Have disk in order to specify a driver location.
8. Click Finish to exit the wizard and finish the printer installation process.
The IP address 192.168.1.1 used in all the configuration examples, is the default LAN
IP address of your Oxygen Multiservice Gateway. Make sure you modify the value
Note accordingly, if you have manually changed the LAN IP address of your device.
Some of the network printing protocols described above may not be available in specific
Oxygen Multiservice Gateway firmware versions.
Note
The list of features supported by the Oxygen Broadband Oxygen series of broadband access devices,
include the creation of a secure, SSL-based Virtual Private Network (VPN) connection.
A VPN connection is the creation of an encrypted tunnel between two endpoints (e.g. the PC of a
remote user and the Oxygen Multiservice Gateway) for the secure and reliable exchange of data. This
way, remote users or sites have access to files and networking resources in a central location just as if
they were physically present.
An SSL VPN is a form of VPN that uses the SSL (Secure Sockets Layer) protocol for ensuring the
security of data transmitted over the Internet. The Oxygen SSL-VPN feature is based on the widely used
opensource OpenVPN project ( http://openvpn.net/ ).
The Oxygen broadband devices support both Server and Client modes for the SSL-VPN Tunnel. This
means that we can use an Oxygen Multiservice Gateway as server at the central site and different
remote users connect to it using their PCs (with software clients) or use another Oxygen terminal from a
remote site.
Configuration of the corresponding parameters is performed using the Web configuration tool, in
239
Oxygen Multiservice Gateway User’s Guide
the SSL VPN sub-menu of the Advanced menu category (see page 155). The first task to be performed
once we enter this configuration page, is to enable the service using the appropriate Status radio button
and to choose whether the device will operate as a Server or as a Client in the SSL-VPN tunnel using the
Operation Mode drop-down list (see Figure 11.3 in page 155).
An important selection for the operation of the VPN tunnel, is its type: Routed or Bridged.
In a Routed VPN tunnel, connection between the server and client is in the IP level. This practically
means that they both have their separate and independent LAN subnets, with non-overlapping ranges
of IP addresses and these subnets are interconnected through the SSL VPN tunnel. Forwarding of the
packets between the different subnets is performed based on the destination IP address.
In a Bridged VPN tunnel, on the other hand, connection between the server and the client is
performed in the Ethernet layer. This results in a simpler network topology, where the LAN subnets behind
the server and the client operate like a single IP network, with the same range of IP addresses. Just as if
they were connected by an Ethernet switch.
The choice between the above two types of tunnels, is not always very easy however. Routed tunnels
are the most common choice, since they are more straightforward to configure and troubleshoot. The
tricky part in configuring Routed tunnels is how to verify, in certain cases, that all hosts in the LANs behind
the server and the client have the proper routing information in order to forward packets through the
VPN tunnel. Additionally, when a Routed tunnel is used, only IP packets traverse it. This means that
applications and services which rely on non-IP protocols or on IP broadcasts (e.g. Windows "Network
Neighborhood"), fail to operate accross the tunnel.
Bridged tunnels, on the other hand, are more difficult to handle. Bridged connections are difficult
to troubleshoot and the corresponding functionality is even absent in some older versions of the PC
Operating Systems. They have the advantage that by bridging the two LANs behind the server and the
client they solve the problem of applications depending on IP broadcasts, however, this can also be
the source of serious network degradation: since the VPN tunnels operate over a, usually low-bandwidth
WAN link, the true capacity of the link can be substabtially reduced by unnecessary broadcast traffic
that should be limited to the high-bandwidth LAN.
When using the Oxygen Multiservice Gateway in Bridged Mode, make sure that ONLY
one DHCP server is active on both sides of the Layer-2 VPN link.
WARNING
Server Mode
When Oxygen Multiservice Gateway is configured to run in Server mode, the configuration page
presented in Figure 11.4 appears. When using a Routed type of tunnel, to configure your device,
you must specify the Network and Netmask values for the subnet used as an IP address pool for the
connected clients. Each remote client that connects to the Oxygen SSL-VPN server will automatically
acquire an IP address from this pool. If, on the other hand, you have selected a Bridged type of tunnel,
no IP addressing info is required and you must only select which LAN Service is going to be bridged over
the SSL VPN tunnel. The DHCP server of the selected Service is also going to be used for providing IP
addressing information to any requests received over the tunnel. Once you have entered the correct
values, click Apply in order to activate your settings.
The final step in order to finish setting up the SSL-VPN server, is to define remote users and generate
the corresponding certificates. To this end click the Manage key under the Users heading. The page
presented in Figure 11.5 appears. The table at the top of the page, displays a list of the configured users.
You can Revoke configured users by clicking on the corresponding icon of Action column.
In order to add a new remote user, enter the username under the Add New User heading and click
the Save key. The new user is added and a message window opens prompting you to save a zip file.
This zip file contains the certificates corresponding to the added user. Save the file and give it using a
secure method (e.g. not via e-mail) to the new remote user. The zip file contains all information needed
in order to connect to the SSL-VPN server running on your Oxygen Multiservice Gateway.
If you have configured IP static routes on your Oxygen SSL-VPN server, these routes are
automatically going to be passed to every client upon successful connection.
Note
Client Mode
When Oxygen Multiservice Gateway is configured to run in Client mode, the following fields appear in
the SSL-VPN web configuration page presented in Figure 11.3. The first task is to specify the hostname or
IP address of the SSL-VPN server in the Host/IP field. When using a Routed type of tunnel, it is also possible
to select if NAT (Network Address Translation) is going to be used over the tunnel. This way, once the
server assigns an IP address to the client, all devices in the LAN behind the client Oxygen Multiservice
Gateway are going to appear to the server as if they have the client’s VPN tunnel IP address. If, on
the other hand, you have selected a Bridged type of tunnel, you must only select which LAN Service is
going to be bridged over the SSL VPN tunnel. Once you have entered the correct values, click Apply in
order to activate your settings.
In order to finish with the secure connection to the SSL-VPN server, you will also need to install the
corresponding certificate files. These certificates must be provided to you by the administrator of the
SSL-VPN server. In the case of an Oxygen Multiservice Gateway acting as the server, this is the zip file
that was generated once the username was added to the users database. The zip file containing all the
appropriate certificate files can be uploaded using the Browse key and finally by clicking the Upload
key.
After successfully uploading the zip file, the last step you may have to perform (unless your SSL VPN
server uses the Dynamic DNS Service), is to correctly specify the public IP address of the VPN Server in
the Host/IP field.
PC Client
In order to connect from a PC to an Oxygen Multiservice Gateway configured to run in Server mode, you
will need to install the OpenVPN client. To download OpenVPN, go to http://openvpn.net/download.html
.
For Microsoft Windows 2000 or later versions, a self-installing exe file can be downloaded. It is highly
recommended that you install OpenVPN version 2.1 or later, since it includes a GUI that significantly
simplifies the OpenVPN operation.
After running the Windows installer, OpenVPN is ready to use. The last thing remaining before being
able to connect to the Oxygen server is to install the corresponding certificate files. To this end, you
must unzip the zip file that was generated by the server upon the user creation. The correct path for
an installation including the OpenVPN GUI is usually under Program Files/OpenVPN/config/.
Place all files contained in the zip archive into this directory. The file connect.ovpn is the main
configuration file containing all the OpenVPN connection parameters.
If your Oxygen server is using the Dynamic DNS service in order to update its dynamic IP address,
you are ready to connect since the connect.ovpn file already contains the corresponding hostname of
the server. Otherwise, you must manually edit the connect.ovpn file and modify accordingly the line
starting with the keyword remote. The syntax of the command is
where server is the hostname or IP address of the OpenVPN server and port is equal to 1194.
Once the connect.ovpn file contains the correct hostname or IP address of the OpenVPN server,
you are ready to connect. You can connect directly from the connect.ovpn file by right-clicking and
selecting Start OpenVPN on this configuration file. Once running, you can use the F4 key to exit.
Alternatively, if you have installed the GUI, start it. The icon appears on the taskbar. Right-click
on it and select Connect in order to start the SSL-VPN connection towards the Oxygen server. Once
connected, the red screens on the GUI icon will turn into green and a notification will appear with the
assigned IP address.
Please refer to http://openvpn.net/ for more detailed information about OpenVPN installation and
configuration for Windows-based PCs but also for other operating systems.
In order to connect from an Android smartphone or table to an Oxygen Multiservice Gateway configured
to run in Server mode, you will need to install the OpenVPN for Android client, which can be found in
Google Play.
After installing the OpenVPN for Android, the next step is to create an appropriate VPN profile. To this
end you must first create a new VPN user on the Oxygen VPN server and then transfer to your Android
device all files contained in the the zip archive that was generated by the server upon the user creation
(seperate files, not in zip format). After having transfered the appropriate configuration and certificate
files to your Android device, start the OpenVPN for Android application and press the folder icon on the
lower-right corner of the screen.
Next step is to select the appropriate connect.ovpn configuration file, which contains all the
OpenVPN connection parameters. After selecting it, the configuration file is loaded and verified by the
device and, if everything is correct, a new VPN profile is generated.
If your Oxygen server is using the Dynamic DNS service in order to update its dynamic IP address,
you are ready to connect, since the configuraion file already contains the corresponding hostname of
the server. Otherwise, you must manually configure the correct Server Address. To this end, press the
Edit button, select the Basic settings menu and finally configure the correct Server Address.
Figure E.3: Importing File Figure E.4: File Validation Figure E.5: New VPN Profile
Figure E.6: Editing VPN Profile Figure E.7: Setting Server Address
Once the profile has been successfully created, you are ready to connect. You can connect by
pressing on the profile name. Logging information will appear.
Once connected, you can see status information on the top menu of your screen.
You must use the same Type (Routed or Bridged) on both ends of the SSL VPN tunnel,
or otherwise the two devices will fail to connect.
WARNING
In the following paragraphs you can find instructions of the key sequences used in order to handle
these supplementary services.
Call Hold
Illustration Action
active on hold
A A
A presses R
dial tone
C C * a dial tone is generated
247
Oxygen Multiservice Gateway User’s Guide
B B
active active
A A
A presses R0
on hold
C C
active
A A
A presses R1
active
on hold
C C
Call Waiting
Illustration Action
active active
A A
A presses R0
incoming
C C
active on hold
A A
A presses R2
active
on hold
C C
active on hold
A A
A presses R2
active
incoming
C C
active
A A
A presses R1
active
incoming
C C
Call Transfer
Illustration Action
on hold
A A
A presses R4
active
active
C C
3-Party Call
Illustration Action
on hold active
A A
A presses R3
active
active
C C
active on hold
A A
A presses R2
on hold
active
on hold active
A A
A presses R
active
on hold
The Oxygen Multiservice Gateway is optionally equipped with one or more ISDN interfaces (BRI or PRI).
These ISDN interfaces are programmable and can be configured to operate either in Terminal (TE) or
Network (NT) mode . Terminal (TE) mode must be selected in order to connect the interface to an ISDN
Network Termination Unit (NT) and the public ISDN network. On the other hand, Network (NT) mode
must be selected in order to connect to an ISDN PBX or and ISDN phone replacing the ISDN Network
Termination Unit and the public ISDN network with the broadband VoIP network.
Although programmable, you will need a different type of cable for each mode of operation. The
default pinout of both BRI and PRI ISDN interfaces corresponds to NT mode of operation. This means
that, when a port is configured to operate in Network (NT) mode, a straight-through cable must be used
for the connection to the corresponding TE ISDN interface (see tables G.2 and G.4). On the other hand,
when a port is configured to operate in Terminal (TE) mode, an ISDN crossover cable is required (see
tables G.3 and G.5).
The BRI S-Interface is a 4-wire interface, with separate Transmit and Receive pairs. It can operate in four
modes:
251
Oxygen Multiservice Gateway User’s Guide
• Point-to-Point: allows one TE (Terminal Equipment) device that may be up to 1 km from the NT
(Network Termination) unit.
• Short Passive Bus: allows connection of up to 8 TE devices in parallel on the S/T bus. Each TE
terminal can be connected at any point of the bus within 100 to 200 meters from the NT unit.
• Extended Passive Bus: allows connection to 8 TE terminals at distances of up to 500 meters from
the NT terminal. All TE devices are situated at the end of the bus, with maximum distance between
them 25 - 50 meters.
An ISDN S-bus must be terminated twice, once at the start and once at the end of the bus, with
100-ohm resistors. In the common case that the NT unit is at one end of the bus, the NT will have 100-ohm
terminators applied, and the farthest TE terminal device will have 100-ohm terminator.
Termination Switches
When configured to operate in Network (NT) mode, the Oxygen Multiservice Gateway BRI interface
emulates the NT unit, whereas when configured to operate in Terminal (TE) mode, it emulates the TE
terminal. In either case, depending on the bus topology, it frequently must be terminated with 100-ohm
resistance. To this end, the Oxygen Multiservice Gateway has for each BRI interface configurable
switches to apply a 100-ohm termination to the S-Interface signal pairs (On position) or not (Off position).
These switches, depending on the Oxygen Multiservice Gateway model, are located either above or
below the BRI interfaces or at the bottom of the device.
There are ITU-T standards which define the maximum acceptable clock signal deviations of each
endpoint from the reference specified clock frequency in ppm (parts-per-million). The corresponding
limits are:
Oxygen Multiservice Gateway internal PLL crystal specifications are much more accurate than the
maximum acceptable deviations indicated by the ISDN recommendations, allowing deviations of up to
±25 ppm.
When endpoints are not synchronized, they each run on their own internally-generated clock signals
(free-running). These unsynchronized free-running clock signals are obviously not running at the exact
same frequency, because of normal hardware deviations. This way, a gradual drift is observed between
the different clock signals leading the clock signals away from each other and a periodical clock (or
frame) slip happens.
255
Oxygen Multiservice Gateway User’s Guide
By definition, a clock slip is the repetition or deletion of a bit (or block of bits) in a synchronous
data stream, due to a discrepancy in the read and write rates at a buffer. Traffic received on an ISDN
interface is inside repeating bit patterns called frames; each frame is a fixed number of bits. The receiving
device simply counts the number of bits in order to determine the start and end of a frame and thus
knows exactly when to expect the end of a frame. However, if the timing between the sending and
the receiving device is not the same, the receiving device might sample the bit stream at the wrong
moment, which results in the return of an incorrect value. This condition is known as a clock slip.
Typical cases where the ISDN synchronization problem appears, is when an ISDN PBX has multiple
trunk lines, which are connected to different Oxygen Multiservice Gateway devices or to a Oxygen
Multiservice Gateway and the PSTN. The PBX expects a synchronous clock on all trunk lines. However,
unless the different Oxygen Multiservice Gateway devices and/or the PSTN are connected to a common
reference clock, the Oxygen Multiservice Gateway clock and the PSTN clock will not be synchronous
leading into bit-slips between different trunk lines of the PBX. These slips do not cause significant problems
with voice calls (small voice errors bearly noticable by the human ear), however fax and modem calls
are significantly affected.
The only universally applicable solution to overcome this problem is to have a common network
clock. In the presence of a PSTN connection to the PBX, the Oxygen Multiservice Gateway device(s)
must be connected to a reference network/clock common with the PSTN or to the PSTN itself. The way
to achieve this is via the special Sync Port which exists on Oxygen Multiservice Gateway models with BRI
or PRI interfaces. As shown in Figure H.1, with this port it is possible to connect the Oxygen Multiservice
Gateway to a reference clock or to the PSTN itself, either directly or via the available Sync Module
accessory (model-dependent).
If, on the other hand, only Oxygen Multiservice Gateway devices are connected to the PBX, the
solution is exactly the same: connect all Oxygen Multiservice Gateway devices to a common reference
clock or use one of them as reference. In the latter case, one Oxygen Multiservice Gateway will serve
as the reference clock MASTER, whereas the rest of the devices (SLAVE(s)) will get clocking information
from the MASTER (e.g. daisy-chain of the SLAVE(s) on the MASTER via an ISDN S-Bus) (Figure H.2).
Term Description
6to4 It is an IPv6 transition technology. This mechanism allows IPv6 sites to communi-
cate with each other over the IPv4 network without explicit tunnel setup. These
sites communicate with native IPv6 domains via relay routers. Using 6 to 4,
IPv6 hosts do not require IPv4-compatible IPv6 addresses or configured tunnels.
Therefore, IPv6 gains considerable independence of the underlying wide area
network and can step over many hops of IPv4 subnets.
802.1q The standard issued by the IEEE defining VLAN tagging in Ethernet networks.
See VLAN.
802.11 A family of specifications for wireless LANs developed by the IEEE. This is an
Ethernet protocol, often called Wi-Fi. The 802.11 family includes many different
modulation techniques that use the same basic protocol, the most popular of
which are 802.11b, 802.11g, 802.11a and the emerging 802.11n.
10BASE-T A designation for the type of Ethernet networks with a data rate of 10 Mbps.
See Ethernet.
100BASE-T A designation for the type of Ethernet networks with a data rate of 100 Mbps.
See Ethernet.
ACS Server Auto-Configuration Server
The ACS is a server responsible for the configuration of the end-user devices in a
broadband network using the TR-069 protocol.
259
Oxygen Multiservice Gateway User’s Guide
Bridged EoA Bridged EoA connections enable an ADSL CPE to bridge Ethernet frames
between the LAN and the WAN just like a normal Ethernet switch, the only
difference being that WAN Ethernet frames are encapsulated into AAL5 using
RFC 1483/2684 bridging.
See EoA.
Bridging Passing data from your network to your ISP and vice versa using the hardware
addresses of the devices at each location. Bridging contrasts with routing which
can add more intelligence to data transfers by using network addresses instead.
The Oxygen Multiservice Gateway can perform both routing and bridging.
See Routing.
Broadband A telecommunications technology that can send different types of data over the
same medium using multiple frequencies, which can be divided into frequency
channels. This apparently leads into an increase of the effective rate of
transmission, since multiple pieces of data are sent simultaneously. DSL is a
broadband technology.
Broadcast To send data to all computers on a network.
Broadcast SSID The routinely transmission of the Wi-Fi network name (SSID) into open air by
wireless access points and routers. Disabling SSID broadcasts, makes the WiFi
network invisible unless a user already knows the SSID value.
See SSID.
CAP Carrier-less Amplitude/Phase
In CAP modulation; incoming data modulates a single carrier that is then
transmitted down a telephone line. The carrier itself is suppressed before
transmission (it contains no information, and can be reconstructed at the
receiver), hence the adjective "carrier-less." CAP and DMT are two modulation
systems on the market for ADSL.
CBR Constant Bit Rate
A service category defined by the ATM Forum for applications and services
which have very stringent cell loss, delay and delay variation requirements.
Cell The basic unit of information transfer in the ATM network. The cell is comprised
of 53 bytes, with five of the bytes making up the header field and the remaining
48 bytes forming the user information field.
See ATM.
Certificate An electronic document which incorporates a digital signature to bind together
a public key with an identity. The public key is used to encrypt information and
a private key is used to decrypt it.
Certificate Authority A certificate authority issues digital certificates and once queried verifies if a
certificate presented is genuine or not.
Channel A transmission path between two points. The term channel usually refers to a
one-way path, but when paths in the two directions of transmission are always
associated, the term channel can refer to this two-way path.
CIFS Common Internet File System
See SMB/CIFS.
Codec COder-DECoder
A device or program capable of encoding and/or decoding a digital data
stream or signal. In VoIP codec represents the encoding method used for the
voice stream data.
Coding Gain The increase in efficiency that a coded signal provides over an uncoded signal.
Expressed in decibels (dB), it is the measure in the difference between the SNR
levels of the uncoded and coded systems required to reach the same BER levels.
An improvement in coding gain can provide the option of achieving the same
efficiency over a link with reduced transmission power or bandwidth.
CPE Customer Premises Equipment
Any equipment provided by the customer at their premises.
CRC Cyclic Redundancy Check
CRC is a method of checking for errors in data transmitted. Using this technique,
the transmitter appends an extra field to every frame of data. This field holds
redundant information about the frame that helps the receiver detect errors in
the frame.
Crossover Ethernet Cable A type of Ethernet cable that is used to interconnect two computers by "crossing
over" (reversing) their respective PIN contacts.
Crosstalk Crosstalk is an undesired coupling from one telecommunication circuit or medium
to another. It is caused by the electric or magnetic fields of one signal affecting
a signal in an adjacent circuit. For example, in a telephone circuit, crosstalk can
result in your hearing part of a voice conversation from another circuit.
Decibel (dB) A measure of signal intensity. It’s a logarithmic unit, so an increase in 3dB is equal
to double the original intensity.
DECT Digital Enhanced Cordless Telecommunications
An ETSI standard for digital portable phones (cordless home telephones), com-
monly used for domestic or corporate purposes.
Default Route The network route used when no other known route exists for a given IP packet’s
destination IP address.
DHCP Dynamic Host Configuration Protocol
DHCP automates address assignment and management. When a computer
connects to the LAN, DHCP assigns it an IP address from a shared pool of IP
addresses; after a specified time limit, DHCP returns the address to the pool.
DHCP Lease Dynamic Host Configuration Protocol Lease
The automatic assignment of network settings using the DHCP protocol. Each
DHCP lease can be static (permanent) or dynamic. In the latter case, it is
characterized by a lease time, which determines the validity period of the lease.
DHCP Relay Dynamic Host Configuration Protocol Relay
A DHCP relay is a computer that forwards DHCP data between computers that
request IP addresses and the DHCP server that assigns the addresses. Each of
the Oxygen Multiservice Gateway’s interfaces can be configured as a DHCP
relay.
See DHCP.
Dynamic IP Addressing The automatic assignment of network settings to computers or other networked
devices. Network settings obtained under a dynamic IP addressing scheme are
usually valid for a specific period of time and must be refreshed or reconfigured
in order to continue operation of the device. This is the most common policy
used by ISPs for their customers and the protocols used are either IPCP (part of
PPP) or DHCP. Compare with Static IP Addressing.
Dynamic IP Routing The use of a special IP routing protocol (e.g. RIP) for the advertisement and
the application of routing entries in the routing table of a networked device.
Compare with Static IP Routing.
DynDNS See Dynamic DNS.
EC Echo Cancellation
One of the two ADSL modes of operation (the other is FDM). In the EC mode,
two separate bands are allocated in the ADSL frequency spectrum: one to
POTS, and one is shared by the Upstream and the Downstream. The Upstream
signal overlaps the lower spectrum of the Downstream signals and this overlap is
resolved by Echo Cancellation techniques.
See FDM.
Encapsulation In general, encapsulation is the inclusion of one protocol within another one
so that the included protocol is not apparent. In ADSL with encapsulation we
typically refer to the LLC and VCMux methods used for the transmission of IP
packets over the ATM link.
Encryption Key The key encrypts data over the WLAN, and only wireless PCs configured with a
key that corresponds to the key configured on the Oxygen Multiservice Gateway
can send/receive encrypted data.
EoA Ethernet over ATM
Ethernet frames are simply encapsulated into the ATM Adaptation Layer 5 (AAL5)
using RFC 1483/2684 bridging. In EoA routed connections the device obtains its
own IP address on the WAN interface and performs routing between the LAN
devices and the Internet, whereas in bridged mode it performs pure Ethernet
bridging between the two networks. In the former case, IP address management
is either static or dynamic with the use of DHCP session management.
Ethernet The most commonly installed computer network technology, usually using twisted
pair wiring. Ethernet data rates are 10 Mbps and 100 Mbps.
See also 10BASE-T, 100BASE-T, Twisted Pair.
EUI-64 It is derived from the interface’s 48-bit MAC address. A MAC address
00:1D:1C:06:37:64 is turned into a 64-bit EUI-64 by inserting FF:FE in the mid-
dle: 00:1D:1C:FF:FE:06:37:64. To form an IPv6 address, the meaning of the
Universal/Local bit (the 7th most significant bit of the EUI-64, starting from 1) is
inverted. To create an IPv6 address with the network prefix 2001:db8:1:1::/64 it
yields the address 2001:db8:1:1:021d:1cff:fe06:3764 (with the underlined U/L bit
inverted to a 1, because the MAC address is universally unique).
Factory Defaults The process of erasing the current configuration of a CPE and restoring the initial
default values for all parameters.
Second SSID The broadcasting of a second WiFi SSID, allowing the partitioning a single physical
access point into two virtual ones.
See SSID.
Secondary DNS A DNS server that can be used if the primary DNS server is not available.
See DNS.
Set-top Box See STB.
Shared LLU Shared Local Loop Unbundling
Shared LLU is a form of LLU, where the incumbent operator retains the use of
the lower POTS frequencies in a local telephony loop and makes the higher DSL
frequencies available to another ISP. This way the ISP can offer the DSL service
over the copper twisted pair, and at the same time the incumbent operator can
still offer traditional telephony service over the same line. Compare with Full LLU.
See LLU.
SIP Session Initiation Protocol
SIP is a signaling protocol, defined by IETF in RFC 3261, which is used for
establishing multimedia sessions, like voice, video, and data conferencing, over
IP networks.
SIP Domain Session Initiation Protocol Domain
A SIP domain describes a collection of SIP users and endpoints that share a
common domain-part in the SIP URI addresses used.
SIP Info See RFC 2976.
SIP Proxy Session Initiation Protocol Proxy
A SIP proxy is the key element of a SIP voice over IP deployment. It is the
component that handles the setup of SIP calls in the network, in a similar fashion
to the role PBXs and Voice Switches had in traditional telephony deployments.
Sixxs An IPv6 tunneling mechanism (see Tunnel Brokers).
SMB/CIFS Server Message Block / Common Internet File System
CIFS/SMB is the network protocol used by all variants of Microsoft Windows to
access and share files and printers over a network. The protocol is also supported
by all recent Macintosh operating systems, and Unix/Linux variations.
SNMP Simple Network Management Protocol
SNMP is network management protocol widely used within TCP/IP networks. It
allows a network management server to get statistics and parameter values
from another computer or networking devices across the intranet or even the
Internet. It also allows the modification of the parameter values. Access
from the managed end-points is controlled using simple password-like character
strings, called the community strings. Usually, each managed end-point has two
different community strings, one with Read-Only access privileges and one with
Read-Write.
Syslog A protocol and the associated service for the control of logging information and
the optional transmission of it over the network.
T.38 A standard defined by the ITU, for the reliable outband transport of fax calls over
IP networks. Compare with Inband.
TCP See TCP/IP.
TCP/IP Transmission Control Protocol/Internet Protocol
The basic protocols used on the Internet. TCP is responsible for dividing data
up into packets for delivery and reassembling them at the destination, while IP
is responsible for delivering the packets from source to destination. When TCP
and IP are bundled with higher-level applications such as HTTP, FTP, Telnet, etc.,
TCP/IP refers to this whole suite of protocols.
Telnet An interactive, character-based program used to access a remote computer.
While HTTP (the web protocol) and FTP only allow you to download files from
a remote computer, Telnet allows you to log into and use a computer from a
remote location. Compare with SSH.
TFTP Trivial File Transfer Protocol
A protocol for file transfers, TFTP is easier to use than File Transfer Protocol (FTP)
but not as capable or secure.
TKIP Temporal Key Integrity Protocol
TKIP provides WPA with a data encryption function. It ensures that a unique
master key is generated for each packet, supports message integrity and
sequencing rules and supports re-keying mechanisms.
TOS Type of Service
A 1-byte long field in the header of IP packets for the indication of the desired
QoS level. Initially, only 3 bits were used out of the whole byte for the traffic
management purposes (IP Precedence bits) whereas modern models take 6 bits
into account (DSCP).
See DSCP.
TR-069 A technical specification by the DSL Forum for the remote management of CPEs
by a central ACS server.
See ACS Server.
Traceroute A program, which (like Ping) can be used to verify whether there is IP connectivity
between two networked hosts, but also reveals all the IP routing hops in-between.
Traffic Class A traffic class is a collection of QoS mechanisms and parameters aiming to
provide a defined level of service to IP packets in the traffic class.
Training The initial negotiation period, when two modems have succeeded contacting
each other and are negotiating in finding a common set of parameters (e.g.
symbol, data rate) for the establishment of a communications channel. Compare
with Synchronization.
Triggers Triggers are used to deal with application protocols that create separate sessions.
Some applications, such as NetMeeting, open secondary connections during
normal operations, for example, a connection to a server is established using
one port, but data transfers are performed on a separate connection. A trigger
tells the device to expect these secondary sessions and how to handle them.
Once you set a trigger, the embedded IP address of each incoming packet is
replaced by the correct host address so that NAT can translate packets to the
correct destination. You can specify whether you want to carry out address
replacement, and if so, whether to replace addresses on TCP packets only, UDP
packets only, or both.
Triple-Play A term usually used for the description of broadband networks supporting Data,
Voice and Video services at the same time.
Tunnel Brokers In networking, tunnelling implies enabling new networking functions while still
preserving the underlying network as is. There may be several reasons why a
network needs tunnelling, for example, to carry a payload over an incompatible
delivery network. IPv6 tunneling enables IPv6 hosts and routers to connect
with other IPv6 hosts and routers over the existing IPv4 Internet. The main
purpose of IPv6 tunneling is to deploy IPv6 as well as maintain compatibility with
large existing base of IPv4 hosts and routers. IPv6 tunneling encapsulates IPv6
datagrams within IPv4 packets. The encapsulated packets travel across an IPv4
Internet until they reach their destination host or router. The IPv6-aware host or
router decapsulates the IPv6 datagrams, forwarding them as needed.
Tunneling Tunneling provides a mechanism to transport packets of one protocol kind within
another protocol. The protocol that is carried is called the passenger protocol,
and the protocol that is used for carrying the passenger protocol is called the
transport protocol. The tunnels behave as virtual point-to-point links that have
two endpoints identified by the tunnel source and tunnel destination addresses
at each endpoint.
Twisted Pair The ordinary copper telephone wiring used by telephone companies. It contains
one or more wire pairs twisted together to reduce inductance and noise. Each
telephone line uses one pair. In homes, it is most often installed with two pairs.
For Ethernet LANs, a higher grade called Category 3 (CAT 3) is used for 10BASE-T
networks, and an even higher grade called Category 5 (CAT 5) is used for
100BASE-T networks.
See 10BASE-T, 100BASE-T, Ethernet.
UBR Unspecified Bit Rate
A service category defined by the ATM Forum primarily for data applications.
This service has no guaranteed quality of service associated with it. However,
the QOS for the UBR service is engineered to meet certain (target) objectives.
USB Host Port A term used for referring to Type-A Female USB ports. A USB host port is used for
connecting peripheral devices (e.g. printers, USB sticks, etc). PCs are equipped
with multiple USB host ports.
Username A sequence of characters used to uniquely identify a user. Usernames, often in
combination with passwords, are required in multi-user systems allowing the user
to gain access to a computer system or an online service.
V.90 / V.92 International standards for 56K data communications.
VBR Variable Bit Rate
A service category defined by the ATM Forum for applications and services
which have less stringent cell loss, delay and delay variation requirements than
the applications which use the CBR service.
VC Virtual Circuit
A point-to-point circuit. Depending on whether they remain constant over time
or are dynamically set-up, VCs in ATM networks are divided into two categories:
Permanent (PVC) and Switched (SVC), with the former being the usual case for
the CPE-to-DSLAM connection in ADSL deployments.
See PVC.
VCI Virtual Circuit Identifier
Together with the Virtual Path Identifier (VPI), the VCI uniquely identifies a PVC.
Your ISP will tell you the VCI for each PVC they provide.
See PVC.
VCMux Virtual Circuit Multiplexing
VCMux is an ATM multiplexing method that allows only one protocol to be
carried per PVC. Note that both ends of the connection must be set to the
same multiplexing method. If they are not the same, the system will discard
all incoming packets that do not match the configured multiplexing method.
Compare with LLC.
VDSL Very High Bit-rate Digital Subscriber Line
A DSL technology variation proposed for shorter local loops, which provides 13 -
53Mbps downstream and 1.5 - 2.3Mbps upstream.
VLAN Virtual Local Access Network
A group of devices on different physical LAN segments which can communicate
with each other as if they were all on the same physical LAN segment. For
Ethernet networks, VLANs are defined using the 802.1q standard.
VLAN ID A 12-bit field specifying the 802.1q VLAN to which an Ethernet frame belongs.
Valid values are 1 up to 4094. VLAN ID 1 is often reserved for management
purposes.
See VLAN.
VoIP See IP Voice.
VPI Virtual Path Identifier
Together with the Virtual Circuit Identifier (VCI), the VPI uniquely identifies a VC.
Your ISP will tell you the VPI for each VC they provide.
See VC.