secure high-availability remote access to industrial devices

3
• The SiteManager™ itself and its moni- tored devices are all centrally managed and accessible from the GateManager server. • Built-in serial, USB and Ethernet access agents for most PLC, HMI and Servo vendors in the market, as well as agent templates for video, voice, PC and Scada systems (including support for Siemens PPI and MPI) • Firewall friendly communication,- uses standard web protocols, and only inside-out. • No requirement for public or fixed IP address. SiteManager is by default DHCP enabled. No need to re-configure the PLC with gateway address etc. • Can operate as carrier of alarms, email alerts etc. between devices and central logging servers over the Internet. • Built-in firewall, AES and x.509 certifi- cates for maximum security • All configuration, firmware and feature upgrades are done remotely through an intuitive web GUI • User-configurable email alerts for status monitoring and configurable I/O ports for custom alarms. • Optional 4G/3G/GPRS/3G broadband support by installing a standard USB modem. • Optional Internet access via the option- al WiFi module installed in the USB port • Automatic failover between Ethernet Uplink and the optional Wireless Uplink. • Includes the unique Secomea EasyTun- nel Client feature for allowing easy enrollment in a VPN network. • Security certified in accordance with leading standards methodologies specified by NIST, ISA/IEC, BSI and ISECOM. Remote Management - SiteManager™ 1129 and 3329 Secure High-Availability Remote Access to Industrial Devices OPTIONAL SiteManager™ is an off-the-shelf component in the Secomea Industrial Communications Solution program that in combination with Secomea’s GateManager™ and LinkManager™ ensures unified, uninterrupted and se- cure access to remote devices. SiteManager™ is security certified according to the highest industry stand- ards of the industry, performed by the independent security organisation ProtectEM GmbH in Germany in close cooperation with the Deggendorf Institute of Technology. The SiteManager™ 1129 and 3329 are robust DIN mountable appliances that installs in the machine control panel, and provides remote access for on- demand servicing and programming of equipment, concurrently with static connections for monitoring and logging. The SiteManager™ 1129 and 3329 provide remote access to all types of industrial equipment via Ethernet,- Serial- or USB, using the equipment’s native protocols (e.g. Modbus, PROFINET, EtherCAT; EtherNet/IP etc.) The SiteManager™ 1129 and 3329 establish access to the Internet through the firewall of the existing wired network infrastructure, or optionally wire- lessly via a broadband modem or WiFi adapter installed in the USB port. Additionally the SiteManager features static VPN powered by the unique Secomea EasyTunnel™ concept. OPTIONAL

Upload: nguyenxuyen

Post on 01-Jan-2017

220 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Secure High-Availability Remote Access to Industrial Devices

• TheSiteManager™itselfanditsmoni-toreddevicesareallcentrallymanagedandaccessiblefromtheGateManagerserver.

• Built-inserial,USBandEthernetaccessagentsformostPLC,HMIandServovendorsinthemarket,aswellasagenttemplatesforvideo,voice,PCandScadasystems(includingsupportforSiemensPPIandMPI)

• Firewallfriendlycommunication,-usesstandardwebprotocols,andonlyinside-out.

• NorequirementforpublicorfixedIPaddress.SiteManagerisbydefaultDHCPenabled.Noneedtore-configurethePLCwithgatewayaddressetc.

• Canoperateascarrierofalarms,emailalertsetc.betweendevicesandcentralloggingserversovertheInternet.

• Built-infirewall,AESandx.509certifi-catesformaximumsecurity

• Allconfiguration,firmwareandfeatureupgradesaredoneremotelythroughanintuitivewebGUI

• User-configurableemailalertsforstatusmonitoringandconfigurableI/Oportsforcustomalarms.

• Optional4G/3G/GPRS/3GbroadbandsupportbyinstallingastandardUSBmodem.

• OptionalInternetaccessviatheoption-alWiFimoduleinstalledintheUSBport

• AutomaticfailoverbetweenEthernetUplinkandtheoptionalWirelessUplink.

• IncludestheuniqueSecomeaEasyTun-nelClientfeatureforallowingeasyenrollmentinaVPNnetwork.

• SecuritycertifiedinaccordancewithleadingstandardsmethodologiesspecifiedbyNIST,ISA/IEC,BSIandISECOM.

RemoteManagement-SiteManager™1129and3329

Secure High-AvailabilityRemote Access to IndustrialDevices

OPTIONAL

SiteManager™ is an off-the-shelf component in the Secomea Industrial

Communications Solution program that in combination with Secomea’s

GateManager™ and LinkManager™ ensures unified, uninterrupted and se-

cureaccesstoremotedevices.

SiteManager™issecuritycertifiedaccordingtothehighestindustrystand-

ardsof the industry,performedby the independentsecurityorganisation

ProtectEM GmbH in Germany in close cooperation with the Deggendorf

InstituteofTechnology.

TheSiteManager™1129and3329arerobustDINmountableappliancesthat

installs inthemachinecontrolpanel,andprovidesremoteaccessforon-

demandservicingandprogrammingofequipment,concurrentlywithstatic

connectionsformonitoringandlogging.

The SiteManager™ 1129 and 3329 provide remote access to all types of

industrial equipment via Ethernet,- Serial- or USB, using the equipment’s

nativeprotocols(e.g.Modbus,PROFINET,EtherCAT;EtherNet/IPetc.)

TheSiteManager™ 1129and3329establishaccesstothe Internetthrough

thefirewalloftheexistingwirednetworkinfrastructure,oroptionallywire-

lessly via a broadband modem or WiFi adapter installed in the USB port.

Additionally the SiteManager features static VPN powered by the unique

SecomeaEasyTunnel™concept.

OPTIONAL

Page 2: Secure High-Availability Remote Access to Industrial Devices

PLC HMI PC Cam

GateManager™ Enabled GateManager™ enabled for easy, centralized configuration, backup,monitoringandaccessforremoteserviceandmaintenanceofSecomeaSiteManagerandindustrialdevices.TheGateManagerisavailablebothasahostedserviceandasastand-alonesoftwarepackage.

LinkManager™ Enabled The LinkManager is a one-step installation Windows application thatrunsonthesupportengineerPC.WorkingwithGateManager™itpro-videssecureon-demandaccess toremoteSerial, IPorUSBdevicesthroughtheSiteManagers.Onceconnected, itmakestheremotede-viceappeartothefieldengineerasiftheWindowsPCwasconnecteddirectlytothedevice.SowithLinkManager,anyremotedeviceisjustafewmouseclicksaway.

LinkManager™ Mobile Enabled The LinkManager Mobile is designed for accessing your devices viaatablet,mobilephoneorPCwithoutneeding installationofsoftware.LinkManagerMobileallowsaccesstodevicesusingWebbrowser,VNC/RDPRemoteDesktopclientsandselectediOSandAndroidRemoteHMIapps.

Static Device/Server Relays connections TheSiteManagerallowsStaticrelaystoaGateManagerenablingacen-tralserverorSCADAsystemtomonitordevicesreal-time,ortoallowdevicestopushstatusupdatesbacktothecentralserver.

Configurable Routing/Forwarding rules TheSiteManagercanbeconfiguredtoportforwardorrouteconnec-tionsbetweenitsUplinkandDevicenetworkports.ItcanevenbeusedassecureInternetrouterviaanintegratedWebproxy.

Optional EasyTunnel™ VPN supportTheSiteManagersupportstheuniqueSecomeaEasyTunnelVPNcon-cept. Enabling the included EasyTunnel Client in the SiteManager, willallowenrollmentinaVPNnetworkcontrolledbyaTrustGateconcen-trator.EasyTunnelworkslikeordinaryIPSecVPN,butwithouttheneedforjugglingcertificatesorkeys.SimplyentertheserialnumberoftheSiteManager,anditisinstantlyenrolledintheVPNnetwork.

State-of-the-Art SecurityTheSiteManagersolutionsareusingstate-of-the-artsecuritystand-ards. This includes a built-in stateful Inspection Firewall, authentica-tionsusingx.509digitalcertificateandencryptionusingthestrongAESstandardwithupto256-bit.TheentiresolutionisSecuritycertifiedac-cordingtothemostcurrentstandardsoftheindustry.

Firewall FriendlyTheend-usernetworksecurityisprioritynumber1.WiththeSiteMan-agerandthesecuritystandardthatthisincludes,it isimportantthatend-user do not need to compromise their own corporate securitystandards.Thereforeallcommunicationisencrypted,evenwhenusingport80fromtheinsideandout.

Local Access Management and loggingTheSiteManagerallowslocaladministeredaccessmanagementviaitsWebGUIordigitalports,inadditiontothecentraluseraccessmanage-ment.Ontopofthis,alluserconnectionsmadetotheSiteManageranditsconnecteddevicesareloggedcentrallyontheGateManager.

Drivers for any type deviceTheSiteManagerhasbuilt-inpreconfigureddrivers“agents”forremoteaccessinganytypeofdevicesuchasPLCs,HMis,IPCs,Robots,Servos,etc. Inaddition to this, it ispossible tocustomizeanagent forotherrequirements regardlessof it beingSerial, Ethernet,WiFi orUSBat-tached.

WiFi operation in Client modeByapplyingtheSecomeaUSBWiFiadapter,theSiteManagerwillauto-maticallyenableWiFiClientmode,andtheSiteManagerwillbeabletoaccesstheInternetviaalocalaccesspoint.

4G/3G/GPRS Option with Wake-on-SMSTheSiteManager 1129/3329featuresanoptionalUSBportforattach-ingastandard4G/3G/GPRSUSBmodemforconnectingtotheInternet.ThisfeatureisusefulincaseswherenolocalinfrastructureexistsforconnectingtotheInternet.

Fail-over / Fail-back (Wired / Wireless)WhenenablingboththewiredandthewirelessUplinkoption(broad-bandorWiFi installed intheUSBport), theSiteManagercanperformfail-overandtherebyensuremaximumuptime.Byprioritizingthewireduplink, theSiteManagerwill automatically fail-back to thewiredcon-nection,thusreducingconsumptionofbroadbanddatacharges.

Flexible Alert notification systemTheSiteManagercanbeusedasgatewayforalertsgeneratedbylocaldevicesviaEthernet,Serialordigitalinputtriggers,orbytheGateMan-agermonitoringstatusoftheSiteManagerandlocaldevices.AlertsareadministeredbythecentralGateManagerfromwheretheycanbesentasSMSorEmail.Inadditionallgeneratedalertarecentrallylogged.

RemoteManagement-SiteManager™3129

Secure High-Availability Remote Access to Industrial Devices

RemoteManagement-SiteManager™1129and3329

Unique Specifications

Page 3: Secure High-Availability Remote Access to Industrial Devices

Secomea A/S

Denmark

E-mail: [email protected]

www.secomea.com

Partnumbers Description

30209 SiteManager1129including5DeviceAgents

30210 SiteManager3329including25DeviceAgents

27101 SecomeaWiFiUSBadapterforoperationasWiFiClient

27250 SecomeaWiFiUSBadapterwithSMAadapterforoperationasWiFiClient

26878 GateManagersettingspreconfigured

26940 MPI/PPIadapter(Ethernet)

Doc rev. 2015-05-15

Electrical Characteristics

• 536MhzARMCortexA5CPU

• Input12-24V/DC,viascrewterminals.

• NetworkInterfaces:2x10/100Mbit Ethernet(UPLINK,DEV1,)–RJ45connection

• 2xUSB2.0fullspeed(Host)

• 1xRS232DB9Serialportwithfullflowcontrol

• Powerconsumption:max3Wexcl.anyoptionalUSBdevice.s(Calculatewithatotalof8Wincl.USBdevices)

• 2xdigitalinputports

• 1xoutputrelay(max0,5A),1xdigitalout-putopendrain(max0,2A)

Regulations

• CE(EN61000-6-2,EN61000-6-4,EN301489-1,EN301489-3)

• FCC47cfrpart15

• ULListed(file#E358541,ITE4ZP8)

• RCMapproval(AvailableJune2015)

Physical Charateristics

• Operatingtemperature:-25°-+60C°,5to95%RH

• Dimensions,unpacked:107(H)x32(W)x97(D)mm,500g

• DINmountbracket.

• AluminiumChassis

• 2-yearsWarranty

Networking Capabilities

• ChoiceofUplink(WAN)Internetaccess:-Ethernet,-WiFiUSBOption(IEEE802.11b/g/n)-BroadbandUSBOption(4G/3G/GPRS)

• ChoiceofUplinkIP-assignmentmode:DHCPclient,PPPoEclient,manual/static

• TelnettoSerialrouting(rfc2217).SiemensMPI/PPIissupportedviaanadapter

• DHCPserveronDeviceLANbyEthernet

• USBportforremoteaccessingUSBena-bleddevices(directlyorviaUSBhub)

• EasyTunnel™supportforenablingVPNviaSecomeaTrustGate

• SupportforremoteaccessbyanyUDP/TCPbasedprotocol

Monitoring and Logging Features

• SystemlogwithSystemWatchdog

• AutomaticeventloggingonGateMan-ager™

• AlertnotificationsgeneratedbySiteMan-agerorGateManagerandsentasemailorSMSfromtheGateManager

Configuration and Management

• ApplianceLauncherforeasyinitialcon-tactandconnectiontoGateManager™

• ConfigurationandmaintenanceofSiteManager™viabrowser(HTTPS/SSL-localorremotefromGateManager™)

• IncludesaSetupAssistantWizardforguidedconfigurationviatheWebGUI

• Easyconfigurationwithpre-definedconfigurationusingaUSBstick

• Configurationbackupmanagement(viaGateManager™)includingscheduledbackupandfasthardwarereplacement(coldbackup)

• Configurationexportandimport(XML)

• Pre-definedDeviceAgentsforeasysetupofaccesstoallPCs,webdevicesandallcommonPLCsandHMIs.

LED Signaling and I/Os

• 3LEDsforsignallingPower,StatusandLinkManagerconnection.

• DigitalInputportforsiteoperatorcontrolofremoteaccess

• DigitalorRelayoutputforsignallingactiveLinkManagerconnections,andGateMan-agerconnectionstatus.

• ConfigurabledigitalinputportforcustomEmail/SMSalerttriggering

• OutputportforcustomtogglingfromtheSiteManagerGUI

RemoteManagement-SiteManager™1129and3329

Technical Specifications