DHCP Server Set Up. DHCP Freeware ‘HaneWIN’ »Available from // This freeware DHCP allows.
Secure High-Availability Remote Access to Industrial...
Transcript of Secure High-Availability Remote Access to Industrial...
![Page 1: Secure High-Availability Remote Access to Industrial …cdn-ecomm.dreamingcode.com/public/187/documents/Current...• DHCP server on Device LAN by Ethernet or as access point via external](https://reader036.fdocuments.us/reader036/viewer/2022070722/5f01c2767e708231d400e6d4/html5/thumbnails/1.jpg)
• TheSiteManager™itselfanditsmonitoreddevicesareallcentrallymanagedandac-cessiblefromtheGateManagerserver.
• Built-inserial,USBandEthernetaccessagentsformostPLC,HMIandServovendorsinthemarket,aswellasagenttemplatesforvideo,voice,PCandScadasystems(includingsupportforSiemensPPIandMPI)
• Firewallfriendlycommunication,-usesstandardwebprotocols,andonlyinside-out.
• NorequirementforpublicorfixedIPad-dress.SiteManagerisbydefaultDHCPenabled.Noneedtore-configurethePLCwithgatewayaddressetc.
• Canoperateascarrierofalarms,emailalertsetc.betweendevicesandcentralloggingserversovertheInternet.
• Built-infirewall,AESandx.509certificatesformaximumsecurity
• Allconfiguration,firmwareandfeatureupgradesaredoneremotelythroughanintuitivewebGUI
• User-configurableemailalertsforstatusmonitoringandconfigurableI/Oportsforcustomalarms.
• IntegratedWiFiforconnectingtotheInter-netviaalocalAccessPoint.
• CanoperateasWiFiaccesspointviaexternalUSBWiFiadapter(availablefromrelease6.0,Q22015)
• OptionalInternetaccessviaastandard4G/3G/GPRSmodeminstalledintheUSBport(availablefromrelease6.0,Q22015)
• IncludestheuniqueSecomeaEasyTunnelClientfeatureforallowingeasyenrollmentinaVPNnetwork.
• Securitycertifiedinaccordancewithlead-ingstandardsmethodologiesspecifiedbyNIST,ISA/IEC,BSIandISECOM.
RemoteManagement-SiteManager™1149and3349
Secure High-AvailabilityRemote Access to IndustrialDevices
SiteManager™ is an off-the-shelf component in the SecomeaIndustrial Communications Solution program that in combinationwith Secomea’s GateManager™ and LinkManager™ ensures unified,uninterruptedandsecureaccesstoremotedevices.
SiteManager™issecuritycertifiedaccordingtothehighestindustrystandards of the industry, performed by the independent securityorganisationProtectEMGmbHinGermanyinclosecooperationwiththeDeggendorfInstituteofTechnology.
The SiteManager™ 1149 and 3349 are robust DIN mountable appli-ancesthatinstallsinthemachinecontrolpanel,andprovidesremoteaccess for on-demand servicing and programming of equipment,concurrentlywithstaticconnectionsformonitoringandlogging.
TheSiteManager™1149and3349provideremoteaccesstoalltypesofindustrialequipmentviaEthernet,-Serial-orUSB,usingtheequip-ment’snativeprotocols(e.g.Modbus,PROFINET,EtherCAT;EtherNet/IPetc.)
The SiteManager™ 1149 and 3349 establish access to the Internetthrough the firewall of the existing wired network infrastructure,or wireless by the built-in WiFi option. Additionally the SiteManagerfeatures static VPN powered by the unique Secomea EasyTunnel™concept.
![Page 2: Secure High-Availability Remote Access to Industrial …cdn-ecomm.dreamingcode.com/public/187/documents/Current...• DHCP server on Device LAN by Ethernet or as access point via external](https://reader036.fdocuments.us/reader036/viewer/2022070722/5f01c2767e708231d400e6d4/html5/thumbnails/2.jpg)
PLC HMI PC Cam
GateManager™ Enabled GateManager™ enabled for easy, centralized configuration, backup,monitoringandaccessforremoteserviceandmaintenanceofSecomeaSiteManagerandindustrialdevices.TheGateManagerisavailablebothasahostedserviceandasastand-alonesoftwarepackage.
LinkManager™ Enabled The LinkManager is a one-step installation Windows application thatrunsonthesupportengineerPC.WorkingwithGateManager™itpro-videssecureon-demandaccess toremoteSerial, IPorUSBdevicesthroughtheSiteManagers.Onceconnected, itmakestheremotede-viceappeartothefieldengineerasiftheWindowsPCwasconnecteddirectlytothedevice.SowithLinkManager,anyremotedeviceisjustafewmouseclicksaway.
LinkManager™ Mobile Enabled The LinkManager Mobile is designed for accessing your devices viaatablet,mobilephoneorPCwithoutneeding installationofsoftware.LinkManagerMobileallowsaccesstodevicesusingWebbrowser,VNC/RDPRemoteDesktopclientsandselectediOSandAndroidRemoteHMIapps.
Static Device/Server Relays connections TheSiteManagerallowsStaticrelaystoaGateManagerenablingacen-tralserverorSCADAsystemtomonitordevicesreal-time,ortoallowdevicestopushstatusupdatesbacktothecentralserver.
Configurable Routing/Forwarding rules TheSiteManagercanbeconfiguredtoportforwardorrouteconnec-tionsbetweenitsUplinkandDevicenetworkports.ItcanevenbeusedassecureInternetrouterviaanintegratedWebproxy.
Optional EasyTunnel™ VPN supportTheSiteManagersupportstheuniqueSecomeaEasyTunnelVPNcon-cept. Enabling the included EasyTunnel Client in the SiteManager, willallowenrollmentinaVPNnetworkcontrolledbyaTrustGateconcen-trator.EasyTunnelworkslikeordinaryIPSecVPN,butwithouttheneedforjugglingcertificatesorkeys.SimplyentertheserialnumberoftheSiteManager,anditisinstantlyenrolledintheVPNnetwork.
State-of-the-Art SecurityTheSiteManagersolutionsareusingstate-of-the-artsecuritystand-ards. This includes a built-in stateful Inspection Firewall, authentica-tionsusingx.509digitalcertificateandencryptionusingthestrongAESstandardwithupto256-bit.TheentiresolutionisSecuritycertifiedac-cordingtothemostcurrentstandardsoftheindustry.
Firewall FriendlyTheend-usernetworksecurityisprioritynumber1.WiththeSiteMan-agerandthesecuritystandardthatthisincludes,it isimportantthatend-user do not need to compromise their own corporate securitystandards.Thereforeallcommunicationisencrypted,evenwhenusingport80fromtheinsideandout.
Local Access Management and loggingTheSiteManagerallowslocaladministeredaccessmanagementviaitsWebGUIordigitalports,inadditiontothecentraluseraccessmanage-ment.Ontopofthis,alluserconnectionsmadetotheSiteManageranditsconnecteddevicesareloggedcentrallyontheGateManager.
Drivers for any type deviceTheSiteManagerhasbuilt-inpreconfigureddrivers“agents”forremoteaccessinganytypeofdevicesuchasPLCs,HMis,IPCs,Robots,Servos,etc. Inaddition to this, it ispossible tocustomizeanagent forotherrequirements regardlessof it beingSerial, Ethernet,WiFi orUSBat-tached.
WiFi operation in both Client and Access Point modeTheSiteManager1149and3349featureabuilt-inWiFimodule,whichcanbeused foraccessing the Internetviaa localaccesspoint.Applyingan external USB adapter will allow operation as an access point forprovidingremoteaccesstoWiFiclientenableddevicesatthelocation.
4G/3G/GPRS Option with Wake-on-SMS(NOTE: available from release6.0,Q22015) TheSiteManager 1149and3349featureanoptionalUSBportforattachinga4G/3G/GPRSadapterforconnectingtotheInternet.ThisfeatureisusefulincaseswherenolocalinfrastructureexistsforconnectingtotheInternet.InadditiontheSiteManager supports a Wake-on-SMS that prevent consuming datatrafficchargeswheninidlemode.
Fail-over / Fail-back (Wired / Broadband)(NOTE:availablefromrelease6.0,Q22015).ByconnectingthewiredUp-linkandanoptional4G/3G/GRPSUplink,theSiteManagercanperformfail-overandtherebyensuremaximumuptime.Byprioritizingthewireduplink, theSiteManagerwill automatically fail-back to thewiredcon-nection,thusreducingconsumptionof4G/3G/GPRSdatacharges.
Flexible Alert notification systemTheSiteManagercanbeusedasgatewayforalertsgeneratedbylocaldevicesviaEthernet,Serialordigital input triggers,by theGateMan-agermonitoringstatusoftheSiteManagerandlocaldevices.AlertsareadministeredbythecentralGateManagerfromwheretheycanbesentasSMSorEmail.Inadditionallgeneratedalertarecentrallylogged.
RemoteManagement-SiteManager™3129
Secure High-Availability Remote Access to Industrial Devices
RemoteManagement-SiteManager™1149and3349
Unique Specifications
![Page 3: Secure High-Availability Remote Access to Industrial …cdn-ecomm.dreamingcode.com/public/187/documents/Current...• DHCP server on Device LAN by Ethernet or as access point via external](https://reader036.fdocuments.us/reader036/viewer/2022070722/5f01c2767e708231d400e6d4/html5/thumbnails/3.jpg)
Secomea A/S
Denmark
E-mail: [email protected]
www.secomea.com
Partnumbers Description
30102 SiteManager1149including5DeviceAgents
30103 SiteManager3349including25DeviceAgents
27101 SecomeaWiFiUSBadapterforoperationasAccessPoint(supportedfromfirmwarerelease6.0,availableQ2,2015)
27250 SecomeaWiFiUSBadapterwithSMAadapter(foroperationasAccessPoint)
26878 GateManagersettingspreconfigured
26940 MPI/PPIadapter(Ethernet)
Doc rev. 2015-03-20
Electrical Characteristics
• 536MhzARMCortexA5CPU
• Input12-24V/DC,viascrewterminals.
• NetworkInterfaces:2x10/100Mbit Ethernet(UPLINK,DEV1,)–RJ45connection
• 2xUSB2.0fullspeed(Host)
• 1xRS232DB9Serialportwithfullflowcontrol
• Powerconsumption:5W(dimensionpowersupplyto8Wpeak)
• 2xdigitalinputports
• 1xoutputrelay(max0,5A),1xdigitaloutputopendrain(max0,2A)
• Integrated2.4GHzWiFimoduleforClientmode,IEEE802.11b/g/n(Supportforupto8concurrentclients)
• WiFiantennaconnector,RP-SMAFemale
Regulations
• FCCClassA,CE
• EN55022ClassA
• EN55024
• EN61000-3-2,3
• EN61000-4-2,3,4,5,6,8,11
• IEC60950
• C-TickN29451
• ULListed(file#E358541)
Physical Charateristics
• Operatingtemperature:-25°-+60C°,5to95%RH
• Dimensions,unpacked:107(H)x32(W)x97(D)mm,500g
• DINmountbracket.
• AluminiumChassis
• 2-yearsWarranty
Networking Capabilities
• ChoiceofUplink(WAN)Internetaccess:-Ethernet,-WiFi-Optional3G/4G/GPRSUSBmodem(Availablefromrel6.0,Q22015)
• ChoiceofUplinkIP-assignmentmode:DHCPclient,PPPoEclient,manual/static
• TelnettoSerialrouting(rfc2217).SiemensMPI/PPIissupportedviaanadapter
• DHCPserveronDeviceLANbyEthernetorasaccesspointviaexternalWiFiUSBadapter(availablefromrelease6.0)
• USBportforremoteaccessingUSBena-bleddevices(directlyorviaUSBhub)
• EasyTunnel™supportforenablingVPNviaSecomeaTrustGate
• SupportforremoteaccessbyanyUDP/TCPbasedprotocol
Monitoring and Logging Features
• SystemlogwithSystemWatchdog
• AutomaticeventloggingonGateMan-ager™
• AlertnotificationsgeneratedbySiteMan-agerorGateManagerandsentasemailorSMS
Configuration and Management
• ApplianceLauncherforeasyinitialcon-tactandconnectiontoGateManager™
• ConfigurationandmaintenanceofSiteManager™viabrowser(HTTPS/SSL-localorremotefromGateManager™)
• IncludesaSetupAssistantWizardforguidedconfigurationviatheWebGUI
• Easyconfigurationwithpre-definedcon-figurationusingaUSBstick
• Configurationbackupmanagement(viaGateManager™)includingscheduledbackupandfasthardwarereplacement(coldbackup)
• Configurationexportandimport(XML)
• Pre-definedDeviceAgentsforeasysetupofaccesstoallPCs,webdevicesandallcommonPLCsandHMIs.
LED Signaling and I/Os
• 4LEDsforsignallingPower,Status,WiFistatusandLinkManagerconnection.
• DigitalInputportforsiteoperatorcontrolofremoteaccess
• DigitalorRelayoutputforsignallingactiveLinkManagerconnections,andGateManagerconnectionstatus.
• ConfigurabledigitalinputportforcustomEmail/SMSalerttriggering
• OutputportforcustomtogglingfromtheSiteManagerGUI
RemoteManagement-SiteManager™1149and3349
Technical Specifications