myUTN
img
Select your language  

myUTN Control Center
Online Help
Version 4.1

NETWORK - IPv4

Element Description
DHCP Enables/disables the DHCP protocol.
The protocol offers a possibility to assign the IP address of the UTN server automatically.
BOOTP Enables/disables the BOOTP protocol.
The protocol offers a possibility to assign the IP address of the UTN server automatically.
ARP/PING Enables/disables the IP address assignment via ARP/PING.
The assignment of the IP address to the hardware address can be done via the ARP table.
IP address IP address of the UTN server
Subnet mask Subnet mask of the UTN server
Gateway Gateway address of the UTN server

NETWORK - IPv4 VLAN

Element Description
IPv4 management VLAN Enables/disables the forwarding of IPv4 management VLAN data.
Note: If this option is enabled, SNMP is only available in the IPv4 management VLAN.
IPv4 management VLAN - VLAN ID ID for the identification of the IPv4 management VLAN (1–4094).
IPv4 management VLAN - IP address IP address of the UTN server
IPv4 management VLAN - Subnet mask Subnet mask of the UTN server
IPv4 management VLAN - Gateway Gateway address of the IPv4 management VLAN
IPv4 management VLAN - Access from any VLAN Enables/disables the administrative access (web) to the UTN server via IPv4 client VLANs.
If this option is enabled, the UTN server can be administrated via all VLANs.
IPv4 management VLAN - Access via LAN (untagged) Enables/disables the administrative access to the UTN server via IPv4 packets without tag.
If this option is disabled, the UTN server can only be administrated via VLANs.
IPv4 client VLAN - VLAN Enables/disables the forwarding of IPv4 client VLAN data.
IPv4 client VLAN - IP address IP address of the UTN server within the IPv4 client VLAN.
IPv4 client VLAN - Subnet mask Subnet mask of the UTN server within the IPv4 client VLAN.
IPv4 client VLAN - Gateway Gateway address of the IPv4 client VLAN.
IPv4 client VLAN - VLAN ID ID for the identification of the IPv4 client VLAN (1–4094).

NETWORK - IPv6

Element Description
IPv6 Enables/disables the IPv6 functionality of the UTN server.
Automatic configuration Enables/disables the automatic assignment of the IPv6 address for the UTN server.
IPv6 address Defines a UTN server IPv6 unicast address assigned manually in the format n:n:n:n:n:n:n:n. Every 'n' represents the hexadecimal value of one of the eight 16 bit elements of the address.
Router Defines the IPv6 unicast address of the router. The UTN server sends its 'Router Solicitations' (RS) to this router.
Prefix length Defines the length of the subnet prefix for the IPv6 address. The value 64 is preset.
Address ranges are indicated by prefixes. The prefix length (number of bits used) is added to the IPv6 address and specified as a decimal number. The decimal number is separated by '/'.

NETWORK - DNS

Element Description
DNS Enables/disables the name resolution via a DNS server.
DNS allows for the mutual assignment of names and addresses.
Primary DNS server Defines the IP address of the primary DNS server.
Secondary DNS server Defines the IP address of the secondary DNS server.
The secondary DNS server is used if the primary DNS server is not available.
Domain name (suffix) Defines the domain name of an existing DNS server.

NETWORK - SNMP

Element Description
SNMPv1 Enables/disables SNMPv1.
Read-only Enables/disables the write protection for the community.
Community SNMP community name
The SNMP community is a basic form of access protection in which several participants with the same access rights are grouped together.
SNMPv3 Enables/disables SNMPv3.
Note: For SNMPv3 you have to define user accounts.
Hash Defines the hash algorithm.
Access rights Defines the access rights of the SNMP user.
Encryption Defines the encryption method.

NETWORK - Email

Element Description
POP3 Enables/disables the POP3 functionality.
POP3 - Server name Defines a POP3 server via the IP address or the host name.
(The host name can only be used if a DNS server was configured beforehand.)
POP3 - Server port Defines the port used by the UTN server for receiving emails. The port number 110 is preset. When using SSL/TLS, enter 995 as port number.
POP3 - Security Defines the authentication method to be used (APOP / SSL/TLS).
When using SSL/TLS, the encryption strength is defined via the encryption protocol and level.
POP3 - Check mail every Defines the time interval (in minutes) for retrieving emails from the POP3 server.
POP3 - Ignore emails exceeding Defines the maximum email size (in Kbyte) to be accepted by the UTN server.
(0 = unlimited)
POP3 - User name Defines the user name used by the UTN server to connect to the POP3 server.
POP3 - Password Defines the password used by the UTN server to connect to the POP3 server.
SMTP - Server name Defines an SMTP server via the IP address or the host name.
(The host name can only be used if a DNS server was configured beforehand.)
SMTP - Server port Defines the port number used by the UTN server to send emails to the SMTP server. The port number 25 is preset.
SMTP - SSL/TLS Enables/disables SSL/TLS. SSL/TLS is used to encrypt the transmission between the UTN server and the SMTP server.
The encryption strength is defined via the encryption protocol and level.
SMTP - Sender name Defines the email address used by the UTN server to send emails.
Note: Very often the name of the sender and the user name are identical.
SMTP - Login Enables/disables the SMTP authentication for the login.
SMTP - User name Defines the user name used by the UTN server to log on to the SMTP server.
SMTP - Password Defines the password used by the UTN server to log on to the SMTP server.
SMTP - Security (S/MIME) Enables/disables the encryption and signing of emails via S/MIME.
SMTP - Signing emails Defines the signing of emails. A signature created by the sender allows the recipient to verify the identity of the sender and to make sure that the email was not modified. An S/MIME certificate is required for the signing of emails.
SMTP - Full encryption Defines the encryption of emails.
Only the recipient can open and read the encrypted email. An S/MIME certificate is required for the encryption.
SMTP- Attach public key Sends the public key together with the email. Many email clients require the public key to be attached in order to view the emails.

NETWORK - Bonjour

Element Description
Bonjour Enables/disables Bonjour.
Bonjour describes a technology used for the automatic recognition of computers, devices and network services in IP networks.
Bonjour name Defines the Bonjour name of the UTN server.
The UTN server uses this name for its Bonjour services. If no Bonjour name is entered, the default name will be used (device name@ICxxxxxx).

DEVICE - Description

Element Description
Host name Defines the host name of the UTN server.
Description Freely definable description
Contact person Freely definable description

DEVICE - Date/Time

Element Description
Date/Time Enables/disables the use of a time server (SNTP).
A time server synchronizes the time of devices within a network.
Time server Defines a time server via the IP address or the host name.
(The host name can only be used if a DNS server was configured beforehand.)
Time zone The time zone is used to equalize the difference between the time received over the time server and the local time, including country-specific particularities such as Daylight Saving Time.

DEVICE - UTN port

Element Description
UTN port Defines the number of the UTN port.
Client and UTN server communicate via the UTN port. The port number 9200 is preset.
Note: The UTN port must not be blocked by a firewall.
UTN SSL port Defines the number of the UTN SSL port.
Encrypted connection means that client and UTN server communicate via the UTN SSL port. The port number 9443 is preset.
Note: The UTN SSL port must not be blocked by a firewall.
To define an encrypted connection, see: Encryption.

DEVICE - USB port

Element Description
Port Disables/enables the power supply for the USB port (i.e. the USB device connected to the port).
This function can be used to turn on/off a USB device connected to the USB port (e.g. in case of an error).
Port name Freely definable description of the USB port.
If no port name is defined, the default name of the USB device connected will be used. Using the port description, the connected USB device can be displayed with the desired name.

DEVICE - Notification

Element Description
Email address Defines the email address of the recipient for notifications.
Send email if UTN server is restarted Enables/disables the sending of emails when the UTN server is restarted.
Send email if USB devices are connected or disconnected Enables/disables the sending of emails after a USB device was connected to/removed from the UTN server.
Send email if USB port is activated or deactivated Enables/disables the sending of emails after a USB port was activated/deactivated.
Status email - Recipient Enables/disables the periodical sending of a status email to recipient 1 or 2.
Status email - Interval Specifies the interval at which a status email is sent.
SNMP traps - Address Defines the SNMP trap address of the recipient.
SNMP traps - Community Defines the SNMP trap community of the recipient.
Send trap if UTN server is restarted Enables/disables the sending of SNMP traps when the UTN server is restarted.
Send trap if USB devices are connected or disconnected Enables/disables the sending of SNMP traps after a USB device was connected to/removed from the UTN server.
Send trap if USB port is activated or deactivated Enables/disables the sending of SNMP traps after a USB port was activated/deactivated.

SECURITY - SSL connections

Element Description
Encryption protocol Defines the encryption protocol to be used for SSL/TLS connections. Which protocols can be chosen depends on the product and its software version.
With 'Any', the protocol is automatically negotiated by both communicating parties.
Encryption Level Defines the encryption level to be used for SSL/TLS connections:
- Any (The encryption is automatically negotiated by both communicating parties. The strongest encryption supported by both parties will always be chosen.)
- Low (weak encryption)
- Medium
- High (strong encryption)

Detailed information (connection status, cipher suites, etc.) can be found on the Details page.

SECURITY - Device access

Element Description
HTTP/HTTPS Defines the permitted type of connection (HTTP/HTTPS) to the myUTN Control Center.
If HTTPS is exclusively chosen as the connection type, the administrative access to the myUTN Control Center is protected via SSL/TLS. The encryption strength is defined via the encryption protocol and level.
User accounts Defines the two user accounts (name and password) for restricted myUTN Control Center access and SNMP access.
- Administrator: Complete access to the myUTN Control Center. The user can see all pages and administrate.
- Read-only user: Very restricted access to the myUTN Control Center. The user can only see the 'START' page.
Restrict Control Center access Enables/disables the myUTN Control Center access restriction.
If access is restricted, a login screen is displayed when opnening the myUTN Control Center.
Note: If access is restricted, user accounts must be defined.
Login screen displays Defines the type of login screen. Alternatively are displayed
- a list of users (User names are displayed. Only the password must be entered.)
- name and password request (Neutral login screen in which user name and password are to be entered.)
Session timeout Enables/disables the session timeout. If there is no activity during the timeout defined, the connection to the myUTN Control Center is terminated for security reasons. In the box, enter the time in seconds after which the timeout is to be effective.
SNMPv1 Enables/disables SNMPv1.
Read-only Enables/disables the write protection for the community.
SNMPv3 Enables/disables SNMPv3.
Disable input devices (HID class) De-/activates the blocking of input devices (HID - human interface devices).
Use this function to protect the UTN server from USB devices that present themselves as HID class devices but actually used for abuse (known as "BadUSB").

SECURITY - TCP port access

Element Description
Port access control Enables/disables the locking of the selected ports.
The port types to be locked are defined in the 'Security level' area.
Caution: It may no longer be possible to send information to the UTN server (e.g. DNS server, SNTP server) and the configurability of the UTN server may be lost.
In the 'Exceptions' area, define elements excluded from port locking, in order to ensure the configurability of the UTN server. Test the access control by enabling the 'Test mode'.
Test mode Enables/disables the test mode.
The test mode allows you to test the parameters set using the access control. If the test mode is activated, the access protection remains active until the UTN server is rebooted.
Caution: After a successful test, you must deactivate the test mode so that access protection remains permanently active.
Security level Locks the access to the selected port types.
- Lock UTN access (UTN ports)
- Lock TCP access (TCP ports: HTTP/HTTPS/UTN)
- Lock all (all IP ports)

Note: The parameter 'Port access control' must be enabled for the lock to be effective. In the 'Exceptions' area, define elements excluded from port locking, in order to ensure the configurability of the UTN server.
Exceptions Defines elements that are excluded from port locking using the IP or hardware address. A total of 16 exceptions can be defined.The use of wildcards (*) allows you to define subnetworks.
Note: Hardware addresses (MAC) are not delivered through routers!

SECURITY - USB port access

Element Description
Method Specifies a method to control the access (via the USB ports) to the USB devices that are connected to the UTN server.
- Port key control: Specifies the deployment of a key to use with the USB device connected to the USB port.
- Device assignment: Device assignment means that a USB device is permanently assigned to a USB port. A USB device can then only be operated together with its assigned USB port.
(Both security methods can also be used in combination.)
Key Specifies the key for the port key control. The key can be entered manually or can be generated automatically. (max. 64 characters are allowed)
USB device Shows the VID (Vendor ID) and PID (Product ID) of the USB device that is assigned to the USB port via the device assignment.
Allocate VLAN Allocates a VLAN to the USB port.

SECURITY - Certificates

Element Description
Certificates status Click the magnifying glass icon to display the installed certificates. Displayed certificates can be deleted.
By clicking the floppy disk icon, an installed certificate is saved locally.
Self-signed certificate Displays a page to create a self-signed certificate. The self-signed certificate will be installed on the device.
Certificate request Displays a page for the creation of a certificate request.
In order to use a certificate that has been issued especially for the UTN server, a certificate request may be created. It must be sent to the certification authority which creates a certificate on the basis of this request. When the certificate has been received, it must be saved in the device.
PKCS#12 certificate Displays a page for the installation of a PKCS#12 certificate.
PKCS#12 certificates are used to save private keys and their respective certificates and to protect them by means of a password.
Note: The PKCS#12 certificate must be in 'base64' format.
Requested certificate Displays a page for the installation of a certificate that has been created by a certification authority (CA) for the UTN server on the basis of a certificate request.
Note: The requested certificate must be in 'base64' format.
CA certificate Displays a page for the installation of a certification authority's (CA) certificate.
CA certificates are used for verifying certificates that have been issued by the respective certification authority.
Note: The CA certificate must be in 'base64' format. Up to 32 CA certificates can be installed.
S/MIME certificate Displays a page for the installation of an S/MIME certificate.
S/MIME certificates (*.pem file) are used to sign and encrypt the emails that are sent by the UTN server.
Note: The S/MIME certificate must be in 'base64' format.

SECURITY - Authentication

Element Description
Authentication method Defines the authentication method that is used to identify devices or users in the network.
User name Defines the name of the UTN server as saved in the authentication server (RADIUS).
Password Defines the password of the UTN server as saved in the authentication server (RADIUS).
PEAP/EAP-FAST options Defines the kind of external authentication for the EAP authentication methods TTLS, PEAP, and FAST.
Inner authentication Defines the kind of inner authentication for the EAP authentication methods TTLS, PEAP, and FAST.
EAP root certificate Defines the root certificate for the authentication procedure.
Choose the root CA certificate of the certification authority that has issued the certificate of the authentication server (RADIUS).
Note: The certificate must already be installed on the device; see: CA certificate.
Anonymous name Defines the anonymous name for the unencrypted part of the EAP authentication methods TTLS, PEAP, and FAST.
WPA add-on Optional expansion for WPA

SECURITY - Encryption

Element Description
USB port Enables/disables the SSL/TLS encryption of the USB port.
If the encryption is enabled, the payload between the clients and the USB devices (that are connected to the USB ports) will be transferred in an encrypted way. The encryption strength is defined via the encryption prtocol and level.

MAINTENANCE - Parameter backup

Element Description
Parameter status Click the magnifying glass icon to show the current0 parameter values of the UTN server.
By clicking the floppy disk icon, a text file with the current parameter values is saved locally.
Parameter setup Imports a previously selected text file with parameter values to the UTN server. The parameter values in the file are applied to the UTN server.

MAINTENANCE - Default settings

Element Description
Default settings Resets the parameters of the UTN server to their default values.
Note: Since the IP address of the UTN server will be reset as well, the myUTN Control Center cannot be started or displayed in the browser after the reset. Installed certificates will not be deleted.

MAINTENANCE - Update

Element Description
Update Installs a previously selected update file (firmware/software) on the UTN server.
In the course of an update, the existing firmware/software will be overwritten and replaced by a new version. The original parameter values remain unchanged.

MAINTENANCE - Restart

Element Description
Restart Initiates a restart of the UTN server.