secure high-availability remote access to industrial devices · pdf filevendors in the market,...
TRANSCRIPT
• TheSiteManager™itselfanditsmoni-toreddevicesareallcentrallymanagedandaccessiblefromtheGateManagerserver.
• Built-inserial,USBandEthernetaccessagentsformostPLC,HMIandServovendorsinthemarket,aswellasagenttemplatesforvideo,voice,PCandScadasystems(includingoptionalsupportforSiemensPPIandMPI)
• Built-inSetupAssistantforintuitivefirsttimenetworksetup.
• AutomaticdiscoveryofEthernetandUSBdevicesforeasysingleclickconfiguration
• Allconfiguration,firmwareandfeatureupgradesaredoneremotelythroughanintuitivewebGUIaccessiblelocallyorviatheGateManager.
• Firewallfriendlycommunication,-usesstandardwebprotocols,andonlyinside-out.
• NorequirementforpublicorfixedIPaddress.SiteManagerisbydefaultDHCPenabled.Noneedtore-configurethePLCwithgatewayaddressetc.
• Canoperateascarrierofalarms,emailalertsetc.betweendevicesandcentralloggingserversovertheInternet.
• Built-infirewall,AESandx.509certifi-catesforandsecuritycertifiedinaccord-ancewithleadingstandardsmethodolo-giesspecifiedbyNIST,ISA/IEC,BSIandISECOM.
• User-configurableemailalertsforstatusmonitoringandconfigurableI/Oportsforcustomalarms.
• 4G/3G/GPRSinternetaccessviaviaexternalUSBadapter.
• WiFisupportviaUSBadapter,configur-ableforeitherClientmode(Internetac-cess)orAPmode(devicesaccess)
• AutomaticfailoverbetweenEthernet,WiFiandBroadbandforuninterruptedinternetaccess.
• IncludesSecomeaEasyTunnelClientsupportforallowingeasyenrollmentinastandardVPNnetwork.
• LogTunnelsupportallowingstatictunnelconnetionstoacentralSCADAsystem,whichoperatesconcurrentlywithotherservicessuchason-demandaccessandVPN.
• Uniquebuilt-introubleshootingfunction-alityforautomaticdiscoveryofnetwork-ingconflictsandconfigurationissues.
RemoteManagement-SiteManager™1129and3329
Secure High-AvailabilityRemote Access to IndustrialDevices
OPTIONAL
SiteManager™isanoff-the-shelfcomponentintheSecomeaIndustrialCommunicationsSolutionprogramthat incombinationwithSecomea’sGateManager™ and LinkManager™ ensures unified, uninterrupted andsecureaccesstoremotedevices.
SiteManager™ is security certified according to the highest industrystandardsof the industry,performedby the independentsecurityor-ganisation ProtectEM GmbH in Germany in close cooperation with theDeggendorfInstituteofTechnology.
TheSiteManager™ 1129and3329arerobustDINmountableappliancesthatinstallsinthemachinecontrolpanel,andprovidesremoteaccessforon-demandservicingandprogrammingofequipment,concurrentlywithstaticconnectionsformonitoringandlogging.
TheSiteManager™1129and3329provideremoteaccesstoalltypesofindustrialequipmentviaEthernet,-Serial-orUSB,usingtheequipment’snativeprotocols(e.g.Modbus,PROFINET,EtherCAT;EtherNet/IPetc.)
TheSiteManager™1129and3329establishaccesstotheInternetthroughthe firewall of the existing wired network infrastructure, or optionallywirelesslyviaabroadbandmodemorWiFiadapterinstalledintheUSBport.
AdditionallytheSiteManagersupportsSecomeaLogTunnelinbothClientand Master mode. LogTunnel allows you by drag’n’drop to establish acomplete static infrastructure for linking a central SCADA system toremotedevicesindependentofIPsubnets,firewallsetc.
OPTIONAL
PLC HMI PC Cam
GateManager™ Enabled GateManager™ enabled for easy, centralized configuration, backup,monitoringandaccessforremoteserviceandmaintenanceofSecomeaSiteManagerandindustrialdevices.TheGateManagerisavailablebothasahostedserviceandasastand-alonesoftwarepackage.
LinkManager™ Enabled The LinkManager is a one-step installation Windows application thatrunsonthesupportengineerPC.WorkingwithGateManager™itpro-videssecureon-demandaccess toremoteSerial, IPorUSBdevicesthroughtheSiteManagers.Onceconnected, itmakestheremotede-viceappeartothefieldengineerasiftheWindowsPCwasconnecteddirectlytothedevice.SowithLinkManager,anyremotedeviceisjustafewmouseclicksaway.
LinkManager™ Mobile Enabled The LinkManager Mobile is designed for accessing your devices viaatablet,mobilephoneorPCwithoutneeding installationofsoftware.LinkManagerMobileallowsaccesstodevicesusingWebbrowser,VNC/RDPRemoteDesktopclientsandselectediOSandAndroidRemoteHMIapps.
Static Device/Server Relays connections TheSiteManagerallowsStaticrelaystoaGateManagerenablingacen-tralserverorSCADAsystemtomonitordevicesreal-time,ortoallowdevicestopushstatusupdatesbacktothecentralserver.
Configurable Routing/Forwarding rules TheSiteManagercanbeconfiguredtoportforwardorrouteconnec-tionsbetweenitsUplinkandDevicenetworkports.ItcanevenbeusedassecureInternetrouterviaanintegratedWebproxy.
Optional EasyTunnel™ VPN supportTheSiteManagersupportstheuniqueSecomeaEasyTunnelVPNcon-cept. Enabling the included EasyTunnel Client in the SiteManager, willallowenrollmentinaVPNnetworkcontrolledbyaTrustGateconcen-trator.EasyTunnelworkslikeordinaryIPSecVPN,butwithouttheneedforjugglingcertificatesorkeys.SimplyentertheserialnumberoftheSiteManager,anditisinstantlyenrolledintheVPNnetwork.
State-of-the-Art SecurityTheSiteManagersolutionsareusingstate-of-the-artsecuritystand-ards. This includes a built-in stateful Inspection Firewall, authentica-tionsusingx.509digitalcertificateandencryptionusingthestrongAESstandardwithupto256-bit.TheentiresolutionisSecuritycertifiedac-cordingtothemostcurrentstandardsoftheindustry.
Firewall FriendlyTheend-usernetworksecurityisprioritynumber1.WiththeSiteMan-agerandthesecuritystandardthatthisincludes,it isimportantthatend-user do not need to compromise their own corporate securitystandards.Thereforeallcommunicationisencrypted,evenwhenusingport80fromtheinsideandout.
Local Access Management and loggingTheSiteManagerallowslocaladministeredaccessmanagementviaitsWebGUIordigitalports,inadditiontothecentraluseraccessmanage-ment.Ontopofthis,alluserconnectionsmadetotheSiteManageranditsconnecteddevicesareloggedcentrallyontheGateManager.
Drivers for any type deviceTheSiteManagerhasbuilt-inpreconfigureddrivers“agents”forremoteaccessinganytypeofdevicesuchasPLCs,HMis,IPCs,Robots,Servos,etc. Inaddition to this, it ispossible tocustomizeanagent forotherrequirements regardlessof it beingSerial, Ethernet,WiFi orUSBat-tached.
WiFi operation in both Client and Access Point modeApplyingtheSecomeaUSBWiFiadaptertotheSiteManagerwillauto-maticallyenableWiFiClientmode,andtheSiteManagerwillbeabletoaccesstheInternetviaalocalaccesspoint.OptionallytheWiFimodulecanbeconfiguredasAccessPointforprovidingremoteaccesstoWiFiclientenableddevicesatthelocation
4G/3G/GPRS Option with Wake-on-SMSTheSiteManager 1129/3329featuresanoptionalUSBportforattach-ingastandard4G/3G/GPRSUSBmodemforconnectingtotheInternet.ThisfeatureisusefulincaseswherenolocalinfrastructureexistsforconnectingtotheInternet.
Fail-over / Fail-back (Wired / Wireless)WhenenablingboththewiredandthewirelessUplinkoption(broad-bandorWiFi installed intheUSBport), theSiteManagercanperformfail-overandtherebyensuremaximumuptime.Byprioritizingthewireduplink, theSiteManagerwill automatically fail-back to thewiredcon-nection,thusreducingconsumptionofbroadbanddatacharges.
Flexible Alert notification systemTheSiteManagercanbeusedasgatewayforalertsgeneratedbylocaldevicesviaEthernet,Serialordigitalinputtriggers,orbytheGateMan-agermonitoringstatusoftheSiteManagerandlocaldevices.AlertsareadministeredbythecentralGateManagerfromwheretheycanbesentasSMSorEmail.Inadditionallgeneratedalertarecentrallylogged.
RemoteManagement-SiteManager™1129and3329
Unique Specifications
Partnumbers Description
30209 SiteManager1129including5DeviceAgents
30210 SiteManager3329including25DeviceAgents
27250 SecomeaWiFiUSBadapterwithSMAadapterforoperationasWiFiClient
Doc rev. 2017-10-18
Electrical Characteristics
• 536MhzARMCortexA5CPU
• Input12-24V/DC,viascrewterminals.
• NetworkInterfaces:2x10/100Mbit Ethernet(UPLINK,DEV1,)–RJ45connection
• 2xUSB2.0fullspeed(Host)
• 1xRS232DB9Serialportwithfullflowcontrol
• Powerconsumption:max3Wexcl.anyoptionalUSBdevice.s(Calculatewithatotalof8Wincl.USBdevices)
• 2xdigitalinputports
• 1xoutputrelay(max0,5A),1xdigitalout-putopendrain(max0,2A)
Regulations
• CE,RCMCompliant
• FCC47cfrpart15,CANICES-3(A)/NMB-3(A)
• ULListed(file#E358541,ITE4ZP8),IECCBcertified(DK-30193-A2-UL)
• Japan:[T]D170047007
Physical Charateristics
• Operatingtemperature:-25°-+60C°,5to95%RH
• Dimensions,unpacked:107(H)x32(W)x97(D)mm,500g
• DINmountbracket.
• AluminiumChassis
• 2-yearsWarranty
Networking Capabilities
• ChoiceofUplink(WAN)Internetaccess:-Ethernet,-WiFiUSBOption(IEEE802.11b/g/n)-BroadbandUSBOption(4G/3G/GPRS)
• ChoiceofUplinkIP-assignmentmode:DHCPclient,PPPoEclient,manual/static
• TelnettoSerialrouting(rfc2217).SiemensMPI/PPIissupportedviaanadapter
• DHCPserveronDeviceLANbyEthernetorasaccesspointviaexternalWiFiUSBadapter.
• USBportforremoteaccessingUSBena-bleddevices(directlyorviaUSBhub)
• SecomeaLogTunnelsupportforeasysetupofremoteSCADAlogginginfra-structure
• EasyTunnel™supportforenablingVPNviaSecomeaTrustGate
• SupportforremoteaccessbyanyUDP/TCPbasedprotocol
Monitoring and Logging Features
• SystemlogwithSystemWatchdog
• AutomaticeventloggingonGateMan-ager™
• AlertnotificationsgeneratedbySiteMan-agerorGateManagerandsentasemailorSMSfromtheGateManager
• Unique built-in trouble shooting function-ality for automatic discovery of network-ing conflicts and configuration issues.
Configuration and Management
• ApplianceLauncherforeasyinitialcon-tactandconnectiontoGateManager™
• ConfigurationandmaintenanceofSiteManager™viabrowser(HTTPS/SSL-localorremotefromGateManager™)
• IncludesaSetupAssistantWizardforguidedconfigurationviatheWebGUI
• Easyconfigurationwithpre-definedconfigurationusingaUSBstick
• Configurationbackupmanagement(viaGateManager™)includingscheduledbackupandfasthardwarereplacement(coldbackup)
• Configurationexportandimport(XML)
• Pre-definedDeviceAgentsforeasysetupofaccesstoallPCs,webdevicesandallcommonPLCsandHMIs.
• Unique device scanning feature for au-tomatic detection of IP and USB devices and configuration with a single click.
LED Signaling and I/Os
• 3LEDsforsignallingPower,StatusandLinkManagerconnection.
• DigitalInputportforsiteoperatorcontrolofremoteaccess
• DigitalorRelayoutputforsignallingactiveLinkManagerconnections,andGateMan-agerconnectionstatus.
• ConfigurabledigitalinputportforcustomEmail/SMSalerttriggering
• OutputportforcustomtogglingfromtheSiteManagerGUI
RemoteManagement-SiteManager™1129and3329
Technical Specifications
Secomea A/S - Denmark-www.secomea.com