Service for fee - Secomea Secure Communication Made Easy

Download Report

Transcript Service for fee - Secomea Secure Communication Made Easy

Complete Remote Management
Click
____ to
__edit
____Master
_____text
____
styles
______
Second
_____ _____
level
Third
____ level
_____
Fourth
_____ _____
level
Fifth
____level
_____
1
A complete Remote Management
solution must provide…
2
1. Remote
Service
access
fortext
service
engineers
to program and diagnoze devices
Click
____
to
__edit
____Master
_____
____
styles
______
Engineers
can be at any location
Second
_____
_____
level
Third
____Conflicting
level
_____subnets must not be an issue (all locations uses same IP addresses)
Individual
access for the enginees must be controlled centrally
Fourth
_____
_____
level
Fifth
____The
level
_____
engineer should not make configurations locally on the PC
The engineer must access Ethernet, Serial and USB devices remotely
2. Remote Monitoring access by central servers to log status and events.
Push/pull data collection of specific device info from a central site.
Optionally allow a traditional routed infrastructure (full VPN network access)
3. Central Management of all communication components
Configuration, user access, etc. must be available from a central location.
Secomea solves all 3 requirements
3
A. Remote
Service
access
fortext
programming,
trouble shooting and monitoring with
Click
____
to
__edit
____Master
_____
____
styles
______
Secomea_____
LinkManager:
Second
_____
level
Third
____LinkManager
level
_____ full access from Windows to any IP, Serial or USB device.
LinkManager
Fourth
_____
_____
level Mobile access for monitoring and operation of devices from handheld
(e.g. Remote HMI, Remote desktop, Scada web etc.)
Fifth
____devices
level
_____
B. Remote Monitoring access for data logging via Secomea SiteManager:
1. SiteManager Relay Chains, for logging on specific ports, or push messages from
devices, or..
2. SiteManager EasyTunnel VPN access for full network access
3. SiteManager SMS Gateway for receving and sending SMS messages.
C. Central Management from the central M2M Server called GateManager that is
operated by a web based administration portal.
A. LinkManager access
for programming and diagnostics
4
TLS/AES Encrypted connection
A technician can obtain access
from anywhere directly to a PLC
or Panel, regardless of where
the GateManager is located.
etc.Status Polling
Click
____ to
__edit
____Master
_____text
____
styles
______ SNMP/Ping
Serial /USB Proping
GateManager
Second
_____ _____
level
Heartbeats (Status, Alerts)
Optional Email Alerts and Reports
Third
____ level
_____
Optional SMS send/receive (SMS Gateway)
Fourth
_____ _____
level
Email alerts
Backup and other scheduled ”actions”
TLS/AES with 2 factor login (certificate and password)
Fifth
____level
_____
IP, Serial and USB access to devices from native
programming tool
IP attached devices
LinkManager
SMS Alerts/instructions
RUN
SiteManager
Serial or USB attached device
B. Advantages of each of the
Remote Monitoring solutions
5
1.
Relay
Chains
between
SiteManager
Soft on server site via GateManager to
Click
____
to
__
edit
____Master
_____
text
____
styles
______
SiteManagers
Second
_____
_____
levelon remotes sites.
Third
____Alllevel
_____
remote sites can have the same subnet. Subnet conflicts do not occur.
Fourth
_____
level
The_____
firewall friendly connection via GateManager is used for all
Fifth
____communication.
level
_____
Ideal for push and/or pull data logging and defined ports
2. EasyTunnel VPN access from EasyTunnel Server on server site via
EasyTunnel module in SiteManagers on remotes sites
Ideal when a traditional routed VPN infrastructure is desired
Ideal for QoS and other routing sensitives protocols (e.g. Advanced Video
streaming)
B1. Relay Chains
Logging via GateManager
7
All devices can have the same IP addresses.
Subnet conflicts does not occur!
Click
____
to
__friendly
edit
____
Master
_____
text
____
styles
The firewall
connection
via GateManager
is ______
used for all communication.
No separate
Second
_____
_____
level
connections are needed.
Third
____ level
_____
Fourth
_____ _____
level
Fifth
____level
_____
SiteManager
Dynamic
Public IP
3G/GPRS
or ADSL
10.0.0.6:3389
Panel
SiteB
PLC
Logserver
10.0.0.1
Dynamic
Public IP
192.168.0.10
10.0.0.5:8000
10.0.0.5:443
SiteA
3G/GPRS
or ADSL
Main Site
PLC
10.0.0.1
172.31.1.1:8000
172.31.1.1:443
172.31.1.2:3389
172.31.1.3:8000
172.31.1.3:443
172.31.1.4:3389
GateManager
Server
SiteManager
10.0.0.5:8000
10.0.0.5:443
10.0.0.6:3389
Panel
”alias” addresses represents each device
B2. EasyTunnel VPN
Full Network Access
8
Direct tunnels allow for complex IP
protocols (e.g. advanced video streaming)
GateManager
Server
Click
____
to
__edit
____
Master
_____
____
styles
______
QoS challanging
protocols
can
be used text
(e.g. Certain_____
Video
protocols)
Second
_____
level
Functions as a traditional fully routed VPN
Third
____
level
_____
infrastructure
Fourth
_____ _____
level
Fifth
____level
_____
SiteManager
Dynamic
Public IP
3G/GPRS
or ADSL
PLC
10.0.1.1
SiteA
TrustGate
(EasyTunnel Server)
10.0.1.6:3389
Panel
3G/GPRS
or ADSL
Main Site
SiteB
PLC
Log server
10.0.2.1
Dynamic
Public IP
192.168.0.10
10.0.1.5:8000
10.0.1.5:443
10.0.1.5:8000
10.0.1.5:443
10.0.1.6:3389
10.0.2.5:8000
10.0.2.5:443
10.0.2.6:3389
(mask 255.255.255.0)
SiteManager
10.0.2.5:8000
10.0.2.5:443
GateManager also monitors the TrustGate!
10.0.2.6:3389
Panel
(mask 255.255.255.0)
Detailed Technical Descriptions
9
Click
____ to
__edit
____Master
_____text
____
styles
______
Second
_____ _____
level
Third
____ level
_____
Refer to
the documents:
Fourth
_____
_____
level
GateManager Entry account
Fifth
____Logging
level
_____
via SiteManager Relay Chains – Deployment
Overview
Logging via SiteManager
EasyTunnel
– Deployment Overview
LinkManager
FloatingClient
License
(for an unlimited number of LinkManager users)
0
250
SiteManager 3134
750
Total
EUR 1000