POTS in a BOXTM CDS9070 LTE VoIP Dual Band Wi-Fi / ATA

User Manual V1.0

1

Table of Contents

1 Preface ...... 6 2 LED Indicators and Connectors ...... 7 2.1 LED Indicators ...... 7 DC ...... 9 Connector for a power adapter ...... 9 WAN ...... 9 Connector for accessing the ...... 9 LAN 1/2/3/4 ...... 9 Connectors for local networked devices...... 9 2.2 Hardware Installation ...... 10 3 Interactive Voice Response ...... 11 4 Configuring Basic Settings ...... 14 4.1 Administrator Management ...... 14 4.2 Accessing Management Portal ...... 15 4.2.1 From LAN port ...... 15 4.3 CDS-9070 Management Portal Layout ...... 17 4.4 Setting up the Time Zone ...... 19 4.5 Setting up the Internet/WAN Connection ...... 20 4.5.1 DHCP ...... 23 4.5.2 PPPoE ...... 25 4.6 Setting up the Internet/LTE Connection ...... 28 4.6.1 LTE...... 28 4.7 Setting up the Wireless Connection ...... 30 4.7.1 Enable Wireless and Setting SSID ...... 30

2

4.7.2 Encryption ...... 33 4.8 Setting up WAN Failover ...... 35 4.8.1 WAN Failover List ...... 35 4.8.2 Connection Manager Wan Detection Probe ...... 37 4.9 Register ...... 38 4.9.1 Get the Accounts ...... 38 4.9.2 Connections ...... 38 4.9.3 View the Register Status ...... 39 4.10 Make Call ...... 40 4.10.1 Calling phone or extension numbers ...... 40 4.10.2 Direct IP calls ...... 41 4.10.3 Call Hold ...... 42 4.10.4 Blind Transfer ...... 42 4.10.5 Attended Transfer ...... 42 4.10.6 Conference ...... 43 5 Management Portal ...... 44 5.1 Login ...... 44 5.2 Status ...... 46 5.3 Network ...... 48 5.3.1 WAN ...... 48 5.3.2 LAN ...... 56 5.3.3 VPN/L2TP ...... 58 5.3.4 DMZ/Port Forward ...... 66 5.3.5 DDNS ...... 69 5.3.6 QoS ...... 70 5.3.7 MAC Clone ...... 72 5.3.8 ...... 74 5.4 Wireless ...... 75

3

5.4.1 Basic ...... 75 5.4.2 Security ...... 78 5.4.3 WPS ...... 80 5.4.4 Station list ...... 82 5.4.5 Client ...... 82 5.5 Phone ...... 84 5.5.1 VoIP QoS ...... 84 5.5.2 Dial Plan...... 84 5.5.3 Blacklist ...... 86 5.5.4 Call Log ...... 87 5.6 SIP Account...... 88 5.6.1 FXS1/2 SIP Account ...... 88 5.6.2 FXS1/2 Audio Configuration ...... 89 5.6.3 FXS1/2 Supplementary Service Subscription ...... 91 5.7 Security ...... 93 5.7.1 Filtering Setting ...... 93 5.7.2 Content Filtering ...... 95 5.8 Application ...... 97 5.8.1 Advance Nat ...... 97 5.8.2 UPnP ...... 98 5.8.3 IGMP ...... 99 5.9 Administration ...... 100 5.9.1 Management ...... 100 5.9.2 Firmware Upgrade ...... 105 5.9.3 Scheduled Tasks ...... 106 5.9.4 Provision ...... 108 5.9.5 TR069 ...... 111 5.10 System Log ...... 113

4

5.10.1 Logout ...... 114 5.10.2 Reboot ...... 114 6 Troubleshooting Guide ...... 115 6.1 Setting up your PC to get an IP automatically ...... 115 6.2 Cannot connect to the Management Portal ...... 117 6.3 Forgotten Password ...... 117 7 Statement ...... 118

5

1 Preface

Thank you for choosing CDS9070 wireless router with VoIP. This product will allow you to make ATA calls using your

broadband connection, and it will also provide Wi-Fi router function.

This manual provides basic information on how to install and connect your CDS9070 wireless router with VoIP to the Internet. It

also includes features and functions of LTE connection, wireless router with VoIP components, and how to use it correctly.

Before you can connect your CDS9070 to the Internet and use it, you must have a high-speed broadband connection installed.

A high-speed connection includes environments such as DSL, LTE , cable , and a leased line.

The CDS9070 wireless router with VoIP is a stand-alone device which requires no PC to make Internet calls. This product

guarantees clear and reliable voice quality over the Internet. It is fully compatible with SIP industry standards and able to interoperate

with many other SIP devices and software on the market.

6

2 LED Indicators and Connectors

Before you use your high-speed router, please get acquainted with the LED indicators and connectors first.

2.1 LED Indicators

Front Panel LED Status Explanation

The router is powered on (External On (GREEN) Power) and running normally. PWR The router is powered on (Internal On Blinking (GREEN) Power - BAT) and running normally. OFF The router is powered off. On (GREEN) System OK SYS On (RED) System Fault (SW or HW) On (GREEN) Battery Charged BATTERY On Blinking (GREEN) Battery Charging Red Battery Low or not connected

Phone On (GREEN) Registered 1/2 OFF Not Registered OFF Not Registered WPS On (GREEN) Active for Key registration

7

OFF Non active for Key registration WLAN On (GREEN) Wireless Client Connected Client On Blinking (GREEN) Wireless traffic (Data) The Wireless Client is powered off or OFF WLAN not connected AP On (GREEN) Wireless AP ready On Blinking (GREEN) Wireless traffic (Data) OFF The Wireless AP is powered off WAN On (GREEN) Connected (Registered) ETH On Blinking (GREEN) Connected (Data) OFF Disconnected LTE SVC On (GREEN) Connected (Registered) On Blinking (GREEN) Connected (Data) OFF Disconnected RSSI On (GREEN) Strong On Blinking (GREEN) Medium On (RED) Weak CELL On (GREEN) LTE DCD On Blinking (GREEN) 3G Off No Service SIM On (GREEN) SIM Accepted

8

Rear Panel Interface Description

DC Connector for a power adapter

WAN Connector for accessing the Internet

LAN 1/2/3/4 Connectors for local networked devices

9

2.2 Hardware Installation

Before starting to configure the router, you must ensure your devices are connected correctly.

Step 1. Connect the Line port to the analog Jack (Phone/Alarm Panel) with an RJ-11 Phone cable.

Step 2. Connect the WAN port to a modem, switch, router, or Internet with an RJ-45 cable.

Step 3. Connect one port (of 4) LAN ports to your with an RJ-45 Ethernet cable. This device allows you

to directly connect 4 PC’s or VoIP Phones, etc.

Step 4. Connect one end of the power cord to the power port of this device. Connect the other end to an

electrical outlet.

Step 5. Check the Power, WAN, and LAN LED’s to assure network connections.

10

3 Interactive Voice Response

Interactive Voice Menu

Step 1. Pick up the phone and dial “****” to start IVR.

Step 2. Choose your desired options as dictated by the attendant with designated numbers 1-9.

Step 3. If prompted to "Please enter password,” input your password followed by the “#” key.  The password in IVR is the same as the WEB login password ‒ user can enter the password directly with the phone keypad.  For example: If WEB login password is “@dmin123,” the password, “@dmin123” is translated to “03646123.” The attendant will respond “operation successful” if password is correct.

Step 4. Choose your desired function as dictated by the attendant with designated numbers 1-9.

 Dial the “*” key at any time to return to the main menu.

11

Notice:

 When using the Interactive Voice Menu, press the “*” key to return to the main menu

 If any changes are made in the IP assignment mode, please reboot the CDS9070 to allow the settings to

take effect

 When entering an IP address or subnet mask, use the “*” key to replace “.”

For example: To enter the IP address “192.168.20.159” by keypad, you would dial, “192*168*20*159”

followed by the “#” key to indicate that you have finished entering the IP address.

 When assigning IP addresses in Static IP mode, you must set the IP address, subnet mask, and default

gateway. If in DHCP mode, please make sure that a DHCP is available in your existing broadband

connection and appropriately connected to the WAN port of the CDS9070

 The default LAN port IP address of the CDS9070 is 192.168.1.1/24. Therefore, do not set the WAN port IP

address of CDS9070 to the same network subnet of the LAN port of the CDS9070. Doing so may lead to a

network failure.

 To enter the password via phone keypad, the matching table between letters and number are as follows:

12

 To input: D, E, F, d, e, f ‒ dial ‘3’  To input: G, H, I, g, h, I ‒ dial ‘4’  To input: J, K, L, j, k, l ‒ dial ‘5’  To input: M, N, O, m, n, o ‒ dial ‘6’  To input: P, Q, R, S, p, q, r, s ‒ dial ‘7’  To input: T, U, V, t, u, v ‒ dial ‘8’  To input: W, X, Y, Z, w, x, y, z ‒ dial ‘9’  To input any other characters ‒ dial ‘0’ E.g. “@dmin123” = ‘03646123’

13

4 Configuring Basic Settings

4.1 Administrator Management

This chapter explains how to setup a password for an administrator user and how to adjust

settings for accessing the Internet successfully.

The CDS9070 supports two-tier management: administrator and user. Login to the

administrator tier with the credentials, “driadmin/DRIAdmin1” (Username/Password) and click the

Login button.

14

4.2 Accessing Management Portal

4.2.1 From LAN port

1. Make sure your PC is connected to the router’s LAN port correctly.

Notice: You may either set up your computer to get an IP dynamically from the router or set up the IP address of the computer to have the same subnet as the default subnet of the router 192.168.1.1/24. For more detailed information, please refer to the later section - Troubleshooting Guide.

2. Open a web browser on your PC and type http://192.168.1.1. The following window will open,

and you will be asked for username and password credentials.

3. For administrator operation, please use “driadmin/DRIAdmin1” for Username/Password.

15

Notice: If you fail to access the web configuration, please see the Troubleshooting Guide for potential solutions.

4. The web configuration page will timeout after 30 minutes of inactivity.

Notice: You can change this setting by navigating to: The “Administration” Tab → the “Management” Sub-Tab → the “Web Access” Section → “Web Idle Timeout(0 – 60min).”

✧ Changing the Web Idle Timeout value to “0” will disable the timeout function altogether.

16

4.3 CDS-9070 Management Portal Layout

No. Name Description

Click the navigation bar, many Navigation 1 sub-navigation bars will bar appear in the place 2

Click the sub-navigation bar to

2 Title choose the corresponding

configuration page

3 Parameter Individual value fields

 Any time a change is

made the user should press

this button to confirm the

changes

17

 After pressing this button, and depending on the changes made, a red notice will appear requesting a reboot for the changes to take effect

Press this button to cancel any changes

Press this button to reboot the router

18

4.4 Setting up the Time Zone

Navigate to the “Administration” Tab → the “Management” Sub-Tab → the “NTP Settings” Section, specify

the NTP server, and set the update interval in NTP synchronization.

19

4.5 Setting up the Internet/WAN Connection

Navigate to the “Network” Tab → the “WAN” Sub-Tab → the “WAN” Section → “WAN IP Mode.” Select the

appropriate IP Mode according to the information from your ISP. There are four modes provided: Static, DHCP,

PPPoE, and Bridge.

20

Choose from eight different Service types: “Voice,” “Management,” “Internet,” Service “Management_Internet,” “Management_Voice,” “Voice_Internet,” “Management_Voice_Internet,” and “Other”

The mode used to obtain an IP WAN IP address. Choose between “Static,” Mode “DHCP,” “PPPoE,” and “Bridge”

Choose “Disable,” “Enable,” or “Trunk.” If “Enable” or “Trunk” VLAN are selected, you should set your

Mode VLAN ID to any number 1-4094 and select any number 0-7 for 802.1p

21

Set the DNS Mode to Auto or Manual: DNS Mode If manual, you should fill-in the desired primary DNS address and Secondary DNS address

22

4.5.1 DHCP

It is not necessary for you to type any IP address manually with this option. Simply choose this type and

the system will obtain the IP address automatically from the DHCP server.

Choose from eight different Service types: “Voice,” “Management,” “Internet,” Service “Management_Internet,” “Management_Voice,” “Voice_Internet,” “Management_Voice_Internet,” and “Other”

The mode used to obtain an IP WAN IP address. Choose between “Static,” Mode “DHCP,” “PPPoE,” and “Bridge”

23

Choose “Disable,” “Enable,” or “Trunk.” If “Enable” or “Trunk” VLAN are selected, you should set your Mode VLAN ID to any number 1-4094 and select any number 0-7 for 802.1p

Set the DNS Mode to Auto or Manual: DNS Mode If manual, you should fill-in the desired primary DNS address and Secondary DNS address

24

4.5.2 PPPoE

PPPoE stands for Point-to-Point Protocol over Ethernet. It relies on two widely accepted standards:

PPP and Ethernet. It connects users through an Ethernet to the Internet with a common broadband

medium such as a single DSL line, wireless device, or cable modem. All the users over the Ethernet can

share a common connection.

PPPoE is used for most of DSL modem users. All local users can share one PPPoE connection for

accessing the Internet. Your service provider will provide you information about username, password, and

authentication mode.

25

Assign a specific, valid PPPoE username provided by Account your ISP

PPPoE Assign a valid password Password provided by your ISP

Confirm Input the password again Password

Input the destination of Service the PPPoE server, leave Name empty for auto detect

26

Operation Select “Keep Alive”, “On Mode Demand” or “Manual”

Keep Alive Redial The interval time for Period(0- redialing 3600s) On Demand The interval time for idle Idle timeout Time(0- 60m)

27

4.6 Setting up the Internet/LTE Connection

4.6.1 LTE

LTE Select “Disable,” “Auto Modem Connect,” or “Always Enable Connect” 4G 4G connection type ,auto Connection or manual Type Access Point Name APN (Supplied by LTE Carrier) Dial LTE connection dial Number number Username Authorization username Password Authorization password

28

Internet Here you can choose 3G, 4G, or auto mode Connection

Lock Cell Lock cell function

Status PIN code bind status SIM bind Input the SIM bind code Limit of operation error The remaining time messages, should number of be less than or equal to unlock 3

When LTE has connected successfully, return to the Status page to check the link status and the IP address obtained from your ISP.

29

4.7 Setting up the Wireless Connection

To set up the wireless connection, please read the following steps.

4.7.1 Enable Wireless and Setting SSID

Open Wireless 2.4GHz or 5GHz / Basic webpage as shown below

Radio On/Off Select to enable or disable wireless

Wireless

Connection Select Access Point or Client

Mode

Choose a network mode from the drop- Network Mode down list

Multiple SSSD Set and name multiple SSID’s

30

Broadcast Broadcast or hide the SSID (SSID) Prevents a wireless client from AP Isolation communicating with other wireless clients. Other clients outside the Access Point MBSSID AP cannot access the clients under this Isolation Access Point A group of wireless workstations and a wireless access point BSSID form a basic service set (BSS), each

computer in the BSS must be

configured with the same BSSID

Frequency Choose a channel frequency

The HT (High Throughput) Physical HT Physical mode settings allow for control of the Mode 802.11n wireless environment.

Operating Mixed Mode: In this mode, packets are

Mode transmitted with a preamble compatible

31

with the legacy 802.11a/g, the rest of

the packet has a new format Green Field: In this mode, high throughput packets are transmitted without a legacy compatible part Channel 20 Channel Width = 20 MHz Bandwidth 20/40 Channel Width = 20/40 MHz Extension Choose the extension channel Channel(5G frequency Hz Only) With IEEE 802.11ac standard, very- VHT high-throughput packets can be Option(5GHz configured to operate on the 5 GHz Only) frequency band

VHT 20/40 Channel Width = 20/40 MHz Bandwidth(5 80 Channel Width = 80 MHz GHz Only)

32

4.7.2 Encryption

Open Wireless 2.4GHz or 5GHz / Wireless Security webpage to set the encryption.

WAP-PSK/WAP2-PSK/WAPPSKWAP2PSK SSID Choose one SSID from the drop-down Choice list Choose an encryption method from the drop-down list, if disabled, wireless Security transmissions to and from your wireless Mode network can be easily intercepted and interpreted by unauthorized users “TKIP” (Temporal Key Integrity Protocol) provides per-packet key generation and is based on WEP, “AES” (Advanced Encryption WPA Standard) is a very secure block-based Algorithms encryption, and the “TKIPAES” option has the router negotiate the cipher type

with the client and uses AES when available.

33

Wireless Connection Security Password Pass Phrase (min. 8 characters)

Key The amount of time before the group Renewal key used for broadcast and multicast Interval data is changed Select one of the four WEP keys, the Default Key key settings on the client network card also need to correspond with this Set the WEP key: a 64-bit, Hex key will be 10 characters long, and a 64-bit, ASCII key will be 5 characters long; a WEP Keys 128-bit, Hex key will be 26 characters long, and a 128-bit, ASCII key will be 13 characters long

Policy Choose an Access Policy Add a Use this section to add MAC addresses station to your Access Policy MAC

34

4.8 Setting up WAN Failover

4.8.1 WAN Failover List

WAN Failover works With the Wan, LTE, And Wi-Fi bands to assure that you maintain Internet

connectivity if a loss of connection occurs. If one of your ISP links goes down, WAN Failover will

automatically route all traffic over the other WAN interface(s) until service is restored.

35

The CDS9070 allows failover of the default route to WAN interfaces. You can rank each interface in order of preferred usage for the default route. The default route will always be set to the highest- priority connected interface. The assignment changes as interfaces connect or disconnect from the current network. Default Route Selection supports WAN/ Wi-Fi 2.4G/ LTE and Wi-Fi 5.0G. The

WAN Failover list switches between

Number 1 (highest priority) to Number 4 (lowest priority).

36

4.8.2 Connection Manager Wan Detection Probe

Enabling this function will cause the WAN Failover to be based on ping result, Enable disabling this function will cause the WAN Failover to be based on each interface’s physical connection status Detect Interval time for detecting Interval WAN connection The IP address for ping Ping this IP detection

Max Try The number of re-try times Times for for ping detection Ping

37

4.9 Register

4.9.1 Get the Accounts

The CDS9070 has 2 Analog phone ports that can be used to make SIP calls, but you should get the SIP

account from your administrator or provider before registering.

4.9.2 Connections

Connect your CDS9070 to the Internet properly.

38

4.9.3 View the Register Status

To view the status, please open the Status webpage and view the FXS Account registration status. If your

FXS Account registration status resembles the following picture below, your CDS9070 has registered

normally and you are ready to make calls.

39

4.10 Make Call

4.10.1 Calling phone or extension numbers

To make a phone or extension number call: a) Both ATA and the other VoIP device (i.e. another ATA or other SIP product) have public IP addresses

- or - b) Both ATA and the other VoIP device (i.e. another ATA or other SIP product) are on the same LAN using private or public IP addresses

- or - c) Both ATA and the other VoIP device (i.e. another ATA or other SIP product) can be connected through a router using public or private IP addresses

To make a call, first pick up the analog phone, input the IP address directly, and end with “#”

40

4.10.2 Direct IP calls

Direct IP calling allows two phones (an ATA with an analog phone and another VoIP Device) to talk to each other without a SIP proxy. VoIP calls can be made between two phones if: a) Both ATA and the other VoIP device (i.e. another ATA or other SIP product) have public IP addresses

- or - b) Both ATA and the other VoIP device (i.e. another ATA or other SIP product) are on the same LAN using private or public IP addresses

- or - c) Both ATA and the other VoIP device (i.e. another ATA or other SIP products) can be connected through a router using public or private IP addresses

To make a call, first pick up the analog phone, input the IP address directly, and end with “#”

41

4.10.3 Call Hold

While in a conversation, dialing “*77” will put the remote party on hold. You will then hear dial tone while the remote party will hear hold tone.

Dialing “*77” again will reverse the hold state and resume the bi-directional media.

4.10.4 Blind Transfer

While in a conversation, Party A wants to Blind Transfer Party B to Party C:

Step 1. Party A dials “*78” to hold Party B and get a dial tone, then dials Party C’s number, and immediately dialing the “#” key (or wait for 4 seconds) to dial out.

Step 2. Party A may hang up as the Blind Transfer has been completed.

4.10.5 Attended Transfer

While in a conversation, Party A wants to Attended Transfer Party B to Party C:

Step 1. Party A dials “*77” to hold Party B and get dial tone, then dials Party C’s number. Party A and party C are now in a conversation.

42

Step 2. Party A dials “*78” to transfer Party C to Party B.

Step 3. If the transfer doesn’t succeed, then Party A and Party B will be returned to their original conversation.

4.10.6 Conference

While in a conversation, Party A and Party B want to add Party C to a Conference:

Step 1. Party A dials “*77” to hold Party B and get dial tone, then Party A dials Party C’s number. Party A and party C are now in a conversation.

Step 2. Party A dials “*88” to add Party C. Party A, Party B, and Party C are now in a Conference.

43

5 Management Portal

This chapter will guide users through admin level configuration.

5.1 Login

Step 1. Connect the LAN port of the CDS-9070 to your PC

Step 2. Open a web browser on your PC and type in http://192.168.1.1. You will be prompted for

username and password. Here, you can also choose your preferred default language.

Step 3. For administrator operation, please use “driadmin/DRIAdmin1” for Username/Password.

44

After successfully logging-in, the webpage will show the basic information about your

CDS9070 such as the current Firmware

Version, received signal strength indicator

(RSSI), WAN IP, DNS server IP, WAN port connection mode, LAN port connection, wireless broadcast status, wireless channel, and wireless connection mode

45

5.2 Status

46

The picture above depicts the CDS9070’s Status webpage.

This Status / Basic webpage shows the status information about product information, network and system.

It also shows other basic information about your CDS-9070 such as product name, serial number, MAC address, hardware version, and firmware version.

The current time and the running time of your CDS-9070 will also be displayed.

47

5.3 Network

You can configuration the WAN port, LAN port, DDNS, Multi WAN, DMZ, MAC Clone, Port Forward and so on in these two bars.

5.3.1 WAN

This page allows you to set WAN configuration with different modes. Use the Connection Type drop-down list to choose a WAN mode and then the corresponding options will be displayed.

Static IP:

You will receive a fixed public IP address or a public subnet, namely multiple public IP addresses from

your DSL or Cable ISP service providers. In most cases, a Cable service provider will offer a fixed public

IP, while a DSL service provider will offer a public subnet. If you have a public subnet, you could assign

an IP address to the WAN interface.

48

Choose from eight different Service types: “Voice,” “Management,” “Internet,” Service “Management_Internet,” “Management_Voice,” “Voice_Internet,” “Management_Voice_Internet,” and “Other”

The mode used to obtain an IP WAN IP address. Choose between “Static,” Mode “DHCP,” “PPPoE,” and “Bridge”

Choose “Disable,” “Enable,” or “Trunk.” If “Enable” or “Trunk” VLAN are selected, you should set your

Mode VLAN ID to any number 1-4094 and select any number 0-7 for 802.1p

49

Set the DNS Mode to “Auto” or “Manual”: DNS Mode If manual, you should fill-in the desired primary DNS address and Secondary DNS address

50

DHCP:

IP address will be automatically set for you with this option selected. Simply choose DHCP from the drop-

down list and the system will obtain an IP address automatically from the DHCP server.

Choose from eight different Service types: “Voice,” “Management,” “Internet,” Service “Management_Internet,” “Management_Voice,” “Voice_Internet,” “Management_Voice_Internet,” and “Other”

The mode used to obtain an IP WAN IP address. Choose between “Static,” Mode “DHCP,” “PPPoE,” and “Bridge”

VLAN Choose “Disable,” “Enable,” or

Mode “Trunk.” If “Enable” or “Trunk”

51

are selected, you should set your VLAN ID to any number 1-4094 and select any number 0-7 for 802.1p Set the DNS Mode to Auto or Manual: DNS Mode If manual, you should fill-in the desired primary DNS address and Secondary DNS address

PPPoE:

PPPoE stands for Point-to-Point Protocol over Ethernet. It relies on two widely accepted standards:

PPP and Ethernet. It connects users through an Ethernet to the Internet with a common broadband

medium, such as a single DSL line, wireless device or cable modem. All the users over the Ethernet can

share a common connection.

52

PPPoE is used for most of DSL modem users. All local users can share one PPPoE connection for accessing the Internet. Your service provider will provide you information about user name, password, and authentication mode.

Choose from eight different Service types: “Voice,” “Management,” “Internet,” Service “Management_Internet,” “Management_Voice,” “Voice_Internet,” “Management_Voice_Interne t,” and “Other” The mode used to obtain an IP address. Choose between WAN IP “Static,” “DHCP,” “PPPoE,” Mode and “Bridge”

53

Choose “Disable,” “Enable,” or “Trunk.” If “Enable” or

“Trunk” are selected, you VLAN should set your VLAN ID to Mode any number 1-4094 and select any number 0-7 for 802.1p Set the DNS Mode to Auto or Manual: If manual, you should fill-in DNS Mode the desired primary DNS

address and Secondary DNS address Assign a specific, valid PPPoE username provided by your Account ISP Assign a valid password PPPoE provided by your ISP Password

54

Confirm Input the password again Password Input the destination of the Service PPPoE server, leave empty Name for auto detect Operation Select “Keep Alive”, “On Mode Demand” or “Manual” Keep Alive Redial The interval time for Period(0- redialing 3600s) On Demand The interval time for idle Idle timeout Time(0- 60m)

55

5.3.2 LAN

LAN Port:

The most generic function of router is NAT. NAT translates the packets from public IP addresses to local IP addresses, forwarding the right packets to the right host.

Local IP Type in the local IP address for Address connecting to a local private network Local Subnet Type in an address code that Mask determines the size of the network Local DHCP Enable or Disable Local DHCP Server server DHCP Start Enter the Start Address for the Address DHCP Server IP address pool DHCP End Enter the End Address for the DHCP Address Server IP address pool Choose “Auto” from the drop-down DNS Mode list to automatically enter the DNS

Server addresses or choose

56

“Manual” from the drop-down list to

manually enter the DNS Server addresses Client Lease Set the lease time for the specified Time address DHCP Client Check which LAN devices are List currently leasing IP addresses DHCP Static Specify DHCP addresses to reserve Allotment Enable to use a device as a DNS DNS Proxy proxy server

57

5.3.3 VPN/L2TP

VPN

Enable PPTP or VPN Enable L2TP VPN Client Initial Service VPN server IP IP address The account for User Name authentication The password for Password authentication The remote VPN As virtual IP as Default Route default gateway. MPPE Stateless Stateful(PPTP encryption Only) provides a lower

58

level of performance, but will be more reliable in a noisy network environment. Enable MPPE (Microsoft Point- to-Point Require Encryption). It’s MPPE(PPTP a protocol for Only) encrypting data

across PPP and VPN links. L2TP Tunnel Enter L2TP Name Tunnel Name. Enter L2TP L2TP Tunnel tunnel password Password in this item.

59

L2TP Server

L2TP Server Select to enable L2TP server. Enable Local IP Set the IP address of L2TP server. Address

Pool Start Set the IP pool start IP address which Address will assign to the L2TP clients.

Pool End Set the IP pool end IP address which Address will assign to the L2TP clients. Maximum Transmission Unit. It is the identifier of the maximum size of Max MTU packet, which is possible to transfer in a given environment. Maximum Receiving Unit. It is the

identifier of the maximum size of Max MRU packet, which is possible to receive in a

given environment.

60

Set the username which will assign to User Name L2TP client. Set the password which will assign to Password L2TP client.

61

IPsec Connection

IPsec The connection status of Connection List the IPsec VPN IPsec Select to specify VPN Connection Connection The name of the IPsec Name VPN Select to enable or IPsec Enable disable IPsec VPN Select the interface for Interface encryption IPsec The connection type of Networking networking Type

The authentication Authentication method of the IPsec Type VPN

PSK The pre-shared key of

62

the IPsec VPN

Select the local ID type Local ID Type for the IKE negotiation Local IP address or Local WANs IP domain name for the Address/FQDN IKE negotiation Select the remote ID Remote ID type for the IKE Type negotiation Remote WANs The address of remote IP side IPsec VPN server Address/FQDN Local LAN IP Address/ IPsec local protected Subnet Mask subnet’s address Length

Remote LAN IPsec remote protected IP Address/ subnet’s address

63

Subnet Mask Length The policy protocol for Policy Protocol encryption Encapsulated Select the security Mode protocols Enable NAT Traversal for IPsec. This item NAT Enable must be enabled when

router under NAT environment Select from “Main” and “aggressive” for the IKE Mode negotiation mode in phase 1 Select Encryption Encryption Algorithm to be used in Algorithm IKE negotiation

64

Select Integrity Integrity Algorithm to be used in Algorithm IKE negotiation Select Diffie-Hellman Diffie-Hellman Group to be used in key (DH) Group negotiation phase 1 SA Lifetime of Set the lifetime in IKE Phase 1 negotiation Set the interval after which DPD is triggered DPD Time if no IPsec protected Interval(s) packets is received from the peer DPD Set the timeout of DPD Timeout(s) packets Select Encryption Encryption Algorithm to be used in Algorithm IPsec SA negotiation

65

Select Integrity Integrity Algorithm to be used in Algorithm IPsec SA negotiation SA Lifetime of Set the lifetime in IPsec Phase 2 SA negotiation Enable or disable PFS: (Perfect Forward PFS Secrecy)PFS will ensure the same key will not be generated again

5.3.4 DMZ/Port Forward

DMZ

DMZ Enable Enable or disable DMZ DMZ Host Enter the private IP address of IP Address the DMZ host

66

Get the current PC’s IP address Get Current automatically, this IP address PC IP would be used as the DMZ host

Port Forward

Port

Forwarding Assign a meaningful name Comment for IP Address The IP address for LAN The port range for LAN Port Range host, from 1 to 65535 Select from “TCP”, “UDP” Protocol or “TCP&UDP”

Virtual

67

Servers Assign a meaningful name Comment to the virtual server The IP address of the

system on your internal IP Address network that will provide

the virtual service The port that will be Public Port accessed from the Internet. The port that will be used Private Port on your internal network. Select from “TCP”, “UDP” Protocol or “TCP&UDP” The IP address allow to Friendly IP access from WAN side.

The IP address of friendly IP Address IP

68

5.3.5 DDNS

Select the DDNS Dynamic service which you DNS have established an Provider account with Enter account that Account DDNS server provided Enter password that Password DDNS server provided Enter the DDNS DDNS Domain name or IP URL address Show current status Status of DDNS

69

5.3.6 QoS

QoS Enable Select to enable QoS function

Upstream Prescribe uplink speed of router. Downstream Prescribe downlink speed of router. Set server name of the service that you Name want to set it with QoS Control. Enter source IP address of the user (for Source IP example, PC) who you want to set it with Address QoS Control.

Enter destination IP address of the user Destination (for example, PC) who you want to set it IP Address with QoS Control.

Protocol Select from TCP /UDP /ICMP

Src.Port Source port range of the service that you Range want to set it with QoS Control. Dst.Port Destination port number of the service

Range that you want to set it with QoS Control.

70

Physical Port Select from WAN/LAN

set the Differentiated Services Code DSCP Point (DSCP) values in Quality of

Service (QoS) 802.1p is an IEEE standard that describes 802.1p mechanisms to prioritize traffic and perform dynamic multicast filtering. When configuring a VLAN tag-based QoS policy map, the router applies the VLAN ID policy to one Ethernet port and only to the VLANs on that particular port. Remark Remark DSCP Tag DSCP Remark Remark 802.1p Tag 802.1p Remark Remark VLAN_ID Tag VLAN_ID Priority Select from voice (VO), video (VI), best

71

effort (BE), and background (BK) Drop Select to Drop or not drop the packet Rate Limit Limit the speed of this rule

5.3.7 MAC Clone

Some ISPs will require you to register your MAC address. If you do not wish to re-register your MAC address, you can have the router clone the MAC address that is registered with your ISP. To use the Clone Address button, the computer viewing the Web-based utility screen will have the MAC address automatically entered in the Clone

WAN MAC field.

MAC Address Select to enable or disable Clone

72

MAC The MAC address for Address clone

Get clone the currently PC Current MAC address to router’s PC Internet port automatically MAC

73

5.3.8 Routing

The IP address of packets Destination that will take this route

Select the Host or Host/Net Networking

Specifies the next hop to Gateway be taken if this route is used. Specifies the interface Interface LAN/ INTERNET/ VOICE/ TR069/ VPN

Set comment of this Comment routing

74

5.4 Wireless

5.4.1 Basic

Radio On/Off Select to enable or disable wireless Wireless

Connection Select Access Point or Client Mode Choose a network mode from the drop- Network Mode down list Multiple SSSD Set and name multiple SSID’s Broadcast Broadcast or hide the SSID (SSID) Prevents a wireless client from AP Isolation communicating with other wireless

clients.

MBSSID AP Other clients outside the Access Point Isolation cannot access the clients under this

75

Access Point

A group of wireless workstations and a wireless local area network access point BSSID form a basic service set (BSS), each computer in the BSS must be configured with the same BSSID Frequency Choose a channel frequency The HT (High Throughput) Physical HT Physical mode settings allow for control of the Mode 802.11n wireless environment. Mixed Mode: In this mode, packets are transmitted with a preamble compatible with the legacy 802.11a/g, the rest of Operating the packet has a new format Mode Green Field: In this mode, high throughput packets are transmitted without a legacy compatible part

76

Channel 20 Channel Width = 20 MHz Bandwidth 20/40 Channel Width = 20/40 MHz Extension Choose the extension channel Channel(5G frequency Hz Only) With IEEE 802.11ac standard, very- VHT high-throughput packets can be Option(5GHz configured to operate on the 5 GHz Only) frequency band

VHT 20/40 Channel Width = 20/40 MHz Bandwidth(5 80 Channel Width = 80 MHz GHz Only)

77

5.4.2 Security

Open 2.4G (5G)/Security webpage to set the encryption of routers.

WAP-PSK/WAP2-PSK/WAPPSKWAP2PSK SSID Choose one SSID from the drop-down Choice list Choose an encryption method from the drop-down list, if disabled, wireless Security transmissions to and from your wireless Mode network can be easily intercepted and interpreted by unauthorized users “TKIP” (Temporal Key Integrity Protocol) provides per-packet key generation and is based on WEP, “AES” (Advanced Encryption WPA Standard) is a very secure block-based Algorithms encryption, and the “TKIPAES” option has the router negotiate the cipher type

with the client and uses AES when available.

78

Wireless Connection Security Password Pass Phrase (min. 8 characters)

Key The amount of time before the group Renewal key used for broadcast and multicast Interval data is changed Select one of the four WEP keys, the Default Key key settings on the client network card also need to correspond with this Set the WEP key: a 64-bit, Hex key will be 10 characters long, and a 64-bit, ASCII key will be 5 characters long; a WEP Keys 128-bit, Hex key will be 26 characters long, and a 128-bit, ASCII key will be 13 characters long

Policy Choose an Access Policy Add a Use this section to add MAC addresses station to your Access Policy MAC

79

5.4.3 WPS

WPS (Wi-Fi Protected Setup) provides easy procedure to make network connection between wireless station and (vigor router) with the encryption of WPA and WPA2.

It is the simplest way to build connection between wireless network clients and vigor router. Users do not need to select any encryption mode and type any long encryption passphrase to setup a wireless client every time. He/she only needs to press a button on wireless client, and WPS will connect for client and router automatically. Press button less than 5s for 2.4G, press button between 5 to 10s for 5.0G.

WPS If or not enable WPS Configuration WPS The status for Current connection, Summary SSID and so on PIN: In the following PIN options, fill WPS in the PIN code of the client (wireless Progress card, etc.) that needs to be accessed,

80

and then click Apply. PBC: PBC mode There are two ways to start, you can directly press the PBC button on the hardware, or select to PBC mode, and then click Apply

There are three WPS states: WSC: Idle state is idle WSC: Start WSC Process Status is to WPS Status start sending messages WSC: Success: If a client accesses an AP, the WPS connection succeeds

81

5.4.4 Station list

You could monitor stations which associated to this AP here

5.4.5 Client

Enable Wi-Fi Client would be one option for WAN Failover, select as the default route.

Connection Current Wi-Fi Client

Status connect status

82

Select one SSID and press the button, Connect enter the password for the SSID

Refresh the SSID Refresh scan result

Add one new/hidden Add SSID manually

83

5.5 Phone

5.5.1 VoIP QoS

QoS services can improve the quality

of voice applications. The default value SIP QoS(0-63) is 46, and the range of values can be set from 0 to 63. Once Multi-WAN port is enabled, select the corresponding voice PPPoE RTP QoS(0-63) server VID, the devices under the same

VLAN can transmit voice data.

5.5.2 Dial Plan

Dial Plan Select to enable or disable Unmatched Select from Accept or Reject Policy FXS Select the FXS port

84

Fill in the expression of digital map, Digital Map please refer to the digital map syntax.

Select the match action of the digital map, Deny means the device will reject Action the matching number dialing, and Dial Out means the device can dial out the matching number

85

5.5.3 Blacklist

You can upload or download the phone book, blacklist

86

5.5.4 Call Log

On this page, users can view replay lists (outgoing calls), received calls, and missed calls.

87

5.6 SIP Account

5.6.1 FXS1/2 SIP Account

Select to enable or disable Line Enable line Outgoing Select to enable or disable Call without this function Registration Display The display name of this Name SIP number Phone The phone number provided Number by SIP server The account provided by Account SIP server for authentication The password provided by Password SIP server for authentication

88

5.6.2 FXS1/2 Audio Configuration

Select the appropriate Audio Codec Type encoding Select from 5.3kbps or G.723 Coding Speed 6.3kbps Set the RTP packetization period. Packet Cycle(MS) The default configuration is 20ms Silence Supp Mute enable Echo Cancellation is Echo Cancel enabled by default Used to automatically adjust the speech level Auto Gain Control of an audio signal to a predetermined value Use First Matching Select to enable or Vocoder in 200OK SDP disable

89

Select from local or Codec Priority remote Packet Cycle Follows Select to enable or Remote SDP disable Select from T.30/ FAX Mode T.38/ Bypass Select from Bypass Attribute Value fax/modem or X- fax/X-modem T.38 CNG Detect Select to enable or Enable disable T.38 CED Detect Select to enable or Enable disable Select to enable or gpmd attribute Enable disable Select to enable or T.38 Redundancy disable Select from 14400/ Max Fax Rate 9600/ 4800

90

5.6.3 FXS1/2 Supplementary Service Subscription

Call Select to enable or disable Waiting Fill in the hotline number. After the subscriber is set up Hot Line successfully, the hotline number will be automatically dialed immediately after off-hook Enable WMI (Message Waiting MWI Indication), enable this function Enable if you want to use voicemail Voice Fill in the voicemail code Mailbox Numbers provided by your ISP MWI Subscribe Select to enable or disable Enable VMWI Select to enable or disable Serv After enable this option, any DND phone call cannot be dialed in,

91

default is disable

Speed Pre-set the phone number for Dial Fast call

92

5.7 Security

5.7.1 Filtering Setting

Select to enable Filtering or disable

Default Select from Drop Policy or Accept

Select from LAN Interface or WAN

Fill MAC Mac address for address Filtering control Fill Destination Dest IP IP address for Address Filtering control

93

Fill source IP Source IP address for Address Filtering control

Select from TCP/ Protocol UDP /ICMP

Fill Destination Dest. Port port range for Range Filtering control Fill source port Src Port range for Range Filtering control

Select from Action Accept or Drop

Fill the comment Comment for this filtering rule

94

5.7.2 Content Filtering

Select to Filtering enable or disable Select from Default Drop or Policy Accept Select the Local File local file for upload Current Existing URL Webs filtering rules URL Filters (blacklist)

Add a Add a URL URL Filter filtering rule

95

Fill the URL URL for webs filtering Current Existing Website keywords Host Filters (blacklist) Add a Host Add a (keyword) keyword rule Filter

Fill the Keyword keyword for filtering

96

5.8 Application 5.8.1 Advance Nat

In this page, you can choose to enable / disable FTP, SIP, H323, PPTP, L2TP, IPsec services.

97

5.8.2 UPnP

UPnP (Universal Plug and Play) supports null-setting for networking, can automatically find a variety of networked devices. When UPnP is enabled, UPnP- enabled devices are allowed to dynamically access the network, obtain IP addresses, and transmit performance information. If you have DHCP and DNS servers on your network, you can automatically obtain DHCP and DNS

services. UPnP-enabled devices can be automatically disconnected from the network without affecting the device or other devices on the network.

98

5.8.3 IGMP

Multicast has the function of sending the

same data to multiple devices. An IP host uses the IGMP (Internet Group Management Protocol) to report multicast group memberships to send data to neighboring routers, and the multicast router uses IGMP to discover which hosts belong to the same multicast

group.

99

5.9 Administration

5.9.1 Management

Save Configuration File

Select the local file for Local File configuration Use this option to restore

Upload previously saved router configuration settings. This option allows you to export and then save the router's configuration to a file on your computer. Be Download sure to save the configuration before performing a firmware upgrade

100

Administrator Settings

New User New user name for

Name management

New Type the password for Password user

Confirm Type the same password Password again Setup the language for Language operation, select from English or Spanish

Refresh The auto refresh interval Interval for LTE status

Management Select to enable or disable using VPN

Allow host remote access Remote Web Login from Active WAN

101

Enter the HTTP port Local Web number for accessing from Port local side

Enter the HTTP port Web Port number for accessing from

remote side

Web Idle Timeout for web idle Timeout (0 -60min) activity

Allow the host with Allowed Remote IP specified IP address to (IP1; IP2 ;...) access from webpage

102

Time/Date Settings

Select this

option if you want to synchronize the NTP Enable router's clock to a Network Time Server over the Internet. Obtain NTP Option 42 Server via DHCP Server Displays the time currently Current Time maintained by the router Synchronize Sync with host with your

103

current host's system time Select your local NTP Settings time zone from drop-down list Type the primary Primary NTP Network Time Server Server for synchronization Type the secondary Secondary NTP Network Time Server Server for synchronization Interval time for NTP synchronization NTP (1 -1440min) synchronization

104

Reset to Factory Default

This option restores all configuration

settings back to the settings that were in effect at the time the router was shipped from the factory. Any settings that have not been saved will be lost.

5.9.2 Firmware Upgrade

Once you have a firmware update on your computer, use this option to browse for the file and then upload the information into the router.

105

5.9.3 Scheduled Tasks

Scheduled Select to enable or Wi-Fi Enable disable Choose the specified SSID SSID for scheduled Wi- Fi

Scheduled Select the Schedule Mode mode for cycle time Wi-Fi Setup the working time Work Time for Wi-Fi broadcast

Scheduled Select to enable or Reboot disable

Scheduled Select the Schedule Mode mode for cycle time

Time Setup the reboot timing

106

Scheduled Select to enable or

PPPOE disable

Scheduled Select the Schedule Mode mode for cycle time Setup the Pope Time connection timing

107

5.9.4 Provision

Please refer to the provision user manual to test provision.

Provision Select to enable or disable Enable

Resin On Enable or disable DIV378 Reset Resin after rebooting Setup the maximum delay Resin Random for request Delay(sec) synchronization If the last resynchronization is unsuccessful, after the Resin "Sync Retry Delay Error" Periodic(sec) time, after "time, the device will retry the resynchronization Resin Error Set the timed Retry Delay(sec) resynchronization

108

If it is time to re-sync, but the device is busy, in this case, the device will wait for some time, the longest Forced Resin is "forced Delay(sec) resynchronization delay", the default is 14400s, time after the device will be forced to re-sync. After the

Resin After resynchronization, enable Upgrade or disable the firmware update function

Resin From Select to enable or disable SIP resin from SIP Specifies the TFTP Option 66 (Simple File Transfer Protocol) server address

109

Specifies the startup file Option 67 name Config File Configure the file name Name User Agent The name of user agent

The URL of the configuration file Note that the specified file Profile Rule path is relative to the root directory of the TFTP server Upgrade Select to enable or disable Enable Interval time for retry Upgrade Error Retry upgrade firmware if error Delay(sec) happen

Upgrade The path of firmware Rule located

110

5.9.5 TR069

TR069 Select to enable Enable or disable

Select to enable CWMP or disable

ACS The URL of URL ACS agent

User The user name Name of ACS agent

The password Password of ACS agent

111

Select to enable or disable the Periodic Inform periodic Enable notification function is Setup periodic Periodic Inform Notification Interval Interval User name for

User TR069 server Name connected to DUT Password for TR069 server Password connected to DUT

112

5.10 System Log

If you enable the system log in Status/syslog webpage, you can view the system log in this webpage.

113

5.10.1 Logout

Press the logout button to logout, and then the login window will appear.

5.10.2 Reboot

Press the Reboot button to reboot CDS9070.

114

6 Troubleshooting Guide

6.1 Setting up your PC to get an IP automatically

Following are the process of setting your PC gets IP automatically

Step 1. Click the “begin”

Step 2. Select “”, then double click “network connections” in the “control panel”

Step 3. Right clicks the “network connection” that your PC uses, select “attribute” and you can see the interface as picture

1: Step 4. Select “Internet Protocol (TCP/IP)”, click “attribute” button, and you can see the interface as following Picture 2 and you should click the “Get IP address automatically”.

115

Picture 2 Picture 1

116

6.2 Cannot connect to the Management Portal

Solution:

Check if the Ethernet cable is properly connected, then

Check if the URL is Written Correctly, the format of URL is: http:// the IP address.

Check if the version of IE is IE8, or use other browser such as Firefox or Mozilla, then Contact your administrator, supplier, or ITSP for more information or assistance.

6.3 Forgotten Password

If user changed the password and then forgot, you cannot access to the configuration website.

Solution:

To factory default: press reset button for 10s. The unit will then revert back to its Factory Configuration.

117

7 Statement

FCC Radiation Exposure Statement

Data Remote Incorporated. Declares that this device is in compliance with the essential requirements and other relevant provisions of Directive 1999/5/EC.

This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to part 15 of the

FCC rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, many cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:

-Reorient or relocate the receiving antenna.

-Increase the separation between the equipment and receiver.

118

-Connect the equipment into an outlet on a circuit different from that to which the receiver is

Connected.

-Consult the dealer or an experienced radio/TV technician for help.

To assure continued compliance, any changes or modifications not expressly approved by the party

Responsible for compliance could void the user’s authority to operate this equipment. (Example- use

Only shielded interface cables when connecting to computer or peripheral devices)

FCC Radiation Exposure Statement

This equipment complies with FCC RF radiation exposure limits set forth for an uncontrolled

Environment. This transmitter must not be co-located or operating in conjunction with any other

Antenna or transmitter.

This equipment complies with Part 15 of the FCC Rules. Operation is subject to the following two

Conditions:

(1) This device may not cause harmful interference, and

(2) This device must accept any interference received, including interference that may cause

119

Undesired operation.

This equipment should be installed and operated with minimum distance 20cm between the radiator

And your body.

120