Setting up remote access to meteocontrol bluelog retroactively

Prev Next

In this case study, we explain how remote access can be set up retrospectively on an existing system fitted with a bluelog from meteocontrol and an INSYS router, without having to visit the site

Situation

meteocontrol customers have already installed INSYS routers in their systems, which act as internet access points. Remote access is often not set up initially. If remote access to the bluelog or the plant becomes necessary during operation, an expensive initial on-site visit is usually required to set up remote access for the first time. Remote access is then provided via the icom Connectivity Suite – VPN.

Solution

A simple solution is available using icom Router Management: rather than, as before, sending the VPN configuration from the icom Connectivity Suite – VPN to the customer so that they can install it manually on the router on site, icom Router Management can be used conveniently for this in just three steps:

  1. When the system (the INSYS router) is installed, the INSYS router is also integrated into the icom Router Management system.

    Integration of the router in the icom Router Management!

    Ideally, this measure should be implemented when the system is first installed. For systems that are already in operation, implementation can take place as part of a scheduled on-site visit in order to use synergies.

  2. meteocontrol generates a secure and customised VPN configuration for the plant's INSYS router and transmits this configuration to the customer via a secure channel.

  3. The customer installs the VPN configuration in the icom Router Management interface and deploys it remotely to the router – from this point onwards, remote access can be used.

Prerequisites

Prerequisites for operating the services!

The following example assumes that the icom Connectivity Suite – VPN is operated by meteocontrol, and that the icom Router Management is operated by the customer.

For the customer, use of icom Router Management is free of charge in the initial stage. The Cloud Free version can be used. A Cloud Basic licence is only required once the download function for VPN configurations onto the routers is utilised. Further benefits of icom Router Management, which are already included in Cloud Free, include the ability to monitor the router’s connection status and to distribute firmware updates.

In our example solution, we have based our approach on a typical installation with the following initial conditions:

  • IP address of the meteocontrol bluelog: 192.168.1.20/24

  • IP address of the INSYS routers MIRO-L200: 192.168.1.1/24 (default)

The meteocontrol configuration PC was set up in the icom Connectivity Suite – VPN and connected to it (by meteocontrol).

The router was set up in icom Router Management as described here in steps 1 and 2 (by the customer).

The router was set up as described in the Quick Installation Guide (by the customer).

The router was set up using the Startup Wizard and configured for icom Router Management in step 6 (by the customer).

The router is configured as starting point for the next steps, has a stable internet connection via the cellular network and is connected to the customer’s icom Router Management account.

Steps that have to be taken by meteocontrol

Before configuring the router in the icom Connectivity Suite – VPN, it is important to find out the local IP address, subnet and port assignments of the customer’s device, as these have already been set. For the rest of this procedure, we will assume that the router can be accessed on both ports via the IP address 192.168.1.1/24.

  1. Log in to the icom Connectivity Suite - VPN and add a router as described in this Configuration Guide.  

    Please ensure you configure the following individual settings:

  2. Click on the device information page of this router on Download configuration and download the ASCII configuration file for the icom Connectivity Suite - VPN.

  3. Open the downloaded configuration file in a text editor and add the line cli(‘administration.profiles.activate’) at the end of the configuration, before the end of the Lua block, as follows:

    cli("administration.profiles.activate")

  4. Save the extended ASCII configuration file and send it to the customer via a secure channel.

Steps that have to be taken by the customer

In order to upload the ASCII configuration file to the router, the customer must upload it to their icom Router Management account.

  1. Click on the Package ManagementFile Storage page on Upload and select the ASCII configuration file received from meteocontrol.

  2. Select ASCII-Configuration as type and click on Upload.

  3. Select the uploaded file, click on   and select Create Update Package.

  4. Enter a meaningful Name and Description so that you can identify the file later, and click on Crate.

  5. Click on the InventoryRouter page on behind the router to which you want ro roll out the ASCII configuration and select Deploy update package.

  6. Check the update package uploaded above and click on Continue >.

  7. If necessary, edit the Name and Description of the update job, select Run immediately, and click on Run update job.

  8. Click on Go to update jobs.

  9. Notify meteocontrol once the update job has changed from Active to Success.

Confirmation of successful configuration

The customer can confirm that the configuration has been successful if the connection to the icom Connectivity Suite – VPN is shown as Online in the router’s dashboard.

meteocontrol can confirm that the configuration has been successful if the router is shown as Online in the icom Connectivity Suite - VPN.