Asentria SiteBoss 530 User Manual

Asentria SiteBoss 530 User Manual

Remote site manager
Table of Contents

Advertisement

User's Manual
Installation and Operation Guidelines
SiteBoss™ 530 Remote Site Manager
Version 2.05.740
Asentria Corporation
1200 North 96
Street
th
Seattle, Washington,
98103
U.S.A.
Tel: 206.344.8800
Fax: 206.344.2116
www.asentria.com

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SiteBoss 530 and is the answer not in the manual?

Questions and answers

Summary of Contents for Asentria SiteBoss 530

  • Page 1 User’s Manual Installation and Operation Guidelines SiteBoss™ 530 Remote Site Manager Version 2.05.740 Asentria Corporation 1200 North 96 Street Seattle, Washington, 98103 U.S.A. Tel: 206.344.8800 Fax: 206.344.2116 www.asentria.com...
  • Page 2 Examples, data, and names used in this manual are examples and fictitious unless otherwise noted. No part of this document may be reproduced or electronically transmitted without permission from Asentria Corporation. SiteBoss 530, S530, SitePath and EventSensor are trademarks of Asentria Corporation.
  • Page 3: Table Of Contents

    Cables and Power..............................1 Power Requirements ..............................1 Accessing the Command Line via a Serial Connection..................... 3 Accessing the Command Line via the Asentria OmniDiscover program..............3 Network Setup ................................3 via OmniDiscover connection: ........................... 3 via serial connection: ..............................3 Testing Network Connectivity ............................
  • Page 4 Data Alarm Macros ..............................92 Action List .................................. 94 Types of Alarm Notices............................. 96 SNMP Traps ................................96 Email Alarms................................97 Asentria Alarms................................ 97 SMS Alarms ................................100 Pager Alarms ................................. 100 EventSensor Configuration ............................ 101 Contact Closure Setup............................101 Temperature Sensor Setup............................
  • Page 5 Configuration................................125 DSL Routing Example............................126 DSL Glossary ................................126 Battery Module ........................... 128 Setup..................................128 Operation.................................. 128 Appendices..........................129 User Rights Table ..............................129 Control Characters ..............................130 Internal Modem Guidelines............................. 131 Canadian Department of Communications......................132 Warranty Information .............................. 134...
  • Page 7: Quick Start

    Asentria SiteBoss 530 User Manual Quick Start What's Included This chapter is a brief guide to help get your SiteBoss 530 (S530) up and running quickly. Hardware Needed • Asentria SiteBoss 530 • 15VDC power adaptor (Included if AC power option) •...
  • Page 8 Asentria SiteBoss 530 User Manual CONTENTS: Please inventory the package contents and ensure you have the following items pertaining to the -48VDC Power Option: A cable harness consisting of 2 red and 2 blue wires connected to a white nylon “Molex” connector.
  • Page 9: Accessing The Command Line Via A Serial Connection

    Documentation and Utilities CD, download the OmniDiscover program. This program will allow you to locate devices on your network (ie: the S530) with Asentria MAC addresses, and allow you to assign the network settings directly over the network, thus eliminating the need for the serial port connection as described above.
  • Page 10: Testing Network Connectivity

    Asentria SiteBoss 530 User Manual Testing Network Connectivity 1. Verify that the network router is available to the unit by typing the command PING <IP_address>. A router is always a good candidate to test pings on. The following screenshot is an example of a successful ping test.
  • Page 11: What Is A Siteboss 530

    Fig 1: SiteBoss 530 (S530-2 on top, S530-6 on bottom) The SiteBoss 530 is a versatile mid-range system used for monitoring and control of remote equipment sites. The S530 provides remote monitoring of serial devices, equipment I/O, and environmental conditions at these remote sites and forwards notification when conditions fall outside limits.
  • Page 12: Remote Access

    Setup menu, via the TYPE AUDIT command, FTP, or the web interface. Integration with SitePath Using the S530 in conjunction with Asentria’s SitePath Remote Management System, you can create secure and controlled IP access to remote servers and appliances co-located on the same remote network as the S530.
  • Page 13: Leds, Ports, Dip Switches And Buttons

    Asentria SiteBoss 530 User Manual Options Each of the following components is optional and may be installed on a S530: • Additional RJ45 DTE serial I/O ports in sets of 4 to total 6, 10, 14, 18, 22, or 26 ports •...
  • Page 14 The above drawings show both the 2-port model of the S530 which has the new 9-pin Mini DIN SensorJack port for connecting Asentria Type2 EventSensors, and the 6-port model which does not have the Sensor Jack port. You may be using either size of the S530 with or without the SensorJack port. EventSensors connect to S530’s without the SensorJack port via Serial Port 1 set to ESBus Mode.
  • Page 15 * Expansion Card Slots The S530 features two or six Expansion Card slots in which optional Expansion Cards can be installed to expand the capabilities of the S530. Contact Asentria Sales (sales@asentria.com) for more information on Expansion Cards. DIP Switches The bank of 8 DIP switches on the back panel of the S530 are used to control the baud and parity settings of I/O 2, to set the operational mode for I/O 2, and to put the unit into “boot load mode”...
  • Page 16 Asentria SiteBoss 530 User Manual Buttons The only button on the S530 is the Reset button located on the back panel to the left of serial port I/O 2. The Reset button can be used for two different functions: 1) To reset the S530 – press the Reset button for approximately 1 second and S530 will be begin the reboot...
  • Page 17: Getting Connected

    COMPLETE > SiteBoss 530 indicates that this product is the S530, followed by 2.05.740, the currently loaded firmware version. Site Name is the identifier assigned to each S530 by the end user in the General Settings menu. Date and Time display the current date and time.
  • Page 18: Setup Menu

    The Setup menu contains all of the configuration options available on the S530. It is organized in a logical tree structure with all settings classified under the following groups: SiteBoss 530 - Main Setup Menu A) Network Settings B) Serial Settings...
  • Page 19: Web Interface

    Features chapter for more information. Option list The option list type is similar to the toggle type in that it has a list of options to choose from: SiteBoss 530 - Serial Port 2 Baud Rate A) 300 B) 600 C) 1200...
  • Page 20: Network Settings

    Event Sensor Reporting menu where the parameters for using Event Sensor Reporting Settings Event Sensors on other Asentria site monitoring hosts can be configured. displays the SNMP Settings menu where you can configure version of SNMP, community SNMP Settings names, and other SNMP trap settings.
  • Page 21 Asentria SitePath secure, unified administration portal software. displays the Customer Premises Equipment (CPE) Settings menu where up to 64 different CPE Settings networked devices can be configured to communicate with the optional Asentria SitePath secure, unified, administration portal software. Ethernet Settings...
  • Page 22 Open FTP and RTS connections will fail if these settings are changed during an open connection. Name Resolution Settings SiteBoss 530 - Name Resolution Settings A) DNS Server 1 [0.0.0.0] B) DNS Server 2 [0.0.0.0]...
  • Page 23 Asentria SiteBoss 530 User Manual Event Sensor Report To Port sets the TCP Port that a sensor connected to this S530 would use to report to a host S530. Enable EventSensor Reporting Host is an ON/OFF toggle to enable this S530 to be a host for EventSensor reporting from another Asentria device.
  • Page 24 Select Files to Push displays the FTP File Selection menu where you can select which files are pushed by toggling ON or OFF. Default setting for all is ON, except for Audit Log, which is OFF. SiteBoss 530 - FTP File Selection A) Data File 1...
  • Page 25 Asentria SiteBoss 530 User Manual SiteBoss 530 - FTP File Names A) Include Date in Filename [OFF] B) Include Time in Filename [OFF] C) Include Sequence #s in Filename [OFF] D) Data File 1 [FILE1] E) Data File 2 [FILE2]...
  • Page 26 Values are ON or OFF (default OFF). ON means that if FTP Push raised PPP, then it kills PPP when finished. PPP Hosting Settings SiteBoss 530 - PPP Hosting Settings A) PPP Hosting Enabled [OFF] B) Idle Connection Disconnect (sec)
  • Page 27 Default setting is ETH1. Refer to the IP Routing section in the Features chapter for a detailed explanation of IP Routing. Route Test Settings SiteBoss 530 - Route Test Settings A) Route Test Enable [OFF] B) Minutes Between Tests [10]...
  • Page 28 SiteBoss 530 - Real-Time Socket Setup A) FILE1 B) FILE2 C) EVENTS Enter your Selection: a SiteBoss 530 - FILE1 Real-Time Data Socket Setup A) Real-Time Socket Mode [LISTEN] B) Show Answer String on Connection [ON] C) Require Xon to Start Data Flow...
  • Page 29 Refer to the Telnet/TCP Connections section in the Features chapter for a detailed explanation of Real-Time Sockets. SNMP Trap Capture Settings SiteBoss 530 - SNMP Trap Capture Settings A) SNMP Trap Capture Enable [OFF] B) Store Collected Traps In [FILE1] SNMP Trap Capture Enable is an ON/OFF toggle to enable the capturing of SNMPv1 traps and SNMPv2c inform-requests (informs).
  • Page 30 Asentria SiteBoss 530 User Manual Static routes are network routes that specify in a more or less permanent way (static) that traffic to a certain destination (destination host or destination network) gets routed out a certain interface or via a certain gateway.
  • Page 31 C) VPN 2 D) Commissioning Settings Following describes the menu options for configuring VPN Settings. These settings are only for use with the Asentria SitePath secure, unified administration portal software. More information concerning the use of VPNs can be found in VPN chapter in this User Manual, or in the SitePath User Manual.
  • Page 32 Asentria SiteBoss 530 User Manual VPN1 / VPN2 SiteBoss 530 - VPN 1 Settings A) Description B) Start Mode [MANUAL] C) Public Interface [ANY] D) Remote Address E) Remote Network [0.0.0.0/0] F) IPsec Remote Authentication Key G) IPsec Key Lifetime (seconds)
  • Page 33 Following describes the menu options for configuring Customer Premises Equipment (CPE) Settings. These settings are only for use with the Asentria SitePath secure, unified administration portal software and set up is beyond the scope of this manual. Contact Asentria Technical Support for further information.
  • Page 34: Serial Settings

    Asentria SiteBoss 530 User Manual Name sets the name given to the CPE. The only restriction on the name is that it cannot have any single or double quotes ( ' or " ) in it. (Max length is 24 chars) Description sets a description of what the CPE device is.
  • Page 35 RS232 data port. ACCESS READER does not currently set I/O1 to do anything and should not be used. ESBUS configures the port to communicate with external RS485 Asentria EventSensors. (This requires the use of an RS232-RS485 adapter). Default setting is DATA.
  • Page 36 Blank Line Count sets the number of blank lines that must come between records. Default setting is 0. Complex Multiline Detection displays settings for detecting complex multiline records. Default setting is OFF. SiteBoss 530 - Serial Port 1 Complex Multiline Record Settings A) Complex Multiline Record Enable...
  • Page 37: Modem Settings

    B) Wireless Modem The Modem Settings menu displays two sub-menus for configuring either the optional internal 33.6K modem, or an optional wireless modem expansion card. Dialup Modem SiteBoss 530 - Dialup Modem Settings A) Data Format [8N1] B) Duplex [FULL]...
  • Page 38 Asentria SiteBoss 530 User Manual SiteBoss 530 - Caller ID Security A) Enable [OFF] B) Caller ID 1 U) Caller ID 20 V) Add Number From Log List Caller ID must be available on the phone line connected to the S530 for this feature to work.
  • Page 39: Security Settings

    S530. General Security Settings Specific Security Settings – User Profile Security Settings SiteBoss 530 - User Profile Security Settings A) User 1: admin/********/COMMAND/FILE1 B) User 2: C) User 3:...
  • Page 40 S530 responds as follows: Invalid Entry - Confirm Password does not match. Press any key to continue... User Setup Menu SiteBoss 530 - User Setup Menu A) Enable This User Access [ON] B) User Name...
  • Page 41 Asentria SiteBoss 530 User Manual Menu SiteBoss 530 Version 2.05.740 at 530-530000251 1. Pass-Through to I/O 1 2. Pass-Through to I/O 2 P. 530 Command Prompt M. 530 Setup Menu S. 530 Status Menu X. Exit (end connection) Passthrough SiteBoss...
  • Page 42 Asentria SiteBoss 530 User Manual CHALLENGE requires the user send their username/password and then they are prompted with a short challenge code. This S530 does not support this option. SEND PASSWORD will generate a single-use password and send it to the Email address(es) specified by the Send Password To option.
  • Page 43 For a complete description and explanation of RADIUS security, please refer to the RADIUS Security Note: section in the Features chapter. General Security Settings SiteBoss 530 - Global Password/Security Settings Menu A) Show Username/Password Prompt [OFF] B) Globally Allow Access via [MTFRSs]...
  • Page 44: Alarm/Event Definitions

    Refer to the Data Events section in the Features chapter for an example-driven approach to defining Note: alarm definitions. SiteBoss 530 - Alarm/Event Definitions Menu A) Class Table B) Data Alarm/Filter Settings C) EventSensor Device Settings D) No-Data 1 Alarm Settings...
  • Page 45 The class number and name are reported in Asentria Alarms, and SNMP traps. It is a mechanism for you to provide varying severities for different alarms so that you can act on them upon receipt.
  • Page 46 Field Type toggles between Alpha and Numeric. Alpha is used for most alphanumeric data alarming, and Numeric is used if you need to alarm on a range of numbers. Default setting is Alpha. Data Alarm Macro Settings SiteBoss 530 - Data Alarm Macro Settings A) Macro 1 P) Macro 16...
  • Page 47 Asentria SiteBoss 530 User Manual Data Alarm/Filter n Settings SiteBoss 530 - Settings For Data Alarm/Filter 1 A) Alarm/Filter Enable [OFF] B) Alarm/Filter Mode [ALARM] C) Alarm/Filter Name D) Alarm/Filter Equation E) Threshold F) Auto-Clear when Threshold Reached [ON] G) Alarm Counter Clear Interval...
  • Page 48 Internal sensors are those on Expansion Cards that can be installed in the expansion bays on the back of the S530. External sensors are separate devices available from Asentria that are connected to serial I/O 1 (set to ESBUS mode) via an RS232-RS485 ES Bus Adapter. Additionally, the two serial I/O ports on the S530 can also be wired as contact closures.
  • Page 49 Asentria SiteBoss 530 User Manual displays the Sensor Unresponsive Menu where you can configure the actions Sensor Unresponsive Settings the S530 takes if an ES becomes unresponsive. EventSensor Slots SiteBoss 530 - Internal Events Menu A) Device Name [INTERNAL] B) Contact Closure 1 [unnamed]...
  • Page 50 No Data Alarms can be configured on the S530 to monitor data coming in via the serial ports, and take an alarm action if a certain period of time passes with no data. SiteBoss 530 - No-Data Alarm 1 Settings A) Alarm Enable...
  • Page 51 Scheduled Events allow you to schedule specific a specific date/time for an alarm action to occur. For example, you might want the S530 to send you an Email every morning at 8:00 just so you know it is live on the network. SiteBoss 530 - Scheduled Event 1 Setup A) Enable Event [ON]...
  • Page 52 F) Return to Normal Trap Number [511] G) Return to Normal Class [Info] These settings are only for use with Customer Premises Equipment (CPE) managed via the Asentria SitePath secure, unified administration portal software. Contact Asentria Technical Support for further information.
  • Page 53: Action Definitions

    Class Table is displayed, from which you can select one to be assigned to this alarm. Event Message Settings SiteBoss 530 - Event Message Settings A) Include Date and Time [ON] B) Include Site Name [ON]...
  • Page 54 Action List. displays the Action Schedule Settings menu where actions can be limited to defined days and Action Settings times. Pager n Settings Menu SiteBoss 530 - Pager 1 Settings A) Pager Type [NUMERIC] B) Pager Callout Number C) Pager ID...
  • Page 55: General Settings

    Default setting is 120 minutes. Asentria Alarm Version toggles between 1.0 and 1.1 to indicate which type of Asentria Alarm notification will be displayed. Refer to the Asentria Alarms section in the Features chapter for a detailed explanation of Asentria Alarms.
  • Page 56 Asentria SiteBoss 530 User Manual Answer String sets the string that is presented when a user connects to the S530 via Telnet or modem. (Max length 31 chars) Default setting is SiteBoss. Escape Key is the decimal ASCII character code of the key you must press three times to escape from passthrough or other transparent modes.
  • Page 57: Event Log Settings

    - 129.6.15.29 - Gaithersburg, MD Event Log Settings The Event Log is a record of all data events that occur within the S530. SiteBoss 530 - Event Log Settings A) List Events File B) Clear Events File C) Enable Events Log File...
  • Page 58: Audit Log Settings

    The Audit Log is a record of a variety of actions that occur within the S530. Data in this log can be very useful to Asentria Tech Support when troubleshooting problems, or for your own use. SiteBoss 530 - Audit Log Settings...
  • Page 59: Features And How To Use Them

    Asentria SiteBoss 530 User Manual Features and How To Use Them Upgrading the S530 Save the update file (530-x.yy.zzz-std-a71.udf) to a directory on your PC or an FTP server. FTP upgrades can be done in either of two ways: by using the S530’s FTP client to get the update file, or sending the update file from another host to the S530’s FTP server.
  • Page 60: Setting Keys

    Asentria SiteBoss 530 User Manual Setting Keys Setting Keys (SK) provide a flat file, human readable, means of setting and retrieving settings within the unit. Setting Keys are commonly used to clone settings across multiple units or in automated processes.
  • Page 61: Securing A Siteboss 530

    Asentria SiteBoss 530 User Manual Securing a SiteBoss 530 This section discusses all facets of security that must be considered when installing a SiteBoss 530. For adequate security, you must consider the following: • Security mode • SNMP • Telnet/FTP •...
  • Page 62 With the Button Unlock feature, you can regain access to a unit that you have been locked out of. This is meant as an insurance policy against the only other resort to locking yourself out, which is returning the unit to Asentria.
  • Page 63: Telnet/Tcp Connections

    Asentria SiteBoss 530 User Manual Telnet/TCP Connections The S530 provides support for Telnet/TCP connections via two internal Ethernet interfaces. Refer to the Ethernet Settings menu for information on how to configure these. All Telnet connections are TCP connections but not all TCP connections are Telnet connections. A Telnet connection is made to the S530 by using the Telnet protocol and by specifying a TCP port address.
  • Page 64: Vpns

    This section of the Features chapter is a discussion of Virtual Private Networks relating to how the S530 communicates with SitePath, Asentria’s secure, unified administration portal software. For a full description of how SitePath is configured and administered, please refer to the SitePath User Manual and other user documentation that comes with SitePath.
  • Page 65 Asentria SiteBoss 530 User Manual Raising a VPN In SitePath version < 1.01.000, a SitePath user clicked the Connect button in the SitePath web UI in order to initate remote access. The Connect button immediately turned into a Disconnect button (meaning the connection was set up immediately).
  • Page 66: Restricted Trust

    Asentria SiteBoss 530 User Manual Restricted trust Restricted trust (introduced in SitePath 1.01.000 and Omnix Release 2.04.030) is a way of using a unit with SitePath such that the end user does not trust SitePath completely; in other words, the end user maintains full admin privileges over the unit (and SitePath does not have full admin privilege of the unit) and restricts their trust of SitePath.
  • Page 67 Asentria SiteBoss 530 User Manual end user can configure the CPEs (because the CPE settings require master rights to change). Under restrictred trust, SitePath (and its adminsitrator and its users) do not have master rights to a unit. Therefore, this feature solves of the problem of "how to prevent SitePath from unauthorized access to nodes on the end user LAN".
  • Page 68: Vpn Client

    Asentria SiteBoss 530 User Manual VPN Client SSL VPN Client support is where the unit runs OpenVPN version 2.1_rc15 to connect to a an OpenVPN server to form a VPN where SSL/TLS is used for authentication and key exchange. The benefits of using SSL VPN Client are: •...
  • Page 69 Asentria SiteBoss 530 User Manual How do I know the VPN is working? To check the status of the VPN, read the key. It returns one of 3 values: net.vpn[x].status • 0 (which means the VPN is off) • 1 (which means the VPN is trying to start) •...
  • Page 70 Asentria SiteBoss 530 User Manual 2. Some of the things you must transfer using the SSLC command are secret data (the key and the TLS- auth key). "Secret" means that only the unit knows about it (and possibly the server as well, if that is kept in secure location), and if this key is compromised then the security of the entire VPN is compromised.
  • Page 71 Asentria SiteBoss 530 User Manual Example Here is an example OpenVPN server configuration. It discusses what it means for the server and what it means for the unit. To get a better understanding of OpenVPN configuration, consult the documentation at www.openvpn.org.
  • Page 72 Asentria SiteBoss 530 User Manual The "server 10.8.0.0 255.255.255.0" item specifies the addressing method; again this is used only for the server, but impacts the unit in that the unit typically is assigned its address on the VPN from the server.
  • Page 73: Vpn Server

    Asentria SiteBoss 530 User Manual VPN Server SSL VPN Server support is where the unit runs OpenVPN version 2.1_rc15 to listen for a connection from an OpenVPN where SSL/TLS is used for authentication and key exchange. The benefits of using SSL VPN Server are: •...
  • Page 74 Asentria SiteBoss 530 User Manual How does the unit know the VPN client is authentic (and vice versa)? The unit uses certificate-based SSL/TLS security to authenticate the client (and the client uses the same thing to authenticate the unit). Configuring certificates can be done with Setting Keys, but is likely more simple for a user to use the SSLC command on the unit.
  • Page 75 Asentria SiteBoss 530 User Manual I'm paranoid about security, how do I make it as secure as possible? There are three things you can do to improve security with OpenVPN. 1. Add more HMAC authentication using a pre-shared key called a TLS-auth key. This is manipulated with the SSLC command with the "TLS-auth key"...
  • Page 76 Asentria SiteBoss 530 User Manual The "client" item specifies that the server will operate in the mode secured by SSL/TLS. This the only mode the unit supports, so if the server does not use tls-server mode then the unit is incompatible with it. This item also specifies that the client will allow the server to configure addressing information for it.
  • Page 77: Default Router

    Asentria SiteBoss 530 User Manual Default Router The Default Router setting allows you to select the default router (gateway) for the S530. This tells the S530 which router to use if a packet is not on any of the LANs defined on the network port. The default router is selected from the routers defined for the Ethernet ports.
  • Page 78: Static Routes

    Asentria SiteBoss 530 User Manual Static Routes Static routes are network routes that specify in a more or less permanent way (static) that traffic to a certain destination (destination host or destination network) gets routed out a certain interface or via a certain gateway.
  • Page 79: Ip Address Restrictions

    These devices should not be restricted so the function can be completed successfully. The Asentria unit evaluates the list of IP restrictions from top to bottom. When it finds an entry that specifically allows or disallows access, it uses that entry and stops looking. For example, examine the following list: SiteBoss 530 - IP Address Restrictions 1.
  • Page 80: Ip Routing

    Asentria SiteBoss 530 User Manual IP Routing Description When you connect to the S530 via PPP you can make the unit act as a router between you and devices on one of the unit's local networks. This allows you to communicate IP traffic between you and devices you wish to remotely access.
  • Page 81: Snmp Trap Capture

    Asentria SiteBoss 530 User Manual SNMP Trap Capture The S530 can receive and buffer SNMPv1 traps and SNMPv2c inform-requests (informs), collectively referred to here as “notifications”. Each notification can be subjected to data event evaluation, stored in the Event Log, and delivered via normal Event Log delivery.
  • Page 82: Snmp Informs

    Event Log (TYPE EVENTS command, FTP, or setup menu). Setting Key net.trapcap.enable SNMP Informs SNMP Inform requires a SMIv2 MIB. When loaded into an SNMP manager, the Asentria SMIv2 MIBs require an associated MIB called Asentria-Root. Both are available from the Asentria website (www.asentria.com) or Asentria Technical Support.
  • Page 83: Passthrough

    Asentria SiteBoss 530 User Manual Passthrough Passthrough (also known as “Bypass”) is a bi-directional communication link for either a modem or Telnet connection through the S530 to a device attached to a serial port. Passthrough is useful for configuring or maintaining devices connected to the S530 without having to be in the same physical location.
  • Page 84 Asentria SiteBoss 530 User Manual character will not be interpreted as a break. This also allows the client to, within the same passthrough session, load binary data files that may include the break character without unintentionally applying the break condition.
  • Page 85: Call Failure Tracking

    Asentria SiteBoss 530 User Manual Call Failure Tracking Description Call failure tracking is a feature added for A-tick compliance that limits the number of times the S530 calls any one number that doesn't appear to work. Each number dialed is tracked for how many consecutive failures it has racked up.
  • Page 86: Radius Security

    Asentria SiteBoss 530 User Manual RADIUS Security Description RADIUS (Remote Authentication Dial In User Service) is feature is used to offload authentication, authorization, and accounting (AAA) work to a RADIUS server, instead of doing that work on the unit. Prior to the introduction of the RADIUS feature, AAA was done on the unit via the User Profiles settings and the Audit Log, although it was never explicitly called AAA in our documentation up to this point.
  • Page 87 Asentria SiteBoss 530 User Manual The remaining subsections discuss details of each part of AAA. Authentication The RADIUS feature enables the unit to offload (and centralize) user authentication responsibilities to a RADIUS server. The unit does this for the following services in Phase 2 implementation: •...
  • Page 88 • Standard attribute: User-Name (to specify who logged in or logged out) • Vendor-specific attribute: Asentria-Service-Type, which is a string that describes the kind of login session the user started. Limits of support The unit does not support RADIUS Access-Challenge frame (which the RADIUS server can send in response to an Access-Request frame);...
  • Page 89 Access-Accept frames. All authorization data is encapsulated by these vendor-specific attributes in a file called the RADIUS dictionary. The Asentria RADIUS dictionary (named dictionary.asentria) is included on the resource CD that ships with the unit, or can be requested from Asentria Technical Support.
  • Page 90 Asentria SiteBoss 530 User Manual Required by Corresponding User Profiles Attribute Allowed values connection Setting method Asentria-Connect- ON,OFF sec.user[x].connectvia.local Via-Local Asentria-Connect- ON,OFF sec.user[x].connectvia.modem M Via-Modem Asentria-Connect- ON,OFF sec.user[x].connectvia.telnet Via-Telnet Asentria-Connect- ON,OFF sec.user[x].connectvia.ftp Via-FTP Asentria-Connect- ON,OFF sec.user[x].connectvia.rts Via-RTS Asentria-Connect- N/A in phase ON,OFF sec.user[x].connectvia.ssh...
  • Page 91 Asentria SiteBoss 530 User Manual Asentria-File14- DENY, ALLOW sec.user[x].file[14].readaccess FTMLWR Read-Access Asentria-File15- DENY, ALLOW sec.user[x].file[15].readaccess FTMLWR Read-Access Asentria-File16- DENY, ALLOW sec.user[x].file[16].readaccess FTMLWR Read-Access Asentria-Events- DENY, ALLOW sec.user[x].events.readaccess FTMLWR Read-Access Asentria-Audit- DENY, ALLOW sec.user[x].audit.readaccess FTMLWR Read-Access Asentria-File1- DENY, ALLOW sec.user[x].file[1].writeaccess FTMLWR...
  • Page 92 The Asentria-Service-Type attribute is N/A for the last two columns because it does not deal with authorization -- it is used in accounting RADIUS transactions only.
  • Page 93: Benefit

    Asentria SiteBoss 530 User Manual Note that the Asentria-Filex-* and Asentria-Portx-* attributes are required for only however many serial ports on the unit. For example, if you have a unit with only 2 ports, then only Asentria-File1-*, Asentria-File2-*, Asentria-Port1-*, and Asentria-Port2-* attributes are required by that unit for the given connection method.
  • Page 94 Asentria SiteBoss 530 User Manual Then configure RADIUS on the unit according to the Configuration section above, verify the unit can reach the RADIUS server by pinging it, and then log out. Then try logging in to test the RADIUS setup. If you or "bob" cannot log in then you have locked yourself out of the unit.
  • Page 95: Data Events

    Settings", and then "Data Alarm Field Settings". The following menu allows a user to define up to 16 data event fields to be used when scanning for event data. Below is an abbreviated example of this menu: SiteBoss 530 - Data Alarm Field Definition Table Start...
  • Page 96 Asentria SiteBoss 530 User Manual Other Setup Return to the Main Setup Menu, select “Action Definitions”, select “Hostname/IP Address 1” and enter either the hostname or IP address of the SNMP Manager where the trap will be sent. Go to the Serial Setup Menu for serial port I/O 1 (or whichever port incoming data will be monitored) and set the Data Alarm Enable setting to ON.
  • Page 97: Configuring Data Alarm Equations

    Asentria SiteBoss 530 User Manual Configuring Data Alarm Equations The equation is the heart of any data event. The following are a few examples event equations: • alarm_code = "L31" • ext >= "A 600" AND exit_code = "DN" • (alarm_code > "1051" OR exit_code = "1Ow74x") AND switch = " 001.1.9*.**"...
  • Page 98: Data Alarm Macros

    Asentria SiteBoss 530 User Manual Data Alarm Macros Data alarm macros provide a way to define up to 100 equations that can be used in one or more data alarm equations. Each macro consists of an equation and an associated name that can be used to reference the macro in a data alarm equation.
  • Page 99 Asentria SiteBoss 530 User Manual Incoming records 0000001 N 019 00 DN1042 T001034 02/25 09:21 00:00:50 A 5558481677 0000002 N 020 00 DN5280 T001033 02/25 09:22 00:00:08 A 5551377443 0000003 N 021 00 T002014 DN6502 02/25 09:22 00:00:10 0000004 N 022 00 T007002 DN5700...
  • Page 100: Action List

    Action Definitions menu. • Malert: malert(phone# or index) Send an malert (Asentria Alarm via modem); the parameters are the same as for the dispatch keyword. • Modem: modem(phone# or index) Make the unit dial a phone number and start a login session (to the unit's command processor) with the answering machine.
  • Page 101 Send an SMS message to a specific phone number or index which refers to a phone number configured in the Actions Definition menu. • Talert: talert(ipaddress or index) Send a talert (Asentria Alarm via TCP). ° ipaddress is the destination machine; ° index is the IP address configured with action.ip. E.g., action.ip[index].
  • Page 102: Types Of Alarm Notices

    Support). The first trap is a ‘Standard’ SNMP trap. This is the original SNMP trap format supported by Asentria products. In this trap there are two name/value pairs in the trap payload; ‘siteName’ which is the sitename of the device sending the trap and ‘stockTrapString’...
  • Page 103: Email Alarms

    Version 1.1 (default) for TCP An Asentria Alarm sent via TCP is called a Notice. A notice is a piece of data formatted in printable ASCII: a set of lines delimited by CRLF. Each line is of the format <field>: <data>CRLF. The first line has <field> = "ID" (without the quotes).
  • Page 104 VPNG Down Alarm notice Version 1.0 for modem dialout An Asentria Alarm can also be sent over dial-up modem when the Asentria Alarm Version is set to 1.0. Details of this alarm follow: When an Asentria Alarm is initiated, the box dials into the callout number specified by the action. Once connected, it sends a header and waits for a specific response.
  • Page 105 If Require Asentria Alarm ACKs is enabled, the S530 will require a positive CRC mode response or it will disconnect and retry the call. To enable CRC, the receiver must respond with the following after the header is...
  • Page 106: Sms Alarms

    Asentria SiteBoss 530 User Manual SMS Alarms SMS Messaging is only supported with an EDGE wireless modem installed in the S530. Note: SMS alarm messages contain a concatenated alarm string, which follows the format of: Date Time :: SiteName :: Sensor Pod/Bank name...
  • Page 107: Eventsensor Configuration

    Type2 EventSensor devices as described in this section. The setup menus are the same regardless of whether the device is internal or external to the S530. If using external Asentria Type2 EventSensors with the S530, please refer to the Type2 EventSensor User Manual for a full description of each type of sensor and hardware specifications.
  • Page 108: Temperature Sensor Setup

    (drops below the High/Very High settings, or rises above the Low/Very Low settings) can be configured. Very High / High / Low / Very Low Event Settings Setup SiteBoss 530 - External Temperature Event Settings Device Number: 2 Device ID: EST000027...
  • Page 109: Humidity Sensor Setup

    Asentria SiteBoss 530 User Manual Return to Normal Settings Setup SiteBoss 530 - External Temperature Event Settings Device Number: 2 Device ID: EST000027 Device Name: Test ES-T A) Return to Normal Event Actions B) Return to Normal Event Trap Number...
  • Page 110: Analog Voltage / Current Sensor Setup

    High Event Class sets the class for the alarm. When this option is selected, a list of the classes previously defined in Class Table is displayed, from which you can select one to be assigned to this event. Return to Normal Settings Setup SiteBoss 530 - External Humidity Event Settings Device Number: 3 Device ID: ESTH00042 Device Name: Test ES-TH...
  • Page 111 Settings is ON, then there will be a confirmation prompt (Are you sure (y/n)?) displayed before clearing the configured settings. Return to the Sensor Events menu to assign it a new slot, if desired, and reconfigure it. Analog Input n SiteBoss 530 External Analog Input Event 1 Device Number: 5 Device ID: 20020000...
  • Page 112: Relay Output Setup

    Class Table is displayed, from which you can select one to be assigned to this event. Return to Normal Settings SiteBoss 530 External Analog Input Event Settings Device Number: 5 Device ID: ESIO00122 Device Name: Test ES-8V...
  • Page 113 Sensor Events menu (except for Internal Sensors). Return to the Sensor Events menu to assign it a new slot, if desired, and reconfigure it. Relay n SiteBoss 530 - Internal Relay Event 1 A) Relay Name B) Relay Active State [CLOSED] Relay Name is a text-entry field that allows you to name this relay.
  • Page 114: Eventsensor Reporting

    Asentria SiteBoss 530 User Manual EventSensor Reporting EventSensor Reporting (formerly known as Contact Mirroring) is the feature where a unit can transmit/receive EventSensor (ES) data to/from other units. When transmitting, you can select which physical ES’s should report their data, and one IP address to report to. When receiving, you can configure the unit to monitor an ES as if it were attached to the unit with a cable, when it is actually attached to the unit only with a TCP connection.
  • Page 115: Type2 Eventsensorâ„¢ Setup

    The S530 supports up to 16 Type2 EventSensors. Type2 EventSensors are different than the Type1 EventSensors sold by Asentria but support similar and expanded monitoring capabilities. Type2 EventSensors work only with the SiteBoss and TeleBoss line of Asentria products. Data-Link and SNMP-Link products use only the Type1 Event Sensors.
  • Page 116 Asentria SiteBoss 530 User Manual Example calibration procedure for humidity sensor: 1) Place the ES-TH in a controlled-humidity environment along with an accurate humidity reference. 2) Set the humidity to some level toward the low end of the range, like 10-20%, and wait for it to stabilize.
  • Page 117: Relays As Alarm Action

    Asentria SiteBoss 530 User Manual Relays as Alarm Action Relays can be used to open or close part of a circuit of your design or part of another product. You can use the relays on an optional Expansion Card installed in the S530 to control these devices. Relays can be toggled based on sensor readings, data events, or even remotely by SNMP.
  • Page 118: Customizable Command Prompts

    Asentria SiteBoss 530 User Manual Customizable Command Prompts This feature allows the prompt in the command processor to be customized, and includes the ability to embed one or more settings values in the prompt. A customized command prompt can help simplify administration of units, particularly where multiple units are involved.
  • Page 119: Command Reference

    Asentria SiteBoss 530 User Manual Command Reference User Interface Commands Note: The HELP command can give helpful context sensitive information for most commands. Command Summary Syntax Description Disconnect from unit Disconnect a processor session. Exit command EXIT Ends the console session.
  • Page 120: System Commands

    Asentria SiteBoss 530 User Manual System Commands Command Summary Syntax Description COLDSTART Cold boot unit COLDSTART Restores all settings to defaults, deletes all record data, and reboots the unit. Restore factory DEFAULT Resets all settings to factory default DEFAULT defaults...
  • Page 121: Usage Commands

    Asentria SiteBoss 530 User Manual Usage Commands Usage for certain functions (SK, TCPDUMP, TELNET, TRACEROUTE and XF) can be displayed by simply entering the function command without any arguements, as shown below: >SK Usage: sk key[<operator>[value]] | get [x|a][ filter|custom|@] |...
  • Page 122 Asentria SiteBoss 530 User Manual TCPDUMP >TCPDUMP tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on ixp0, link-type EN10MB (Ethernet), capture size 68 bytes <CTRL-C to escape> > TELNET >TELNET BusyBox v1.00 (2009.09.19-20:48+0000) multi-call binary...
  • Page 123: Expansion Card Insertion Procedures

    Asentria SiteBoss 530 User Manual Expansion Card Insertion Procedures The S530 can be purchased with a variety of optional Expansion Cards that are normally inserted in the expansion bays on the back panel of the unit when it is built at the factory. These Cards can also be purchased separately and inserted by field technicians after the unit has been installed in the field.
  • Page 124: Wireless Modem

    Asentria SiteBoss 530 User Manual Wireless Modem The wireless modem Expansion Card supports the same features as connecting directly to the S530 interface, including Telnet, FTP, SSH, and so on. It also supports PPP routing, which allows communication with devices connected to one of the local Ethernet interfaces.
  • Page 125: Setup Menu

    Setup Menu All of the settings above can be accessed in the setup menu at: Modem Setting -> Wireless net.wireless Modem SiteBoss 530 - Wireless Modem Settings A) Mode [OFF] B) APN C) PIN D) Idle Timeout (minutes)
  • Page 126: Status Commands

    Asentria SiteBoss 530 User Manual Status Commands ?W or STATUSW commands display the current status of the wireless connection. (Note that ?WIRE or ?WIRELESS or STATUS WIRELESS are also valid commands.) The unit will respond with: Wireless modem status: <state> Possible states are:...
  • Page 127: Adsl Modem

    Certain Asentria SiteBoss units can have an ADSL modem expansion card installed to provide an interface to a line. The machine on the other end of the line is a DSLAM (Digital Subscriber Line Access Multiplexer). DSLAMs exist typically inside telephone company central offices (COs) but also exist in standalone hutches (remote DSLAMs).
  • Page 128: Activation

    Asentria SiteBoss 530 User Manual Required Settings Regardless of Connection Protocol net.dsl.vpi This specifies the (Virtual Path Identifier) used on the DSL interface. This is provided for you by your DSL provider and is required for DSL operation. Values are: 0 to 4095 net.dsl.vci...
  • Page 129 Asentria SiteBoss 530 User Manual In manual activation the DSL interface will not activate unless some purpose requires it: either you tell it to activate or your ADSL-based VPN, when it is being raised, tells it to activate. If you tell the interface to activate then do this by setting net.dsl.command=1.
  • Page 130: Dsl Status

    Asentria SiteBoss 530 User Manual net.dsl.info.ver.dslhal Read this key to see the ADSL modem DSL HAL version. net.dsl.info.ver.sarhal Read this key to see the ADSL modem SAR HAL version. net.dsl.info.ver.pump Read this key to see the ADSL modem data pump version.
  • Page 131: Dsl Routing

    Asentria SiteBoss 530 User Manual DSL Routing DSL routing is used to make the unit route, and do network address translation (NAT) on, NAT-capable traffic (TCP, UDP, and ICMP) from the unit's Ethernet ports to the unit's DSL peer, and hence on to the Internet. For example, a PC that uses one of the unit's Ethernet addresses as its default router can browse the web via the unit's DSL connection.
  • Page 132: Dsl Routing Example

    Asentria SiteBoss 530 User Manual DSL Routing Example 1) Configure the unit so it sits on an Ethernet network. 2) Enter the following keys to configure the unit for routing: net.dsl.startmode=manual net.default.router=dsl net.dsl.routing.enable=on 3) Say the DSL provider sent you these settings:...
  • Page 133 The value must be valid for that particular Setting Key, and the unit will respond with COMPLETE when it is accepted. If the value is invalid, the unit will respond with Invalid Value. Contact Asentria Tech Support for more information on Setting Keys if necesary.
  • Page 134: Battery Module

    Asentria SiteBoss 530 User Manual Battery Module The SiteBoss 530 is available with an optional battery backup that provides backup power for the unit in the event of power loss. Setup Ensure the front panel battery enable/disable switch is in the 'enable' position. There is no other setup associated with using the battery module, nor are there any settings related to it.
  • Page 135: Appendices

    Asentria SiteBoss 530 User Manual Appendices User Rights Table The following tables contain the rights available to each access level within the user profiles. Command Permissions Command None View Admin1 Admin2 Admin3 Master ADDLF BYPASS COLDSTART DEFAULT DELETE DOALARM DOMAIL...
  • Page 136: Control Characters

    Asentria SiteBoss 530 User Manual Control Characters Some of the following control characters may be used in various functions within the S530, including CRC mode for AsentriaAlarms and the Escape Key. Char Control Key Control Action Null Start of heading...
  • Page 137: Internal Modem Guidelines

    If you experience trouble with the modem, contact Asentria at (206) 344-8800 for information on obtaining service or repairs. The telephone company may ask you to disconnect the device from the network until the problem has been corrected or until you are sure that the device is not malfunctioning.
  • Page 138: Canadian Department Of Communications

    Asentria SiteBoss 530 User Manual Canadian Department of Communications NOTICE: The Canadian Department of Communications Label identifies certified equipment. This certification means that the equipment meets certain telecommunications network protective, operational and safety requirements. The Department does not guarantee the equipment will operate to the user's satisfaction.
  • Page 139 Asentria SiteBoss 530 User Manual L'indice de charge (IC) assigné a chaque dispositif terminal indique, pour éviter toute surcharge, le pourcentage de la charge totale qui peut etre raccodée a un circuit téléphonique bouclé utilisé par ce dispositif. La terminaison du circuit bouclé...
  • Page 140: Warranty Information

    Warranty Information Asentria Corporation hereby warrants that it will, as the buyers sole remedy, repair or replace, at its option, any part of the S530 which proves to be defective by reason of improper materials or workmanship, without charge for parts or labor, for a period of 12 (twelve) months.

Table of Contents