RED Optimise Connectivity Options Quick Guide
RED Optimise Connectivity Options Quick Guide
Connectivity options
F.A.Q
Technical requirements
and guidelines
The purpose of this document is to provide the configuration parameters needed to permit the
correct communication between the local supervisors and the RED optimise cloud environment
offered by Carel (red-opti-carel.digital-service.com).
Index
1. Web access for end users ............................................................................................... 2
The parameters to set on local supervisors to communicate with RED optimise in case of
access from internet are defined as follows:
NOTE: In this scenario a valid DNS server is needed in order to correctly solve the FQDN (Fully
Qualified Domain Name) mentioned above.
2.2. ACL (Access Control List) firewall rules for Internet connectivity
In order to guarantee the communication between RED optimise and supervisors devices
connected via Internet, the network needs to permit traffic for the following IP addresses and
ports:
Traffic type
TIP: In order to simplify the ACL firewall rule configuration, it can be set to accept any
connection from and to both the IP addresses reported above.
3.1. Access from VPN (without cross-VPN DNS) for local supervisors
The parameter to set on local supervisors to communicate with RED optimise in case of
access from VPN without cross-VPN DNS support are defined as follows:
- pCOWeb – 10.160.0.3
- PlantWatchPRO – address: 10.160.0.3
- PlantVisorPRO – address: 10.160.0.3
- Boss Family – address: 10.160.0.3
3.2. Access from VPN (with cross-VPN DNS) for local supervisors
The parameters to set on local supervisors to communicate with RED optimise in case of
access from VPN with cross-VPN DNS support are defined as follows:
- pCOWeb – s1.remotepro.io
- PlantWatchPRO – address: s1.remotepro.io
- PlantVisorPRO – address: 10.160.0.3
- Boss (until version 1.1.1) – address: 10.160.0.3
- Boss (from version 1.1.1) – address: s1.remotepro.io
3.3. ACL (Access Control List) firewall rules for VPN connectivity
In order to guarantee the communication between RED optimise cloud and supervisors
devices connected via VPN the network need to permit the traffic for the following IP
addresses and ports.
Traffic type
IKEv1 or IKEv2
IKE TYPE
Main Mode (not aggressive mode)
IKE Phase1 Lifetime 28800 seconds (other values can be agreed upon)
ESP Phase2 Lifetime 3600 seconds (other values can be agreed upon)
In order to integrate boss family devices with RED optimise Cloud, it is possible to use the
“OpenVPN client” feature.
· A boss family supervisor with version equal or higher of version 1.5.0 should be present;
· Enable DHCP on both router and boss;
· Possibility to exit on UDP port 1194, UDP port 1194 must be OPEN (OpenVPN port);
·In order to safely assign a static IP Address to the supervisor connected in a network with a
DHCP server, it is mandatory to perform an IP reservation to avoid address conflicts;
· Verify that boss is able to reach the internet and a correct DNS server must be set up (e.g. you
can ping from "Terminal", available as Integrator user, a common website provider e.g.
www.google.com);
· Always check that the date and time indicated on the supervisor are correct.
after few seconds the VPN Client icon should become green.
boss-<uuid>.prod.rmpro.openvpn
where <uuid> is the filename (without the extension) of the .P7MB64 file
Example:
filename: b45d8f60-f17b-11e9-a73c-000babc76dc7.P7MB64
uuid: b45d8f60-f17b-11e9-a73c-000babc76dc7
composed string to use in RED optimise as supervisor IP address:
boss-b45d8f60-f17b-11e9-a73c-000babc76dc7.prod.rmpro.openvpn
Configuration > I/O Configuration > RemotePRO tab and then restart the Engine
Starting from release 1.8.0 of the Boss family supervisory service pack, the procedure for activating
the VPN Client service has slightly changed.
c) Download the REQ file, we suggest to reset the file before downloading it (Reset Request
Button)
e) Press the “Play” button on the VPN Client from “Security services”:
after few seconds the VPN Client icon should become green .
boss-<uuid>.prod.rmpro.openvpn
where <uuid> is the filename (without the extension) of the .P7MB64 file
Example:
filename: b45d8f60-f17b-11e9-a73c-000babc76dc7.P7MB64
uuid: b45d8f60-f17b-11e9-a73c-000babc76dc7
composed string to use in RED optimise as supervisor IP address:
boss-b45d8f60-f17b-11e9-a73c-000babc76dc7.prod.rmpro.openvpn
x. RELEASE NOTES