IX14 User Guide 2 Revision History—90002291
Total Page:16
File Type:pdf, Size:1020Kb
IX14 User Guide Revision history—90002291 Revision Date Description A January 2019 Initial release of Digi IX14 firmware version 19.1.x. B September 2019 Digi IX14 firmware version 19.8.x release. IX14 User Guide 2 Revision history—90002291 Revision Date Description C November 2019 Digi IX14 firmware version 19.11.x release. This firmware release includes the following features and enhancements: n Re-themed web UI with improved navigation and functionality. New functionality includes: l New Dashboard overview page. l The ability to view local filesystem contents. l Access configuration settings from status pages. l Enhanced for use on hand-held and mobile devices. n Default user changed from root to admin. l If you have a configured user named admin prior to upgrading to 20.5.38.39, it will not be affected by the upgrade. l If you do not have a configured user named admin prior to upgrading to 20.5.38.39, an admin user account will be created with the same credentials and configuration settings as the root user. l If your root user account has been modified from the factory default settings, it will not be affected by the upgrade. l If you restore the device to factory default settings after upgrading to 20.5.38.39, only the admin user will exist. If you have a root user and perform a factory default, log in with the admin user instead of root, using the same default password printed on the bottom of the device. n New network analyzer and packet capture tool. n SIM slot prioritization and SIM slot failback. n IPsec enhancements: l Preferred tunnel option to configure a tunnel to be a primary or failover tunnel. l Ability to use the device's MAC address or serial number as its local endpoint ID. n DHCP hostname option to allow the device to advertise its hostname to the DHCP server upon connection. n Receive encrypted SMS commands from Digi Remote Manager. n Ability in OpenVPN to push routes in subnet mode. n New Edge firewall zone to prevent the device's DNS services from being advertised on the network, while still allowing SSH and web UI access. n Removed the 192.168.210.254 default IP gateway. IX14 User Guide 3 Revision history—90002291 Revision Date Description n Support for sending RFC2136-compatible DNS updates to external DNS servers. D February 2020 Release of DigiIX14 firmware version 20.2. E June 2020 Release of Digi IX14 firmware version 20.5: n Support for LDAP user authentication. n Firmware installation from the Digi firmware server. n Enhanced Digi Remote Manager support: l Support for remote proxy server for Digi Remote Manager. l Watchdog support for connection to Digi Remote Manager. l Locally authenticate CLI option added to Digi Remote Manager configuration to control whether a user is required to provide device-level authentication when accessing the console of the device through Digi Remote Manager. l Added a randomized two minute delay window for uploading health metrics to the Digi Remote Manager to avoid situations where multiple devices are uploading metrics at the same time. n Enhanced Python support: l Support for the Python serial module to allow programmatic access to serial ports. l Support for the Python HID module to allow programmatic access to a USB Human Interface Device (HID) from within a Python script. n Application mode for serial ports to allow for Python programmatic control. Trademarks and copyright Digi, Digi International, and the Digi logo are trademarks or registered trademarks in the United States and other countries worldwide. All other trademarks mentioned in this document are the property of their respective owners. © 2020 Digi International Inc. All rights reserved. Disclaimers Information in this document is subject to change without notice and does not represent a commitment on the part of Digi International. Digi provides this document “as is,” without warranty of any kind, expressed or implied, including, but not limited to, the implied warranties of fitness or merchantability for a particular purpose. Digi may make improvements and/or changes in this manual or in the product(s) and/or the program(s) described in this manual at any time. IX14 User Guide 4 Revision history—90002291 Warranty To view product warranty information, go to the following website: www.digi.com/howtobuy/terms Customer support Gather support information: Before contacting Digi technical support for help, gather the following information: Product name and model Product serial number (s) Firmware version Operating system/browser (if applicable) Logs (from time of reported issue) Trace (if possible) Description of issue Steps to reproduce Contact Digi technical support: Digi offers multiple technical support plans and service packages. Contact us at +1 952.912.3444 or visit us at www.digi.com/support. Feedback To provide feedback on this document, email your comments to [email protected] Include the document title and part number (IX14 User Guide, 90002291 E) in the subject line of your email. IX14 User Guide 5 Contents Revision history—90002291 2 What's new in Digi IX14 version 20.5 Digi IX14 hardware reference IX14 features and specifications 14 IX14 front view 14 IX14 back view 14 IX14 power supply requirements 15 IX14 LEDs 15 Digi IX14 serial connector pinout 16 IX14 accessory kits 17 IX14 antennas 17 Digi IX14 quick start Quick start with Digi Remote Manager mobile app Step 1: What's in the box 19 Step 2: Gather accessories 20 Step 3: Connect hardware 21 Step 4: Quick setup using the Digi Remote Manager mobile app 21 Next steps 22 Quick start with IX14 local WebUI Step 1: What's in the box 23 Step 2: Gather accessories 24 Step 3: Connect hardware 25 Step 4: Sign up for Digi Remote Manager 25 Step 5: Access the IX14 local web interface 26 Step 6: Configure cellular connection using the web interface 26 Step 7: Add your IX14 to your Digi Remote Manager account 26 Next steps 28 IX14 User Guide 6 Reset the device to factory defaults Hardware setup Install SIM cards 30 Attach and position antennas 30 Connect the WAN/ETH1 port 31 Connect the serial port 31 Power on the IX14 31 Configuration and management Review IX14 default settings 32 Reset default password for the default admin user 32 Configuration methods 34 Using Digi Remote Manager 34 Access Digi Remote Manager 35 Using the web interface 35 Log out of the web interface 36 Using the command line 37 Access the command line interface 37 Log in to the command line interface 37 Exit the command line interface 38 Initial configuration Configure cellular modem APNs 40 Change the default LAN subnet 44 Change the LAN address type 45 Configure SIM PIN 47 Configure system settings 47 Enable or disable Bluetooth service 54 User authentication IX14 user authentication 58 User authentication methods 58 Add a new authentication method 60 Delete an authentication method 62 Rearrange the position of authentication methods 64 Authentication groups 66 Change the access rights for a predefined group 68 Add an authentication group 70 Delete an authentication group 74 Local users 77 Change a local user's password 78 Configure a local user 80 Delete a local user 87 Terminal Access Controller Access-Control System Plus (TACACS+) 89 TACACS+ user configuration 90 TACACS+ server failover and fallback to local authentication 91 Configure your IX14 device to use a TACACS+ server 91 IX14 User Guide 7 Remote Authentication Dial-In User Service (RADIUS) 97 RADIUS user configuration 98 RADIUS server failover and fallback to local configuration 98 Configure your IX14 device to use a RADIUS server 99 LDAP 104 LDAP user configuration 105 LDAP server failover and fallback to local configuration 106 Configure your IX14 device to use an LDAP server 106 Disable shell access 111 Set the idle timeout for IX14 users 113 Example user configuration 115 Example 1: Administrator user with local authentication 115 Example 2: RADIUS, TACACS+, and local authentication for one user 117 Firewall Firewall configuration 125 Create a custom firewall zone 125 Configure the firewall zone for a network interface 127 Delete a custom firewall zone 129 Port forwarding rules 130 Configure port forwarding 130 Delete a port forwarding rule 135 Packet filtering 138 Configure packet filtering 138 Enable or disable a packet filtering rule 142 Delete a packet filtering rule 144 Configure custom firewall rules 146 Configure Quality of Service options 147 System administration Review device status 160 Configure system information 161 Update system firmware 163 Manage firmware updates using Digi Remote Manager 163 Certificate management for firmware images 164 Update cellular module firmware 166 Reboot your IX14 device 167 Reboot your device immediately 168 Schedule reboots of your device 168 Reset the device to factory defaults 170 Configuration files 174 Save configuration changes 174 Save configuration to a file 175 Restore the device configuration 176 Schedule system maintenance tasks 179 Create a Virtual LAN (VLAN) route 186 Serial port 189 Configure the serial port 189 Show serial status and statistics 199 IX14 User Guide 8 Services Allow remote access for web administration and SSH 202 Configure the web administration service 206 Configure SSH access 213 Use SSH with key authentication 219 Generating SSH key pairs 219 Configure telnet access 222 Configure DNS 227 Simple Network Management Protocol (SNMP) 234 SNMP Security 234 Configure Simple Network Management Protocol (SNMP) 234 Download MIBs 239 System time 240 Configure the system time 240 Network Time Protocol 243 Configure the device as