Network Management System Industrial HiVision 8.2. User Manual (2021) - page 1

 

  Index      Manuals     Network Management System Industrial HiVision 8.2. User Manual (2021)

 

Search            copyright infringement  

 

 

 

 

 

 

 

 

 

 

 

Content      ..      1       2         ..

 

 

 

Network Management System Industrial HiVision 8.2. User Manual (2021) - page 1

 

 

Contents
Contents
1
The Management Tool
13
1.1
Integration of third-party devices
14
1.2
Enhanced auto-topology discovery
15
1.3
MultiConfig™ for network installation
16
1.4
MultiConfig™ for live operation
17
1.5
Engineered through experience
18
1.6
30 days free trial
19
1.7
Third Party Libraries
20
2
Software Overview
23
2.1
System Requirements
24
2.2
Installation
25
2.2.1
Downloading the Industrial HiVision software
27
2.2.2
Installation under Windows
28
2.2.3
Installation under Linux
30
2.3
Update
33
2.3.1
Updating under Windows
33
2.3.2
Updating under Linux
34
2.4
Maintenance
35
2.5
Starting
36
2.5.1
Starting under Windows
36
2.5.2
Starting under Linux
37
2.6
Deinstallation
39
2.6.1
Deinstallation under Windows
39
2.6.2
Deinstallation under Linux
39
3
Contents
3
Preparation
41
3.1
Improving the security of Industrial HiVision
42
3.1.1
Physical protection
43
3.1.2
Measures before and during the installation of
Industrial HiVision
43
3.1.3
Industrial HiVision configuration actions
46
3.1.4
Restrict File Access
51
3.2
Outside the program
52
3.3
Network structure
53
3.3.1
Advantages of the hierarchical network structure
53
3.3.2
Application Example
54
3.3.3
Configuration of the application example
56
3.3.4
Status display of the subdomains
58
3.4
Program default settings
59
3.5
Using Industrial HiVision with Firewalls
62
3.6
Fingerprint verification
65
4
Interface of the program
71
4.1
Main window of Industrial HiVision
72
4.2
Menu bar
74
4.2.1
File
75
4.2.2
Edit
76
4.2.3
View
77
4.2.4
Configuration
78
4.2.5
Tools
81
4.2.6
Help
82
4.3
Tool bar
83
4.3.1
Edit Mode
84
4.3.2
Preferences
88
4.4
Event line
89
4.4.1
Number of events
90
4.4.2
Types of events
91
4.4.3
Acknowledge events
92
4.4.4
Properties of an event
93
4
Contents
4.5
Folder frame
94
4.6
Navigation field
96
4.7
Detail display
97
4.7.1
Map
97
4.7.2
List
98
4.7.3
Devices
100
4.7.4
Ports
102
4.7.5
Connections
104
4.7.6
Properties
106
4.7.7
Security Status
107
4.7.8
PoE
108
4.8
Event list
112
4.8.1
Event History
114
4.9
To navigate with the Keyboard
119
4.9.1
Navigating in a table
119
4.9.2
Changing the frame
119
5
Creating a network plan
121
5.1
Device detection
122
5.1.1
Device Icons
125
5.1.2
HiProvision
125
5.2
Assigning device icons
128
5.3
Device arrangement
130
5.3.1
Creating a network plan
130
5.3.2
Moving devices into the network plan
131
5.3.3
Creating new devices
132
5.3.4
Arrange devices in the detail display
133
5.3.5
Naming devices and ports
134
5.3.6
Copying devices
134
5.3.7
Paste as new Network
135
5.3.8
Devices with multiple IP addresses
138
5.3.9
Creating a link
139
5.4
Device connection
140
5.4.1
Automatically displaying the topology
140
5.4.2
Connecting devices manually
141
5
Contents
5.4.3
Reshaping a connection line
141
5.4.4
Specifying the line thickness
142
5.4.5
Other connections
143
5.4.6
Detecting a link to another folder
143
5.4.7
Specifying connection properties
144
5.4.8
Link types
145
5.4.9
Representation of the connection medium
146
5.5
The Network changing over time
147
5.5.1
Adding devices with HiDiscovery V1
147
5.5.2
Adding devices with network scan
148
5.5.3
Adding devices manually
148
5.5.4
Startup procedure for Hirschmann devices
149
5.5.5
Interrupting device monitoring
149
5.5.6
Removing devices
150
5.5.7
Exchanging devices
150
5.6
Network Documentation
152
5.6.1
Saving Industrial HiVision projects
152
5.6.2
Saving reporting data
152
5.6.3
Exporting the content of the detail display
153
5.6.4
Printing the content of the detail display
153
5.6.5
Exporting the event list
153
5.6.6
Printing the event list
154
5.6.7
Creating device documentation
154
5.6.8
Printing or exporting the status configuration
155
5.6.9
Agent
155
6
Configuring the network
157
6.1
Using the dialog box
159
6.1.1
Description of the menu tree
160
6.1.2
Description of the object frame
160
6.1.3
Description of the function frame
161
6.1.4
Description of the control elements
163
6.2
Examples for using the MultiConfig™
164
6.2.1
Same contact person on multiple devices
164
6.2.2
Software update on similar devices
166
6.2.3
Restarting multiple devices
167
6
Contents
6.2.4
Loading/saving the configuration for multiple devices
168
6.2.5
Configuring a trap destination on multiple devices
170
6.2.6
Make firewall rules on multiple devices
170
6.2.7
Configuring the Industrial HiVision property
173
6.2.8
Saving reference values for each device
174
6.2.9
Password synchronization
174
6.2.10 MultiConfig™ Search Function
175
6.2.11 MultiConfig™User Management
176
6.2.12 MultiConfig™ Time Sensitive Networking
180
6.2.13 Configure polling of device properties
189
7
Monitoring the network
193
7.1
Improving security on the network
194
7.1.1
Password-protecting devices on your network
194
7.1.2
Password change during first time log on
195
7.1.3
Security status view and configuration
198
7.1.4
Security-related settings of devices on the network
202
7.1.5
Configuring security-relevant settings on the network
204
7.2
Status configuration
208
7.3
Status determination
209
7.3.1
Trap destination address
210
7.3.2
Updating device status
210
7.4
Status propagation
211
7.5
Management actions
213
7.5.1
Event actions
213
7.5.2
Time-linked actions
214
7.5.3
Industrial HiVision “I'm alive” event
214
7.6
Time-related recordings
215
7.6.1
History
215
7.6.2
Reports
216
7.7
User-defined properties
219
7.7.1
Description of user-defined properties
219
7.7.2
Application example for user-defined properties
219
7
Contents
7.8
Effect on system resources
222
7.8.1
Detecting utilization of system resources
223
7.8.2
Influencing utilization of system resources
224
7.8.3
Minimizing polling
225
7.8.4
Minimizing network load
226
7.9
Process visualization systems
227
7.9.1
Link to process visualization system
227
7.9.2
Structure of the transfer data for OPC
229
7.9.3
Connection as ActiveX control element
232
7.9.4
Supported applications for ActiveX
233
7.9.5
Supported applications OPC DA
233
7.9.6
Supported applications OPC UA
233
7.9.7
OPC UA Connection Example
234
7.9.8
OPC UA Server Custom Certificates
236
7.10
Remote access to Industrial HiVision
239
7.10.1 Web access to Industrial HiVision
239
7.10.2 App access to Industrial HiVision
242
7.10.3 Certificate for the HTTPS connection
245
7.11
Interface to InfluxDB® and Grafana®
248
7.11.1 Configure InfluxDB® and Grafana®
248
7.11.2 Import the Grafana® dashboard templates
251
7.11.3 Security
252
8
References
253
8.1
File
254
8.1.1
New Project
255
8.1.2
New
255
8.1.3
Login
257
8.1.4
Open...
257
8.1.5
Save
257
8.1.6
Save as...
258
8.1.7
Save Backup
258
8.1.8
Load Backup
259
8.1.9
Export...
260
8.1.10 Export Events...
260
8.1.11 Print
261
8
Contents
8.1.12
Print Events
261
8.1.13
Exit and Stop Service
261
8.1.14
Exit
262
8.2
Edit
263
8.2.1
Undo
263
8.2.2
Redo
263
8.2.3
Edit Mode
263
8.2.4
Switch to the free version
264
8.2.5
Cut
264
8.2.6
Copy
265
8.2.7
Paste
265
8.2.8
Paste as Link
265
8.2.9
Delete
266
8.2.10
Rename
266
8.2.11
Select All
266
8.2.12
Acknowledge Status Change
266
8.2.13
Manage
267
8.2.14
Unmanage
267
8.2.15
Set Device and Port Names
267
8.2.16
Set Default Device Icon
268
8.2.17
Device Documentation
268
8.2.18
Drawing Size
268
8.2.19
Background Image
269
8.2.20
Find...
270
8.2.21
Auto Topology...
271
8.2.22
Auto Layout
275
8.2.23
Properties of a folder/device
276
8.2.24
Properties of a component detail
283
8.2.25
Properties of a connection
290
8.2.26
Adding a component detail to a port
292
8.2.27
Add to reporting
293
8.2.28
Device and Port Signaling
295
8.3
View
297
8.3.1
Select VLAN
297
8.3.2
Refresh VLANs
297
8.3.3
Protocol Statistics
298
9
Contents
8.3.4
Filter Events for Object
299
8.3.5
Back
300
8.3.6
Forward
301
8.3.7
Up
301
8.3.8
Home View
301
8.3.9
Set Home View Settings
302
8.3.10 Geographical Location View
302
8.3.11 Zoom
303
8.4
Configuration
304
8.4.1
Monitor
304
8.4.2
PSM Manager
306
8.4.3
Reporting
307
8.4.4
Export to InfluxDB®
311
8.4.5
Scheduler
312
8.4.6
Preferences
319
8.5
Status Configuration
403
8.6
Scan Ranges
405
8.7
User defined Properties
407
8.7.1
Creating a new user-defined property
407
8.8
MultiConfig™
409
8.8.1
Power Limit
409
8.9
MAC/IP List
411
8.9.1
MAC/IP Addresses
411
8.9.2
MAC/IP Address Pair Security
412
8.10
Refresh
413
8.11
IP Configuration
414
8.12
Trap Destination
416
8.13
Tools
418
8.13.1 Dashboard
418
8.13.2 Web Interface
435
8.13.3 Device Configuration
436
8.13.4 CLI
437
8.13.5 SNMP Browser
438
8.13.6 Ping
438
8.13.7 HiDiscovery Scan
438
10
Contents
8.13.8 Scan Network
439
8.13.9 Demo Network
440
8.13.10Calculate Availability
441
8.14
Help
447
8.14.1 Online Help F1
447
8.14.2 Readme
447
8.14.3 Release Notes
448
8.14.4 Tutorial
448
8.14.5 Online
448
8.14.6 Kernel Info
449
8.14.7 About
450
A
Appendix
453
A.1
FAQ
454
A.2
Monitored properties
455
A.2.1
Monitored properties in the basic setting
455
A.3
CSV export
457
A.3.1
Microsoft Excel before 2010
457
A.3.2
Microsoft Excel 2010
458
A.4
Language support
459
A.5
Ports used
460
A.6
Maintenance
461
A.7
Literature references
462
A.8
Copyright of Integrated Software
463
B
Index
464
C
Further support
469
D
Readers’ Comments
470
11
The Management Tool
1
The Management Tool
Wherever individual network components are to be combined to create an
overall system, Industrial HiVision 8.2 is the ideal solution for configuring and
monitoring the administrable Hirschmann devices, including switches,
routers, and EAGLE 20/30/40 firewalls, wireless BAT units and products
from various manufacturers.
Designed for effective industrial supervision, Industrial HiVision can be easily
integrated into SCADA applications. It offers a built-in SNMP to OPC server.
The graphical user interface is available as an ActiveX control.
Note: Regarding security:
An attacker can spoof SCADA systems which can lead to unauthorized
access to ActiveX Native. Hirschmann OPC DA technology uses Distributed
COM (DCOM) from Microsoft, to communicate between hardware and
software. To help protect access to ActiveX Native and the OPC DA server,
configure access rights with a DCOM configuration tool.
Hirschmann recommends that you do not use ActiveX Native.
13
The Management Tool
1.1 Integration of third-party devices
1.1
Integration of third-party
devices
Of course, network management software from a specific manufacturer of
network components is optimized for operating these components. In
comparison, a generic, manufacturer-independent network monitoring
system will only provide superficial product integration.
However, in the real world, networks are usually a heterogeneous
environment with devices from multiple manufacturers.
Industrial HiVision makes it easier for the network administrator to also
integrate non-Hirschmann products, as long as they are administrable. This
applies to components of the network infrastructure as well as field devices.
Managed products have a range of standard characteristics that can be
monitored, such as the device status. In addition, the direct standard
interface can be used to enter further device-specific information, such as the
long-term history and status messages. You decide for yourself how detailed
the monitoring of your application is to be.
Advantages:
Monitoring and trend mapping for administrable devices from any
manufacturer
Status display for your entire system
Comprehensive network monitoring using a single network management
system.
14
The Management Tool
1.2 Enhanced auto-topology disco-
very
1.2
Enhanced auto-topology
discovery
To monitor an industrial network reliably, precise knowledge of the network
topology is essential. The network administrator should know how and where
which devices are linked to each other in order to manage a complex network
efficiently and perform any maintenance measures that are required.
Existing customers are already familiar with the intuitive Industrial HiVision
user interface.
This allows rapid visualization of the network topology. The standardized
LLDP protocol is used to scan network infrastructure components and the
received information allows Industrial HiVision to build a representation of the
network connectivity. End devices such as PLCs, I/O, and HMIs are also
detected and their location is accurately depicted on the graphical topology
map.
Industrial HiVision software enables you to detect unmanaged switches and
hubs and display their position within your network diagram. The software is
also able to determine the network topology of devices which are located
behind a router. This results in an increased level of topology detail.
Because industrial networks evolve over time, documentation can easily
become out of date. The auto-topology discovery function assists you to
know what is connected where in your network.
Key benefits:
Network maps are created automatically, without manual intervention
Topology maps are very accurate
Network documentation is up to date
15
The Management Tool
1.3 MultiConfig™ for network installa-
tion
1.3
MultiConfig™ for network
installation
Many network infrastructure devices require identical configuration
parameters. But those parameters will differ from one network to the next.
Which redundancy protocol is required?
What is the temperature threshold of the devices?
Where is the time server located?
Should the web interface be disabled for live operation?
To which management station should alarms be sent?
Should unused ports be disabled?
The list goes on and on.
Configuring devices individually is a tedious task. A misconfiguration on a
single device can be very difficult to find. As a result, Site Acceptance Tests
will be prolonged or the network may be inoperable. MultiConfig™ helps
prevent these issues from happening.
The configuration tool allows you to configure the same parameters across
multiple devices simultaneously and it also shows you where there is an
inconsistency between parameter configurations. It works across different
types of devices, where those devices have parameters in common.
MultiConfig™ allows you to save multiple device configurations, both locally
and to a server, without touching each device individually.
Key benefits:
Reduced network installation time
Network infrastructure configuration consistency
16
The Management Tool
1.4 MultiConfig™ for live operation
1.4
MultiConfig™ for live
operation
Throughout a network’s lifetime operation, it is necessary to carry out
repetitive but essential maintenance tasks. The threat of cyber attacks
means that responsible network administrators will change device
passwords regularly. Technology innovations can have great benefits for
your network and your company, but to take advantage of them you will need
to update your device firmware. And in the worst case scenario, if your
network breaks down, your support organization will need immediate access
to the current configuration files and event logs of your network devices.
Of course, for a small network, the above can be done by accessing each
device individually. But for both small and large industrial networks, network
security and availability are the ultimate goals. MultiConfig™ can fulfill the
above requirements with a few clicks of a mouse. As a result, network
administrators can meet their daily objectives with less effort and minimal
disruption.
Key benefits:
Highest network availability.
Least effort required for network administration and maintenance.
Minimized operational disruption.
Note: If you change user access parameters on a device that contains
identical SNMP, WEB- and CLI access parameters, then the changes are
applied simultaneously to the 3 access modes.
17
The Management Tool
1.5 Engineered through experience
1.5
Engineered through
experience
Industrial HiVision 8.2 is the fourth generation network management
software from Hirschmann. We have built on our experience with previous
releases to evolve a product which is unique in the industrial space. Industrial
HiVision 8.2 encompasses the features and benefits of earlier versions.
These include:
Key benefits:
Client/Server architecture
Web browser client
Edit and Run modes
Network hierarchy display
Global and individual status display and propagation
Flexible event handling
Customizable data acquisition
Long-term trending
Comprehensive export functions
Asset Management
18
The Management Tool
1.6 30 days free trial
1.6
30 days free trial
As a network administrator, you need cutting edge tools to help you meet
your targets. Hirschmann is famous for innovation. We are committed to
evolving Industrial HiVision to match our new hardware functionality, meet
the requirements of our customers, and exceed the demands of the Industrial
Ethernet marketplace.
Everybody knows, seeing is believing. Words cannot do justice to network
management software. Download Industrial HiVision, and test it free of
charge for 30 days at your convenience. Longer evaluation periods are
available on request.
The current version 8.2 of Industrial HiVision is available for download at
www.belden-solutions.com.
19
The Management Tool
1.7 Third Party Libraries
1.7
Third Party Libraries
Copyright (c) 2007-2008 Trilead AG (http://www.trilead.com)
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
a.) Redistributions of source code must retain the above copyright notice, this
list of conditions and the following disclaimer.
b.) Redistributions in binary form must reproduce the above copyright notice,
this list of conditions and the following disclaimer in the documentation and/
or other materials provided with the distribution.
c.) Neither the name of Trilead nor the names of its contributors may be used
to endorse or promote products derived from this software without specific
prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
CONTRIBUTORS “AS IS” AND ANY EXPRESS OR IMPLIED
WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY
DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
DAMAGE.
Trilead SSH-2 for Java includes code that was written by Dr. Christian
Plattner during his PhD at ETH Zurich. The license states the following:
Copyright (c) 2005 - 2006 Swiss Federal Institute of Technology (ETH
Zurich), Department of Computer Science (http://www.inf.ethz.ch), Christian
Plattner.
All rights reserved.
20
The Management Tool
1.7 Third Party Libraries
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
a.) Redistributions of source code must retain the above copyright notice, this
list of conditions and the following disclaimer.
b.) Redistributions in binary form must reproduce the above copyright notice,
this list of conditions and the following disclaimer in the documentation and/
or other materials provided with the distribution.
c.) Neither the name of ETH Zurich nor the names of its contributors may be
used to endorse or promote products derived from this software without
specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
CONTRIBUTORS “AS IS” AND ANY EXPRESS OR IMPLIED
WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY
DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
DAMAGE.
The Java implementations of the AES, Blowfish and 3DES ciphers have
been taken (and slightly modified) from the cryptography package released
by “The Legion Of The Bouncy Castle”.
Their license states the following:
Copyright (c) 2000 - 2004 The Legion Of The Bouncy Castle (http://
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the “Software”), to deal
In the Software without restriction, including without limitation the rights to
use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies
of the Software, and to permit persons to whom the Software is furnished to
do so, subject to the following conditions:
21
The Management Tool
1.7 Third Party Libraries
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY
KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE
WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF
CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
DEALINGS IN THE SOFTWARE.
22
Software Overview
2
Software Overview
This chapter describes the following topics:
The prerequisites for installing and operating the software
Installing the software
Updating the software
Maintaining the software
Starting the program
Deinstalling the software
You will find requirements for operating the software in the appendix (see on
page 24 “System Requirements”).
Note: Regarding security:
Industrial HiVision helps to protect the edit mode of the user interface by
requesting a password.
When you login to your network management station as an administrator and
start the user interface of Industrial HiVision, then Industrial HiVision allows
you to switch directly to the “Edit Mode“. You can thus avoid having to enter
a password.
Note: Regarding security:
The Industrial HiVision database contains the information for your Industrial
HiVision project.
Hinder the access to this file by means of selected access rights for the
directory <installation directory>\database.
23
Software Overview
2.1 System Requirements
2.1
System Requirements
You can find a detailed description of the system requirements in the readme
file.
License
License keys for Industrial HiVision depend on the number of devices you
want to monitor.
You can get license keys for 16, 32, 64, 128, 256, 512, 1024, 2048 and
4096 devices.
24
Software Overview
2.2 Installation
2.2
Installation
Industrial HiVision consists of a number of components. A service performs
a large part of the work in the background.
This service has a close connection to a database containing the relevant
data for the settings of Industrial HiVision and the devices to be monitored.
When you reboot Industrial HiVision, Industrial HiVision gets the
configuration data from the database which were current when you last quit
the program.
Notification
Server
1
1
2
IP
Network
Management Station
Configuration
daten
read/write
Display-
data
Database
Services
User interface
Figure 1: Architecture
1 - SNMP Get/Set/Trap, HiDiscovery V1, Ethernet/IP, Modbus/TCP, Ping,
HTTP, HTTPS,
2 - HTTP, HTTPS
25
Software Overview
2.2 Installation
The program Industrial HiVision, which you call up directly on the screen,
maintains a connection with the background service, from which it gets the
required data.
You can install Industrial HiVision additionally to a former release of Industrial
HiVision. If you start different releases simultaneously each release
maintains a connection to its own background service.
Industrial HiVision enables you to install the following features on different
computers:
the user interface (Industrial HiVision Client)
Note: For Windows 10 users. If you install Industrial HiVision as a client,
then it is possible that client access is denied. To correct this, give the
user read permission to the <Installation directory>\lib folder.
the service with the database (Industrial HiVision Server)
You can thus access a central network management station from different
locations with multiple user interfaces. The number of user interfaces that
can access a central network management station depends on the capacity
of the network management station. To avoid access conflicts, only one user
interface can access a network management station in the “Edit Mode“ (see
on page 369 “Program Access”).
However, you can access multiple decentralized Industrial HiVision servers
with one user interface.
Note: Installing an external firewall with NAT between the service and the
user interface:
In the external firewall you activate port forwarding for the connection port in
the service direction for the following ports:
11195, Industrial HiVision proxy server for the communication between
the service and the user interface.
11194, Industrial HiVision Web server to also open the user interface in
the browser.
(see on page 373 “Services Access”)
26
Software Overview
2.2 Installation
Note: Industrial HiVision writes events (see on page 112 “Event list”) with
dates and times in the database. The time written refers to the time in the
system on which the service is running. When you start the user interface on
a computer in a different time zone, Industrial HiVision displays the event
times in the time zone of the computer on which the service is running.
2.2.1
Downloading the Industrial HiVision
software
To install Industrial HiVision on your computer, perform the following steps:
 Open the website: hirschmann-support.belden.com/en/login
 When you have an account, login to your account. To make an account,
click the Register button.
 Select the software link that best suits your needs.
 Click the Download button.
 After you read the End User License Agreement (EULA), click the I
Agree button.
 Extract the files located in the downloaded ZIP file to a temporary folder.
Note: Before you install the software, compare the sha256 hash on the web
page with the sha256 hash calculated from the zip file. Use the Windows
utility "certutil" to calculate the sha256 hash. In the cmd window navigate to
the file location, then enter the following command:
CertUtil -hashfile path\file_name.ext SHA256
Example: CertUtil -hashfile C:\Industrial_HiVision.zip SHA256
27
Software Overview
2.2 Installation
2.2.2
Installation under Windows
 Download and extract the Industrial HiVision files as described in
“Downloading the Industrial HiVision software” on page 27.
 Navigate to the location of the extracted Industrial HiVision files.
 For Windows computers, double click the ihivision8.2_windows.exe file.
 In the Open File - Security Warning dialog, click the Run button.
 Answer the questions of the installation script and follow its instructions.
If you do not answer a question of the installation script, then the
installation script selects the default answer.
Note: If you get the message Error during installation of
ikernel.exe, this means that the user does not have any administration
rights.
Depending on your selection, the installation assistant installs the following
items:
the Hirschmann Industrial HiVision 8.2 Service with integrated database
(= Industrial HiVision Server)
OPC services
the Industrial HiVision Client (= user interface) program
the ActiveX control
If you want to connect to a SCADA system, you need the OPC services on
the Industrial HiVision server and/or the ActiveX control on the SCADA
system.
OPC services function as the data source for SCADA systems.
The ActiveX control visualizes the network in SCADA systems.
To perform a HiDiscovery V1 scan, Industrial HiVision requires the WinPcap
program.
During the installation of Industrial HiVision, Industrial HiVision checks
whether the version of WinPcap installed on your PC fulfills the requirements
of Industrial HiVision. If not, you agree to the installation of WinPcap using
the installation wizard.
28
Software Overview
2.2 Installation
During the installation, you can select how the Hirschmann Industrial
HiVision 8.2 Service starts from the following options:
start automatically each time the computer is rebooted
start manually when the program starts
Note: You will find the status of the service in Windows 2008 R2, Windows
Server 2012 R2, under Start:Control Panel:Administration
Tools:Computer Management:Services and Applications:Services.
Here you can also terminate the service and restart it.
If you are running other resource-intensive programs on the computer, then
close the Industrial HiVision program and the “Hirschmann Industrial
HiVision 8.2 Service”. This service requires considerable computer
resources. When it starts, the Industrial HiVision program asks you whether
you want to start the service. When you select File > Exit and Stop
Service to leave the program, the Industrial HiVision program asks you
whether you want to close the service.
Note that when the service is switched off, there is no network monitoring,
which means that no events are recorded.
Note: In the default setting of the service properties on the “Logon” tab,
no data exchange between the service and the GUI is permitted for the local
system account (Start:Control Panel:Administration
Tools:Computer Management:Services and Applications:Services,
right-click on the “Hirschmann Industrial HiVision 8.2 Service” and select
Properties). This means that you can start a program from Industrial
HiVision (see on page 334 “Event Actions”) and that the process runs in the
background, but that the program is not visible on the monitor. Permitting the
data exchange between the service and the GUI is a security risk, because
this program can then be started independently of the user who is logged on.
So-called Trojan horse attacks use this security gap. To automatically send
a Short Message Service (SMS) or an e-mail when an event occurs, you do
not need a data exchange between the service and the GUI.
29
Software Overview
2.2 Installation
2.2.3
Installation under Linux
 Logon with the su command so that you have root access rights.
 Quit the current kernel.
 Start the installation script with the command
sh /mnt/cdrom/Software/IndustrialHivision/linux/install.sh
 Answer the questions of the installation script and follow its instructions.
If you do not answer a question of the installation script, then the
installation script selects the default answer.
Example of a run of the installation script:
Welcome to Industrial HiVision
This script will install Industrial HiVision on your system.
You can abort the setup process anytime by pressing ctrl-c.
Do you wish to continue? [y]es, [n]o (default=no)
y
Please specify a destination directory for the installation
(default=/opt/ihivision8.2)
The directory /opt/ihivision8.2 does not exist.
Do you wish to create it? [y]es, [n]o (default=no)
y
Unpacking Industrial HiVision...
Running setup script...
*** Checking database user ***
*** Initialising installation directory ***
*** Initialising log directory ***
*** Configuring Services ***
*** Configuring Executables ***
*** Preparing Init Script ***
*** Industrial HiVision successfully installed ***
30
Software Overview
2.2 Installation
Industrial HiVision is now installed and ready for use.
 Start the Industrial HiVision service with the following command:/etc/
init.d/ihivision8.2 start
Industrial HiVision requires that you have logged on with su.
 You can quit the service with the following command: /etc/init.d/
ihivision8.2 stop
 You can restart the service with the following command: /etc/init.d/
ihivision8.2 restart
 You can check whether the service is running with the command: /etc/
init.d/ihivision8.2 status
To start the service when starting the operating system, you include the
service start in the init sequence of your system.
The various Linux distributions provide you with a whole range of options for
this.
For some start sequences compatible with Sys V, the installation copies the
start script ihivision8.2 into the init.d directory of the system.
Depending on your requirements the following options are available:
integrate this script into the various run levels
start it manually with the above command
The Init script was developed and tested under Red Hat, Ubuntu/Kubuntu
and Mandriva Linux. Other distributions (such as Gentoo) use a different
script format and thus require different scripts.
Syslog Server Configuration
Linux applications save generated events in log files. The system utility
Rsyslogd provides support to log events in a Linux system. You configure
the Rsyslogd utility with the rsyslog.conf file. You can configure the
rsyslog.conf file to save the Industrial HiVision events on a Syslog server.
The Linux Syslog includes the following events:
Log in and out of the Industrial HiVision application,
Actions which result in an SNMP Set Request being sent to a device,
this includes the MIB variable that was set, and the new value,
Actions from HiDiscovery V1 within Industrial HiVision,
Start of external applications,
Actions for which the “Edit Mode“ is needed.
31
Software Overview
2.2 Installation
To configure the rsyslog.conf file to save events on a Syslog server,
proceed as follows:
 Navigate to the /etc folder in the installation directory.
 Open the rsyslog.conf file.
 Uncomment the following lines:
-
$ModLoad imudp,
$UDPServerRun 514.
Example of the rsyslog.conf file:
#/etc/rsyslog.conf
Configuration file for rsyslog
#
For more information see
#
/user/share/doc/rsyslog-doc/html
/rsyslog_conf.html
#################
#### MODULES ####
#################
$ModLoad imuxsock # provides support for local system logging
$ModLoad imklog
# provides kernel logging support
$ModLoad immark
# provides --MARK-- message capability
|
# provides UDP syslog reception
|$ModLoad imudp
|$UDPServerRun 514
|
|
|# provides TCP syslog reception
|$ModLoad imudp
|$UDPServerRun 514
|
|
|"/ect/rsyslog.conf" 121 lines, 2630 characters
|
32
Software Overview
2.3 Update
2.3
Update
2.3.1
Updating under Windows
To update a version of Industrial HiVision already installed, you install the
new version as described on “Installation under Windows” on page 28.
During the installation, you can choose whether the installation routine
transfers the database contents from a previous installation into the new
installation.
If you want to transfer the database contents from an earlier version, you only
uninstall the earlier version after the update. Industrial HiVision permits the
installation of different versions on a PC.
Note: In the “Event History“ tab, Industrial HiVision notifies you when a new
version of Industrial HiVision is available.
Note: In order to correctly transfer the data from the previous version, the
installation routine terminates the previous version of the service, with your
permission, if it is still active. Therefore, there is no network monitoring during
the update procedure.
Note: The Industrial HiVision backup is version dependent. Make a backup
file after every software update (see on page 258 “Save Backup”).
33

 

 

 

 

 

 

 

 

Content      ..      1       2         ..

 

 

///////////////////////////////////////