EasyManua.ls Logo

Alstom DS Agile C26 Series - User Manual

Alstom DS Agile C26 Series
12 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Loading...
DS Agile C26x
Addendum to Technical Manual
System version: from 5.1.0 to 5.1.7
C26x/EN M/C67
Question and Answer IconNeed help?

Do you have a question about the Alstom DS Agile C26 Series and is the answer not in the manual?

Summary

Introduction to Firewall Usage

Firewall Usage Requirements

Firewall Configuration via SCE

Configure the Firewall usage in SCE. Parameter can be set to Yes (Enabled) or No (Disabled).

SCS Level Firewall Settings

SCS level sets the value of attributes Firewall Usage, defining access rights and system parameters.

Computer Level IP Configuration

Computer level defines IP addresses for Sbus (ETH1) and Maintenance (ETH2) ports for network configuration.

Network Separation: SBUS and Maintenance Access

Details network separation requirements for SBUS and maintenance access points using firewall functionality.

Firewall Enabled: SBUS and Maintenance Access

When Firewall is enabled, SBUS network is managed by Eth1. Maintenance features are available on Eth2 or Eth1 depending on boot mode.

Firewall Disabled: SBUS and Maintenance Access

When Firewall is disabled, SBUS network is managed by Eth1, and maintenance access is allowed on both Eth1 and Eth2.

Usage Limits and Constraints

Firmware Upgrade Procedures

Firmware upgrade commands must start in Bootrom boot on Eth1, including Update BootRom, Flash Format, and BootInstall.

Overview

The DS Agile C26x is a device that provides network separation and enhances security by enforcing firewall usage. This addendum to the technical manual covers system versions from 5.1.0 to 5.1.7 and provides instructions for installation, commissioning, and operation of the DS Agile C26x. It is crucial to refer to the System Release Notes for new features and to contact Alstom technical sales office for any questions or specific problems, as the guide cannot cover all conceivable circumstances or include detailed information on all topics. Any agreements, commitments, legal relationships, and obligations on the part of Alstom, including settlement of warranties, result solely from the applicable purchase contract and are not affected by the contents of this guide.

Function Description:

The primary function of the DS Agile C26x is to implement network separation through firewall usage, thereby enhancing security and reducing the risk of intrusions. This device utilizes configuration settings within the System Configuration Editor (SCE) to manage the firewall function. The network separation is specifically applied between the Eth 1 Sbus network and the Eth 2 Maintenance access network.

The firewall usage function is activated under specific conditions:

  • The firewall function must be enabled in the configured database.
  • The configured database with the enabled firewall function must be set as the current database.

If there is no operational database on the C26x BCU, the firewall function is disabled.

Important Technical Specifications:

The C26x BCU requires specific network configurations for the firewall usage function:

  • IP Addresses: Different subnet IP addresses must be used on Eth1 and Eth2. The default subnet mask is 255.255.255.0.
  • Operational Database: An operational database is essential for the firewall function to be active.

Configuration Levels:

The firewall usage is configured at two levels within the SCE:

  1. SCS Level: At the SCS (Substation Control System) level, the Firewall Usage attribute can be set to either Yes (Enabled) or No (Disabled). This setting determines the overall firewall status for the system.

  2. Computer Level: The computer level defines the IP addresses for the Sbus port (Eth1) and the Maintenance port (Eth2).

    • TCP/IP Address (Eth 1): Configured for the Sbus network.
    • TCP/IP Address (Eth 2): Configured for the Maintenance access network.

It is critical that the IP addresses for Eth1 and Eth2 are set in different subnets via the CMT (Configuration Management Tool). The configured IP addresses must match those of the C26x BCU.

Network Separation SBUS and Maintenance Access Point:

The DS Agile C26x manages network separation between the SBUS and Maintenance Access Point based on the firewall usage setting:

  • Firewall Usage Set to YES (Enabled):

    • The SBUS network is managed exclusively by Eth1.
    • When the C26x BCU starts in Network Boot / Flash Boot mode, maintenance application features are only available on Eth2.
    • When the C26x BCU starts in Bootrom boot mode, maintenance application features are only available on Eth1.
  • Firewall Usage Set to NO (Disabled):

    • The SBUS network is managed exclusively by Eth1.
    • Maintenance access is allowed on both Eth1 and Eth2.

Maintenance Features:

The CMT tool is used for several maintenance-related configurations:

  • Configuring different IP addresses on Eth1 and Eth2.
  • Defining the host IP.
  • Enabling/disabling individual tools of the Maintenance applications, depending on whether the Firewall is enabled or disabled.

Host IP Address during Software Upgrade Phase:

The host IP address provides the C26x BCU with the IP address of the PC containing the C26x software. Software upgrades are only available from Eth1. The host IP address must be defined within the sub-network of Eth1.

Host IP Address during Operational Phase:

The host IP address provides the C26x BCU with the IP address of the PC from which to retrieve settings. This address must be set to the IP address of the PC supporting Micom S1 in the sub-network of Eth2.

Limitations:

The firewall usage function has specific limitations:

  • Forbidden Architectures: Firewall usage is forbidden when the C26x BCU is used in:
    • Multirack mode
    • RTU mode
    • PBus mode
  • Configuration Mode: The firewall is only configurable in Off-line mode through the SCE.
  • SCE Application: The SCE applies the Firewall Usage settings to all C26x BCUs configured in the database.
  • Reboot Requirement: When the C26x maintenance IP address is changed, the computer must be rebooted, which interrupts the service on the SBUS network for 60 seconds.
  • Database Reload: If the C26x SBUS IP address is changed, reloading the database is required.
  • T104 Gateway Usage: If the C26x BCU with firewall usage is employed as a T104 gateway, the Eth1 port must be used for SCADA connection.

Firmware Upgrade:

Commands for firmware upgrades must initiate in Bootrom boot on Eth1. These commands include:

  • Update BootRom
  • Flash Format
  • BootInstall

Alstom DS Agile C26 Series Specifications

General IconGeneral
BrandAlstom
ModelDS Agile C26 Series
CategoryControl Systems
LanguageEnglish