Page 5
10.8. Compliance Federal Communications Commission and Innovation, Science and Eco- nomic Development Canada ....................174 10.9. Warranty ......................... 179 10.10. RipEX2 Availability and service life time ..............179 10.11. RipEX2 maintenance ....................179 A. Abbreviations ..........................181 Index ..............................183 Revision History ..........................
). The ETH/USB contains a built-in DHCP server, so if you have a DHCP client in your PC as most users, you do not need to set anything up. The default IP address of RipEX2 unit, for access over the ETH/USB adapter, is 10.9.8.7.
Section 2.2.9, “HW button”. 1.1. Bench testing Before installing a RipEX2 network in the field, a bench-test should be performed in the lab. The RipEX2 Demo case is great for this as it contains everything necessary: 3× RipEX2 unit, Power supply, dummy load antennas, etc.
2. Product RipEX2 is a radio modem platform renowned for overall data throughput in any real-time environment. RipEX2 radio modems are native IP devices, Software Defined with Linux OS that have been designed with attention to detail, performance and quality.
Page 16
This rugged connector connects to a power supply and it contains control signals. A Plug with screw- terminals and retaining screws for power and control connector is supplied with each RipEX2. It is Tyco 7 pin terminal block plug, part No. 1776192-7, contact pitch 3.81 mm. The connector is designed for electric wires with a cross section of 0.5 to 1.5 mm...
Page 18
The SFP modules listed in Accessories are thoroughly tested by RACOM and are guaranteed to function with RipEX2 units. It is possible to use any other SFP module, but RACOM cannot guarantee they will be completely compatible with RipEX2 units.
Page 19
RipEX2 unit should be DTE (Data Terminal Equipment) and a straight-through cable should be used. If a DCE device is connected to the serial port of RipEX2, a null modem adapter or cross cable has to be used.
Page 20
RxD COM2 TxD COM2 This interface is not compatible with RipEX2-HS. If the RipEX2 unit is installed in the RipEX2-HS (Hot Standby chassis), the DI/DO interface is dedicated for the Hot Standby operation. 2.2.6. USB RipEX2 uses USB 3.0, Host A interface. USB interface is wired as standard: Tab.
Page 21
Product RipEX2 can be equipped with an internal GPS. The GPS module is used for time synchronization of the NTP server inside RipEX2. In this case the AUX connector serves for connecting the GPS antenna: • active antenna • 3.3 VDC supply 2.2.8.
Page 23
Adaptive mode of receiver opera- Cognitive function of receiving mode selection is implemented in tion RipEX2. When exposed in a radio environment where strong inter- fering signals (stronger than -45 dBm) are present, RipEX2 senses them and adaptively increases its resistance to interference (and lowers its sensitivity by 3 dB).
8. Ingress Protection IP52 https://www.racom.eu/eng/products/radio-modem-ripex.html#accessories_mounting 9. Dummy load antenna Dummy load antenna for RipEX2 is used to test the configuration on a desk. It is unsuitable for higher output – use transmitting output of 1.0 W only. https://www.racom.eu/eng/products/radio-modem-ripex.html#accessories https://www.racom.eu/eng/products/radio-modem-ripex.html#accessories_mounting https://www.racom.eu/eng/products/radio-modem-ripex.html#accessories_mounting...
(recommended) or widthwise; in both cases with the RipEX2 lying flat. The choice is made by mounting the clips, one M4 screw per clip. RipEX2 is delivered with two clips, two screws and four threaded holes. Use solely the M4×5 mm screws that are supplied.
Page 31
4.1.4. IP52 mounting RipEX2 unit provides IP41 level of environmental protection. It is possible to reach higher level of pro- tection IP52 (Limited dust ingress protection and protection from water spray < 15 degrees from vertical). To obtain IP5x protection: plug in all connectors and cover unused ports (COM port does not need to be covered) with dust covers from the SET-RipEX2-IP52 Fig.
Use 50 Ω impedance cables only. The shorter the feed line, the better. If RipEX2 is installed close to antenna, the data cable can be re- placed by an Ethernet cable for other protocols utilizing the serial port, see Section 7.1.4, “Terminal servers”.
Ethernet ports The whole radio network build from RipEX2 radio modems behaves as a standard Ethernet bridge. An Ethernet bridge ("Network interface" in RipEX2) automatically learns which devices (MAC addresses) are located in the local LAN and which devices are accessible over the radio channel.
The COM port needs to be Enabled and a Protocol needs to be selected to transfer any data. "Trans- parent" type of COM protocol is dedicated for Bridge mode purposes. This protocol transfers data between the COM port and the RipEX2 network transparently. Any other Protocol can be selected when needed.
Page 37
RipEX2 C and RipEX2 A send the received packet to their COM ports. Packet is addressed to RTU C, so only RTU C responds. RipEX2 A is set as a repeater, so it retransmits the packet on Radio channel. Packet is received by all RipEX2 units. Step 4 RipEX2 B sends repeated packet to its COM.
You can see an example of IP addresses of the SCADA equipment and RipEX2 ETH interfaces in the picture below. In Bridge mode, the IP address of the ETH interface of RipEX2 is not relevant for user data communic- ation. However it is strongly recommended to assign a unique IP address to each RipEX2 Network in- terface, since it allows for easy local as well as remote service access.
RipEX2 in detail 5.2. Router mode RipEX2 works as a standard IP router with multiple independent interfaces: Radio and Ethernets. Each interface has its own MAC address, IP address and mask. IP packets are processed according to routing table rules. You can also set the router’s default gateway (applies to both interfaces) in the routing table.
Page 40
As already mentioned, RipEX2 works as a standard IP router with multiple independent interfaces: Radio and Ethernets. Each interface has its own MAC address, IP address and mask. When Base driven protocol is used, Radio IP addresses for all RipEX2 units must share the same IP subnet.
CSMA and TDMA; the Radio channel is deemed to be free when there is no noise, no interfering signals and no frames being transmitted by other RipEX2 stations. In this situation, a random selection of time slots follows and a frame is then transmitted on the Radio channel.
Page 43
RipEX2 1 receives this packet, checks data integrity and transmits the acknowledgement. At the same time packet is sent to RTU1 through COM. RipEX2 3 receives this packet too. It doesn’t react, because this packet is directed to RipEX2 1 only. Step 3 RipEX2 2 waits untill previous transaction on Radio channel is finished (anti-collision mechanism).
Page 44
Ethernet port. This helps to keep the routing tables clear and simple. Note Even if the IP addresses of all RipEX2 units in a radio channel share a single IP network, they may not be communicating directly as in a common IP network. Only the RipEX2 units that are within the radio range of each other can communicate directly.
Page 45
• Based on this record, all packets with addresses in the range from 192.168.2.1 to 192.168.2.254 are routed to 10.10.10.1 • Because RipEX2 50’s radio IP is 10.10.10.50/24, the router can tell that the IP 10.10.10.1 belongs to the radio channel and sends the packet to that address over the radio channel •...
5.3.1. Detailed Description Generally, a Terminal server (also referred to as Serial server) enables connection of devices with a serial interface to a RipEX2 over the local area network (LAN). It is a virtual substitute for the devices used as serial-to-TCP(UDP) converters.
Page 47
Terminal server in RipEX2. User data are extracted from the TCP messages and processed as if it came from a COM port. When the data reaches the destination RipEX2, it can be transferred to the RTU either via the serial interface or via TCP (UDP), using the Terminal server again.
(via LAN) or a high-speed WAN (e.g. Internet). The RipEX2 which you are logged-in to in this way is called Local. Then you can manage any remote RipEX2 in the network over-the-air in a throughput-saving way: all the static data (e.g. Web page graphic objects) is downloaded from the Local RipEX2 and only information specific to the remote unit is transferred over the Radio channel.
Page 49
Web interface The login page informs you about the Unit name and IP address of the RipEX2 unit you are trying to log in. The login page allows changing of the language of the whole web interface (English language is default).
• Discard all changes via Reset All 6.3. Notifications With RipEX2 new way of showing important system events to the user is introduced. It is called Notific- ation Centre and is used consistently throughout the interface. Notification Centre is located on the top right corner of the interface.
RipEX2 network). RipEX2 local unit must have the highest firmware version in the whole network to ensure proper Remote access functionality. Nevertheless it is recommended to keep the same version of firmware in the whole network.
Page 54
Web interface The IP address of the actually connected RipEX2 unit is displayed as part of the Remote access button. All the configuration settings are remotely available using standard web interface. Some of the Diagnostic features are available via local connection only.
7.1. Interfaces 7.1.1. Ethernet RipEX2 provides 5 physical Ethernet ports ETH1, ETH2, ETH3, ETH4 and ETH5. First 4 ETH ports are metallic, the 5th port is a SFP port. There is a possibility to define an Ethernet bridge - a logical Network interface - by bridging (joining) together multiple physical Ethernet interfaces.
(e.g. when a repeater receives a packet from another repeater) or duplicate packets delivered to the user interface (e.g. when RipEX2 receives a packet directly and then from a repeater). Transparent protocol does not solve collisions on the radio channel protocol. There is a CRC check of data integrity, however, i.e.
Page 59
MUST be set in all units in the network, including the Repeater units themselves. After transmitting to or receiving from the Radio channel, further transmission (from this RipEX2) is blocked for a period calculated to prevent collision with a frame transmitted by a Repeater. Furthermore, a copy of every frame transmitted to or received from the Radio channel is stored (for a period).
Settings slave RipEX2. The length of responding frame, the length of Radio protocol overhead, modulation rate have to be taken into account. 7.1.2.2. Base driven protocol (Router mode) Router mode with Base driven protocol (BDP) is suitable for a star network topology with up to 256 Remotes under one Base station.
List box {On, Off}, default On 7.1.2.3. Flexible Protocol (router mode) RipEX2 works as a standard IP router with 2 independent interfaces: Radio and ETH. Each interface has its own MAC address, IP address and mask. IP packets are processed according to routing table rules. You can also set the router’s default gateway (applies to both interfaces) in the routing table.
Such UDP frames received by the RipEX2 unit from the RipEX2 network (based on the unit IP address and UDP port of the Protocol module) are translated into original frame format (by the Protocol module) and send out through the COM port.
RTS/CTS (Request To Send / Clear To Send) hardware flow control (handshake) between the DTE (Data Terminal Equipment) and RipEX2 (DCE - Data Communications Equipment) can be enabled in order to pause and resume the transmission of data. If RX buffer of RipEX2 is full, the CTS goes down.
Page 68
UDP ports for COM or Terminal servers can be used or UDP port can be set manually. If the destination IP address belongs to a RipEX2 and the UDP port is not assigned to COM or to a Terminal server or to any other special SW module running in the destination RipEX2, the packet is discarded.
The None protocol switches the COM port off. All incomming data will be thown away, No data will be send into the COM interface. 7.1.3.3.2. Transparent protocol Operates in Bridge mode only. All the traffic is bridged transparently to RipEX2 network (see Section 5.1, “Bridge mode” for details). 7.1.3.3.3. Async link Async link creates an asynchronous link between two COM ports on different RipEX2 units.
Each frame in the DNP3 protocol contains the source and destination addresses in its header, so there is no difference between Master and Slave in terms of the RipEX2 configuration. The DNP3 allows both Master-Slave polling as well as spontaneous communication from the remote units.
7.1.3.3.5. DF1 Each frame in the Allen-Bradley DF1 protocol contains the source and destination addresses in its header, so there is no difference between Master and Slave in the Full duplex mode in terms of RipEX2 configuration. • Connected service mode...
7.1.4. Terminal servers Generally, a Terminal Server (also referred to as a Serial Server) enables connection of devices with serial interface to a RipEX2 over the local area network (LAN). It is a virtual substitute for devices used as serial-to-TCP(UDP) converters.
Up to 5 independent Terminal servers can be set up. Each one can be either TCP or UDP Type, TCP Inactivity is the timeout in seconds for which the TCP socket in RipEX2 is kept active after the last data reception or transmission. As source IP address of a Terminal server will be used the IP address of the RipEX2 ETH interface (Local preferred source address if exists see Section 7.2.1, “...
OSPF and BGP standard routing protocols are available in RipEX networks. 7.2.1. Static RipEX2 works as a standard IP router with multiple independent interfaces: Radio interface, Network interfaces (bridging physical Ethernet interfaces), COM ports, Terminal servers, optional Cellular interface etc.
Page 85
Switches the rule on / off • Destination IP / mask Each IP packet, received by RipEX2 through any interface (Radio, ETH, COM, ...), has got a destin- ation IP address. RipEX2 (router) forwards the received packet either directly to the destination IP address or to the respective Gateway, according to the Routing table.
Local preferred source address: (Routing_LocalUseSrcAddr) Local IP address used as a source address for packets originating in the local RipEX2 unit being routed by this routing rule. It might be for example packets originating from the COM port or from the Terminal Server. If the address is set to 0.0.0.0 it is not considered active.
• Connection state New list box {Off, On}, default Off - active only for TCP protocol Relates to the first packet when a TCP connection starts (Request from TCP client to TCP server for opening a new TCP connection). Used e.g. for allowing to open TCP only from RipEX2 network to outside.
L3 Firewall settings do not impact packets received and redirected from/to Radio channel. The problem described in NOTE 2 will not happen, if the affected RipEX2 router is a radio repeater, i.e. when it uses solely the radio channel for input and output.
Page 105
NAT-T (NAT Traversal) or MOBIKE (MOBile IKE) are active, the UDP port 4500 is used instead. Note NAT-T is automatically recognized by IPsec implementation in RipEX2. The IPsec tunnel is provided by Security Association (SA). There are 2 types of SA: •...
Page 108
The PFS (Perfect Forward Secrecy) feature is performed using the Diffie-Hellman group method. PFS increases IKE SA key exchange security. The RipEX2 unit load is seriously affected when key exchange is in process. The "legacy" marked methods are recognized as unsafe. Peer configuration must match.
Page 109
The PFS (Perfect Forward Secrecy) feature is performed using the Diffie-Hellman group method. PFS increases IKE CHILD SA key exchange security. The RipEX2 unit load is seriously affected when key exchange is in process. The "legacy" marked methods are recognized as unsafe.
7.6.5. SW keys Certain RipEX2 features needs to be activated by a SW key to be available. When the respective SW key is not present, the feature can not be configured. If the feature is enabled in a configuration backup file and the file is loaded to a unit which is not equipped with the respective key, the configuration is refused (no changes are made in the unit).
– depending on the connection speed between the management PC and the RipEX2 unit. In case of slow connection and file transfer longer than 120 s, the web browser will shut down the connection and the action will not finish successfully. This action does not update the running unit firmware yet.
It is possible to change severities of individual events in the menu SETTINGS/Device/Events. 8.3. Statistics RipEX2 unit permanently monitors various system 'channels'. There are several types of those channels: Physical interfaces (Ethernet ports, serial ports, radio interface, additional module interface (e.g. LTE module) when installed), virtual interfaces (e.g.
Page 138
Terminal Server) and vice versa. When an external interface (e.g. Interface COM) is monitored, the Tx also means packets being transmitted from the RipEX2 over the respective interface (Rx means "received"). Understanding the directions over the internal interfaces may not be that straightforward, please consult Fig.
Page 140
When Promiscuous mode is enabled, the unit is capable to monitor (receive) frames from the other RipEX2 units even if the other unit(s) is(are) working in the other Unit mode (Bridge versus Router). Frames transmitted under another Unit mode may not be properly 'analyzed'. In such a case frames are displayed in raw data format.
Page 148
Case opening evidence When full-duplex with full power (40 dBm PEP) and the surrounding temperature above + 60°C the external passive cooler shall be used (e.g. installation in RipEX2-RS chassis Will be available in further FW release. Diagnostic and Management...
10.0 10.3. High temperature If the RipEX2 is operated in an environment where the ambient temperature exceeds 55 °C, the RipEX2 must be installed within a restricted access location to prevent human contact with the enclosure heatsink. 10.4. Battery disposal Battery Disposal - This product may contain a battery (e.g.
Everyone can copy and spread word-for-word copies of this license, but any change is not permitted. The program (binary version) is available for free on the contacts listed on https://www.racom.eu. This product contains open source or another software originating from third parties subject to GNU General Public License (GPL), GNU Library / Lesser General Public License (LGPL) and / or further author li- censes, declarations of responsibility exclusion and notifications.
• any requirements for authorisation of use. Fig. 10.2: EU restrictions or requirements The RipEX2 radio modem predominantly operates within frequency bands that require a site license be issued by the radio regulatory authority with jurisdiction over the territory in which the equipment is being operated.
С настоящото RACOM s.r.o. декларира, че този тип радиосъоръжение RipEX2 е в съответствие с Директива 2014/53/ЕС. Por la presente, RACOM s.r.o. declara que el tipo de equipo radioeléctrico RipEX2 es conforme con la Directiva 2014/53/UE. Tímto RACOM s.r.o. prohlašuje, že typ rádiového zařízení RipEX2 je v souladu se směrnicí 2014/53/EU.
Page 173
Με την παρούσα ο/η RACOM s.r.o., δηλώνει ότι ο ραδιοεξοπλισμός RipEX2 πληροί την οδηγία 2014/53/ΕΕ. Hereby, RACOM s.r.o. declares that the radio equipment type RipEX2 is in compliance with Directive 2014/53/EU. Le soussigné, RACOM s.r.o., déclare que l'équipement radioélectrique du type RipEX2 est conforme à...
Safety, regulations, warranty RACOM s.r.o. týmto vyhlasuje, že rádiové zariadenie typu RipEX2 je v súlade so smernicou 2014/53/EÚ. RACOM s.r.o. potrjuje, da je tip radijske opreme RipEX2 skladen z Direktivo 2014/53/EU. RACOM s.r.o. vakuuttaa, että radiolaitetyyppi RipEX2 on direktiivin 2014/53/EU mukainen.
The serviced equipment shall be returned by RACOM to the customer by prepaid freight. If circumstances do not permit the equipment to be returned to RACOM, then the customer is liable and agrees to reim- burse RACOM for expenses incurred by RACOM during servicing the equipment on site. When equipment does not qualify for servicing under warranty, RACOM shall charge the customer and be reimbursed for costs incurred for parts and labour at prevailing rates.