background image

PSU

Power supply unit

RAM

Random access memory

RIO600

Remote I/O unit

S-NAT

Source network address translation

SCADA

Supervision, control and data acquisition

SIM

Subscriber identity module

SNMP

Simple Network Management Protocol

SSH

Secure shell

TCP

Transmission Control Protocol

UDP

User datagram protocol

USB

Universal serial bus

VGA

Video graphics array

VPN

Virtual Private Network

WAN

Wide area network

WHMI

Web human-machine interface

iDRAC

Integrated Dell remote access control

Section 10

1MRS758861 A

Glossary

56

ARM600

User Manual

Summary of Contents for ARM600

Page 1: ...M2M Gateway ARM600 User Manual ...

Page 2: ......

Page 3: ...Document ID 1MRS758861 Issued 2017 09 29 Revision A Product version 4 3 Copyright 2017 ABB All rights reserved ...

Page 4: ...ed in this document is furnished under a license and may be used copied or disclosed only in accordance with the terms of such license Trademarks ABB is a registered trademark of the ABB Group All other brand or product names mentioned in this document may be trademarks or registered trademarks of their respective holders Warranty Please inquire about the terms of warranty from your nearest ABB re...

Page 5: ...cted and communicate data and information via a network interface which should be connected to a secure network It is the sole responsibility of the person or entity responsible for network administration to ensure a secure connection to the network and to take the necessary measures such as but not limited to installation of firewalls application of authentication measures encryption of data inst...

Page 6: ...nd concerning electrical equipment for use within specified voltage limits Low voltage directive 2006 95 EC This conformity is the result of tests conducted by ABB in accordance with the product standard EN 60255 26 for the EMC directive and with the product standards EN 60255 1 and EN 60255 27 for the low voltage directive The product is designed in accordance with the international standards of ...

Page 7: ...rconnected computers on which the Product software is installed and configured such that the computers cooperate as a system to perform the functions of the Product The Product may include software which is owned by a third party For such software separate license terms and conditions may apply which you agree to comply with 2 Grant of license ABB grants you the following non exclusive and restric...

Page 8: ...and ground support equipment missile technology and facilities for weapons of mass destruction unless this use is explicitly approved by ABB in writing in each and every case Such approval shall be granted only if ABB s liability for damage to property personal injury and death damage to plant as well as property located there or in its vicinity and all consequential and incidental costs and losse...

Page 9: ...ge that the Product contains certain proprietary software licensed to ABB by third parties You agree to such third party software license agreements provided by the said third parties Such third parties may enforce this Agreement and their own license terms directly against You to the extent of such third party s interest in the Software 6 Limitation on reverse engineering de compilation and disas...

Page 10: ...ase you must return all copies of the Product and all of its component parts to ABB 12 Applicable law This Agreement shall be governed by and construed in accordance with the substantive laws of Finland All disputes differences or questions between the Parties with respect to any matter arising out of or relating to the Agreement shall be finally determined in arbitration in accordance with the ru...

Page 11: ...as bugs The foregoing warranties shall not apply to Software which 1 have been improperly modified or altered 2 have been subjected to misuse negligence or accident 3 have been used in a manner contrary to ABB s instructions including instructions concerning appropriate environmental specifications 4 are used in combination with equipment components or products not specified by ABB and or 5 where ...

Page 12: ...ion loss of data loss of business information or other pecuniary loss as well as for any special indirect or consequential losses or damages arising out of the use or inability to use the Product even if ABB or any of its suppliers has been advised of the possibility of such damages In any case ABB s entire liability under any provision of this Agreement shall be limited to the amount actually pai...

Page 13: ... support machines or weapons systems in which the failure of the hardware or software described in this manual could lead directly to death personal injury or severe physical or environmental damage To prevent damage both the product and any terminal devices must always be switched off before connecting or disconnecting any cables It should be ascertained that different devices used have the same ...

Page 14: ......

Page 15: ...sical interfaces 9 Standard edition 9 Front panel 9 Back panel 10 Health indicators 10 Enterprise edition 11 Front panel 11 Back panel 12 LCD panel 12 Deployment scenarios 13 Section 3 Cyber security 15 Cyber security definition 15 Configuring firewall and services 15 Section 4 Getting started 17 Configuring ARM600 17 Rack mounting ARM600 17 Connecting cables 17 Logging in 18 Section 5 Web HMI 19 ...

Page 16: ... networks 35 Asset management 36 Selecting devices for device management 37 Arctic device management 38 Updating Arctic device firmware 38 Rebooting Arctic devices 39 RIO600 device management 40 Updating RIO600 configuration 41 Updating RIO600 firmware 43 Exporting RIO600 configurations from PCM600 44 Section 8 Troubleshooting 49 Common problems and solutions 49 Questions and answers 50 Section 9 ...

Page 17: ...ng in the company s environment The personnel involved in installing and managing the Arctic devices are expected to be experienced in secure network practices 1 3 Product documentation 1 3 1 Product documentation set Product series and product specific manuals can be downloaded from the ABB Web site http www abb com substationautomation 1 3 2 Document revision history Document revision date Produ...

Page 18: ...n personal injury The caution icon indicates important information or warning related to the concept discussed in the text It might indicate the presence of a hazard which could result in corruption of software or damage to equipment or property The information icon alerts the reader of important facts and conditions The tip icon indicates advice on for example how to design your project or how to...

Page 19: ...ontains definitions of important terms Menu paths are presented in bold Select Main menu Settings Parameter names are shown in italics The function can be enabled and disabled with the Operation setting Parameter values are indicated with quotation marks The corresponding parameter values are On and Off 1MRS758861 A Section 1 Introduction ARM600 5 User Manual ...

Page 20: ...6 ...

Page 21: ...600 provides static IP addressing for the central control and monitoring system This means that the Arctic 600 series wireless gateways in remote locations can utilize normal SIM cards with dynamic IP addresses from any operator This allows the user to utilize different operators depending on the coverage and pricing Both standard public and private APN type SIM cards can be used in this communica...

Page 22: ...tic IP addressing of Arctic 600 series wireless gateways for SCADA Full routing capability allows integrating remote LAN into a central LAN Configuration via Web UI and console SSH access Arctic Patrol offers condition monitoring and centralized device management application that supervises the cellular connections to the connected Arctic 600 series wireless gateways and enables advanced remote ma...

Page 23: ...UID 257E5F22 2ADB 47CA A85F 4ABB94710FE9 V1 EN Figure 2 Front panel 1 Power on indicator power button 2 Video VGA connector 3 LCD menu buttons 4 LCD panel 5 Two USB 2 0 connectors 6 Service tag EST 7 Optical drive 8 Hard drive 1MRS758861 A Section 2 ARM600 overview ARM600 9 User Manual ...

Page 24: ...r Description Health indicator Solid blue System is on and in good health Flashing amber Error condition for example a failed fan or hard drive Hard drive indicator Flashing amber Hard drive error Electrical indicator Flashing amber Electrical error for example voltage out of range or a failed power supply Temperature indicator Flashing amber Thermal error for example temperature out of range or f...

Page 25: ...nel 1 5 6 2 3 4 GUID 4673F94B E625 408D B504 8BDC8D9E6D50 V1 EN Figure 4 Front panel 1 Two USB connectors 2 Optical drive 3 Service tag EST 4 LCD panel 5 Hard drive 1 6 Hard drive 2 1MRS758861 A Section 2 ARM600 overview ARM600 11 User Manual ...

Page 26: ...he system s LCD panel provides system information and status and error messages to indicate if the system is operating correctly or if the system needs attention Table 2 LCD backlight statuses Status Color Description ON Blue Normal operation Amber Error condition OFF Standby mode The LCD backlight can be turned on by pressing either the Select Left or Right button on the LCD panel The LCD backlig...

Page 27: ...n between the Arctic 600 series wireless gateways and ARM600 is initiated by the wireless gateways If a private APN is used ARM600 does not need a public IP address Instead a private static IP address can be used The cellular operator s access router provides routing between IP addresses of the SIM cards and M2M gateway The added value of ARM600 in a private APN use case comes from the added secur...

Page 28: ...RM600 Company LAN Firewall ARM600 Eth0 Eth1 GUID 2A5B1F08 E46A 483D 9F36 38FD6734A129 V2 EN Figure 8 Border firewall installation ARM600 directly connected to the Internet In the simplest scenario ARM600 is directly connected to the internet that is the public static IP is configured to the WAN interface of ARM600 ARM600 itself works as a firewall and border router in this case Company LAN ARM600 ...

Page 29: ...s remote networks 3 2 Configuring firewall and services Enable the firewall and disable the unused services and interfaces in the device To start disallow traffic and allow only the needed traffic Use the default policy to drop connections Check that the firewall is enabled For incoming connections always filter drop all unused ports which may include DNS L2TP VPN SNMP and so on Check that the def...

Page 30: ...16 ...

Page 31: ...nterface 5 Configure the eth0 interface 6 Configure the VPN firewall and time settings 4 2 Rack mounting ARM600 To install ARM600 to 19 computer rack follow the instructions provided with the ARM600 server Some racks require specific mounting kits and power cords See the rack s documentation for details 4 3 Connecting cables 1 Verify that the available AC operating voltage complies with the hardwa...

Page 32: ...cable to the port marked with 1 This port is seen in ARM600 s WHMI as the eth0 port The VGA display and USB keyboard are not needed for configuring ARM600 They can be used if a local console access is needed 4 4 Logging in 1 Configure the computer to use the same IP address space as the device Example Laptop IP is 10 10 10 11 with netmask 255 255 255 0 2 In a Web browser connect to the ARM600 WHMI...

Page 33: ...us The menu structure is always visible on the left pane System Network VPN Firewall Arctic Patrol Tools GUID 45F85539 9F74 4477 BA08 6A4E57D384C5 V1 EN Figure 10 Menu structure 5 2 System menu The system menu contains the system overview and time settings 1MRS758861 A Section 5 Web HMI ARM600 19 User Manual ...

Page 34: ...e to the LAN or VPN connected devices By default the time setting is configured as NTP client using the NTP pool servers If another NTP server is required the NTP server s name or IP address can be entered and the availability tested by clicking the Test NTP servers button Configure the DNS server s IP address if DNS names are used for the NTP server 5 3 Network menu The network menu contains the ...

Page 35: ...ust match the hostname of the Arctic wireless gateway controller The public SSH keys must be interchanged between ARM600 and Arctic wireless gateways controllers OpenVPN Used to configure OpenVPN OpenVPN utilizes UDP protocol by default There are two operating modes Layer 3 is a routed solution meaning that ARM600 and the Arctic wireless gateways work as routers ARM600 and each Arctic device has u...

Page 36: ...ng is not needed in ARM600 S NAT Used to adjust the source addresses of packets The S NAT is needed for example when ARM600 is used as a border router to Internet Custom rules The custom rules are for the experienced user who has knowledge of iptables configuration When custom rules are used the rule set must contain all needed tables incoming forwarded outgoing D NAT and S NAT 5 6 Arctic Patrol m...

Page 37: ...s Devices Shows most important details of the Arctic wireless devices like VPN and Patrol connections hostnames firmware versions signal levels IP addresses uptimes and data amounts of VPN tunnels The WHMI of the Arctic device can be accessed by clicking the Web UI button Management Provides fleet management functions for upgrading the firmware or rebooting of multiple devices as a batch run The d...

Page 38: ...600 server Table 9 Tools submenus Menu Description User Administration Used to define user rights change passwords and add new users The default users are arctic adm and root The root user logging is allowed from console only As for the other users they can be granted WHMI access SSH command line access or both The enabled Patrol users that is Arctic wireless gateways with Patrol enabled are also ...

Page 39: ... PC The support log is used for troubleshooting purposes Release Notes Contains the release notes for the currently running ARM600 firmware version Reboot Used to reboot the ARM600 server A verification dialog opens after the reboot button is clicked 1MRS758861 A Section 5 Web HMI ARM600 25 User Manual ...

Page 40: ...26 ...

Page 41: ... PC is now connected to ARM600 via the eth0 interface WAN Change the IP address and netmask according to the required setup Either set the netmask or the prefix number of bytes in netmask not both Table 10 Eth1 settings Parameter Value Device eth1 BOOTPROTO none IPADDR IP address NETMASK1 netmask PREFIX1 prefix DEFROUTE No IPV6_DEFROUTE No 1 Set either the netmask or the prefix 6 Click Save 7 Clic...

Page 42: ...he WAN interface in ARM600 9 Click Save 10 Click Restart interface eth0 The IP address of the eth0 interface used for the current connection to ARM600 has now been changed After the changes to the eth0 IP address have been applied the browser will not be able to connect to ARM600 using the address https 10 10 10 10 10000 11 Switch the Ethernet cable from ARM600 s WAN interface to the LAN interface...

Page 43: ...nterface PREFIX0 Number of netmask bits for the first additional IP address IPADDR1 Second additional IP address associated to this interface PREFIX1 Number of netmask bits for the second additional IP address IPADDR2 Third additional IP address associated to this interface PREFIX2 Number of netmask bits for the third additional IP address IPV6INIT Enable disable IPv6 for this interface DEFROUTE U...

Page 44: ...30 ...

Page 45: ...wireless devices have reported The Arctic wireless devices local network is scanned for supported ABB products only if the feature has been enabled in the Arctic wireless device 7 2 Registering Arctic devices to Patrol The registration page in Arctic Patrol allows creating a configuration that can be imported into an Arctic device during the configuration phase 1 Log in to ARM600 s WHMI as the arc...

Page 46: ... 5 Define the device information and click Register device Arctic device s serial number ARM600 s IP address usually public Connection mode Connection interval GUID 55D1DC35 DABB 4706 A409 0A0439A3A232 V1 EN Figure 12 Defining device information The next screen shows the ready made configuration content that needs to be copied to the Arctic device Section 7 1MRS758861 A Arctic Patrol 32 ARM600 Use...

Page 47: ...figuration content 6 Log in to the Arctic device as the arctic adm user 7 Click Arctic Patrol and select Import New 8 Paste the configuration content to the Patrol configuration file box and click Submit 1MRS758861 A Section 7 Arctic Patrol ARM600 33 User Manual ...

Page 48: ...he pen and paper icon or deleted by clicking the trash can icon GUID FD39801E 3CC1 4AE8 85FF 39055CC250AD V1 EN Figure 15 Editing configuration 9 Reboot the Arctic device 10 Log in to ARM600 s WHMI click Arctic Patrol and select Devices 11 Select the check box of the new Arctic device select Accept devices from the drop down list and click Do action Section 7 1MRS758861 A Arctic Patrol 34 ARM600 U...

Page 49: ...ocal networks Arctic devices are able to scan their local networks for supported devices such as RIO600 1 Log in to the Arctic device as the arctic adm user 2 To edit the Patrol connection in the Arctic device s WHMI click Services select Arctic Patrol and click the pen and paper icon next to the Patrol connection 3 In the Allow LAN device SCAN drop down list select Yes to enable scanning for the ...

Page 50: ...s clients When one or more devices have been selected in the device list via Arctic Patrol Devices these devices can be managed using the actions available via Arctic Patrol Management The available actions depend on the selected device types Arctic wireless devices report a list of the supported API commands to the Arctic Patrol application These management commands can be executed remotely from ...

Page 51: ...ist The devices are listed as a sub device below the Arctic device that found the device on its local network 1 Log in to the ARM600 s WHMI as the arctic adm user 2 On the left pane under the Arctic Patrol menu select Devices 3 Choose one or more devices to be managed by selecting the check box next to the device The selected devices are listed in the top part of the ARM600 s WHMI 4 Perform an act...

Page 52: ...are file is uploaded to ARM600 via the WHMI and then ARM600 performs the batch update as a background process This requires Arctic devices with firmware version 3 3 1 or later 1 Select the Arctic devices to be managed 2 On the left pane under the Arctic Patrol menu select Management 3 Verify that the hostnames of the selected devices are correct and select system update firmware under API commands...

Page 53: ... shown in the Status column GUID 803923EE ED28 4172 8A3E 83E2F3B5E201 V1 EN Figure 22 Running and old batches list for firmware update 7 3 2 2 Rebooting Arctic devices The system reboot enables rebooting a batch of Arctic devices This is required for example after the firmware has been updated to take the new firmware version into use 1 Select the Arctic devices to be managed 2 Verify the Selected...

Page 54: ... However the RIO600 device configuration and maintenance is always handled with PCM600 If enabled in the Arctic wireless devices configurations the Arctic wireless devices scan their local networks for RIO600 devices and report them to the ARM600 s Patrol view The RIO600 devices are separately listed under each Arctic device the way they were found on the network Although the ARM600 s asset manage...

Page 55: ...ent 4 In the management actions list verify that the correct devices are selected and select RIO600 Configuration Update under Tools 5 In the management actions list select RIO600 Configuration Update and click Next GUID 9F71B52D 21BC 46B7 B813 F9B8341310B9 V1 EN Figure 25 Selecting RIO600 configuration update 6 Click Browse to select the firmware file and then click Upload file The uploaded confi...

Page 56: ...ct a configuration from the left side under Configurations 8 2 Select a RIO600 device from the right side under Devices 8 3 Click the blue arrow to create the association GUID D68CA87B 0943 4789 9D8A 9B2E11BD3D4F V1 EN Figure 27 Creating associations manually Ensure that each configuration is compatible and intended for the selected RIO600 device 9 Click Run update on selected devices to add the t...

Page 57: ...e or many firmware files for the RIO600 modules and are distributed in zip files for example RIO600V1 7 3_FIRMWARE zip LECM module firmware version 1 7 or later supports firmware upgrade SIM8F module firmware version 1 2 or later supports firmware upgrade 1 Select the Arctic devices to be managed 2 Verify the Selected devices shown on the upper part of the pane 3 On the left pane under the Arctic ...

Page 58: ...e on the RIO600 stack 8 Click Run update on selected devices to add the task to the batch GUID C0AFC3D4 C9B9 4AEC BD4B 90597908543F V1 EN Figure 30 Updating RIO600 firmware Ensure that the firmware package is intended and compatible with the selected RIO600 devices 7 3 3 3 Exporting RIO600 configurations from PCM600 RIO600 configurations are always maintained and stored within a PCM600 project Thi...

Page 59: ...en this is enabled for one or more RIO600 devices and the Write to IED command is executed the configuration is exported to a zip file instead of being directly written to a RIO600 device The exported zip file can be uploaded into ARM600 s Patrol WHMI for transfer as a batch to the RIO600 devices connected to the Arctic devices 1 Open or create a new project in PCM600 with any number of RIO600 dev...

Page 60: ... Export Configuration in Write to IED 3 In the ExportConfigurationWindow dialog select each of the RIO600 devices from which the configuration should be exported click Browse to set the Export Path and click OK Section 7 1MRS758861 A Arctic Patrol 46 ARM600 User Manual ...

Page 61: ...uld write directly to the RIO600 device is overwritten A file called project name zip is instead generated to the selected export path The file project name zip that was exported to the chosen export path is now ready to be uploaded to ARM600 s WHMI RIO600 export for ARM600 is available in ABB IED Connectivity Package for RIO600 Ver 1 7 2 or later 1MRS758861 A Section 7 Arctic Patrol ARM600 47 Use...

Page 62: ...48 ...

Page 63: ...g the devices connected to Arctic devices Verify the routing settings both in ARM600 s VPN settings and in Arctic Wireless Gateways Controllers Check that the ARM600 s firewall allows the ICMP ping in the forward table If the ping target is a PC disable the firewall of the PC or allow ICMP messages SCADA server is unable to connect the field devices through ARM600 The SCADA needs to be aware of th...

Page 64: ...o support 300 3000 Arctic Wireless Gateways Controllers One cellular network connection on the ARM600 side is not able to provide the required bandwidth for hundreds or thousands of Arctic field devices Can IEC 61850 GOOSE be transferred over this system Yes with Layer 2 OpenVPN tunnels However note that the contemporary cellular networks are not capable of providing the required latency and speed...

Page 65: ... rack mountable 1U Metal 19 rack mountable 1U Approvals Global CB Scheme CE FCC Global CB Scheme CE FCC Environmental conditions Operational temperature 5 35 C at 5 85 relative humidity with 29 C dew point 5 40 C at 5 85 relative humidity with 29 C dew point Humidity 5 85 noncondensing at a maximum wet bulb temperature of 29 C 84 2 F 5 85 noncondensing at a maximum wet bulb temperature of 29 C 84 ...

Page 66: ... 100 240 V AC autoranging 50 60 Hz Temperature Continuous operation for altitudes less than 950 m or 3117 ft 5 40 C at 10 80 relative humidity with 29 C max dew point De rate maximum allowable dry bulb temperature at 1 C per 300 m above 900 m 1 F per 550 ft Storage 40 65 C 40 149 F with a maximum temperature gradation of 20 C per hour Relative humidity Operating 5 85 noncondensing at a maximum wet...

Page 67: ...2500NA Enterprise edition ARM600B2505NA Ethernet ports 2 4 Power supply single dual HDD single dual RAID no yes CPU type Core 2 Duo Xeon RAM 8 GB 32 GB Max Arctic connections 300 3000 Size 1U 19 1U 19 1MRS758861 A Section 9 Technical data ARM600 53 User Manual ...

Page 68: ...54 ...

Page 69: ...nternet Control Message Protocol IEC International Electrotechnical Commission IEC 61850 International standard for substation communication and modeling IP Internet protocol IP address A set of four numbers between 0 and 255 separated by periods Each server connected to the Internet is assigned a unique IP address that specifies the location for the TCP IP protocol KPI Key performance indicator L...

Page 70: ...iber identity module SNMP Simple Network Management Protocol SSH Secure shell TCP Transmission Control Protocol UDP User datagram protocol USB Universal serial bus VGA Video graphics array VPN Virtual Private Network WAN Wide area network WHMI Web human machine interface iDRAC Integrated Dell remote access control Section 10 1MRS758861 A Glossary 56 ARM600 User Manual ...

Page 71: ...57 ...

Page 72: ... Voltage Products Distribution Automation P O Box 699 FI 65101 VAASA Finland Phone 358 10 22 11 Fax 358 10 22 41094 www abb com mediumvoltage www abb com substationautomation 1MRS758861 A Copyright 2017 ABB All rights reserved ...

Reviews: