While every effort has been made to ensure that this document is complete and accurate at the time of release, the information that it contains is subject to change. Red Lion Controls is not responsible for any additions to or...
Regulations. Cet appareil numérique de la classe A respecte toutes les exigences du Règlement sur le matérial brouilleur du Canada. Trademark Acknowledgments Red Lion Controls, Inc acknowledges and recognizes ownership of the following trademarked terms used in this document. ™ •...
As needed, Documentation Notes and/or Product Bulletins will be provided between major releases to describe any new information or document changes. The latest online version of this document and all product updates can be accessed through the Red Lion web site at www.redlion.net/support/documentation.
USB Device port Set Up Connect a CAT-5 or CAT-6 Ethernet cable between the local PC and the Red Lion RTU or router’s Ethernet port(s). Note: If the Ethernet port’s green LED is lit, this indicates that the connection is running at 100Mb speed. If the Ethernet port’s green LED is not lit, this indicates that the connection is running at 10Mb speed.
Configure Using AutoNet Method Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Configure Using AutoNet Method When using AutoNet, connect the eth0 port to any Ethernet network or directly to a PC. It will discover other DHCP networks and will either join automatically or provide a DHCP address to the connected PC. Inspect the product label on your unit to find the field “Eth0 MAC” and notice the last 6 digits or letters. http://RAM-1A345B.local If your MAC address was 02‐FF‐EE‐1A‐34‐5B, then the unit can be accessed by entering in your browser. Once you configure your Ethernet port for use in production, AutoNet will be automatically disabled. If AutoNet does not seem to be working in your environment, you can always fall back to the previously supported methods of access 1.2 and 1.3. Setup PC IP Address 1.2.1 Open the Control Panel Click on Start and browse the “Control Panel” menu item. The Control Panel should look similar to the following: 1.2.2 Access Network and Settings Click on the link to access network and Internet settings...
Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Setup PC IP Address The displays should be similar to the following: 1.2.3 Access Network Connection Settings Click on the link to access network connection settings. • XP - “Network Connections” • Vista/Windows 7 - “Network and Sharing Center” The display should look similar to the following: ...
Setup PC IP Address Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C 1.2.4 Access Local Area Connection Click on the link to access the local area connection. • XP - “Local Area Connection” icon • Vista/Windows 7 - “View Status” next to Local Area Connection The display should look similar to the following: 1.2.5 Open Properties...
Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Setup PC IP Address Click on the Continue button. The display should look similar to the following: 1.2.6 Access Internet Protocol Properties Click on the Internet Protocol to highlight. • XP - “Internet Protocol (TCP/IP)” •...
Page 14
Setup PC IP Address Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C METHOD 1: PC to: WAN /ETH0, Ethernet on SN/RAM 6000, RAM 9000 Select Use the following IP address and fill in the blank fields with the information below: •...
Page 15
Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Setup PC IP Address • XP Start Run, type in cmd and press the ENTER key. • Vista/Windows 7 Start Search window just above the Start icon, type in cmd, wait for Vista/Windows 7 to locate the program, click on the cmd program if finds.
This shows the connection is up and functioning. Installing RNDIS Driver for Ethernet Connectivity over This section outlines the required method to manually install the correct RNDIS driver for your Red Lion device. This will enable the unit to connect via USB and behave as an Ethernet device.
Page 17
Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Installing RNDIS Driver for Ethernet Connectivity over Select Browse my computer for driver software: Select Let me pick from a list... ® ® Sixnet Series SN/RAM 6000 & RAM 9000 Software Manual - 9 -...
The Update Driver Warning dialog window shown below appears. Click on Yes. Once the install is complete, click on Close. The USB Ethergadget driver should now be loaded and you should be able to access the Red Lion device via USB/ Ethernet at 192.168.111.1:10000.
Revised 2017-08-31 Accessing the Web User Interface Drawing No. LP0997-C Access Red Lion Web Server You will receive a login pop-up screen. 1.4.1 Red Lion RTU or Router Login Instructions • For the User Name, enter: admin (all lowercase) • For Password, enter the last six digits of the serial number, located on the product label (all lowercase)
Drawing No. LP0997-C At this point, you are connected to the Red Lion RTU or router and can configure it to meet your needs. If the ppp0 or wwan0 interface do not show an IP address, this could indicate that the internal SIM/Module has not been properly activated.
Cellular connectivity is obtained through the use of an internal (embedded) RF Module. Your Red Lion RTU or router has an embedded radio that has been detected and may be configured for the intended carrier. If you are using a carrier that supports the use of an Access Point Name (APN), you may have to set your specific APN manually, as covered in the next section.
Page 22
Cellular Configuration Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C Navigate through the Web UI menu to Networking Cellular Connection Configuration screen shown in section ® 2.1.1. 3G and 4G/LTE GSM based carriers, such as AT&T , Bell Mobility and Telus will require a SIM card be inserted into the unit and an APN code to be entered to confirm you are the verified user of that SIM.
Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C Cellular Configuration 2.1.1 Cellular Interface Configuration Select Yes to enable the interface so it becomes active after the new settings are applied and upon subsequent system start-up. Select No to disable the cellular connection feature. More information on setting up the unit’s cellular connection can be found in Section 3.4.1.
Cellular Configuration Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C 2.1.3 Provisioning Provisioning should be used on SN/RAM 66xx devices to activate your CDMA based service. Examples of CDMA based 3G carriers are Verizon, Sprint, Bell, Telus and US Cellular. For SN/RAM 69xx and RAM 99xx devices that are able to switch between carriers this page is used to select the correct carrier profile and firmware images for the cellular module to authenticate on the LTE carrier networks.
If you have any questions about your configuration, please check with your network administrator. If you were able to successfully access the Internet, or your corporate network, your Red Lion unit is up and running. You have successfully completed the Quick Start and you may skip the troubleshooting section.
If you are reading this section, you have followed all previous instructions and your Red Lion RTU or router is not communicating, this section will provide additional information to isolate the cause of difficulties.
Page 27
Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C Cellular Configuration Verifying IP Connectivity First, check to make sure that your device is connecting to the cellular network and obtaining an IP address. Navigate to the Web UI Status screen shown below: If the Signal Strength on your screen does not look similar to the one shown above, you may be having signal reception difficulties.
Page 28
Cellular Configuration Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C SN 6000 units: Observe the signal LED as shown below. No signal available or signal strength is below -100 dBm Excellent signal strength = greater than -69 dBm Signal FLASH Fast: Every 300ms = -79 to -70 dBm Medium: Every 600ms = -89 to -80 dBm Slow: Every 1200ms = -99 to -90 dBm RAM 9000 units: Observe the RSSI LED as shown below.
Page 29
Revised 2017-08-31 Cellular Connections Drawing No. LP0997-C Cellular Configuration If you refresh this screen every few minutes and notice that the IP address is changing frequently, it is possible that the RTU or router is connecting to the network and obtaining an IP address and then the connection to the cellular network is being dropped.
Page 30
RTU or router is still not communicating, then please call Red Lion Technical Support at 1-877-432-9908. Live support is available from 8:00 a.m. - 5:30 p.m. EST. If you call after hours, please leave your contact information and a detailed description of your problem and we will respond to you the following business day.
Summary, Easy Config, Network, Diagnostics, Syslog and Gather Stats. • Admin: The Admin Tab is used to configure how the Red Lion RTU or router is accessed, update the firmware, reset the system defaults, set the system time and reboot the RTU or router remotely. This tab is organized into eight (8) sections: Access Settings, System Time, Certificate Manager, Firmware Update, Configuration Manager, Package Installation, Factory Defaults/Reboot and Job Control.
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab The Status Tab allows you to review the state of the RTU or router functions, such as network connections, interfaces, system processes, services running, and system information. It also allows review of the syslog, update history, and under diagnostic tools, permits testing connectivity through the use of ‘ping’...
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab 3.2.2 Easy Config Wizard The Easy Config Wizard is used to setup your Ethernet IP without having to navigate through multiple dialog windows. The Easy Config Wizard is situated on the Summary page and accessed by clicking on the blue Easy Config Wizard button.
Page 34
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Obtain Network Addresses via DHCP: Select Yes to allow the interface to obtain address information via a DHCP server. The device will obtain its IP address, netmask and remote gateway as the default route. It can also, optionally, obtain DNS server address via DHCP.
Page 35
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab Recommended Setting: Your network administrator should be able to provide an appropriate value. The address must be one within the valid range for the network. Once the desired settings have been entered in the Eth0 (WAN) Settings dialog window, click on the Next button and the following eth1 (LAN) Settings dialog window appears: IP Address (Required): Enter the desired interface IP address into this field.
Page 36
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C SSID: The SSID is a unique name for your wireless network. It is case sensitive and must not exceed 32 characters. All wireless devices in your network must use the same SSID. Pre-shared Key: This option is available when WPA types are selected as an option for Encryption and allow the user to specify the encryption key to be used.
Page 37
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab Click on Back, Save or Apply (see explanation of each setting in dialog window above). ® ® Sixnet Series SN/RAM 6000 & RAM 9000 Software Manual - 29 -...
When you click on the ARP Cache menu item, the ARP Cache dialog window will open. Firewall Rules The Firewall Rules menu item displays a complete listing of the rules used within the firewall for the Red Lion RTU or router. If you are familiar with Linux and IPTables, this will be of great use.
Page 39
Drawing No. LP0997-C Status Tab Scroll through the list of rules to review the entire IPTABLES listing. This information is used to track traffic being allowed and traffic being denied access to and through the Red Lion RTU or router. ®...
Page 40
The Summary table displays a brief description of the interfaces of the Red Lion RTU or router. The Details table displays a system specific description of the interfaces on the Red Lion RTU or router. The Multicast table displays the current multicast settings for various interfaces.
Page 41
The Routing Tables dialog window contains both the Standard System Routing Table and the Policy Routing Table. The Standard System Routing Table displays the current routes for the Red Lion RTU or router and the static routes that have been configured for the RTU or router.
Page 42
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Socket Statuses Sockets are end-points to communication over the Internet. Much like PBX phone systems, where the IP address is the phone number and the port is the extension. Every paired (connected) socket has a source IP/port and a destination IP/port.
Page 43
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab Traffic The Traffic dialog window shows the unit’s traffic history. From the Display Flag drop-down list, select which information is desired and which Interface is to be viewed. The information will then be shown on the dialog window.
The Diagnostics menu is sub-sectioned into Cellular Status, Ping, Traffic Capture, Socket Test, Traceroute and System Info sub menus. These are useful in troubleshooting connectivity of the Red Lion RTU or router to the Internet or the Network the RTU or router is connected to.
Page 45
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab Ping The Ping menu item allows you to input an address either as an IP Address or a URL for testing the destination availability. Host/IP Address field: Type in the IP Address or URL you wish to Ping. It is recommended you start with a locally accessible IP address to confirm communication to an interface’s local subnet.
Page 46
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Traffic Capture Traffic Capture uses the tool tcpdump to perform network traffic captures and generate a widely compatible .cap file. A series of rotating capture files will be generated to prevent exhausting local resources and all may be downloaded for post-capture analysis in the viewer of your choice.
Page 47
Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Status Tab To ignore traffic to/from a specific host: host not 192.168.1.2 To capture only traffic from a specific port: port 1234 To combine these filters use: host not 192.168.1.2 and port 1234 Mode: Select whether you want to generate a capture file or view the live stream of the network traffic.
Page 48
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C Host/IP Address field: Enter the IP Address or domain name (if DNS enabled) you wish to trace. It is recommended to start with a locally accessible IP address to confirm communications to an interface’s local subnet.
3.2.5 Syslog The Syslog window will display the current syslog of the Red Lion RTU or router. Customize your search by configuring the following fields: Filter String (optional): Enter a filter string in the space provided. Only lines containing the filter value(s) will be displayed via a grep (Global Regular Expression Parser) style filter mechanism.
Status Tab Revised 2017-08-31 Web User Interface Drawing No. LP0997-C 3.2.6 Gather Stats The Gather Stats feature creates a collection of system log, configuration and status files for use as a troubleshooting tool when contacting Technical Support to research a reported issue. The device takes an automatic Gather Stats snapshot every night around 4AM and will rotate at three days of snapshots.
Revised 2017-08-31 Admin Tab Drawing No. LP0997-C Access Settings Admin Tab The Admin Tab is where you configure web access methods, manage SSL/IPSec certificates, set passwords, update firmware, manage configurations and set factory defaults. 3.3.1 Access Settings The Access Settings menu item allows you to change how the unit’s Web UI is accessed, either by HTTP, HTTPS or HTTPS/redirect.
Page 52
Admin Tab Revised 2017-08-31 Access Settings Drawing No. LP0997-C Enable ZeroConf Network Utilities: Enabling this option will make this device available on the network via unitname/hostname without a central DNS server. User: admin (Full access) New Password: Enter the new password in the “New Password” field. For a secure password, choose one that is at least six characters long, which is not a common word and comprised of a mixture of upper and lower case characters and numbers as well as special characters.
System Time 3.3.2 System Time The System Time menu item is used to configure the time zone on the Red Lion RTU or router to correspond to your location. Click on the System Time menu time and the following window appears.
Admin Tab Revised 2017-08-31 Certificate Manager Drawing No. LP0997-C 3.3.3 Certificate Manager The Certificate Manager gives the option of adding a certificate, deleting or editing an existing one. Click on the Certificate Manager menu item and the following dialog window appears: There are two ways to add a certificate to the Certificate Manager Table.
Page 55
Revised 2017-08-31 Admin Tab Drawing No. LP0997-C Certificate Manager Certificate Type: Select the type of certificate that you will be uploading. Each certificate is stored in a unique repository, depending on the service that will be using it. The certificate file name can contain only upper and/ or lower case letters, digits, ‘-’, ‘_’...
3.3.4 Firmware Update The Firmware Update menu item is used to upgrade the firmware of the Red Lion RTU or router. Click on the Firmware Update menu item and the following window appears: To upgrade the firmware of the Red Lion RTU or router: Click or drop boot image file: Click on to select the file that will perform the kernel update or drag and drop into this area the file that will perform the kernel update.
Export Web UI Master Configuration File: To save a copy of the Red Lion RTU or router configuration, click on the “Export” button. The pop-up window below asking you to save or open the file appears. Select the desired option.
Page 58
Admin Tab Revised 2017-08-31 Configuration Manager Drawing No. LP0997-C Warning: If the configuration file has many sections, the Forced Apply option can take a long time to process. To apply the settings, you will need to visit the configuration page for each supported sub-system and click its Apply button.
3.3.6 Package Installation The Package Installation feature allows you to upload and install patches from Red Lion. Click on the Package Installation menu item and the following dialog window appears: Package File Source: Select the method (Upload or SD Card) by which you would like to upload the package zip file.
Select the filename to select the file. Note: Be sure to use only genuine Red Lion provided packages in the form of filename.zip. Click on the Open button to populate the Package File field and click on the Upload button. When install is complete, a table appears at the bottom of the dialog window listing the results.
Revised 2017-08-31 Admin Tab Drawing No. LP0997-C Job Control 3.3.8 Job Control The Job Control feature is used to create jobs that will be run at specified intervals. Click on the Job Control menu item and the following dialog window appears: Predefined Job Settings: Predefined Job Interval: Select the appropriate periodic job interval from the drop-down list provided to run at the scheduled job interval.
Page 62
Admin Tab Revised 2017-08-31 Job Control Drawing No. LP0997-C Select Predefined Job: Select the desired job to be scheduled for the selected job interval. The options are: Reboot: Will reboot the unit at selected job interval. Restart Serial IP: Will restart the GWLNX (Serial IP) application at selected job interval. Click on the Apply button once the required changes have been made.
Cellular Connection Network Tab The Network Tab configures aspects of the Red Lion RTU or router affecting the networking functionality of the unit. From here you can configure the Cellular Connection, Ethernet Interfaces, Firewall, Tunneling, DNS Settings, Static Routes, DMNR/NEMO and TCP Global Settings.
Page 64
Network Tab Revised 2017-08-31 Cellular Connection Drawing No. LP0997-C The Config, Status and Provisioning buttons are a quick way to navigate to the three (3) sub-menus of the Cellular Connection menu. Enable Interface: Select Yes to enable the interface to become active after the new settings are applied and upon subsequent system start-up.
Page 65
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Cellular Connection IP Family: Select the IP Family required for your connection.The recommended setting for this field is Auto. Auto: Default IPv4, IPv6 for Verizon firmware. IPv4: Make IPv4 connection only. IPv4v6: Make IPv4 and IPv6 connection. Note: An IPv6 session is not guaranteed, and is not considered an error if an IPv4 session is successful.
Page 66
NTP is being used. Use Default Route: This field allows you to choose to have the default route for the Red Lion RTU or router to be the cellular connection when it is connected, or to designate an Ethernet port as the default route. Select Yes to have the cellular connection use the default route once it is connected.
Page 67
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Cellular Connection Status The Status menu item brings up a dialog window displaying the status of the cellular connection. From here, you can get information such as the type of modem, carrier, MDN, IMEI, MEID, ESN, CCID, IP, RSSI, RSRP, RSRQ, Activation Status, Connection Status, Cellular Uptime CSQ History and Card Stats.
Page 68
Network Tab Revised 2017-08-31 Cellular Connection Drawing No. LP0997-C Provisioning The Provisioning menu displays carrier specific information that may be useful when initially provisioning your device with a new carrier. Click on the Provisioning menu item. If a cellular connection is found, the following window appears with the information about the modem in the upper window: Note: If the cellular SIM is not recognized, go to the Configuration dialog window and enter the required data...
Page 69
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Cellular Connection Also update APN (optional): Enter the APN used to access your cellular wireless data service. Note: If an APN is specified in this field, it will be automatically applied after the module is updated. Note: The maximum amount of characters allowed in this field is 104 characters.
3.4.2 Interfaces The Interfaces menu allows the administrator to configure the Ethernet ports of Red Lion RTU or routers to incorporate within their existing network topology. Interfaces available may include eth0 (WAN), eth1 (LAN), Wifi, USB and IPv6. These will only be present if your hardware supports these interfaces.
Page 71
‘Dynamic’ IP address configuration is selected, as the DHCP server will provide the Red Lion RTU or router with the IP address that it should use. This is a required field.
Page 72
Network Tab Revised 2017-08-31 Interfaces Drawing No. LP0997-C Enter Remote Gateway: Enter the IP Address for the gateway device in the field provided. This field is only available when Obtain Network Addresses via DHCP has been set to NO. This field is required if Use Remote Gateway as Default Route is set to Yes.
Page 73
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Interfaces ensure that there is no conflict with any pre-existing devices on that subnet which may have been already configured to use statically assigned IP addresses. Ending Address: Enter the ending IP address of a range you want the DHCP Server to provide for clients. The recommended setting is a valid address for the subnet for which the interface is configured, beyond that chosen for the starting value of the range.
Page 74
Network Tab Revised 2017-08-31 Interfaces Drawing No. LP0997-C Interface VLANs: Sub-interfacing is essentially the segmenting of a single wire, or port, into multiple IP networks. Instead of subnetting and routing, you can create a sub-interface and then set it up as you would a standard Ethernet interface.
Page 75
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Interfaces Save: The interface will not be activated or deactivated until the device is rebooted. This allows for other configuration changes to be made to the device which can be committed at a later time. Apply: The current settings will be saved and the interface will either be activated or deactivated immediately.
Page 76
Network Tab Revised 2017-08-31 Interfaces Drawing No. LP0997-C Wi‐Fi LAN Interface Enable WLAN Interface: Select YES to enable the Wi-Fi interface. IP Address (Required): The wireless bridge IP Address is entered in this field. The IP Address identifies a device on the TCP/IP network. Every device on a network must have a unique address. The range of valid addresses for a given network and broadcast is determined by the value of the Netmask.
Page 77
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Interfaces SSID (Required): The SSID is a unique name for the wireless network. It is case sensitive and must not exceed 32 characters. All wireless devices in your network must use the same SSID. Verify that the correct SSID is being used and click the “Apply”...
Page 78
Drawing No. LP0997-C The USB interfaces menu item allows the administrator to configure the USB port of the Red Lion RTUs or routers to meet their needs. The default address is set for 192.168.111.1 with the subnet mask of 255.255.255.0 Click on the USB menu item and the USB IP Interface dialog window appears: Enable USB Interface: Select YES to enable the USB interface.
Page 79
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Interfaces IPv6 Enable IPv6: Selecting YES to this option will enable IPv6 routing for devices behind the RTU or router. RTU or Router Advertisement messages will be sent periodically to the specified LAN segment, and RTU or Router Solicitations will be responded to on that LAN segment only.
Page 80
Network Tab Revised 2017-08-31 Interfaces Drawing No. LP0997-C PPP Dial Backup The PPP Dial Backup menu item is used to configure the capability of an alternate connection by dialing into an ISDN should the primary RTU or router get interrupted. Click on the PPP Dial Backup menu item and the PPP Dial Backup dialog window appears: Enable PPP Dial Backup: Select YES to turn on the PPP Dial Backup and NO to turn off PPP Dial Backup.
Page 81
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Interfaces Choose Connection Behavior: In Persistent mode, the unit will always attempt to maintain a constant connection to the POTS network. In On-Demand mode, the connection to the POTS network will only be attempted when packets are destined to leave the modem’s PPP interface.
Page 82
Network Tab Revised 2017-08-31 Interfaces Drawing No. LP0997-C PPP over Ethernet The PPP over Ethernet menu item is used to configure a connection by being able to connect a DSL or cable modem. Click on the PPP over Ethernet menu item and the PPP over Ethernet dialog window appears: Enable PPPoE: Select Yes to enable the PPP over Ethernet service on the specified interface when the Apply button is clicked.
3.4.3 Firewall The Firewall menu item allows you to configure every aspect of the firewall on the Red Lion RTU or router. The Firewall menu is organized in four (4) sub-sections: General Settings, ACL Rules, Masquerade/NAT/DMZ Rules, Port Allow/Forwarding Rules.
Page 84
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C To restrict access via a configured whitelist, select a whitelist name for the list of names available in the drop- down menu. Note: This setting will not override any firewall rules defined on other pages, such as service access or redirect rules.
Page 85
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall To restrict access via a configured whitelist, click the check box marked Use Whitelist and then select a whitelist name for the list of names available in the drop-down list box provided. Whitelists may be viewed/ defined via the Network>Firewall>ACL Rules>Subnet Whitelist Rules screen.
Page 86
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C Allow NAT-Traversal (Required): Specify whether to allow data on UDP port 4500 on untrusted interface. The recommended setting for this field is Yes. Note: This is necessary if you are planning to run any IPSec tunnels through our device. This would support a unit behind a trusted interface to make an IPSec connection to a host beyond an untrusted interface.
Page 87
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall Click on the Finish button to populate the Trusted Interface screen. Untrusted Interfaces Identifies the Primary Untrusted (external) Interface and the following pop-up window appears: Click on the Add button for Untrusted Interface and the following pop-up dialog window appears: Interface: Choose an interface from the drop-down list provided.
Page 88
From the ACL Rules dialog window, Whitelist and Blacklist rules are defined. Whitelist Rules are used to define a single IP Address or an entire network that would be allowed to access the network behind the Red Lion RTU or router.
Page 89
Subnet Blacklist Rules: These rules are used to define a single IP Address or an entire network that are NOT allowed to access the network behind the Red Lion RTU or router. Click on the Add button and the following window appears: Enter Subnet To Blacklist (Required): Enter the network to be banned from making any incoming or outgoing connections, using IP/CIDR notation.
Page 90
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C Note: Once any filter is configured for restricting traffic, ALL traffic is then dropped that does not match the filter(s) for specified interfaces. IPSec traffic for VPN tunnels can also be filtered using these rules. Click on the Add button and the following dialog window appears: Inbound Interface: Select an interface associated with the Source Address/Subnet from the drop-down menu.
Page 91
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall Masquerade/NAT/DMZ Rules DMZ rules are used to configure rules to route through a Demilitarized Zone (DMZ), Masquerade rules are used to configure an interface to give all IP Addresses on a local network access to the Internet, while NAT(Network Address Translation) rules provide access to the Internet through a single machine that translates the IP addresses.
Page 92
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C Click on the Finish button. You will be returned to the Masquerade/NAT/DMZ Rules dialog window and the Masquerade Rules table will now be populated with the recently entered data. To delete an existing rule, select it in the table and click on the Delete button. To edit an existing rule, select it in the table and click on the Edit button.
Page 93
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall Note: Host Redirect and Service Access rules will apply first, and may prevent certain ports from reaching the New Destination. Select Protocol: Choose the protocol type for this port’s data. Options are TCP, UDP, All. Source network via Whitelist: Select a whitelist name from the list of names available in the drop-down list box provided.
Page 94
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C This address may be owned by an interface on this device, or an unowned/fake range with a corresponding route (static or default). One-to-one NAT Range will perform a complete forwarding of all ports for the range of starting/ending Original Destination IP’s to a range of starting/ending New Destination IP addresses entered in New Destination Address Start and New Destination Address End fields.
Page 95
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall DMZ Rules DMZ rules are used to configure routes through a Demilitarized Zone (DMZ). To add a DMZ host rule Click on the Add button and the following dialog window appears: Label: Enter a description to describe this DMZ Rule. This field is not required for DMZ Rules functionality and it is just for DMZ Rule identification.
Page 96
IP Address located behind the Red Lion RTU or router. Service Access (Allow) Rules: The Service Access Rules option is used to define what ports, either as a single port or a range of ports, are authorized access through the firewall on the Red Lion RTU or router. ...
Page 97
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Firewall To add a new Service Access Rule. Click on the Add button and the following dialog window: Label: Enter a description to describe this Allow Rule. This field is not required for Allow Rules functionality and it is just for Allow Rule identification.
Page 98
Network Tab Revised 2017-08-31 Firewall Drawing No. LP0997-C Click on the Add button on the following dialog window appears: Label: Enter a description to describe this Redirect Rule. This field is not required for Redirect Rules functionality and it is just for Redirect Rule identification. Supported characters are alphanumeric plus the following special characters: _@-./',;:?~! #$%^&...
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling 3.4.4 Tunneling The Tunneling menu is divided into two (3) sub-sections: GRE Tunnels, IP in IP Tunnels and IPSec. GRE Tunnels (Generic Routing Encapsulation) The GRE Tunnels menu item is used to configure a GRE Tunnel. GRE is a tunneling protocol that was originally developed by Cisco.
Page 100
Network Tab Revised 2017-08-31 Tunneling Drawing No. LP0997-C To add a GRE Tunnel: Click on the Add button and the Add GRE Tunnel pop-up window appears: Label: Enter a description to describe this tunnel. This field is not required for GRE tunnel functionality and it is just for tunnel identification.
Page 101
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling Inbound Key: Specify a key for use with keyed GRE. Key is either a number or an IP address. The Inbound Key is used for input only. This is an optional field. Outbound Key: Specify a key for use with keyed GRE.
Page 102
Network Tab Revised 2017-08-31 Tunneling Drawing No. LP0997-C To add an IP in IP Tunnel: Click on the Add button and the following window appears: Tunnel ID (Required): Enter a unique numerical identifier in this field. It will be used for naming the tunnel interface which appears in the interface list as tunl1, tunl2, etc.
Page 103
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling IPSec The IPSec dialog window is split into two sections. The top section pertains to the IPSec configuration and the bottom portion is where IPSec tunnels are created and edited. IPSec Configuration Enable IPSec: Specify whether you want to enable the IPSec service.
Page 104
Network Tab Revised 2017-08-31 Tunneling Drawing No. LP0997-C On Connect: The available options are: Do Nothing: Perform no action IPSec Restart: IPSec is restarted IPSec Stop: IPSec is stopped On Disconnect: The available options are: Do Nothing: Perform no action IPSec Restart: IPSec is restarted IPSec Stop: IPSec is stopped With these combinations, the connection management may be fine-tuned so that the tunnel(s) may be able to...
Page 105
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling Tunnel Type: Controls the initial mode of the tunnel at startup. The options given to IPsec are: Client: auto=start Server: auto=add Dynamic: auto=route For more information, please consult an IPsec user guide on aspects of these specific modes. Negotiation Mode: As a default, this field is set to Main mode ISAKMP Negotiation.
Page 106
Network Tab Revised 2017-08-31 Tunneling Drawing No. LP0997-C Click on the Next button and the following Encryption Settings dialog window appears: Phase 1 Encryption: Select the type of encryption needed for phase 1 (IKE). The options are AES, AES128, AES256, 3DES. Phase 1 Authentication: Select the type of authentication needed for phase 1 (IKE).
Page 107
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling Encryption Method: Specify how the two end-points for this tunnel should authenticate with each other. Current options are Pre-Shared Key and X.509 Certificates. You may select certificates only after they are loaded in the Admin > Certificate Manager. The default setting is Pre-Shared Key. Certificate is an available option.
Page 108
Click on the Next button and the Termination Settings dialog window appears: Local Public IP Address: This parameter typically only needs to be specified when the Red Lion RTU or router is configured to use more than one external, untrusted interface. Specify the IP Address of the left participant’s public network interface.
Page 109
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Tunneling This option is primarily used when defining subnet-subnet connections, so that the gateways can talk to each other and the subnet at the other, without the need to build additional host-subnet, subnet-host and host-host tunnels.
Enter Primary DNS Server (Required): This field is already filled in; it is showing the current server in use by the Red Lion server. Enter the IP Address of the Primary DNS Server you want to use. Note: This setting may be overridden if a network interface is set to obtain its configuration information from its peer (either via PPP or DHCP).
Page 111
Drawing No. LP0997-C DNS Settings Static Hosts Static Host entries may be added for local hosts, allowing the Red Lion RTU or router to resolve local host names to IP addresses. Click on the Add button on the following dialog window appears: Enter Host Name (Required): Enter the desired Host Name.
The Static Routes menu allows you to configure a route to a network through an interface manually. Click on the Static Routes menu item and the Static Routes dialog window will open: To add a Static Route on the Red Lion RTU or router: Click on the Add button and the dialog window below appears: Interface: Select the interface to which the route should be applied by selecting one of the available options from the drop-down list.
Page 113
Revised 2017-08-31 Network Tab Drawing No. LP0997-C Static Routes Enter Gateway (Required): Enter the IP Address of the gateway for the specified host or network. A gateway is a device (typically a RTU or router) used to gain access to another network. For example, if a device is attached to a LAN whose a network address is 192.168.1.0 with a netmask of 255.255.255.0, than it can communicate directly with any other device on that network with a range of addresses of 192.168.1.1 through 192.168.1.254 (with 192.168.1.255 reserved for a broadcast).
Network Tab Revised 2017-08-31 DMNR/NEMO Settings Drawing No. LP0997-C 3.4.7 DMNR/NEMO Settings Click on the DMNR/NEMO menu item the following dialog window appears: Enable DMNR/NEMO Client: Yes/No options to enable a DMNR/NEMO client (Dynamic Mobile Network Routing / Network Mobility). Selecting Yes will invoke the DMNR/NEMO Settings screen. ...
Page 115
Revised 2017-08-31 Network Tab Drawing No. LP0997-C DMNR/NEMO Settings 2.4.7.1 DMNR/NEMO Client The DMNR/NEMO Client menu item is used to Specify whether to enable the DMNR/NEMO Client on this device. Select the DMNR/NEMO menu item, select yes to enable and the following window appears: Home Agent (HA) IP Address: Enter the NEMO server address for the client to connect (provided by Verizon) (Required field).
Page 116
Network Tab Revised 2017-08-31 DMNR/NEMO Settings Drawing No. LP0997-C MR Home IP Address: Enter the MR Home IP address - a /32 IPv4 address programmed into the MR configuration and used by the MR as a source of all NEMO signaling. This will be the IP of the MR GRE endpoint and does not need to be different on every device.
Page 117
Revised 2017-08-31 Network Tab Drawing No. LP0997-C DMNR/NEMO Settings Select the desired interface by clicking the name of the available interface (or select all available interfaces using the Select All option) from the Available list on the left side of the screen. Verify your selection(s) move to the Selected side of the screen and click Done when finished or click Clear to revert your selection.
Page 118
Network Tab Revised 2017-08-31 DMNR/NEMO Settings Drawing No. LP0997-C Delete Use this button to delete an existing routed subnet. Select the routed subnet and click on the Delete button to the right of the Additional Routed Subnets area. Confirm the deletion request on the confirmation pop up. Verify the deleted routed subnet no longer appears in the primary display area.
Revised 2017-08-31 Network Tab Drawing No. LP0997-C TCP Global Settings 3.4.8 TCP Global Settings Click on the TCP Global Settings menu item the following dialog window appears: [SYN] Tx Timeout (Required): Specifies the timeout value, in seconds, for SYN packets for connection tracking.
Page 120
Network Tab Revised 2017-08-31 TCP Global Settings Drawing No. LP0997-C There are three available options: • No Source validation • Strict Mode: As defined in RFC3704 Strict Reverse Path, each incoming packet is tested against the FIB and if the interface is not he best reverse path then the packet check will fail. By default failed packets are discarded.
DHCP Server Services Tab The Services Tab is where you can configure the various service offerings of the Red Lion RTU or router. These services include DHCP Server, DHCP Relay, Dynamic DNS, SN Proxy Settings, SixView Manager, GPS Settings, SSH/TELNET Server, SSL Connections, SNMP Agent, Ping Alive, Serial IP, RAMQTT and SMS Handling.
Page 122
Services Tab Revised 2017-08-31 DHCP Server Drawing No. LP0997-C Minimum Lease Time (seconds): Specify the amount of time, in seconds, that the DHCP Server allows clients to maintain their leases. Default “3600”(1 hour). eth0: Enable DHCP: Specify whether you want to enable a DHCP Server for the interface. Note: If the interface is not enabled, or has been set to obtain its addressing parameters via DHCP, this option will be forced to “No”, and disabled until the interface is both enabled and set to use a static...
Page 123
Revised 2017-08-31 Services Tab Drawing No. LP0997-C DHCP Server usb0: Enable DHCP: Specify whether you want to enable a DHCP Server for the interface. Note: If the interface is not enabled, or has been set to obtain its addressing parameters via DHCP, this option will be forced to “NO”, and disabled until the interface is both enabled and set to use a static IP Address.
Page 124
Services Tab Revised 2017-08-31 DHCP Server Drawing No. LP0997-C Enter Client MAC Address (Required): This is the field where you enter the Client’s computer or device MAC (Media Access Control) address. The MAC address is a unique number assigned by the manufacturer to any Ethernet networking device, such as a network adapter, that allows the network to identify it at the hardware level.
Revised 2017-08-31 Services Tab Drawing No. LP0997-C DHCP Relay 3.5.2 DHCP Relay This feature will enable a DHCP Relay service, which will connect a local interface with a remote DHCP Server. DHCP Relay should not be enabled for any interface(s) which have been configured to act as a DHCP server. Click on DHCP Relay and the following dialog window appears: Enable DHCP Relay: Select YES to enable the DHCP Relay, or NO to disable it.
Page 126
Services Tab Revised 2017-08-31 DHCP Relay Drawing No. LP0997-C Click on the Add button and the following dialog window appears: Select Interface: Select the interface to receive its IP from the remote DHCP server from the drop down menu. Click on the Finish button. You will be returned to the DHCP Relay dialog window and the Interface Table will be populated with the entered data.
Dynamic DNS The Dynamic DNS menu item is used to configure a dynamic DNS name for the Red Lion RTU or router that does not have a static public IP Address. A subscription to a service providing Dynamic DNS, such as DYNDNS.ORG, is required.
Page 128
Services Tab Revised 2017-08-31 Dynamic DNS Drawing No. LP0997-C Enter User Name (Required): Enter the User Name used to access your Dynamic DNS Service in this field. Enter Password (Required): Enter the password used to access your Dynamic DNS Service in this field. Confirm Password (Required): Re-enter the password entered in the field above.
SN Proxy Settings SN Proxy is a web relay proxy service used to gain access to devices that are behind our Red Lion RTU or router providing additional security and access control to devices that may not offer such functionality. A proxy based service provides a more robust connection than just using a port forward rule, including the ability to add an additional user login for authentication, encryption via SSL as well as isolation via Access Control Lists.
When changing the Primary Address to your own private SixView Manager server, you may want to consider setting the Secondary Address to the Red Lion SixView Manager test server (server1.sixviewmanager.com) for trial and initial production rollouts This will enable Red Lion support staff to monitor the progress and better assist in diagnosing potential problems.
Page 131
When changing the Primary Address to your own private SixView Manager server, you may want to consider setting the Secondary Address to the Red Lion SixView Manager test server (server2.sixviewmanager.com) for trial and initial production rollouts. This will enable Red Lion support staff to monitor the progress and better assist in diagnosing potential problems.
Services Tab Revised 2017-08-31 GPS Settings Drawing No. LP0997-C 3.5.6 GPS Settings Click on the GPS Settings menu item and the following dialog window appears: GeoFence Engine State: Options and descriptions are listed in this field. Eventable register state is listed in parenthesis next to the label.
Page 133
Revised 2017-08-31 Services Tab Drawing No. LP0997-C GPS Settings Lockdown - Wait for Entries (2): Have data, but waiting on more entries to compute fence. Lockdown - Wait on Satellites (3): Have entries, but waiting on better satellites to compute fence. Lockdown - Failed (4): Lockdown failed to build GeoFence (same behavior as Monitor Only).
Page 134
Services Tab Revised 2017-08-31 GPS Settings Drawing No. LP0997-C When the GeoFence engine begins to build a fence, it will calculate an allowed Minimum Radius using an accuracy figure based on an average of 200 location points acquired over an interval of 15-20 minutes. This value is then multiplied by the Lockdown Radius Multiplier to obtain the Modified Minimum Radius.
Page 135
Revised 2017-08-31 Services Tab Drawing No. LP0997-C GPS Settings Select Violation Action: Select the action to be taken when a protected perimeter violation occurs using the drop-down list provided. The available options are: • Report Only: The device reports violation events to a SixView Manager server. •...
Page 136
Services Tab Revised 2017-08-31 GPS Settings Drawing No. LP0997-C Log Update Interval (seconds): This parameter determines how often (in seconds) the current GPS data point will be saved in NMEA format in a Raw GPS logfile. The allowable range is 5-10000. Click Save to store the settings for the next reboot, or click Apply for the settings to take effect immediately.
The SSH/TELNET Server menu allows you to configure whether the Red Lion RTU or router will communicate with the network via Secure Shell (SSH) and to enable or disable TELNET on the Red Lion RTU or router. Click on the SSH/TELNET menu item and the following dialog window appears: SSH Server...
Page 138
Services Tab Revised 2017-08-31 SSH/TELNET Server Drawing No. LP0997-C Maximum Concurrent Connections: Specifies the maximum number of concurrent unauthenticated connections to the SHH server. Additional connections will be dropped until authentication succeeds, or the Login Grace Time expires for a connection. The recommended setting for this field is 10. Allow Root Login: Specifies whether root can log in directly to the SSH server.
SSL Client and the SSL Server. SSL Client The SSL Client menu item is used to configure the Red Lion RTU or router to be a SSL client and receive a certificate of authorization from an SSL server to authenticate connections for secure communications.
Page 140
Services Tab Revised 2017-08-31 SSL Connections Drawing No. LP0997-C Bind Interface for outgoing SSL Connections: This will restrict the encrypted socket to initiate connections out the specified interface only. Specifying an interface here may conflict with policy routing, however it may be required in a GRE/VPN or other tunneled environment.
Page 141
Revised 2017-08-31 Services Tab Drawing No. LP0997-C SSL Connections Label (Required): Enter a unique name to describe this connection. TCP Listening IP: Enter the IP to listen on for incoming connections. If not using static IP addresses, it is recommended to use the Advanced Setup option “Bind Interface for accepting TCP Connections” instead. The recommended settings for this field are: •...
Page 142
Drawing No. LP0997-C SSL Server The SSL Server menu item is used to configure the Red Lion RTU or router to issue SSL certificates to requesting SSL clients. Click on the SSL Server menu item and the following dialog window appears: Enable SSL: Select Yes to configure SSL client/server.
Page 143
Revised 2017-08-31 Services Tab Drawing No. LP0997-C SSL Connections however it may be required in a GRE/VPN or other tunneled environment. Please consult with a network architect for additional assistance. The recommended setting for this field is Any. Ciphers: This field is a list of openssl ciphers supported. Please consult support staff before attempting to change.
Page 144
Services Tab Revised 2017-08-31 SSL Connections Drawing No. LP0997-C SSL Listening Port (Required): Enter the listening port for SSL connections. Please note that this port must be allowed in the Firewall access rules for any external/untrusted interface. It may be helpful to review the results of StatusNetworkSocket StatusesTCP Only to confirm that your choice of listening port is not already in use.
To retrieve SNMP data from the Red Lion device you must have an SNMP manager or Server at the head end. The Red Lion RTU or router will only act as an SNMP client, providing data it is polled for. It will not act as a manager to poll other devices.
Services Tab Revised 2017-08-31 Ping Alive Drawing No. LP0997-C Contact: Enter the name of the contact person for this managed device. This field is useful in determining who to contact in the event of an issue. The maximum amount of characters that can be used in this field is 250 characters.
Page 147
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Ping Alive many hosts must fail before a failure is declared and Failure Command Script will execute the failure action specified at that time. This can be used to force interface traffic, or to probe connectivity to an end point. Test Interval (in minutes)(Required): Enter the time interval (in minutes) to which the ping packets would be sent.
Crimson Connect Crimson Connect provides a consolidated way to streamline multiple configuration options when coordinating with a Red Lion DSP or HMI product. Using this interface provides HTTPS encapsulation, SMS support, Email encryption and Crimson Link access for remote reconfiguration. Settings for this feature work in conjunction with settings from the Crimson software. Please consult your Crimson manual for setup information as indicated in sections below.
Page 149
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Crimson Connect Crimson Services Setup Walkthrough: This option provides step-by-step instructions for Crimson Services setup. Click on the Walkthrough button to begin the Crimson Services setup. The Crimson SMS API Configuration window will pop-up. Enable Crimson SMS API: Enable the Crimson SMS API interface on port 1000. See Crimson HOWTO guide for more information and instructions on how to configure your Crimson application to connect to these SMS services.
Page 150
Services Tab Revised 2017-08-31 Crimson Connect Drawing No. LP0997-C Service Provider: Select the Domain Name of the remote SSL email server. Destination Email Server (Required): Enter the IP or Domain Name of the remote SSL email server. Example: smtp.gmail.com Destination Email Port (Required): Enter the Port number of the remote SSL email server. Common Secure SMTP ports are 25, 465, and 587.
Page 151
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Crimson Connect External browsers that connect to this port and complete authentication will then be allowed to connect to the Crimson device on the local network. Some cellular carriers block certain incoming ports (like 80). You may need to experiment with different values here.
Page 152
Services Tab Revised 2017-08-31 Crimson Connect Drawing No. LP0997-C Click on the Walkthrough button to begin the Crimson Remote Link setup. The Crimson Remote Link Walkthrough window will pop-up. Crimson Remote Link allows downloading and extracting Crimson databases through this device's cellular connection.
Page 153
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Crimson Connect Confirm that this is in the same subnet as this unit's Ethernet settings, Network Interfaces Eth0 or Eth1, depending on your cabling setup. Click on the Next button. ®...
Page 154
Services Tab Revised 2017-08-31 Crimson Connect Drawing No. LP0997-C Crimson IP Download Port (Required): The port number is found in the CommunicationsNetwork settings in Crimson. Click on the Next button. Time to allow access to Crimson Link (in minutes): Enter time to allow access to Crimson Link (in minutes). Once the Crimson Remote Link is Started, it will only allow the initial connection within the number of minutes specified here.
Page 155
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Crimson Connect Allow Specific IP: Enter a specific IP in the Filter From field. Only this IP will be allowed to connect to the Crimson Link. If your endpoints are connecting through a firewall, a computer's assigned IP might not be the same IP used when connecting to this remote unit.
Page 156
Services Tab Revised 2017-08-31 Crimson Connect Drawing No. LP0997-C All of the Crimson Link functions should now work normally. Please consult your Crimson manual's section “Downloading to a Device” for more information. Click on the Finish button. Quick Config: This option has the same fields as the Walkthrough setup, but can be configured in one dialog window Remote Link Status Once the remote link is running, enter the unit’s cellular IP in the Remote Address field of the download tab.
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Email Client 3.5.12 Email Client Specify whether to enable the SMTP email client support on this device. If this option is disabled, your email action routines will be unable to send. Enable Email Support: Specify whether to enable the SMTP email client support on this device. If this option is disabled, your email action routines will be unable to send.
Page 158
Services Tab Revised 2017-08-31 Email Client Drawing No. LP0997-C Auth Type: Select the authorization type for email client that may log in using an authentication mechanism chosen among those supported by the email server. Any: Any authorization method supported. Plain: Force server to use plain mode (for compatibility). Email Settings Test: Enter an email address for the email message destination.
Revised 2017-08-31 Services Tab Drawing No. LP0997-C SMS Handling 3.5.13 SMS Handling Specify whether to enable the SMS Command Handling Engine. If this option is disabled, all incoming SMS messages will be ignored unless SDK applications are processing them. Enable SMS Processing: Specify whether to enable the SMS processing support on this device. If this option is disabled, your SMS action routines will be unable to send.
Page 160
Services Tab Revised 2017-08-31 SMS Handling Drawing No. LP0997-C Access security: Select the Access security profile for who will be allowed access to the device. There are three available options. Allow any number: Any number can access features for all user types. Login is still required. Allow any number, Admin must be on whitelist: Any number can access Basic/Tech functions, but only whitelist users can access Admin functions.
Page 161
Revised 2017-08-31 Services Tab Drawing No. LP0997-C SMS Handling Permission level: Select the permission level for this incoming number. The available options are Admin user, Tech user and Basic user as defined earlier in this section. Click Save to store the settings for the next reboot, or click Apply for the settings to take effect immediately. Selecting Revert/Refresh, will reset all fields to previously saved defaults.
Services Tab Revised 2017-08-31 RAMQTT Client Drawing No. LP0997-C 3.5.14 RAMQTT Client Specify whether to enable the RAMQTT client support on this device. ® ™ 3.5.14.1 Amazon AWS IoT General IoT Cloud: Select the name of the Cloud Service Provider, from the drop down list, that will be receiving messages from this device.
Page 163
Revised 2017-08-31 Services Tab Drawing No. LP0997-C RAMQTT Client Device Root CA: Root Certificate Authority is required for connecting to AWS. This must be the Root Certificate Authority provided by AWS. Note: You can also click on the file icon to browse to the certificate for use. Advanced Settings Port: Enter the port number associated with the Broker IP address or Domain Name.
Page 164
Services Tab Revised 2017-08-31 RAMQTT Client Drawing No. LP0997-C If Already Registered is selected enter: • Device API Key: The Device API Key is used to allow the device to publish to topics on the cloud. Note: This will be auto generated if the device auto-registers using the Master API Key. •...
Page 165
Revised 2017-08-31 Services Tab Drawing No. LP0997-C RAMQTT Client Broker: Enter the Broker IP address or Domain Name provided by the Cloud Service Provider. Encryption (TLS/SSL): Select whether the connection will be encrypted. Use Authentication: Select whether authentication will be used. Messages See Messages on page -161...
Page 166
Services Tab Revised 2017-08-31 RAMQTT Client Drawing No. LP0997-C Advanced Settings Port: Enter the port number associated with the Broker IP address or Domain Name. The standard ports for MQTT are: • Unencrypted: 1883 • Encrypted: 8883 Keep Alive (seconds): The Keep Alive value is the maximum time in seconds an idle connection will be allowed.
Page 167
Revised 2017-08-31 Services Tab Drawing No. LP0997-C RAMQTT Client Device Root CA: Root Certificate Authority is required for connecting to AWS. This must be the Root Certificate Authority provided by AWS. Note: You can also click on the file icon to browse to the certificate for use. Advanced Settings Port: Enter the port number associated with the Broker IP address or Domain Name.
Page 168
Services Tab Revised 2017-08-31 RAMQTT Client Drawing No. LP0997-C Port: Enter the port number associated with the Broker IP address or Domain Name. The standard ports for MQTT are: • Unencrypted: 1883 • Encrypted: 8883 Keep Alive (seconds): The Keep Alive value is the maximum time in seconds an idle connection will be allowed.
Page 169
Revised 2017-08-31 Services Tab Drawing No. LP0997-C RAMQTT Client Keep Alive (seconds): The Keep Alive value is the maximum time in seconds an idle connection will be allowed. If no data needs to be transmitted for this period, then an empty Keep Alive packet will be transmitted to maintain the connection as active with the server.
Page 170
Services Tab Revised 2017-08-31 RAMQTT Client Drawing No. LP0997-C MESSAGE OPTION MESSAGE DESCRIPTION MESSAGE CONTENT • Unit name • Serial Number Sends a basic/small, predefined list • Cell IP Basic of device information values to the • Up Time cloud •...
Revised 2017-08-31 Services Tab Drawing No. LP0997-C SD Card Manager 3.5.15 SD Card Manager The SD Card Manager menu item is used to safely unmount the SD Card. Options are also available to view, download, or delete files on the SD Card while it is mounted into the device. This feature is only available on the RAM-9000 series (RAM 6000 does not have an SD Card).
Page 172
- This is where any exported gatherstats files will be copied when Save Stats to SD Card is set to Yes. It is best practice to insert the SD Card into the Red Lion device, Apply Directory Structure then move the SD Card to your other environments to copy the applicable files.
Serial IP The Serial IP menu item is used to configure serial communication such as POS device, serial data logging or serial transmitter via serial cable on the Red Lion RTU or router and third party UDP or TCP/IP Client/Server application.
Page 174
Select Yes for standard usage. Select No for serial to TCP Server configuration to insure there is a TCP Server socket available before marking the serial port active. Select Negotiate only if directed by Red Lion Technical Support.
Page 175
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Serial IP Peer IP Address (Required): Enter the peer IP Address into this field. This is required for UDP communication. This specifies the Peer IP address and if set to 0.0.0.0 any remote IP can send UDP packets to our peer port, and return packets will be sent back to the IP of the last host that sent a message.
Page 176
Services Tab Revised 2017-08-31 Serial IP Drawing No. LP0997-C TCP/UDP Independent Activation: This option determines if the TCP/IP port of the device will accept data before the remote side (Serial Port) is active. At least one of the two sides in the configuration must be set for Independent Activation.
Page 177
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Serial IP Extended header normally is used as an indicator First, Mid and Last when dealing with the large TCP messages and possibility of TXP/IP packet fragmentation. Host IP Address (Required): Enter the host destination IP Address into this field. This is required if the device is acting as a TCP/IP Client.
Page 178
Services Tab Revised 2017-08-31 Serial IP Drawing No. LP0997-C UDP communication. The recommended setting for this field is <0.0.0.0> if the additional peer IP address option is not used. Second/Third/Fourth/Fifth Peer IP Port: Enter the second, third, fourth or fifth port number in the respective fields.
Page 179
Revised 2017-08-31 Services Tab Drawing No. LP0997-C Serial IP Enter Port 2/3: This is a Client First Alternative Port address that GWLNX uses to connect to the Host Server Port. Connect Timeout 2/3: Specify the time in seconds to attempt a connection to this TCP Destination, before declaring it unreachable.
Page 180
Services Tab Revised 2017-08-31 Serial IP Drawing No. LP0997-C ® ® - 172 - Sixnet Series SN/RAM 6000 & RAM 9000 Software Manual...
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Automation Tab The Automation menu contains all aspects of managing your Modbus and DNP3 based I/O transfers or messages. This option is only supported in the RAM 6000 and the RAM 9000 series. The RAM 6000 or RAM 9000 acts as a MODBUS Master and as an I/O concentrator for MODBUS/DNP3 devices.
Automation Tab Revised 2017-08-31 Local Station Drawing No. LP0997-C 3.6.1 Local Station Click on the Local Station sub menu item and the following menu appears: Enable Modbus: Select Yes to enable the Modbus option. Station Name (Required): Enter the name of the local station. The station name must be less than or equal to 32 characters.
Serial Ports This section is used to configure the RS-232 port that is facing the front of the Red Lion device as well as the RS- 485 terminal (only available on the RAM 9000 Series) to integrate into your Modbus/DNP3 schema.
Page 184
Automation Tab Revised 2017-08-31 Serial Ports Drawing No. LP0997-C Baud Rate: Baud rate for the serial device. Supported baud rates are: 300, 600, 1200, 2400, 4800, 9600, 19200, 38400, 57600 and 115200. Data Bits: Number of data bits. Supported data bits are 7 and 8. Parity: Parity for serial device.
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Tags 3.6.3 Tags Tagging is a method used to attach a human readable and yet logical name to an IODB register. These tags provide an easier method of organizing and identifying internal registers when designing and monitoring the data in a Modbus environment.
Page 186
Automation Tab Revised 2017-08-31 Tags Drawing No. LP0997-C User Defined Create custom tags for your I/O here. These tags will be listed in drop-down forms throughout this user interface. Tag names must be unique and may not copy the names of Onboard or Status tags. To add a new tag, click on the Add button located at the bottom of the dialog window.
Page 187
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Tags System Status These tags are linked to status metrics internal to the device. They cannot be renamed or otherwise modified. See Appendix B in the user guide for more information. Click on the Refresh button to refresh screen after new entries have been entered. To delete an existing tag, click on the Remove button next to the tag to be deleted.
Automation Tab Revised 2017-08-31 Data Logger Drawing No. LP0997-C 3.6.4 Data Logger Click on the Automation menu item, select Data Logger from the drop-down menu and the following Data Logger configuration screen appears: Data Logger allows for the collection of data from defined points and save them as a log file to an internal destination or to an SD card (only available on RAM 9xxx).
Page 189
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Data Logger Click on any file to select the log file to Download, View, Remove or show the Process log associated with the log file. Click on the Download button to copy the selected Data Logger file to your PC for evaluation. Click on the View button to load a snapshot of the beginning and end of the highlighted file, but does not display the entire file.
Page 190
Automation Tab Revised 2017-08-31 Data Logger Drawing No. LP0997-C Options - Yes/No Toggle Enable from IODB: Toggle logging based on IODB register (optional field). For example: if set to DI42, Points will only be recorded if register DI42 is high. Save Destination: Destination for the log files.
Page 191
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Data Logger When selected enter the FTP configuration data for delivery of the data log by FTP. : FTP Mode Passive: In passive mode FTP the client initiates both connections to the server, solving the problem of firewalls filtering the incoming data port connection to the client from the server.
Page 192
Automation Tab Revised 2017-08-31 Data Logger Drawing No. LP0997-C FTP command PORT (N+1) to the FTP server. The server will then connect back to the client's specified data port from its local data port, which is port 20. FTP Security Mode Implicit: Negotiation is not supported with implicit FTPS configurations.
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Modbus Selected Tags move from Available Selected list. Click Select button when finished making selections. Base 1 0: Display toggle buttons located in the footer bar and will toggle the display of registers visible on the page from 0 based to 1 based.
Page 194
Automation Tab Revised 2017-08-31 Modbus Drawing No. LP0997-C Station Name (Required): Enter the name of the remote station. The remote station name must be less than or equal to 32 characters. All the defined remote station names will be populated in the I/O Transfer screens as a selection for assigning I/O transfer for selected remote station name.
Page 195
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Modbus I/O Transfer Click on the I/O Transfer menu item and the following window appears: Register Allocation: This section is displaying the default values for the following: Analog In: By default we support 5000 Analog Input registers, but the range is 1 - 10000. Analog Out: By default we support 5000 Analog Output registers, but the range is 1 - 10000.
Page 196
Automation Tab Revised 2017-08-31 Modbus Drawing No. LP0997-C I/O Transfer Table Properties Click on the Add button to configure the I/O Transfer for the remote station and the IO Transfer Settings pop-up window will open Station Name: Name of the remote station for this I/O transfer. This option lists the name of all the remote stations that you have already defined and configured in remote station table entry.
Page 197
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Modbus Send Mode: Mode used to send an I/O transfer. Available options are: waitForReply: The Modbus master must wait for an I/O request that it has sent to complete before sending another request to the remote station. rapidFire: The Modbus master may send many I/O requests to a remote station before waiting for responses from the remote station.
Page 198
Automation Tab Revised 2017-08-31 Modbus Drawing No. LP0997-C Click on the Save button for changes to be saved without activating the interface until you reboot the unit, the Apply button will save your settings and apply them immediately. To revert to the previous defaults, click on the Revert button.
Page 199
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Modbus Table 4: Valid Type Combinations for WRITE I/O Xfers Local Type Valid Remote Type Forwards Click on the Forwarding menu item and the following dialog window appears: Click on the Add button to configure the Forwarding and the following pop-up window appears: Station Number (Required): Station number to be forwarded.
Page 200
Automation Tab Revised 2017-08-31 Modbus Drawing No. LP0997-C Communication Type: Select the forwarding method. Valid options are TCP/IP, UDP/IP or Serial (Serial type can be set in next dialog). Forward IP Address or Serial Port Name (Required): The address to forward the modbus request if forwarding on with IP, or the serial device name if forwarding the request on the serial port.
Page 201
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Modbus This option will load the Modbus configuration file into the text box for Configure Modbus Configuration File: editing. The available controls (buttons) are as follows: Save - Save the contents of the text box in to the Modbus configuration file. Stop - Stop the Modbus service, if it is currently running.
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C 3.6.6 DNP3 DNP3 (Distributed Network Protocol) is a set of used between components in communications protocols process systems. Its main use is in utilities such as electric and water companies. Usage in other industries is automation not common.
Page 203
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Unsolicited Responses Enable Unsolicited Responses: Select if the DNP3 Slave should send unsolicited messages to the DNP3 Master. If this selection is checked, then the user should also configure the following: Enter DNP3 Address to Send Unsolicited Messages to: The address of the station to which DNP3 Slave will send unsolicited messages in the DNP3 Address to Send Unsolicited Messages field.
Page 204
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Physical Link Layer Select Mode of Operation: The DNP3 Slave Driver implementation supports RS-232 and RS-485 (two and four wires) over serial port communications as well as TCP/IP and UDP/IP over LAN/WAN communications. When the user selects the Serial Mode, the TCP/UDP section is disabled. The same happens to the Serial section if the Mode of Operation selected is TCP or UDP.
Page 205
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Data Link and Application Layer Use Local Station Number as This Station DNP3 Address: DNP3 address for the slave. This value can be set by the user or automatically assigned by the Add-On. If the check box Same As station Number is selected, then the DNP3 Address will be equal to the Station Number.
Page 206
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Note: The Driver's Data Link Layer will attempt to retry (will resend) an unconfirmed data link primary frame when the confirmation has not been received within the configured timeout. If the confirmation fails to arrive after the configured number of retries, the communications link is considered failed and a reset sequence is required before a new primary frame could be sent.
Page 207
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Binary Inputs Map I/O: This section provides configuration of Mapping Binary Input I/O’s Reg/Index to DNP3 points for generating events based on configured Class Assignments when the status of any Binary Input I/O’s changes. Default Class Assignments are applied to all the Reg/Index defined by Highest Register Address except Reg/Index entries that are defined in Exception Class Assignments Table. Configure DNP3 Points: If option is No, then no Binary Inputs is mapped as DNP3 points. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 208
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Example: If the Highest Register Address is set to 10 and Reg/Index 2, 4, 6-7 are needed to be set for different class assignments than default, then the final result for all 10 registers would be as follows: •...
Page 209
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Binary Outputs Map I/O Configure DNP3 Points: If option is No, then no Binary Outputs are mapped as DNP3 points. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 210
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Default DeadBand and Class Assignments are applied to all the Reg/Index defined by Highest Register Address except Reg/Index entries that are defined in Exception DeadBand and Class Assignments Table. Define Highest Register Address Configure DNP3 Points: If option is set to No, then no Analog Inputs are mapped as DNP3 points. If set to Yes, the Highest Register Address field is shown to enter a Highest Register Address value. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 211
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Change Events) then it should be associated to a class (Class 1, Class 2 or Class 3), otherwise it should be associated to None. By default all DNP3 Points don’t generate events, this feature should be modified by the user.
Page 212
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Object 32 - Analog Change Event: This field is activated on both levels 2 and 2+. It’s used to determine if a DNP3 point will generate events. In case a DNP3 point generates events (Object 2 Binary Change Events) then it should be associated to a class (Class 1, Class 2 or Class 3), otherwise it should be associated to None.
Page 213
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Define Highest Register Address Configure DNP3 Points: If option is set to No, then no Floating Inputs are mapped as DNP3 points. If set to Yes, the Highest Register Address field is shown to enter a Highest Register Address value. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 214
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C associated to None. By default all DNP3 Points don’t generate events, this feature should be modified by the user. Default Object 33 - Frozen Change Event: This field is activated on both Levels 2 and 2+. It’s used to determine if a DNP3 point will generate events.
Page 215
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Object 32 - Analog Change Event: This field is activate by both Levels 2 and 2+. It’s used to determine if a DNP3 point will generates events (Object2 Binary Change Events) then it should be associated to a class (Class 1, Class 2 or Class 3), otherwise it should be associated to None.
Page 216
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Define Highest Register Address Configure DNP Points: If set to No, then no Binary Inputs are mapped as DNP3 points. If set to Yes, the Highest Register Address field is shown to enter a Highest Register Address value. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 217
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 associated to None. By default all DNP3 Points don’t generate events, this feature should be modified by the user. Default Object 33 - Frozen Change Event: This field is activated on both Levels 2 and 2+. It’s used to determine if a DNP3 point will generate events.
Page 218
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C then it should be associated to a class (Class 1, Class 2 or Class 3), otherwise it should be associated to None. By default all DNP3 Points don't’ generate events, this feature should be modified by the user. Object 32 - Analog Change Event: This field is activated on both Levels 2 and 2+.
Page 219
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Define Highest Register Address Configure DNP3 Points: If option is set to No, then no Binary Counters are mapped as DNP3 points. If set to Yes, the Highest Register Address field is shown to enter a Highest Register Address value. Highest Register Address (Required): This field is used to show or set the highest register address to map DNP3 points.
Page 220
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Default Object 23 - Frozen Change Event: This field is activated on both Levels 2 and 2+. It’s used to determine if a DNP3 point will generate events. In case a DNP3 point generates events (Object 2 Binary Change Events) then it should be associated to a class (Class 1, Class 2 or Class 3), otherwise it should be associated to None.
Page 221
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 then it should be associated to a Class (Class 1, Class 2 or Class 3), otherwise it should be associated to None. By default, all DNP3 Points don't generate events, this feature should be modified by the user. Object 23 - Frozen Change Event: This field is activated on both Levels 2 and 2+.
Page 222
Automation Tab Revised 2017-08-31 DNP3 Drawing No. LP0997-C Binary Objects 1: Binary Input: Combo Box that shows the different choices for Object 1 (Binary Input) that the user can select as a default variation. 2: Binary Input Change: Combo Box that shows the different choices for Object 2 (Binary Input Change Events) that the user can select as a default variation.
Page 223
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C DNP3 Display Config File From this screen you are able to import, export and manually edit the DNP3 configuration file. Import Configuration: This option allows you to import a configuration file to replace your existing DNP3 configuration file.
Automation Tab Revised 2017-08-31 I/O Settings (RAM 6000 Models) Drawing No. LP0997-C 3.6.7 I/O Settings (RAM 6000 Models) I/O Control Click on the I/O Control menu item and the following window appears: Enable this interface: Select Yes to enable the I/O CTRL Interface. Digital Input Address: Enter the address of internal IODB database for Digital Input I/O control. Valid values for this field are 1 through 65535 as defined for specified I/O type.
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) displayed on I/O Transfer screen under 'Display Of Modbus Default Slave Addresses' based on configured local register allocation for specified I/O type. Update Interval (ms) (Required): Enter update interval, in milliseconds, for updating the internal IODB database with value of supported I/O CTRL.
Page 226
Automation Tab Revised 2017-08-31 I/O Settings (RAM-9000 Models) Drawing No. LP0997-C When “Drop Physical Outputs” is selected, all outputs are dropped to and OFF stated. When “No Action” is selected, outputs will hold their last known value. In a discrete output module, the OFF state is simply turning the outputs off, in an analog output module, OFF means to set all outputs to a nominal calibrated zero output.
Page 227
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) Note: Two (2) consecutive registers are always allocated in the “CNT IODB/Modbus Address” column whether set for 16-bit or 32-bit mode. Therefore, when using 16-bit Count Returned option, the second register should be ignored.
Page 228
Automation Tab Revised 2017-08-31 I/O Settings (RAM-9000 Models) Drawing No. LP0997-C Discrete Output Click on the Discrete Output button and the following dialog window appears: TPO period (ms): Time Proportioned Outputs (TPO) are outputs that turn on and off in proportion to an analog value.
Page 229
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) Analog Input Click on the Analog Input button and the following dialog window appears: Analog Input Filtering: The table below explains the filtering (integration) options on the analog inputs. The faster the integration time, the quicker the channels will be sampled.
Page 230
Automation Tab Revised 2017-08-31 I/O Settings (RAM-9000 Models) Drawing No. LP0997-C Disabled: This option will completely disable the channel so the channel will always report a zero. The Input Range is configuration will be disabled as well. Voltage Range: When this option is selected, the analog input will be configured to take a DC voltage range.
Page 231
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) Output Range: Select the type of signal to be supplied by the output channels. Disabled: This option will completely disable the output channel. 0-5 VDC: When selected, the analog output will be configured to supply a DC voltage from 0-5 VDC. The output voltage will be scaled to 0-32767 (decimal value in the IODB/Modbus Address field).
Page 232
Automation Tab Revised 2017-08-31 I/O Settings (RAM-9000 Models) Drawing No. LP0997-C Calibration Click on the Calibration button and the following dialog window appears: Channel: A channel is a physical IO point that can be either analog or digital. User Zero Correction: Manually adjust the user offset calibration for analog inputs/outputs. Every analog/ input is calibrated at the factory according to the specified accuracy.
Page 233
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) in the Offset display box. Click the Apply button and observe the effect of the new offset factor. Repeat this step until a satisfactory reading is obtained. 3. Set your analog device for a near full scale (85 to 95% full scale) output. Compare the value currently being reported with the value on your meter.
Page 234
Automation Tab Revised 2017-08-31 I/O Settings (RAM-9000 Models) Drawing No. LP0997-C 2. Select the calibration method and calibration units to use in the calibration. 3. Calibrate the offset for the selected channel by entering known signal’s measured value. 4. Apply the new calibration factors for the channel by clicking Apply button on the Apply Calibration screen. 5.
Page 235
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C I/O Settings (RAM-9000 Models) Status Click on the Status button and the dialog window below will provide you with your system’s I/O Control Status and I/O Control Config Status. View in Test I/O: Click on the Test I/O button to be directed to the Test I/O Access dialog window. See section 3.6.5 for more information on this feature.
Automation Tab Revised 2017-08-31 Test I/O Drawing No. LP0997-C 3.6.9 Test I/O Test I/O is used to verify the functionality of I/O states in gateways, RTUs and I/O modules. When a RAM-9000 model reboots for a power cycle, at the startup the I/O data turns out to no longer represent the previous real world situations if the tags do not have the Retain option checkbox selected.
Page 237
Revised 2017-08-31 Automation Tab Drawing No. LP0997-C Test I/O Register Count: Enter the Register Count for the number of registers you would like to display. To List: Select the list to add the selected tag or create a list by entering its name here and clicking on Add. Lists are used to group I/O points together for more organized viewing.
3.7.1 IP Fallback The IP Fallback option is used to configure the Red Lion RTU or router to failover between two interfaces, e.g. Primary route on T1/ DSL/Cable on eth0, and secondary on Cellular if the primary loses Internet connection. Click on the IP Fallback menu item and the following dialog window appears: Enable IP Fallback: Select YES to enable the IP Fallback.
Page 240
Select Debugging Level: Specify a debug level for logging purpose. This is recommended only when existing configurations do not function as expected, and when directed to change by Red Lion Technical Support. Click on the Save button for changes to be saved without activating the interface until you reboot the unit.
This is useful when it is desired to pass traffic to a legacy firewall, or VPN concentrator located behind the Red Lion RTU or router and not to use the firewall or VPN capabilities of the Red Lion RTU or router itself.
Page 242
Advanced Tab Revised 2017-08-31 IP Transparency Drawing No. LP0997-C Enable IP Transparency: Select Yes to enable the IP Transparency feature. Settings will take effect immediately when the Apply button is clicked or after a reboot when Save is clicked. Note: Enabling IP Transparency will negate all configured firewall rules.
Page 243
Only: Allow connections to/from the associated subnet list only. (Inbound and Outbound Restrictions) In: Allow new incoming connections from the associated subnet list only, but allow any originating outbound connections from the host behind the Red Lion RTU or router. (Inbound Restriction) Click on the Add button and the following window appears: ...
Page 244
Advanced Tab Revised 2017-08-31 IP Transparency Drawing No. LP0997-C Enter Subnet (Required): Enter subnet range for which to restrict traffic in the CIDR form nnn.nnn.nnn.nnn/ xx, where nnn is the IP Address and xx is the subnet in Network Bits format. Click on the Finish button to populate the Table Restrictions screen.
Please refer to the third-party device user manual and/or technical support to determine what type of connection is required to connect with the Red Lion RTU or router from the RS-232 serial port. Click on the Out-of-Band Mgt menu item and the following dialog window appears: Click on the Add button to add an instance for OOB Management and the following window appears: Interface: Select the interface to used.
Page 246
Advanced Tab Revised 2017-08-31 Out-of-Band Management Drawing No. LP0997-C Number of Stop Bits: Select the number of stop bits to be used. Consult the configuration of the remote device being attached, this setting must be compatible. Port Number (Required): Enter a valid port number (1-65535) to be used for the connection. Take care to choose a port number not already used by other system services.
Revised 2017-08-31 Advanced Tab Drawing No. LP0997-C VRRP (Virtual Router Redundancy Protocol) 3.7.4 VRRP (Virtual Router Redundancy Protocol) To configure VRRP, select the option from the Advanced menu. The VRRP menu item allows you to configure the capability of providing redundancy capabilities to each other as well as other third party devices.
Page 248
Advanced Tab Revised 2017-08-31 VRRP (Virtual Router Redundancy Protocol) Drawing No. LP0997-C Yes – If you are not using managed switches, this mode will allow remote devices to reconnect faster to the backup unit in the event of an outage. This is because local ARP tables will not need to expire and reacquire different MAC addresses for the shared IP.
Configure Sub‐Systems The “Configure Sub-Systems” menu item allows you to edit the main configuration files of the Red Lion RTU or router. It is not recommended that you perform configuration activities using this facility unless instructed to do so by Red Lion Technical Support.
Page 250
Advanced Tab Revised 2017-08-31 Expert Mode Drawing No. LP0997-C Interface Name will place the name of the interface into the pull-down menus of interface selections to be used by the system. Click on the Predefined Interface Names menu item and the following dialog window appears: Click on the Add button to add a named interface and the following pop-up window appears: Enter (logical) Interface Name (Required): Enter the name of the interface to be used for the logical interface.
Modem using Dialed Number Identification Service (DNIS) method. Click on the Connect Table Configuration menu item and the following dialog window appears: Generic: Please use the recommended setting unless directed to change by Red Lion Technical Support. The recommended setting for this field is No.
Page 252
Answer/Dial Mode: For incoming calls, choose “ANSWER_2WAY_RAW”. For outbound (Ring Out/Ring Down) mode, choose “DIAL”. The other options should only be used if instructed to do so by Red Lion Technical Support. The recommended setting for this field is ANSWER_2WAY_RAW.
Page 253
Revised 2017-08-31 Advanced Tab Drawing No. LP0997-C GWLNX Transparent: Allow raw communication between the Dial port and the TCP Connection. Visa: Enable local Visa I engine. This will process one transaction, and issue an EOT after the transaction response has been sent to the dial device. Visa2: Enable local Visa II engine.
Page 254
2 (STX and ETX bytes). If Payload was 296 bytes, then the 2BL would be 01 2A (in Hex). Allow Early Connect: Only adjust this option if directed by Red Lion Technical Support. The recommended setting for this field is Yes.
Page 255
To revert to the previous defaults, click on the Revert button. Install Configuration The Install Configuration menu item is used to install the new GWLNX configuration on Red Lion RTU or router devices. The Manage Configuration section is used to install or delete GWLNX configuration files that already reside on Red Lion RTU or router devices.
Page 256
Drawing No. LP0997-C Install Application The Install Application menu item is used to install a new GWLNX application on Red Lion RTU or router devices. Click on the Install Application menu item and the following dialog window appears: Click on the upload box or drag and drop your GWLNX installation file on the file upload box to select a GWLNX zip file to upload from your local system.
Page 257
Revised 2017-08-31 Advanced Tab Drawing No. LP0997-C GWLNX Click on the Add button to define IP Destination Settings. Enter Address 1 (Required): This is a Client Primary IP Address that GWLNX uses to connect to the Host Server. Enter Port 1 (Required): This is a Client Primary Port Address that GWLNX uses to connect to the Host Server Port.
Page 258
Advanced Tab Revised 2017-08-31 GWLNX Drawing No. LP0997-C Click on the Finish button and you will be directed to the IP Destinations dialog window and the IP Destinations Table Properties will be populated with the entered data. Click on the Save button for changes to be saved without activating the interface, the Apply button will save your settings and apply them immediately.
Page 259
Revised 2017-08-31 Advanced Tab Drawing No. LP0997-C GWLNX GWLNX Status The GWLNX Status menu item is used to view the GWLNX process ID and has the ability to restart the application by selecting the process ID from the provided drop-down list. The Refresh button will refresh the process ID, if the Gwnlx application has been restarted.
Page 260
Advanced Tab Revised 2017-08-31 GWLNX Drawing No. LP0997-C Gwnlx Log The GWLNX Log menu item is used to view the logfile generated by GWLNX at startup, which provides the state of each port controller defined in the GWLNX configuration file and logs the Send/Receive traffics for each configured port controller.
Revised 2017-08-31 Advanced Tab Drawing No. LP0997-C Classic View 3.7.7 Classic View Classic View is no longer actively supported or maintained as of Version 4.16. Not all features are available in Classic View that are present in the standard interface. ®...
Note: Not all models have the same Events capabilities. Please call Red Lion Technical Support or your local representative for more details. Enable Events: Select YES to enable the Events Control service. If NO is selected, all events will be disabled.
Page 264
Events Revised 2017-08-31 Drawing No. LP0997-C Add Reboot Alert: Click on the Add Reboot Alert button to define parameters for reboot alerts. Send SMS to (Required): SMS Message: Enter a single phone number for the text message destination. Leading access numbers and area codes may be required based on the carrier, location, account type, and roaming status.
Page 265
Revised 2017-08-31 Events Drawing No. LP0997-C Add Data Usage Alert The Data Source value will change depending on the type of Data Source configured for each event. When an Event Expression is used, a series of bits will indicated the True/False status of terms in the Event Expression.
Page 266
Events Revised 2017-08-31 Add Data Usage Alert Drawing No. LP0997-C Click on the Next button. Send SMS to (Required): SMS Message: Enter a single phone number for the text message destination. Leading access numbers and area codes may be required based on your carrier, location, account type, and roaming status.
Page 267
Revised 2017-08-31 Events Drawing No. LP0997-C Configuration The Data Source value will change depending on the type of Data Source configured for each event. When an Event Expression is used, a series of bits will indicated the True/False status of terms in the Event Expression.
Page 268
Events Revised 2017-08-31 Configuration Drawing No. LP0997-C Click on the Add button and the Event Configuration dialog window appears: Event Name (Required): Enter a unique name to describe this event. The value must be alphanumeric with at least one letter, and may not contain spaces or special characters. This field will be used as an operand when building logical Event Expressions.
Page 269
Revised 2017-08-31 Events Drawing No. LP0997-C Configuration The Event Expression is a logical equation built to combine the condition/status of multiple events into a single action. Other events will be referenced by their Event Name. These operands will evaluate those event's condition/status to be a 0 (false/inactive) or 1 (true/active).
Page 270
Events Revised 2017-08-31 Configuration Drawing No. LP0997-C Data Match: The value of the register is equal to the alarm value. Data Mismatch: The value of the register is not equal to the alarm value. Absolute High: The value of the register exceeds the alarms value. Absolute Low: The value of the register falls below the alarms value.
Page 271
Revised 2017-08-31 Events Drawing No. LP0997-C Configuration Deactivation Delay (in sec) (Required): Used to prevent an event from oscillating between the on and off states when the process is near the alarm value. Default value: 0 to disable. Once an event is active and the input condition then falls to an inactive condition, it must remain in the inactive state for this delay period (in seconds) before the alarm will actually be considered inactive.
Page 272
Events Revised 2017-08-31 Configuration Drawing No. LP0997-C Standard + Custom: Append up to a 60 character Custom message to the standard message. The Standard Message will be constructed as follows: EVT<Num>:<Name> <Cond> <Custom> Duration:<Time> DS:<DSValue> <Clear Condition> Where <Num> is the event number. <Name>...
Page 273
Revised 2017-08-31 Events Drawing No. LP0997-C Configuration Level Triggering: Selecting Yes the action to execute as often as specified in the periodic action while the event remains true. Choosing NO indicates level will not be considered when evaluating the Event condition.
Page 274
Events Revised 2017-08-31 Configuration Drawing No. LP0997-C To view existing Tags, click on the View Tags button. This will bring you to the Tags dialog window found in the Automation menu. From this screen, you can add, edit or delete tags. See section 3.6.3 for more information.
Red Lion website. Red Lion tracks the flow of returned material with our SO system to ensure speedy service. You must include this SO number on the outside of the box so that your return can be processed immediately. Be sure to have your original purchase order number and date purchased available.
Page 276
Service and Support Information Revised 2017-08-31 Drawing No. LP0997-C ® ® - 268 - Sixnet Series SN/RAM 6000 & RAM 9000 Software Manual...
Red Lion. Statement of Limited Warranty (a) Red Lion Controls Inc., (the “Company”) warrants that all Products shall be free from defects in material and workmanship under normal use for the period of time provided in “Statement of Warranty Periods” (available at www.redlion.net) current at the time of shipment of the Products (the “Warranty Period”).
The following MIBs are cellular specific. It is to be noted that all of the following can be retrieved on the SN firmware version of Red Lion's RTUs or routers, the A, M, and R Series RTUs or routers are dependent on the cellular module/aircard installed/inserted into the RTU or router.
Page 280
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents Preferred Roaming List, a list of information that resides in the memory of the module/aircard. It lists the radio frequencies the module/aircard can use in various geographic areas. The part of the list for each area is ordered by the bands the module/ aircard should try to use first.
Page 281
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents The vendor-provided model name of the modem/card/module (e.g. modelName DISPLAYSTRING sierra598U). Firmware version of the module/aircard. fwVersion DISPLAYSTRING Cellular Module Firmware version #. Hardware version of the module/aircard. hwVersion DISPLAYSTRING Cellular Module hardware version #. Service provider for cellular network.
Page 282
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents None, Roaming - SIDS Guaranteed, Roaming - SIDS Not Guaranteed. EVDO Roaming state. hdrRoaming DISPLAYSTRING Cellular Roaming indicator - EVDO. 0 or 1. 0 = currently not roaming, 1 = currently roaming. roaming INTEGER32 Cellular current roaming status.
Page 283
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents Pulls CELLMODEM_TEMPERATURE from /var/log/wireless.cardstats temperature DISPLAYSTRING Cellular Module Temp (not available on all modules). Pulls CELLMODEM_SIM_CONT_APN0 from /var/log/wireless.cardstats simContextApn0 DISPLAYSTRING Cellular SIM APN 0. Pulls CELLMODEM_SIM_CONT_APN1 from /var/log/wireless.cardstats simContextApn1 DISPLAYSTRING Cellular SIM APN 1. Pulls CELLMODEM_SIM_STATUS from /var/log/wireless.cardstats simStatus DISPLAYSTRING...
Page 284
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents lteBand DISPLAYSTRING LTE Band lteRxChan DISPLAYSTRING LTE Receive Channel lteTxChan DISPLAYSTRING LTE Transmit Channel lteBW DISPLAYSTRING LTE Bandwidth lteRSRP DISPLAYSTRING LTE Reference Signal Received Power lteRSRQ DISPLAYSTRING LTE Reference Signal Received Quality lteTracAreaCode DISPLAYSTRING LTE Trac Area Code...
Page 285
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents CurrMonthTxWwan0 DISPLAYSTRING Vnstat Current Month Tx for WWAN0 Interface CurrMonthTotalWwan0 DISPLAYSTRING Vnstat Current Month Total Rx/Tx for WWAN0 Interface PreMonthRxWwan0 DISPLAYSTRING Vnstat Previous Month Rx for WWAN0 Interface PreMonthTxWwan0 DISPLAYSTRING Vnstat Previous Month Tx for WWAN0 Interface PreMonthTotalWwan0 DISPLAYSTRING Vnstat Previous Month Total Rx/Tx for WWAN0 Interface...
Page 286
Revised 2017-08-31 Appendix A Drawing No. LP0997-C RED-LION-RAM.MIB Contents todayTxEth1 DISPLAYSTRING Vnstat Today Tx for Eth1 Interface todayTotalEth1 DISPLAYSTRING Vnstat Today Total Rx/Tx for Eth1 Interface yesterdayRxEth1 DISPLAYSTRING Vnstat Yesterday Rx for Eth1 Interface yesterdayTxEth1 DISPLAYSTRING Vnstat Yesterday Tx for Eth1 Interface yesterdayTotalEth1 DISPLAYSTRING Vnstat Yesterday Total Rx/Tx for Eth1 Interface...
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module Appendix B IODB Status Module The IODB status module is a set of IODB registers that are reserved for system use to collect device based information and make that information available to be polled by any head end or SCADA server appliances via Modbus based I/O transfers.
Page 288
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1062 Onboard_VIN1 Input Voltage 1, in mV Often 1063 Onboard_VIN2 Input Voltage 2, in mV Often 1064 Onboard_VBATT Battery voltage, in mV Often 1068 AI_Calibration Reserved; non-zero A non-zero value indicates user during calibration calibration is in progress 1069...
Page 289
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1103 wwan0_YesterdayTX_A UINT32; LSW Sometimes 1104 wwan0_YesterdayTX_B UINT32; MSW Sometimes 1105 wwan0_YesterdayTotal_A UINT32; LSW Sometimes 1106 wwan0_YesterdayTotal_B UINT32; MSW Sometimes 1107 wwan0_ThisMonthRX_A UINT32; LSW Sometimes 1108 wwan0_ThisMonthRX_B UINT32; MSW Sometimes 1109 wwan0_ThisMonthTX_A UINT32;...
Page 290
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1222 GPS_Source Source of data Quickly 0=unknown; 1=internal; 3=user fixed 1223 GPS_Time_HH GPS Time Hours Quickly 1224 GPS_Time_MM GPS Time Minutes Quickly 1225 GPS_Time_SS GPS Time Seconds Quickly Network Identifiers Index Name Description Frequency...
Page 291
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1339 wwan0_DHCP Often 0 = Static IP, 1 = DHCP Assigned IP 1340 wwan0_Link Link Status Often 0 = No Link, 1 = Link detected 1341 br0_IP_a First Octet Often 1342 br0_IP_b Second Octet...
Page 292
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1599 Event99_Status Quickly 1699 Event99_Clear_Condition Quickly Cellular ‐ All cellular points are from cardstats file Index Name Description Frequency Notes 1701 IMEI_a First 4 digits, UINT16 Often 1702 IMEI_b Next 4 digits Often 1703 IMEI_c Next 4 digits Often 1704 IMEI_d...
Page 293
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1735 MEID_B Often MEID should be found by viewing the number in Hex. 1736 MEID_C Often 1737 MEID_D Often 1738 SIM_ID_A UINT 64 - Little Endian; Often SIM_ID = (Reg1738 + (Reg1739 * 2^16) + (Reg1740 * 2^32) + (Reg1741 * 2^48)) 1739...
Page 294
Revised 2017-08-31 Appendix B Drawing No. LP0997-C IODB Status Module 1759 SERVSYS_MCC Mobile Country Code Often 1760 SERVSYS_MNC Mobile Network Code Often 1761 SERVSYS_SYSTEM_ID Serving System ID Often 1762 SERVSYS_SYSTEM_ID Serving System ID Often 1763 SERVSYS_BS_ID Base Station ID Often 1764 SERVSYS_LAC Location Area Code...
Need help?
Do you have a question about the SN-66 series and is the answer not in the manual?
Questions and answers