background image

3

S M A RT  COM M U N I C ATI ON  C A R D 

M A N UA L

1.  Purpose and Basic Description

This document provides step-by-step instructions for how to set up the Smart Communication Card (SCC), connect devices to  
SCC using OPC UA, Modbus TCP and RTU. The manual also describes how to use JSON files for defining addressing.  In addi-
tion, monitoring of data from the connected devices to the SCC using UsExpert is also described. 
Note: The Smart Communication Card will be referred to as SCC in this user manual. 

2.  Important disclaimers & recommendations

2.1. 

Cyber security legal disclaimer

The SCC is designed to be connected in the ABB and 3

rd

 party products and communicate information data via network inter-

face. It is the user’s sole responsibility to provide and continuously ensure a secure connection between the product and the 
user’s network or any other. The user shall establish and maintain any appropriate measures (such as but not limited to the 
installation of firewalls, application of authentication measures, encryption of data, installation of anti-virus programs, etc.) 
to protect the product, the network, its system, and the interface against any kind of security breaches, unauthorized ac-
cess, interference, intrusion, leakage and/or theft of data or information. ABB and its affiliates are not liable for damages 
and/or losses related to such security breaches, any unauthorized access, interference, intrusion, leakage and/or theft of 
data or information. The data, examples and diagrams in this manual are included solely for the concept or product descrip-
tion and are not to be deemed as a statement of guaranteed properties. All people responsible for applying the equipment 
addressed in this manual must satisfy themselves that each intended application is suitable and acceptable, including that 
any applicable safety or other operational requirements are complied with. Any risks in applications where a system failure 
and/or product failure would create a risk for harm to property or persons (including but not limited to personal injuries or 
death) shall be the sole responsibility of the person or entity applying the equipment, and those so responsible are hereby 
requested to ensure that all measures are taken to exclude or mitigate such risks. This document has been carefully checked 
by ABB, but deviations cannot be completely ruled out. In case any errors are detected, the reader is kindly requested to no-
tify the manufacturer. Other than under explicit contractual commitments, in no event shall ABB be responsible or liable for 
any loss or damage resulting from the use of this manual or the application of the equipment.

2.2. 

JSON files

JSON files are provided as examples of how data can be retrieved from the devices. Please see the “JSON files” chapter for 
details. The user must adapt the files according to the application requirement.

2.3. 

UaExpert

UaExpert is software provided by Unified Automation. We suggest using this software to monitor the data as described in 
the “UaExpert” chapter. 
Important: This software does not belong to ABB, and we take no responsibility for its functionality. 

2.4. 

Firewall set up of SCC 

We strongly recommend using the firewall setting s described in section 5.2 of this instruction manual.

2.5. 

Private certificate for 3rd party clouds

We strongly recommend that, for 3rd party cloud, private key must be generated the by the 3rd party cloud and implemented 
in the SCC

2.6. 

Making your Networks more secure:

Following points are strongly recommended to make networks more secure: 

Isolate your network

  Separate the OT network (operation technology) from the IT network (information technology). This 

helps prevent any attack reaching the IT network from spreading to the OT network. 

Use firewalls

 

Implement firewalls to prevent unauthorized access to the OT network. 

Use access control

 

Implement access controls to restrict the human and device access to the OT network. 

Keep software up to 
date

 

Make sure all software/firmware of the devices are up to date to have the latest  
security updates installed. 

Reduce attack sur-
face

 

on devices

 

Disable device functions, services and ports not needed. 

Replace default 
passwords

 

Replace all default passwords of the devices to prevent attacker from getting access using default 
credentials. 

Monitor network ac-
tivity

 

Monitor the OT network for any malicious activities that could be a sign of an attack. Example of net-
work monitoring tool is intrusion detection system (IDS). 

Train employees

  

Train operators and service people on IT and OT security best practices. 

Содержание Smart Communication Card

Страница 1: ...MANUAL Smart Communication Card User manual for Smart Communication Card for configuring the card and and setting up devices...

Страница 2: ...e of contents 3 Purpose and basic description 3 Important disclaimers recommendations 4 Basic setup 8 Configuring the SCC with devices 10 Webserver based tool 30 Monitoring data in SCC using UaExpert...

Страница 3: ...ed to ensure that all measures are taken to exclude or mitigate such risks This document has been carefully checked by ABB but deviations cannot be completely ruled out In case any errors are detected...

Страница 4: ...e access Local Industrial LAN Modbus TCP RTU Smart temperature monitoring relay CM TCN 012 Grid feeding monitoring relay CM UFD Softstarter Modbus RTU Universal motor controller UMC100 3 Connect your...

Страница 5: ...To ensure sufficient convection in the mounting position the minimum distance from other modules must not be less than 50 mm in the vertical direction and 30 mm in the horizontal direction Details of...

Страница 6: ...photo below 1 2 3 6 4 5 7 8 9 Number Description Order codes 1 Smart Communication Card 1SVM410000R0000 2 Industrial Edge Gateway not in scope of this document 1SDA115509R1 3 24 V DC Power supply 1SVR...

Страница 7: ...power up contactors and L1 L2 L3 pins for UMC and other devices Modbus RTU Connect A of Modbus RTU device to A and A to A of SCC In some devices it is written as D and D equivalent to A and A Modbus...

Страница 8: ...re your computer and SCC are on the same network Please ensure that the ethernet address of your computer is set to the range of 192 168 2 x like 192 168 2 10 This can be done done by searching for ne...

Страница 9: ...as described in chapter 2 please Ping your SCC using the CMD command The CMD command can be opened by pressing the R window button on your keyboard A RUN window will appear type CMD and press enter A...

Страница 10: ...use the following User ID abb Password abb Important Your computer IP address should be in the range of 192 168 2 xx Note the default address of SCC is 192 168 2 1 5 1 2 Functions in webserver based...

Страница 11: ...ur IT person before modifying any values Following are the list of IP network services Port Service Version State 22 tcp SSH Dropbear sshd protocol 2 0 OPEN 53 tcp domain OPEN 80 tcp http OPEN 111 tcp...

Страница 12: ...configured in the firewall tab In the webserver based tool Go to Network Firewall and open the Traffic Rules Tab Traffic rules Click the add button at the bottom of the the page The following window...

Страница 13: ...y reset to re gain access Multiple source address entries are possible Restrict configuration interface Click the SAVE APPLY button 5 2 5 Restrict access to all services to certain IP addresses To onl...

Страница 14: ...ICATION CARD MANUAL 14 Restrict all Click SAVE on the form followed by SAVE APPLY on the Traffic Rules page 5 2 4 Routes Routes listed for both IPV4 and IPV6 5 2 5 System log System Log values are dis...

Страница 15: ...displayed here 5 2 7 Processes All the running processes are listed here Warning Restarting terminating or killing any process can result in the nonfunctioning of the SCC 5 2 8 Real time graphs Real t...

Страница 16: ...3 1 System The user can set up functions like name logging Time language in this tab 5 3 2 Administration The router password can be set in this tab Important It is strongly recommended to change the...

Страница 17: ...t of installed scripts along with the status can be monitored in this tab User can enable disable start restart and stop the scripts 5 3 6 Schedule tasks This is the system crontab in which scheduled...

Страница 18: ...the Generate archive button The backup can be restored using the upload archive button Similarly the user can reset the SCC to default status by clicking on the perform reset button The firm image ca...

Страница 19: ...options 1 General setting Settings given by default in the SCC 2 Resolve and Host settings 3 TFTP settings 4 Advanced settings 5 Statis lease Important Please contact your IP administrator if you wan...

Страница 20: ...ddresses of the device which are connected to the SCC Please check for the MAC address with xB20 this is B R gateway for Novolink Click on this You will see that the DHCP server will assign the IP add...

Страница 21: ...ing the ADD button the user can add Host By clicking the ADD button you will see a list of available IP addresses 5 4 4 Statis routes In this tab the user can set up statis routes for both IP4 and IP6...

Страница 22: ...user to ping certain links to ensure that the SCC is connected to the internet A successful ping would give the following message 5 5 Services Under the services tab there are tabs which enable users...

Страница 23: ...ound by the supplier of the device Client private key The user must select the pem file provided by the supplier In the case of B R Controller Novolink this file test must be used etc opc ua proxy cer...

Страница 24: ...SMART COMMUNICATION CARD MANUAL 24 Click on select file under Register Mapping file Select the file you want to upload Click upload file...

Страница 25: ...ould click on the SAVE APPLY button in the lower left hand corner of the screen 5 5 2 Integrating devices over Modbus RTU In the webserver based tool Go to services Modbus By clicking ADD you will get...

Страница 26: ...file must be used PSTXVBA json In the case of CM TCN 012 this file must be used TCNVBA json In the case of CM UFD this file must be used UFDVBA json Note The JSON files provided are an example of an...

Страница 27: ...you will get this view The following values should be keyed in Name Any recognizable name Address tcp 192 168 2 39 502 where 192 168 2 39 is the Modbus TCP address of the device Modbus ID Must be 1 fo...

Страница 28: ...vailable in the dropdown menu after refreshing the explorer Important After making changes the user should click on the SAVE APPLY button in the lower left hand corner of the screen 5 6 Setting VPN In...

Страница 29: ...C UA features like DataAccess Alarms Conditions Historical Access and the calling of UA Methods The UaExpert is a cross platform OPC UA test client programmed in C It uses the sophisticated GUI librar...

Страница 30: ...the SCC Security setting Security policy Basic256Sha256 Security setting Message Security mode Sign encrypt Username Password User Name abb Password abb Certificate Leave blank Session settings Sessio...

Страница 31: ...ser manual for Novolink 1SAC200230M0001 4 User manual for UMC 2CDC135032D0204 5 User manual for PSRX 1SFC132082M9901 6 User manual for CM UFD 2CDC112270D0201 7 User manual for CM TCN 012 2CDC112285M02...

Страница 32: ...thout prior notice With regard to purchase orders the agreed particulars shall prevail ABB AG does not accept any responsibility whatsoever for potential errors or possible lack of infor mation in thi...

Отзывы: