--- title: "Startup wizard - icom OS Routers" slug: "quickstart-wizard-en" tags: ["icom OS"] updated: 2026-07-16T14:12:24Z published: 2026-07-16T14:12:24Z canonical: "docs.insys-icom.com/quickstart-wizard-en" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # Startup wizard - icom OS Routers **The Startup wizard** (also known as Quickstart wizard) starts an assisted configuration that enables you to set up the router for - System time synchronisation - User authentication - Internet (WAN) connection - VPN connection (icom Connectivity Suite or custom OpenVPN or IPsec) - Local network connection - icom Router Management and makes the router ready for operation. ## Using the Startup wizard Start the **Startup wizard** by selecting it from the splash screen that is displayed when a router in default settings is started up for the first time or from the *Wizards* menu in the user interface of the router. The wizard will take you through the most important configurations to commission your router with just a few steps. ### Step 1 - System time An accurate system time is essential for checking the validity of certificates (e.g. for VPN connections) or log entries. The default setting of this step adopts the time and time zone from your configuration PC and configures a regular time synchronisation using an NTP server. You can use these settings for virtually all applications and proceed to the next step. > [!WARNING] > Note for routers behind an external firewall! > > If you are not using a local time server, UDP port 123 must be opened for the router for time synchronization. ### Step 2 - Authentication The router requires the configuration of an authentication method to protect it against unauthorised access. Enter a user name and a strong password for future access to the router. You may click on *Generate password* to create a random password with high security. The recommended password attributes shown when entering the password are no requirement, but a good advise for entering a strong password. Also refer to the general recommendations for strong passwords. > [!CAUTION] > Do not forget your password! > > If you forget your password, you can only [reset your router to default settings](/kb/docs/en/resetting-to-defaults-en) to get access again. This will delete all data on the router. An optional [authentication via certificates](/kb/docs/en/secured-access-to-the-user-interface-of-the-router-en) can also be configured here. To do this, a client certificate must be installed in the browser that is used to access the router configuration. Additionally, the CA certificate that has been used to generate this client certificate must be uploaded to the router. ### Step 3 - Internet connection One essential function of a router is to provide Internet (WAN) connectivity. Select the primary WAN connection type (the available options depend on the equipment of the router) and provide the required access information. An optional redundant Internet connection can also be configured as well as an additional connection check. > [!NOTE] > APN when using M2M SIM Cards from INSYS icom! > > When using our M2M SIM cards, select the provider **TELE2 (INSYS)** with the APN **m2m.tele2.com** and do not enter a user name or password. > [!NOTE] > Optimized Ethernet port for WAN interface! > > For maximum performance, it is recommended to use Port 4 for a potential WAN interface on routers of the MRX.neo or MOROS.neo series. ### Step 4 - VPN connection The router can optionally be configured for a [VPN](/kb/docs/en/vpn-and-ppp-connections-en) (Virtual Private Network) connection. If you want to configure the router for participation in the [**icom Connectivity Suite - VPN**](https://www.insys-icom.com/en/products/managed-services/vpn-service/), you may either download it’s configuration from the **icom Connectivity Suite - VPN** or upload it to the router. The router must have been [added](/kb/docs/en/adding-an-insys-router-with-icom-os-to-the-icom-connectivity-suite-vpn-en) to the **icom Connectivity Suite - VPN** before this. If you want to configure the router for participation in a generic VPN either as the server or a client, you have to upload it’s configuration file and specify the settings. If you want to configure the router for a generic IPsec connection, you have to upload it’s configuration file and specify the settings. > [!WARNING] > Note for routers behind an external firewall! > > The connection to the **icom Connectivity Suite - VPN** is established by calling the domain. The router must therefore be able to resolve this using a DNS. UDP port 53 must be opened to be able to reach a DNS server. > > UDP port 1196 must be opened to establish a connection to the Init server (is used to download the configuration automatically) of the **icom Connectivity Suite - VPN**. > > The VPN port must also be opened for the subsequent operation of the router in the **icom Connectivity Suite - VPN**. You can find the port and protocol used in the **icom Connectivity Suite - VPN** on the [My VPN Hub](/kb/docs/en/icom-connectivity-suite-vpn-default-code-logs-and-info-on-my-vpn-hub-en) tab. ### Step 5 - LAN connection It is possible to customise the local network environment of the router to suit your individual application. Create one or more local networks to connect network participants in the respective IP range to the router. Use subnets to separate your local networks and control the communication of the network participants using the firewall. The local networks are configured automatically during startup when the router has been configured for the **icom Connectivity Suite - VPN** in the previous step. > [!NOTE] > Do you need a dedicated configuration port ? > > In earlier firmware versions, when the Startup Wizard has been executed, the Configuration port was retained in the **net1** IP network, and the LAN connection was configured in the **net2** IP network. As a result, the router remained accessible at **192.168.1.1** via a computer connected locally to the configuration port, even after the wizard had finished. > > With the current firmware, the router is then accessible only via the IP addresses configured here in the corresponding IP networks on the assigned Ethernet ports. > > If you still need a configuration port, you must assign it here to the desired Ethernet port and add another IP network for your network by clicking under LAN Settings. ### Step 6 - icom Router Management The [**icom Router Management**](https://www.insys-icom.com/en/products/managed-services/device-management/) enables easy rollouts of device firmware, configurations, security certificates and applications including logging. If you have an [**icom Router Management**](https://cloud.insys-icom.com/ui/login) account and already [registered the router](/kb/docs/adding-routers-to-icom-router-management) for this, you can upload the start configuration downloaded there onto the router in this step to connect the router to the **icom Router Management**. > [!WARNING] > Note for routers behind an external firewall! > > An outgoing connection via HTTPS port 443 must be opened for a connection to the **icom Router Management**. ## Completing the Startup wizard When the Startup wizard has been executed, it will show it’s progress on an overview page. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(85).png) Leave the Startup wizard using the EXIT WIZARD button to return to the router interface. A VPN is a communications environment in which access is controlled to permit peer connections only within a defined community of interest. It is constructed though some form of partitioning of a common underlying communications medium, where this underlying communications medium provides services to the network on a non-exclusive basis On routers in default settings, Port 1 (ETH 1) is intended as the configuration port. The router's user interface can be accessed via this Ethernet port at [https://192.168.1.1](https://192.168.1.1). After running the [Startup Wizard](/kb/docs/quickstart-wizard-en) or making other changes to the configuration, the router may no longer be accessible in this way.