Page 2
Table of Contents: Configuration Page Customer Set-Up Information Field Configuration for WIFI (not required if unit is pre-configured at Elkhart Brass) III. Frequently Asked Questions Network Security Network Security Synopsis Attachments Network Security –...
Page 3
The eWON router needs access to the internet. This access can be achieved either through a wired Ethernet connection, or a wireless (WIFI) connection. It also needs to be connected to the Elkhart Brass Monitor network. This connection will be a wired Ethernet connection.
Page 4
• Dongles that have wireless hotspot capability For use on WIFI, it is easiest if the switch is pre-configured at Elkhart Brass before it ships to the customer. In order to complete this, the customer must provide the following wireless network information: •...
Page 5
II. Field Configuration for WIFI Note: Field configuration is not normally required. Elkhart Brass will usually pre-configure an eWON router before sending it to a customer. Field configuration of the PASSPHRASE, SSID, and SECURITY TYPE Screw on the antenna. 2) Power up the EWON with a 24VDC power source (this can be a battery).
EWON is a very high security router that can be connected into a network that controls Elkhart Brass monitors. Once connected, Elkhart Brass can log on to all the PLCs or HMIs on that network remotely through a secure internet connection. Tasks that it can be performed through it are: Remote commissioning of new systems.
Page 7
Does the eWON need to be connected to my business network? No. The eWON only needs access to the internet and the Elkhart Brass equipment network. Can Elkhart Brass access my sensitive business information through the eWON? Absolutely not. How do I connect it to the internet? The internet connection can be wired or wireless (WIFI).
Page 8
OTHER: IP, port, and protocol filtering/firewalling available. Restricted access granularity based on user, group, site for all or single devices or specific port. DEVICE LEVEL: Network segregation, local device authentication (MAC address). Is this established technology? EWON has hosted millions of VPN sessions for numerous customers since this product was launched in 2006. They are an Allen Bradley encompass partner.
Page 9
IV. Network Security Synopsis Everybody is concerned these days about the security of their internet connections. This is exactly why Elkhart Brass is using eWON and their services; because they have unparalleled security. A document that touts all the security measures in detail is attached, but it is hard to read unless you are a network expert. Here is a less technical synopsis: •...
Page 10
eWON Security Paper Secure Industrial Automation Remote Access Connectivity Using eWON and Talk2M Pro solutions www.ewon.us Last Modified: January 13, 2015...
Page 11
Overview eWON is a global provider of secure industrial remote access connectivity. By leveraging a combination of its cloud based, redundant infrastructure called Talk2M and its industrial eWON hardware devices, eWON created a first-to-market integrated approach to secure remote access to industrial control systems. Since its launch in 2006, eWON’s Talk2M has successfully hosted millions of encrypted VPN sessions allowing engineers to easily and securely remotely monitor and troubleshoot their machines.
Page 12
Policies & Procedures: The eWON Security Approach eWON/Talk2M solution enhances and is compatible with existing corporate security policies, firewall rules, and proxy servers. Policies & Procedures Talk2M Network Infrastructure: Globally redundant Tier 1 hosting Talk2M Network partners, 24/7 monitoring, SOC Infrastructure 1/SSAE 16/ISAE 3402 Data Centers, ISO270001, CSA...
Page 13
Security Vs Convenience and Acceptance One of the key challenges with remote connections to industrial control systems is balancing the needs of an engineer or PLC technician with the mandate by the IT department to ensure network security, integrity and reliability. Finding a solution that is readily accepted by both business groups has been a challenge for many years and a source of frustration and inefficiency for all stakeholders.
Page 14
security settings on the device restrict traffic between its two network interfaces. This network segregation limits remote access to only those devices connected to the LAN of the eWON. Access to the rest of the network is prevented. The eWONs themselves have user-level access rights separate from the Talk2M login. Only users with appropriate credentials and access rights can change the security settings on the eWON.
Page 15
device for monitoring purposes but limit the ports used for making programing changes to only specific engineers. Every remote connection is documented on the Talk2M Connection report. The Talk2M Connection report is a powerful IT auditing tool which allows account administrators to monitor which users are connected to which eWON and when and for how long they were connected.
Page 16
Summary A combination of unique hardware and globally redundant cloud infrastructure creates a robust, secure and convenient method to enable encrypted remote access to machines, panels and other industrial automation devices. The key added-value of Talk2M is the full integration of IT security standards by allowing an Internet communication tunnel between the user and the remote machine while still following the existing firewall rules and security policies of each network.
Page 17
COSY 131 Installation Guide This installation guide describes the hardware of the IG 022 / Rev. 1.7 eWON COSY 131 and explains how to get started with the embedded web site. support.ewon.biz...
Table of Contents 1. Product Summary ......................4 1.1. Introduction ............................4 1.2. Concept of the eWON COSY 131 Family ................... 4 1.3. General specification of the hardware platform ..............4 1.4. Typical applications ........................5 1.5. Type and Part Numbers ......................... 5 2.
Page 19
Table of Contents 5.2. Resetting the eWON COSY 131 ....................22 5.2.1. First Level Reset (user reset) ....................22 5.2.2. Second Level Reset (factory reset) ................. 22 5.3. Reset Impact Matrix ........................23 Appendix A - Connector Pinout & Related Specifications ..........24 A.1 - Main Connector .........................
1.1. Introduction The present Installation Guide describes the hardware of the eWON COSY 131 family. The eWON Cosy 131 family is a set of industrial gateways/routers fully compatible with the Talk2M cloud connectivity services (www.talk2M.com). 1.2. Concept of the eWON COSY 131 Family The Cosy 131 is available in different versions depending on their communication media: •...
Table: List of the available part numbers - Note - The MA suffix means Multiple languages A (UK, FR, DE, ES, IT) The part number syntax is explained in 3.1. Label Page 5 / 32 eWON COSY 131 | IG 022...
• Antenna must be mounted on a grounded plate 2.3.2. Applicable Safety Standards The product described in the present Installation Guide is in conformity with the following safety standards: • IEC/EN 60950-1 • UL 60950-1 Page 6 / 32 eWON COSY 131 | IG 022...
2.4. Field implementation & environmental conditions 2.4.1. Ingress Protection The eWON COSY 131 has an IP20 protection grade. Therefore, the eWON COSY is NOT suited for outdoor mounting. It has to be integrated in an electrical cabinet, protected from excessive heat, humidity and dust. Do not push any sharp object into the air vents or openings of the equipment.
Page 24
& lower ventilation openings of the unit. A free gap of at least 1 cm must be respected on each side of the unit. Page 8 / 32 eWON COSY 131 | IG 022...
-25°C to +40°C. 2.4.3. Cabling rules Shielded cables must be used for Ethernet and USB connectivity to comply with the EMC requirements. USB cable must be: • shorter than 3m Page 9 / 32 eWON COSY 131 | IG 022...
3. Hardware description 3.1. Label The identification label of the eWON COSY 131 is placed on the right hand side of the housing. The different parts of the label are described below: Page 10 / 32...
Page 27
Notified Body Number, warrantor of the CE Mark validation UL Listed (Underwriters Laboratories) FCC Federal Communications Commission GITEKI (MIC) Radio Act Conformity Mark Label can have variant marks depending on the model Page 11 / 32 eWON COSY 131 | IG 022...
Page 28
Chapter 3 Hardware description eWON COSY 131 WiFi eWON COSY 131 – 3G Penta eWON COSY 131 – 4G JP EC6133m_ccLL[suffix] Position(s) Description Acceptable values name of the family EC for eWON COSY number corresponding to the HW platform. for “Cosy 131” platform One Ethernet is communication options 1.
See. Digital Output & Digital Inputs Talk2M - Green ON = Talk2M VPN connection established See. Digital Output & Digital Inputs Internet Green ON = Internet is configured on the eWON COSY Page 14 / 32 eWON COSY 131 | IG 022...
Green ON = Modem connected Reception signal level Orange ON = Poor signal Reception signal level Orange ON = Signal is OK Reception signal level Orange ON = Good signal Page 15 / 32 eWON COSY 131 | IG 022...
• Modifications cannot be made by the user if it influences the normal behavior of the device. • This product contains part identified as follows by national authorities: FCC ID: QOQWF111 IC ID: 5123A-BGTWF111 RRA ID: KCC-CRM-BGT-WF111 GITEKI (MIC) ID: 209-J00061 Page 16 / 32 eWON COSY 131 | IG 022...
FFC ID: RI7HE910 IC ID: 5131A-HE910 GITEKI (MIC) ID: 005-100269 1 3G antenna has to be purchased separately. A 3G penta-band antenna is available from eWON with FAC90501_0000 as reference Page 17 / 32 eWON COSY 131 | IG 022...
• This product contains part identified as follows by Japanese authorities: Radio Act: 005-100567 Telecom Act: AD13-0163005 4G antenna has to be purchased separately. A 4G Quad-band antenna is available from eWON with FAC90801_0000 as reference Page 19 / 32 eWON COSY 131 | IG 022...
Hardware description 3.5. LAN Switch Specifications 3.5.1. Boot process After powering ON or requesting a reboot on the eWON COSY 131, a few moment is required to get the LAN switch feature fully operational. (approximately 45 sec) - Note - When an eWON router is configured to operate a certain way, it is part of the strategy, if no other method worked, to reboot itself.
Connect one of the LAN-ports (by default, port N°1 is always a LAN port) of your COSY with your PC point-to-point or through a network where there is no risk that the eWON's default IP-address (10.0.0.53) would conflict with another connected device. Page 21 / 32 eWON COSY 131 | IG 022...
Follow this wizard to configure your eWON Cosy and connect it to the Talk2M server. On our website you can also find a Quick Start Guide which will help you configure your Cosy131: https://ewon.biz/support/product/cosy-131-getting-started/getting-started Page 22 / 32 eWON COSY 131 | IG 022...
GREEN slowly whereas others might be solid green (if you are connected to Internet, Talk2M, ...). 5.2. Resetting the eWON COSY 131 The reset button B1 is located on the front of the COSY unit (see in 3.3.1.Front). The reset function of this button is active only if pressed while powering on.
If you face an error pattern on the USR LED, please check on the troubleshooting page: ewon.biz/support 4 Configuration remains even if the Wizards on eWON web interface indicate otherwise. Page 24 / 32 eWON COSY 131 | IG 022...
(between +12 et +24 VDC) DI_COM Ground of the input (isolated) Input signal 1 Input signal 2 Power in VDD + between +12 et +24 VDC Power in GND - Functional Earth Page 25 / 32 eWON COSY 131 | IG 022...
From 3,8 mA @ 12 VDC to 8,2 mA @ 24 VDC current range 5 During the starting boot process, the DO will be switched ON for a short time (2 sec) Page 26 / 32 eWON COSY 131 | IG 022...
Page 43
Appendix A - Connector Pinout & Related Specifications Page 27 / 32 eWON COSY 131 | IG 022...
Page 44
A relay has been chosen for this sample application but any load within the specifications can be used instead. - Note - This is a sink only output to ground (the transistor acts as a switch ground). Page 28 / 32 eWON COSY 131 | IG 022...
Page 45
Appendix A - Connector Pinout & Related Specifications Possible features : Wiring the Digital Output & Inputs can be use to externalize some features (as connectivity condition) Page 29 / 32 eWON COSY 131 | IG 022...
The configuration of this condition has to be done during the Internet Wizard where you define if the digital input is used or not and for which purpose. A.4 - Supported Wireless WiFi Frequencies Page 30 / 32 eWON COSY 131 | IG 022...
Page 47
Appendix A - Connector Pinout & Related Specifications Channels 12, 13 & 14 are not supported • Supported channels frequencies are between: Channel 1 - 2,412 Ghz and 11 - 2,462 Ghz Page 31 / 32 eWON COSY 131 | IG 022...
No part of this handbook can be reproduced, transmitted or copied in any way without written consent from the manufacturer and/or the authors of this handbook. eWON sa Page 32 / 32 eWON COSY 131 | IG 022...
Page 49
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt Parameters 1. Purpose This document lists the comcfg.txt parameters. Some parameters listed are not relevant to certain eWON types and may hence appear neither in the corresponding comcfg.txt file nor on the interface.
Page 50
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 2. List of Parameters Notes: Some parameters appear only for certain devices or in certain circumstances. ● Default values correspond to 2005CD devices with firmware version 11.0s0. ●...
Page 51
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Disabled PPPSrvCompress Enable PPP server compression Enabled Disabled PPPClNeedChap Enable CHAP authentication Enabled PPPClPhone2 ISP2 Server phone number Phone number PPPClUserName2...
Page 52
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Disabled Authentication for transparent RTEnAuthRt forwarding required Enabled Modem detection trial count, if not ModDetCnt detected after this number eWON Integer [trials]...
Page 53
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Dial on demand exception range 1..# RTDodF1..# 0.0.0.0 IPv4 dotted decimal FROM Dial on demand exception range 1..# RTDodT1..# 0.0.0.0 IPv4 dotted decimal...
Page 54
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values GPRS Quality Of Service Profile QosMinUse (Minimum Acceptable) QosMinPred precedence QosMinDel delay See RG-001 (*) QosMinRel reliability QosMinPk...
Page 55
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values No access Modem WANCnx WAN Network connection Ethernet ADSL Disabled WANPubIP WAN Publish IP address Enabled Integer [minutes] WANRepubInterval...
Page 56
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values VPNLocalIp VPN local IP address 10.254.0.1 IPv4 dotted decimal VPNRemoteIp VPN remote IP address 10.254.0.2 IPv4 dotted decimal #_1_//8=...
Page 57
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Disabled ProxyProto1..# Proxy 1..# protocol Disabled ProxySide1..# Proxy 1..# direction EXT to LAN LAN to EXT ProxyPort1..# Proxy 1..# incoming port Integer max.
Page 58
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Not specified (Depends on 1800 modem type – not GsmBand (in comcfg.txt only) 1900 applicable for all GPRS modem 850 + 1900...
Page 59
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values AdslVPI ADSL VPI Integer AdslVCI ADSL VCI Integer AdslCloneMac Not documented AdslCnxTO ADSL connection time out Integer [seconds] CBPubEMail Publish email destination IP address...
Page 60
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values VpnFDp1..3 VPN protection destination port [empty] Integer #_1_//8= Modem PIN code 4 digit code or [empty] WCDMA/GSM Depends on...
Page 61
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values HBoard5 Internal Use HBoard6 Internal Use HBoard7 Internal Use HBoard8 Internal Use Port 4 in WAN Cosy 131 Switch Configuration.
Page 62
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values TCP Port used for accessing the first Port number UsbIpStartPort 6000 USB device connected to your eWON. Password protection for accessing your Password UsbIpPwd...
Page 63
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comfig.txt name Description Default Value Acceptable Values Primary DNS IP address attributed to IPv4 dotted decimal DHCP Clients. Do not set the eWON LAN IP address since eWON is not a LANDHCPSDns1 0.0.0.0...
Page 64
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 3. Access Path The list below shows how to find the configuration web page associated with the parameters. comcfg.txt name Text as on the interface Access Path Networking >...
Page 65
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path AdslUser User name “ “ “ “ “ “ AdslVCI “ “ “...
Page 66
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path modem answers PPPClientIp PPP Client IP address “ “ “ “ “ “...
Page 67
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path Networking > VPN Connection T2mAccountName Talk2M Account name SystemSetup->Communication->Networking>VPN Connection->Global Talk2M Access Server T2mAccSrvAddr “...
Page 68
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path VPNCnxType During Internet connection: SystemSetup->Communication->Networking->VPN Connection Networking > Publish IP Address CBDDnsDName Dynamic DNS Domain name SystemSetup->Communication->Networking->PublishIPAddress CBDDnsHName Dynamic DNS Host name...
Page 69
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path Highest transparent TFMaxPort “ “ “ “ “ “ “ forwading port Route all gateway traffic VPNRedirect “...
Page 70
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path Networking > IP Services IpsFtpP TCP commands port SystemSetup->Communication->Networking->IPServices IpsHttpP1 Primary HTTP port “...
Page 71
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path WANPxyPass User Password “ “ “ “ “ “ WANPxyPort Proxy server port “...
Page 72
KB Name comcfg.txt Parameters Type Configuration Since revision 11.2s0 KB Number KB-0050-0 Build Knowledge Base Information Mod date 7/07/2016 comcfg.txt name Text as on the interface Access Path EarlySerialCfg comcfg.text only CfgProtoDis comcfg.text only NoSmartArp comcfg.text only GsmBand comcfg.text only AutoEthSw comcfg.text only VPNPreDNS...
Need help?
Do you have a question about the eWON Cosy 131 and is the answer not in the manual?
Questions and answers