secure high-availability remote access to industrial devices
TRANSCRIPT
• TheSiteManager™itselfanditsmoni-toreddevicesareallcentrallymanagedandaccessiblefromtheGateManagerserver.
• Built-inserial,USBandEthernetaccessagentsformostPLC,HMIandServovendorsinthemarket,aswellasagenttemplatesforvideo,voice,PCandScadasystems(includingsupportforSiemensPPIandMPI)
• Firewallfriendlycommunication,-usesstandardwebprotocols,andonlyinside-out.
• NorequirementforpublicorfixedIPaddress.SiteManagerisbydefaultDHCPenabled.Noneedtore-configurethePLCwithgatewayaddressetc.
• Canoperateascarrierofalarms,emailalertsetc.betweendevicesandcentralloggingserversovertheInternet.
• Built-infirewall,AESandx.509certifi-catesformaximumsecurity
• Allconfiguration,firmwareandfeatureupgradesaredoneremotelythroughanintuitivewebGUI
• User-configurableemailalertsforstatusmonitoringandconfigurableI/Oportsforcustomalarms.
• Optional4G/3G/GPRS/3GbroadbandsupportbyinstallingastandardUSBmodem.
• OptionalInternetaccessviatheoption-alWiFimoduleinstalledintheUSBport
• AutomaticfailoverbetweenEthernetUplinkandtheoptionalWirelessUplink.
• IncludestheuniqueSecomeaEasyTun-nelClientfeatureforallowingeasyenrollmentinaVPNnetwork.
• SecuritycertifiedinaccordancewithleadingstandardsmethodologiesspecifiedbyNIST,ISA/IEC,BSIandISECOM.
RemoteManagement-SiteManager™1129and3329
Secure High-AvailabilityRemote Access to IndustrialDevices
OPTIONAL
SiteManager™ is an off-the-shelf component in the Secomea Industrial
Communications Solution program that in combination with Secomea’s
GateManager™ and LinkManager™ ensures unified, uninterrupted and se-
cureaccesstoremotedevices.
SiteManager™issecuritycertifiedaccordingtothehighestindustrystand-
ardsof the industry,performedby the independentsecurityorganisation
ProtectEM GmbH in Germany in close cooperation with the Deggendorf
InstituteofTechnology.
TheSiteManager™1129and3329arerobustDINmountableappliancesthat
installs inthemachinecontrolpanel,andprovidesremoteaccessforon-
demandservicingandprogrammingofequipment,concurrentlywithstatic
connectionsformonitoringandlogging.
The SiteManager™ 1129 and 3329 provide remote access to all types of
industrial equipment via Ethernet,- Serial- or USB, using the equipment’s
nativeprotocols(e.g.Modbus,PROFINET,EtherCAT;EtherNet/IPetc.)
TheSiteManager™ 1129and3329establishaccesstothe Internetthrough
thefirewalloftheexistingwirednetworkinfrastructure,oroptionallywire-
lessly via a broadband modem or WiFi adapter installed in the USB port.
Additionally the SiteManager features static VPN powered by the unique
SecomeaEasyTunnel™concept.
OPTIONAL
PLC HMI PC Cam
GateManager™ Enabled GateManager™ enabled for easy, centralized configuration, backup,monitoringandaccessforremoteserviceandmaintenanceofSecomeaSiteManagerandindustrialdevices.TheGateManagerisavailablebothasahostedserviceandasastand-alonesoftwarepackage.
LinkManager™ Enabled The LinkManager is a one-step installation Windows application thatrunsonthesupportengineerPC.WorkingwithGateManager™itpro-videssecureon-demandaccess toremoteSerial, IPorUSBdevicesthroughtheSiteManagers.Onceconnected, itmakestheremotede-viceappeartothefieldengineerasiftheWindowsPCwasconnecteddirectlytothedevice.SowithLinkManager,anyremotedeviceisjustafewmouseclicksaway.
LinkManager™ Mobile Enabled The LinkManager Mobile is designed for accessing your devices viaatablet,mobilephoneorPCwithoutneeding installationofsoftware.LinkManagerMobileallowsaccesstodevicesusingWebbrowser,VNC/RDPRemoteDesktopclientsandselectediOSandAndroidRemoteHMIapps.
Static Device/Server Relays connections TheSiteManagerallowsStaticrelaystoaGateManagerenablingacen-tralserverorSCADAsystemtomonitordevicesreal-time,ortoallowdevicestopushstatusupdatesbacktothecentralserver.
Configurable Routing/Forwarding rules TheSiteManagercanbeconfiguredtoportforwardorrouteconnec-tionsbetweenitsUplinkandDevicenetworkports.ItcanevenbeusedassecureInternetrouterviaanintegratedWebproxy.
Optional EasyTunnel™ VPN supportTheSiteManagersupportstheuniqueSecomeaEasyTunnelVPNcon-cept. Enabling the included EasyTunnel Client in the SiteManager, willallowenrollmentinaVPNnetworkcontrolledbyaTrustGateconcen-trator.EasyTunnelworkslikeordinaryIPSecVPN,butwithouttheneedforjugglingcertificatesorkeys.SimplyentertheserialnumberoftheSiteManager,anditisinstantlyenrolledintheVPNnetwork.
State-of-the-Art SecurityTheSiteManagersolutionsareusingstate-of-the-artsecuritystand-ards. This includes a built-in stateful Inspection Firewall, authentica-tionsusingx.509digitalcertificateandencryptionusingthestrongAESstandardwithupto256-bit.TheentiresolutionisSecuritycertifiedac-cordingtothemostcurrentstandardsoftheindustry.
Firewall FriendlyTheend-usernetworksecurityisprioritynumber1.WiththeSiteMan-agerandthesecuritystandardthatthisincludes,it isimportantthatend-user do not need to compromise their own corporate securitystandards.Thereforeallcommunicationisencrypted,evenwhenusingport80fromtheinsideandout.
Local Access Management and loggingTheSiteManagerallowslocaladministeredaccessmanagementviaitsWebGUIordigitalports,inadditiontothecentraluseraccessmanage-ment.Ontopofthis,alluserconnectionsmadetotheSiteManageranditsconnecteddevicesareloggedcentrallyontheGateManager.
Drivers for any type deviceTheSiteManagerhasbuilt-inpreconfigureddrivers“agents”forremoteaccessinganytypeofdevicesuchasPLCs,HMis,IPCs,Robots,Servos,etc. Inaddition to this, it ispossible tocustomizeanagent forotherrequirements regardlessof it beingSerial, Ethernet,WiFi orUSBat-tached.
WiFi operation in Client modeByapplyingtheSecomeaUSBWiFiadapter,theSiteManagerwillauto-maticallyenableWiFiClientmode,andtheSiteManagerwillbeabletoaccesstheInternetviaalocalaccesspoint.
4G/3G/GPRS Option with Wake-on-SMSTheSiteManager 1129/3329featuresanoptionalUSBportforattach-ingastandard4G/3G/GPRSUSBmodemforconnectingtotheInternet.ThisfeatureisusefulincaseswherenolocalinfrastructureexistsforconnectingtotheInternet.
Fail-over / Fail-back (Wired / Wireless)WhenenablingboththewiredandthewirelessUplinkoption(broad-bandorWiFi installed intheUSBport), theSiteManagercanperformfail-overandtherebyensuremaximumuptime.Byprioritizingthewireduplink, theSiteManagerwill automatically fail-back to thewiredcon-nection,thusreducingconsumptionofbroadbanddatacharges.
Flexible Alert notification systemTheSiteManagercanbeusedasgatewayforalertsgeneratedbylocaldevicesviaEthernet,Serialordigitalinputtriggers,orbytheGateMan-agermonitoringstatusoftheSiteManagerandlocaldevices.AlertsareadministeredbythecentralGateManagerfromwheretheycanbesentasSMSorEmail.Inadditionallgeneratedalertarecentrallylogged.
RemoteManagement-SiteManager™3129
Secure High-Availability Remote Access to Industrial Devices
RemoteManagement-SiteManager™1129and3329
Unique Specifications
Secomea A/S
Denmark
E-mail: [email protected]
www.secomea.com
Partnumbers Description
30209 SiteManager1129including5DeviceAgents
30210 SiteManager3329including25DeviceAgents
27101 SecomeaWiFiUSBadapterforoperationasWiFiClient
27250 SecomeaWiFiUSBadapterwithSMAadapterforoperationasWiFiClient
26878 GateManagersettingspreconfigured
26940 MPI/PPIadapter(Ethernet)
Doc rev. 2015-05-15
Electrical Characteristics
• 536MhzARMCortexA5CPU
• Input12-24V/DC,viascrewterminals.
• NetworkInterfaces:2x10/100Mbit Ethernet(UPLINK,DEV1,)–RJ45connection
• 2xUSB2.0fullspeed(Host)
• 1xRS232DB9Serialportwithfullflowcontrol
• Powerconsumption:max3Wexcl.anyoptionalUSBdevice.s(Calculatewithatotalof8Wincl.USBdevices)
• 2xdigitalinputports
• 1xoutputrelay(max0,5A),1xdigitalout-putopendrain(max0,2A)
Regulations
• CE(EN61000-6-2,EN61000-6-4,EN301489-1,EN301489-3)
• FCC47cfrpart15
• ULListed(file#E358541,ITE4ZP8)
• RCMapproval(AvailableJune2015)
Physical Charateristics
• Operatingtemperature:-25°-+60C°,5to95%RH
• Dimensions,unpacked:107(H)x32(W)x97(D)mm,500g
• DINmountbracket.
• AluminiumChassis
• 2-yearsWarranty
Networking Capabilities
• ChoiceofUplink(WAN)Internetaccess:-Ethernet,-WiFiUSBOption(IEEE802.11b/g/n)-BroadbandUSBOption(4G/3G/GPRS)
• ChoiceofUplinkIP-assignmentmode:DHCPclient,PPPoEclient,manual/static
• TelnettoSerialrouting(rfc2217).SiemensMPI/PPIissupportedviaanadapter
• DHCPserveronDeviceLANbyEthernet
• USBportforremoteaccessingUSBena-bleddevices(directlyorviaUSBhub)
• EasyTunnel™supportforenablingVPNviaSecomeaTrustGate
• SupportforremoteaccessbyanyUDP/TCPbasedprotocol
Monitoring and Logging Features
• SystemlogwithSystemWatchdog
• AutomaticeventloggingonGateMan-ager™
• AlertnotificationsgeneratedbySiteMan-agerorGateManagerandsentasemailorSMSfromtheGateManager
Configuration and Management
• ApplianceLauncherforeasyinitialcon-tactandconnectiontoGateManager™
• ConfigurationandmaintenanceofSiteManager™viabrowser(HTTPS/SSL-localorremotefromGateManager™)
• IncludesaSetupAssistantWizardforguidedconfigurationviatheWebGUI
• Easyconfigurationwithpre-definedconfigurationusingaUSBstick
• Configurationbackupmanagement(viaGateManager™)includingscheduledbackupandfasthardwarereplacement(coldbackup)
• Configurationexportandimport(XML)
• Pre-definedDeviceAgentsforeasysetupofaccesstoallPCs,webdevicesandallcommonPLCsandHMIs.
LED Signaling and I/Os
• 3LEDsforsignallingPower,StatusandLinkManagerconnection.
• DigitalInputportforsiteoperatorcontrolofremoteaccess
• DigitalorRelayoutputforsignallingactiveLinkManagerconnections,andGateMan-agerconnectionstatus.
• ConfigurabledigitalinputportforcustomEmail/SMSalerttriggering
• OutputportforcustomtogglingfromtheSiteManagerGUI
RemoteManagement-SiteManager™1129and3329
Technical Specifications