
36
Chapter 9
TCP/IP – network terms
Exigo tool manual
EXO
In general, NAT also works with EXOscada and EXO controllers, although the connection must be
initiated from within the black network and target the white network.
NAT router
You can also have a NAT router to forward traffic from the white net to a computer on the black net.
This is accomplished by letting traffic to a specific TCP port or UDP port to be forwarded to an IP
address on the black net.
EXO controllers
There are Internet Service Providers that target, e.g. housing co-operatives, offering only private
dynamic addresses. EXO controllers with a TCP/IP port can manage controllers connected this way,
provided that the main computer has a static or a DNS registered public address. The EXO system
can also manage the reverse condition, and allows a main computer with a private address to contact
controllers with public addresses.
9.5 Tunnels
Two private networks
Another way to manage a connection via the Internet from a work computer to a main computer on a
company network that uses private IP addresses, is to create a tunnel going into the network. A tunnel
means connecting two networks using private IP addresses via the Internet, by encrypting all network
packages to the destination network (encryption includes IP addresses and other information). The
encryption is done by the firewall of one of the networks. The package is issued a new "address label"
specifying the other firewall's public address. This firewall decrypts the contents and forwards it to
the destination work station within its network. Any listeners that do not have knowledge of the
password will not be able to decrypt the traffic. This technology is also called VPN.
PC – black network
A tunnel can also be created between a single computer and a private network. Nowadays, it is
common for travelling salesmen to connect their mobile stations via GPRS and the Internet, and then
connect to the company network using a tunnel. The same technology can be used by the duty
technician to work with the EXOscada work station from his home, from the service vehicle or
similar.