| Element | Description |
|---|---|
| DHCP | Enables/disables the DHCP protocol. The protocol offers a possibility to assign the IP address of the UTN server automatically. |
| BOOTP | Enables/disables the BOOTP protocol. The protocol offers a possibility to assign the IP address of the UTN server automatically. |
| ARP/PING | Enables/disables the IP address assignment via ARP/PING. The assignment of the IP address to the hardware address can be done via the ARP table. |
| IP address | IP address of the UTN server |
| Subnet mask | Subnet mask of the UTN server |
| Gateway | Gateway address of the UTN server |
| Element | Description |
|---|---|
| IPv4 management VLAN | Enables/disables the forwarding of IPv4 management VLAN data. Note: If this option is enabled, SNMP is only available in the IPv4 management VLAN. |
| IPv4 management VLAN - VLAN ID | ID for the identification of the IPv4 management VLAN (1–4094). |
| IPv4 management VLAN - IP address | IP address of the UTN server |
| IPv4 management VLAN - Subnet mask | Subnet mask of the UTN server |
| IPv4 management VLAN - Gateway | Gateway address of the IPv4 management VLAN |
| IPv4 management VLAN - Access from any VLAN | Enables/disables the administrative access (web) to the UTN server via IPv4 client VLANs. If this option is enabled, the UTN server can be administrated via all VLANs. |
| IPv4 management VLAN - Access via LAN (untagged) | Enables/disables the administrative access to the UTN server via IPv4 packets without tag. If this option is disabled, the UTN server can only be administrated via VLANs. |
| IPv4 client VLAN - VLAN | Enables/disables the forwarding of IPv4 client VLAN data. |
| IPv4 client VLAN - IP address | IP address of the UTN server within the IPv4 client VLAN. |
| IPv4 client VLAN - Subnet mask | Subnet mask of the UTN server within the IPv4 client VLAN. |
| IPv4 client VLAN - Gateway | Gateway address of the IPv4 client VLAN. |
| IPv4 client VLAN - VLAN ID | ID for the identification of the IPv4 client VLAN (1–4094). |
| Element | Description |
|---|---|
| IPv6 | Enables/disables the IPv6 functionality of the UTN server. |
| Automatic configuration | Enables/disables the automatic assignment of the IPv6 address for the UTN server. |
| IPv6 address | Defines a UTN server IPv6 unicast address assigned manually in the format n:n:n:n:n:n:n:n. Every 'n' represents the hexadecimal value of one of the eight 16 bit elements of the address. |
| Router | Defines the IPv6 unicast address of the router. The UTN server sends its 'Router Solicitations' (RS) to this router. |
| Prefix length | Defines the length of the subnet prefix for the IPv6 address. The value 64 is preset.
Address ranges are indicated by prefixes. The prefix length (number of bits used) is added to the IPv6 address and specified as a decimal number. The decimal number is separated by '/'. |
| Element | Description |
|---|---|
| DNS | Enables/disables the name resolution via a DNS server. DNS allows for the mutual assignment of names and addresses. |
| Primary DNS server | Defines the IP address of the primary DNS server. |
| Secondary DNS server | Defines the IP address of the secondary DNS server. The secondary DNS server is used if the primary DNS server is not available. |
| Domain name (suffix) | Defines the domain name of an existing DNS server. |
| Element | Description |
|---|---|
| SNMPv1 | Enables/disables SNMPv1. |
| Read-only | Enables/disables the write protection for the community. |
| Community | SNMP community name The SNMP community is a basic form of access protection in which several participants with the same access rights are grouped together. |
| SNMPv3 | Enables/disables SNMPv3. Note: For SNMPv3 you have to define user accounts. |
| Hash | Defines the hash algorithm. |
| Access rights | Defines the access rights of the SNMP user. |
| Encryption | Defines the encryption method. |
| Element | Description |
|---|---|
| POP3 | Enables/disables the POP3 functionality. |
| POP3 - Server name | Defines a POP3 server via the IP address or the host name. (The host name can only be used if a DNS server was configured beforehand.) |
| POP3 - Server port | Defines the port used by the UTN server for receiving emails. The port number 110 is preset. When using SSL/TLS, enter 995 as port number. |
| POP3 - Security | Defines the authentication method to be used (APOP / SSL/TLS). When using SSL/TLS, the encryption strength is defined via the encryption protocol and level. |
| POP3 - Check mail every | Defines the time interval (in minutes) for retrieving emails from the POP3 server. |
| POP3 - Ignore emails exceeding | Defines the maximum email size (in Kbyte) to be accepted by the UTN server. (0 = unlimited) |
| POP3 - User name | Defines the user name used by the UTN server to connect to the POP3 server. |
| POP3 - Password | Defines the password used by the UTN server to connect to the POP3 server. |
| SMTP - Server name | Defines an SMTP server via the IP address or the host name. (The host name can only be used if a DNS server was configured beforehand.) |
| SMTP - Server port | Defines the port number used by the UTN server to send emails to the SMTP server. The port number 25 is preset. |
| SMTP - SSL/TLS | Enables/disables SSL/TLS. SSL/TLS is used to encrypt the transmission between the UTN server and the SMTP server. The encryption strength is defined via the encryption protocol and level. |
| SMTP - Sender name | Defines the email address used by the UTN server to send emails. Note: Very often the name of the sender and the user name are identical. |
| SMTP - Login | Enables/disables the SMTP authentication for the login. |
| SMTP - User name | Defines the user name used by the UTN server to log on to the SMTP server. |
| SMTP - Password | Defines the password used by the UTN server to log on to the SMTP server. |
| SMTP - Security (S/MIME) | Enables/disables the encryption and signing of emails via S/MIME. |
| SMTP - Signing emails | Defines the signing of emails. A signature created by the sender allows the recipient to verify the identity of the sender and to make sure that the email was not modified. An S/MIME certificate is required for the signing of emails. |
| SMTP - Full encryption | Defines the encryption of emails. Only the recipient can open and read the encrypted email. An S/MIME certificate is required for the encryption. |
| SMTP- Attach public key | Sends the public key together with the email. Many email clients require the public key to be attached in order to view the emails. |
| Element | Description |
|---|---|
| Bonjour | Enables/disables Bonjour. Bonjour describes a technology used for the automatic recognition of computers, devices and network services in IP networks. |
| Bonjour name | Defines the Bonjour name of the UTN server. The UTN server uses this name for its Bonjour services. If no Bonjour name is entered, the default name will be used (device name@ICxxxxxx). |
| Element | Description |
|---|---|
| Host name | Defines the host name of the UTN server. |
| Description | Freely definable description |
| Contact person | Freely definable description |
| Element | Description |
|---|---|
| Date/Time | Enables/disables the use of a time server (SNTP). A time server synchronizes the time of devices within a network. |
| Time server | Defines a time server via the IP address or the host name. (The host name can only be used if a DNS server was configured beforehand.) |
| Time zone | The time zone is used to equalize the difference between the time received over the time server and the local time, including country-specific particularities such as Daylight Saving Time. |
| Element | Description |
|---|---|
| UTN port | Defines the number of the UTN port. Client and UTN server communicate via the UTN port. The port number 9200 is preset. Note: The UTN port must not be blocked by a firewall. |
| UTN SSL port | Defines the number of the UTN SSL port. Encrypted connection means that client and UTN server communicate via the UTN SSL port. The port number 9443 is preset. Note: The UTN SSL port must not be blocked by a firewall. To define an encrypted connection, see: Encryption. |
| Element | Description |
|---|---|
| Port | Disables/enables the power supply for the USB port (i.e. the USB device connected to the port). This function can be used to turn on/off a USB device connected to the USB port (e.g. in case of an error). |
| Port name | Freely definable description of the USB port. If no port name is defined, the default name of the USB device connected will be used. Using the port description, the connected USB device can be displayed with the desired name. |
| Element | Description |
|---|---|
| Email address | Defines the email address of the recipient for notifications. |
| Send email if UTN server is restarted | Enables/disables the sending of emails when the UTN server is restarted. |
| Send email if USB devices are connected or disconnected | Enables/disables the sending of emails after a USB device was connected to/removed from the UTN server. |
| Send email if USB port is activated or deactivated | Enables/disables the sending of emails after a USB port was activated/deactivated. |
| Status email - Recipient | Enables/disables the periodical sending of a status email to recipient 1 or 2. |
| Status email - Interval | Specifies the interval at which a status email is sent. |
| SNMP traps - Address | Defines the SNMP trap address of the recipient. |
| SNMP traps - Community | Defines the SNMP trap community of the recipient. |
| Send trap if UTN server is restarted | Enables/disables the sending of SNMP traps when the UTN server is restarted. |
| Send trap if USB devices are connected or disconnected | Enables/disables the sending of SNMP traps after a USB device was connected to/removed from the UTN server. |
| Send trap if USB port is activated or deactivated | Enables/disables the sending of SNMP traps after a USB port was activated/deactivated. |
| Element | Description |
|---|---|
| Encryption protocol | Defines the encryption protocol to be used for SSL/TLS connections. Which protocols can be chosen depends on the product and its software version. With 'Any', the protocol is automatically negotiated by both communicating parties. |
| Encryption Level | Defines the encryption level to be used for SSL/TLS connections: - Any (The encryption is automatically negotiated by both communicating parties. The strongest encryption supported by both parties will always be chosen.) - Low (weak encryption) - Medium - High (strong encryption) |
Detailed information (connection status, cipher suites, etc.) can be found on the Details page. |
| Element | Description |
|---|---|
| HTTP/HTTPS | Defines the permitted type of connection (HTTP/HTTPS) to the myUTN Control Center. If HTTPS is exclusively chosen as the connection type, the administrative access to the myUTN Control Center is protected via SSL/TLS. The encryption strength is defined via the encryption protocol and level. |
| User accounts | Defines the two user accounts (name and password) for restricted myUTN Control Center access and SNMP access. - Administrator: Complete access to the myUTN Control Center. The user can see all pages and administrate. - Read-only user: Very restricted access to the myUTN Control Center. The user can only see the 'START' page. |
| Restrict Control Center access | Enables/disables the myUTN Control Center access restriction. If access is restricted, a login screen is displayed when opnening the myUTN Control Center. Note: If access is restricted, user accounts must be defined. |
| Login screen displays | Defines the type of login screen. Alternatively are displayed - a list of users (User names are displayed. Only the password must be entered.) - name and password request (Neutral login screen in which user name and password are to be entered.) |
| Session timeout | Enables/disables the session timeout. If there is no activity during the timeout defined, the connection to the myUTN Control Center is terminated for security reasons. In the box, enter the time in seconds after which the timeout is to be effective. |
| SNMPv1 | Enables/disables SNMPv1. |
| Read-only | Enables/disables the write protection for the community. |
| SNMPv3 | Enables/disables SNMPv3. |
| Disable input devices (HID class) | De-/activates the blocking of input devices (HID - human interface devices). Use this function to protect the UTN server from USB devices that present themselves as HID class devices but actually used for abuse (known as "BadUSB"). |
| Element | Description |
|---|---|
| Port access control | Enables/disables the locking of the selected ports. The port types to be locked are defined in the 'Security level' area. Caution: It may no longer be possible to send information to the UTN server (e.g. DNS server, SNTP server) and the configurability of the UTN server may be lost. In the 'Exceptions' area, define elements excluded from port locking, in order to ensure the configurability of the UTN server. Test the access control by enabling the 'Test mode'. |
| Test mode | Enables/disables the test mode. The test mode allows you to test the parameters set using the access control. If the test mode is activated, the access protection remains active until the UTN server is rebooted. Caution: After a successful test, you must deactivate the test mode so that access protection remains permanently active. |
| Security level | Locks the access to the selected port types. - Lock UTN access (UTN ports) - Lock TCP access (TCP ports: HTTP/HTTPS/UTN) - Lock all (all IP ports) Note: The parameter 'Port access control' must be enabled for the lock to be effective. In the 'Exceptions' area, define elements excluded from port locking, in order to ensure the configurability of the UTN server. |
| Exceptions | Defines elements that are excluded from port locking using the IP or hardware address. A total of 16 exceptions can be defined.The use of wildcards (*) allows you to define subnetworks. Note: Hardware addresses (MAC) are not delivered through routers! |
| Element | Description |
|---|---|
| Method | Specifies a method to control the access (via the USB ports) to the USB devices that are connected to the UTN server. - Port key control: Specifies the deployment of a key to use with the USB device connected to the USB port. - Device assignment: Device assignment means that a USB device is permanently assigned to a USB port. A USB device can then only be operated together with its assigned USB port. (Both security methods can also be used in combination.) |
| Key | Specifies the key for the port key control. The key can be entered manually or can be generated automatically. (max. 64 characters are allowed) |
| USB device | Shows the VID (Vendor ID) and PID (Product ID) of the USB device that is assigned to the USB port via the device assignment. |
| Allocate VLAN | Allocates a VLAN to the USB port. |
| Element | Description |
|---|---|
| Certificates status | Click the magnifying glass icon to display the installed certificates. Displayed certificates can be deleted. By clicking the floppy disk icon, an installed certificate is saved locally. |
| Self-signed certificate | Displays a page to create a self-signed certificate. The self-signed certificate will be installed on the device. |
| Certificate request | Displays a page for the creation of a certificate request. In order to use a certificate that has been issued especially for the UTN server, a certificate request may be created. It must be sent to the certification authority which creates a certificate on the basis of this request. When the certificate has been received, it must be saved in the device. |
| PKCS#12 certificate | Displays a page for the installation of a PKCS#12 certificate. PKCS#12 certificates are used to save private keys and their respective certificates and to protect them by means of a password. Note: The PKCS#12 certificate must be in 'base64' format. |
| Requested certificate | Displays a page for the installation of a certificate that has been created by a certification authority (CA) for the UTN server on the basis of a certificate request. Note: The requested certificate must be in 'base64' format. |
| CA certificate | Displays a page for the installation of a certification authority's (CA) certificate. CA certificates are used for verifying certificates that have been issued by the respective certification authority. Note: The CA certificate must be in 'base64' format. Up to 32 CA certificates can be installed. |
| S/MIME certificate | Displays a page for the installation of an S/MIME certificate. S/MIME certificates (*.pem file) are used to sign and encrypt the emails that are sent by the UTN server. Note: The S/MIME certificate must be in 'base64' format. |
| Element | Description |
|---|---|
| Authentication method | Defines the authentication method that is used to identify devices or users in the network. |
| User name | Defines the name of the UTN server as saved in the authentication server (RADIUS). |
| Password | Defines the password of the UTN server as saved in the authentication server (RADIUS). |
| PEAP/EAP-FAST options | Defines the kind of external authentication for the EAP authentication methods TTLS, PEAP, and FAST. |
| Inner authentication | Defines the kind of inner authentication for the EAP authentication methods TTLS, PEAP, and FAST. |
| EAP root certificate | Defines the root certificate for the authentication procedure. Choose the root CA certificate of the certification authority that has issued the certificate of the authentication server (RADIUS). Note: The certificate must already be installed on the device; see: CA certificate. |
| Anonymous name | Defines the anonymous name for the unencrypted part of the EAP authentication methods TTLS, PEAP, and FAST. |
| WPA add-on | Optional expansion for WPA |
| Element | Description |
|---|---|
| USB port | Enables/disables the SSL/TLS encryption of the USB port. If the encryption is enabled, the payload between the clients and the USB devices (that are connected to the USB ports) will be transferred in an encrypted way. The encryption strength is defined via the encryption prtocol and level. |
| Element | Description |
|---|---|
| Parameter status | Click the magnifying glass icon to show the current0 parameter values of the UTN server. By clicking the floppy disk icon, a text file with the current parameter values is saved locally. |
| Parameter setup | Imports a previously selected text file with parameter values to the UTN server. The parameter values in the file are applied to the UTN server. |
| Element | Description |
|---|---|
| Default settings | Resets the parameters of the UTN server to their default values. Note: Since the IP address of the UTN server will be reset as well, the myUTN Control Center cannot be started or displayed in the browser after the reset. Installed certificates will not be deleted. |
| Element | Description |
|---|---|
| Update | Installs a previously selected update file (firmware/software) on the UTN server. In the course of an update, the existing firmware/software will be overwritten and replaced by a new version. The original parameter values remain unchanged. |
| Element | Description |
|---|---|
| Restart | Initiates a restart of the UTN server. |