6 VPN Function

6.0.1 Unauthorized

  • In the unauthorized case, users can only choose whether to enable VPN. After enabling VPN, they can remotely configure IoTBoX, which can only be used with our company’s IoTBoX Management Platform. After closing, no one will be able to remotely control IoTBoX. Companies with high security requirements can disable the VPN function

6.0.2 Authorized

  • After VPN is authorized, you can map collection devices, use custom configuration files, and use bridge mode
  • Wuyun configuration is our company’s default configuration and can be used with our company’s platform (recommended)
  • Map Device: The address is the IP address of the machine tool device to be controlled through VPN. Please ensure it can be pinged on the debugging page. Supports TCP and UDP point-to-point protocols, does not support UDP broadcast. To map devices, you need to set the device’s default gateway (Default Gateway, router address in Fanuc) to IoTBoX’s IP address
  • Bridge Mode: After bridge mode is enabled, VPN will switch to switch mode. All machine tool devices connected to net1, IoTBoX itself, and the customer’s computer’s VPN network card will be on the same virtual switch. This solution is suitable for VPN batch machine tool devices, or when the control protocol of machine tools/PLCs is not a TCP protocol
  • The password for Wuyun configuration is the platform configuration password and must match the platform password

6.0.3 Usage Method

First contact customer service to get a Wuyun platform account

Open the Wuyun Intelligent Gateway Management System https://www.woody.vip/custom and log in (account contact administrator for assignment)

The homepage has configuration files and software, please choose according to your platform

The device list page shows the status of all devices in your company. The IP address shown in the list is the IoTBoX VPN IP address, which can be used to manage the gateway

6.0.3.1 Map Device Usage Method

  1. On the IoTBoX VPN page, fill in the IP address of the device to be mapped in the mapping IP address
  2. The network configuration interface of the device to be mapped needs to set the Gateway to IoTBoX’s IP address

Then the mapping from IoTBoX to the device can be achieved. At this time, on a computer connected to VPN, you can directly perform machine tool/PLC upload/download functions on IoTBoX’s VPN IP, which is equivalent to operating the machine tool/PLC itself

6.0.3.2 Bridge Mode Usage Method

On the IoTBoX VPN page, set bridge mode to on to use VPN bridge mode. This solution is more complex and is suitable when the mapping solution cannot solve the problem.

The core of this solution is to place machine tools/PLCs and users on the same switch, so users need to manually configure IP addresses to make the network reachable. The network configuration method is as follows (if IP address configuration is not needed, you can skip it and directly use related software for broadcast scanning)


6.0.3.2.2 Computer IP Address Modification

If the machine tool already has its own network address and it’s inconvenient to modify, you can achieve a subnet by modifying the computer IP 1. Find the VPN network card in Windows Network Center, the driver contains Tap field 2. Open cmd (may require administrator privileges) and enter the following command

netsh interface ip add address "以太网卡名" 192.168.x.x 255.255.255.0

Replace the Ethernet card name with the name found in the previous step, and modify the IP address according to your own rules

6.0.3.2.2.1 Possible Issues
  • If multiple IoTBoX devices have bridge mode enabled at the same time, it may cause machine tool IP conflicts
  • The IP address added in this solution will be lost after VPN reconnection, and needs to be reconfigured each time you reconnect

6.0.3.3 Port Mapping Mode

  1. Ensure IoTBoX can ping the device to be mapped and can access the port to be forwarded
  2. On IoTBoX’s VPN page, add the IP and port to be mapped
  3. As shown in the figure below, the internal port is automatically generated. You can access the mapped service through IoTBoX’s VPN address plus the internal port

6.0.3.4 Route Mode

  • Open the device control interface as shown below

  • Enable router mode

  • Ensure IoTBoX can ping the device to be accessed

  • Open Windows cmd command box, need Administrator Mode to enter the following command

route add 192.168.1.0 mask 255.255.255.0 10.8.0.22
:: 192.168.1.0 is the network segment to be routed, can also be a single IP
:: 255.255.255.0 is the subnet mask of the network segment to be routed, use 255.255.255.255 for a single IP
:: 10.8.0.22 is **IoTBoX**'s VPN IP
  • After setting is complete, you can directly access the device’s internal IP, such as 192.168.1.x under the above configuration

6.0.3.5 Special Network Topology

Contact after-sales personnel for configuration guidance

6.0.4 Notes

  1. VPN can directly connect to the enterprise intranet. If security requirements are very high, operate with caution
  2. If you need private deployment of gateway management platform, please contact business
  3. Since VPN service data traffic will pass through the server, it will definitely cause high latency. For low-latency scenarios, avoid using VPN