Remotewatch I/A Series Data Acquisition System (Das) V3.2 Installation and Configuration
Remotewatch I/A Series Data Acquisition System (Das) V3.2 Installation and Configuration
Remotewatch I/A Series Data Acquisition System (Das) V3.2 Installation and Configuration
RemoteWatch
I/A Series Data
Acquisition System
(DAS) V3.2
Installation and
Configuration
B0860AY
Rev A
August 30, 2012
Invensys, Foxboro, I/A Series, and the Invensys logo are trademarks of Invensys plc, its subsidiaries, and
affiliates.
All other brand names may be trademarks of their respective owners.
Preface................................................................................................................................... vii
Revision Information .............................................................................................................. vii
Reference Documents ............................................................................................................. vii
Glossary of Terms ................................................................................................................... vii
Appendix A. I/A Series Secure Environment Remote Watch Server Communications Setup 17
Enable/IP Configure Second Network Interface ...................................................................... 17
I/A DAS Mailbox Station and RW Server Not Connected to the Same Subnet ....................... 17
Add HIPS Firewall Rule .......................................................................................................... 18
Index .................................................................................................................................... 27
iii
B0860AY – Rev A Contents
iv
Figures
1-1. RemoteWatch I/A Series Installer Account .................................................................... 3
1-2. RemoteWatch I/A Series Installer Account - New Name ............................................... 3
1-3. RemoteWatch Server’s IP Address Dialog Box .............................................................. 4
1-4. IP Address Confirmation Dialog Box ............................................................................ 4
1-5. Invensys DAS Install Options Dialog Box ..................................................................... 5
1-6. RemoteWatch I/A Series Services Account .................................................................... 6
1-7. RemoteWatch RwDasServices Account - New Name .................................................... 6
1-8. RemoteWatch RwDasService Account - Password ........................................................ 7
1-9. RemoteWatch I/A Series Services Account Password Prompt -
for Each Station ............................................................................................................ 7
1-10. RemoteWatch Password Confirmation - Subsequent Installations ................................ 8
1-11. Command Window Displaying Installation Messages ................................................... 8
3-1. Certificate Error: Navigation Blocked Screen .............................................................. 19
3-2. Log In - McAfee EPolicy Orchestrator Administrator Account ................................... 19
3-3. Select Product - Host Intrusion Prevention 7.0.4 Firewall ........................................... 20
3-4. Add Rule - Invensys Firewall Rules ............................................................................. 21
3-5. Define Rule - Invensys Fire Wall ................................................................................. 22
3-6. Select I/A Series Stations to Receive the New RW DAS Rule ...................................... 23
3-7. Select Wake up Agents - More Actions Menu ............................................................. 24
3-8. Accept Defaults - Wake Up McAfee Agent Screen ...................................................... 25
3-9. Close - ePolicy Orchestrator Web Page ....................................................................... 26
v
B0860AY – Rev A Figures
vi
Preface
This document provides the details required to install the RemoteWatch (RW) Data Acquisition
System (DAS) V3.2 on workstations with I/A Series® software V8.5, V8.6, V8.7 and V8.8. For
operational details of the 70 Series RW DAS, refer to the RemoteWatch User’s Guide (B0860AJ).
The 70 Series RW DAS V3.2 is supported for I/A Series software V8.5, V8.6, V8.7 and V8.8.
The 70 Series RW DAS software may be installed system wide from a single 70 Series worksta-
tion. Based on the installation option chosen, the software installation can propagate the 70 Series
RW DAS software to the other 70 Series workstations on the I/A Series system.
The installation procedures for 70 Series workstations includes the following:
Executing the software installation procedure
Validating the Mailbox and FIST station designation
Testing the installation
Revision Information
This is the initial release of the document.
Reference Documents
In addition to the information presented herein, you should be familiar with the following
I/A Series® documents:
RemoteWatch Server Software Version 3.1 Installation Guide (B0860AS)
Station Access Manager User's Guide (B0860AF)
RemoteWatch Server Version3.1 Upgrade (B0860AR)
RemoteWatch User’s Guide (B0860AJ)
RemoteWatch Version 3.2 Release Notes (B0860RF)
Most are available on the I/A Series RemoteWatch Electronic Documentation CD-ROM
(CG500EL). The latest revisions may also be available through the Invensys Operations Manage-
ment Global Customer Support Center at http://support.ips.invensys.com.
Glossary of Terms
The following terminology, used throughout this user’s guide, relates to the RemoteWatch V3.1
and V3.2 software and associated equipment.
vii
B0860AY – Rev A Preface
RemoteWatch The RemoteWatch Server is the central point of control for the Remote-
Server Watch system at your site. The RemoteWatch Server collects data from an
I/A Series system, which are then historized and transferred to the Global
Customer Support Center where RemoteWatch engineers can monitor the
health of the system.
The RemoteWatch Server also provides a connection between IPS and
your site that allows Invensys experts to remotely view and troubleshoot
issues from the Global Customer Support Center. Using the remote con-
nection, it is possible navigate through an I/A Series system to determine
and fix the source of the problem and before it is allowed to escalate.
RW_WinExec
RW_WinExec is a Windows® based Service Application that runs in the
background on 70 Series workstations with I/A Series software V8.5,
V8.6, and V8.7. This service is responsible for executing the data gather-
ing probe scripts used by the DAS system.
RW_WinExec_Service
RW_WinExec_Service is a Windows based Service Application that runs
in the background on pre I/A Series V8.5 workstations (70 Series). This
service is responsible for executing the data gathering probe scripts used by
the DAS system.
viii
1. 70 Series DAS Installation for
I/A Series Workstations
This chapter describes how to install the 70 Series RemoteWatch Data Acquisition System
(70_Series_RW_DAS) on 70 Series workstations with I/A Series V8.5, V8.6, V8.7 and V8.8
software.
The 70 Series RW DAS software may be installed system wide (that is, all 70 Series stations on an
instance of The Mesh control network) from a single 70 Series workstation on the system. The
software installation can propagate the 70 Series RW DAS software to the other 70 Series work-
stations on the I/A Series system based on the installation option chosen.
Installation Prerequisites
The following is required before and during the installation procedure.
The IP address of the RemoteWatch Server
For a Secure I/A Series System, the IA Installer account name, the IA Services account
name and password
For a Standard I/A Series System, the fox account password
The RemoteWatch Server must have RW File Services (IFS) Version 3.1.
1
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
NOTE
If the Windows Task bar is not accessible, a cmd window can be opened using the
following steps:
a. Open Windows Explorer (Start -> Programs -> Accessories -> Windows
Explorer).
b. Navigate to C:\Windows\System32.
c. For stations with I/A Series V8.5, V8.6 and V8.7, right-click CMD.exe and
select Run as...
For stations with I/A Series V8.8, right-click CMD.exe and select Run as
administrator.
d. When prompted, select The following User from the popup window.
e. From the drop down menu, select FOX. for a standard I/A Series station or
IaInstaller for a secure I/A Series station.
f. Enter the password.
g. Select OK.
CMD will now run as the fox account. You can now execute scripts from this
CMD to install DAS.
2
1. 70 Series DAS Installation for I/A Series Workstations B0860AY – Rev A
NOTE
When the installation runs, the command window will contain lines of text indicat-
ing the steps and some of the instructions that are taking place. For this information
to be more readable, adjust the command window properties to allow a screen buf-
fer width of 200 characters and the height to be at least 300 lines as follows:
a. Right-click on the title bar at the top of the command window and select
Properties.
b. Select the Layout tab and change the Screen Buffer Size Width property to
200.
Change the Screen Buffer Size Height property to 300 or more. A confirmation
dialog appears asking if you want to apply the changes to the current window
only or on the shortcut that started the window. Select one of the choices and
click OK.
a. If the I/A Series Installer account has not been renamed, click No.
Verify that you are logged into the I/A Series Installer account, typically IAIn-
staller.
b. If the I/A Series Installer account has been renamed, click Yes.
The following dialog box appears prompting for the I/A Series Installer account
name. Enter the new name for the I/A Series Installer account. Click OK.
3
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
6. A dialog box appears prompting for the IP Address of the RemoteWatch Server. Enter
the IP Address and click OK.
7. When prompted verify that the RemoteWatch Server IP address is correct and click
Yes.
8. Next a dialog box appears (Figure 1-5) with three choices of installation type. Enter
the number of the desired selection and click OK.
Select 1 to install on all 70 Series workstations.
Select 2 to install only on this workstation
Select 3 to choose one or more stations from a list of stations.
By default, all available stations are displayed in the list. When 3 is selected, Note-
pad executes and displays a file (list) of station letterbugs that are contained in the
System Definition that are connected to the MESH network. Edit the list - only
the letterbugs remaining in the file will have the RW_WinExec software installed.
Save the file, then close the Notepad application. The installation automatically
continues from this point.
4
1. 70 Series DAS Installation for I/A Series Workstations B0860AY – Rev A
9. During installation, dialog boxes appear prompting the user to provide the account
password for the station that is being installed.
NOTE
It is important that the correct account password is supplied. The installation pro-
cess relies on the password to make the network connections to the remote station
being installed; the RW_WinExec service application relies on it for proper installa-
tion.
5
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
For stations with I/A Series V8.8, enter RwDasService as the account name as
shown in Figure 1-7. Click OK. If the IAServices account was renamed, enter the
new name account of the IAService account, and then click OK.
6
1. 70 Series DAS Installation for I/A Series Workstations B0860AY – Rev A
b. After the password is entered, a confirmation dialog box (Figure 1-10) appears
with the following question:
Do you want to use this password for all subsequent installa-
tions? (y/n).
If you respond “Yes”, you are not prompted again to enter the password.
The password entered in the previous step is used for all the workstations
being processed.
If you respond “No”, the Account Password Prompt dialog box appears for
every workstation being installed.
7
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
NOTE
The confirmation dialog box in Figure 1-10 will not reappear again during this
installation session. It only appears after the first password is entered.
10. After the account password is entered, the installation continues and the command
window displays information regarding the various steps being executing. The exam-
ple in Figure 1-11 illustrates three 70 Series stations being installed: MHIST1,
MSRIA1 and MSRIA2. MSRIA1 is off-line.
After the DAS installation is executed for all stations, the DAS Mailbox and FIST configuration
files are updated using the bld_mbxCfg.vbs and distribute_mbxCfg.vbs programs. The
bld_mbxCfg.vbs program determines the workstation on the system that is to be used as the
Mailbox station for those workstations that cannot directly access the RemoteWatch Server and
then saves the data to a configuration file mbx_cfg.csv. The distribute_mbxCfg.vbs pro-
8
1. 70 Series DAS Installation for I/A Series Workstations B0860AY – Rev A
gram updates the DasMailbox.txt file on each workstation to the value specified in the
mbx_cfg.csv file.
NOTE
The bld_mbxCfg.vbs and distribute_mbxCfg.vbs portion of the installation takes
the longest time to complete. This is especially true if many of the configured work-
stations are not connected or do not exist. This process can take 10 to 15 minutes or
more.
After the Mailbox is configured, the installation collects system information for every station on
the system. This information consists of: Host Letterbug, System Monitor Letterbug, System
Monitor Name, Station Type, NSAP and MAC Addresses. This process takes several minutes
depending on the number of stations configured (and not connected).
The last step in the installation process is to transfer the collected system information to the
RemoteWatch Server. See the following section “Verify the RemoteWatch Mailbox”.
9
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
Verify that the letterbug contained in the file is acceptable. If this file must be modified with a dif-
ferent station letterbug, then only a 70 Series workstation with a second Ethernet network con-
nection to the RemoteWatch Server is acceptable. Refer to RemoteWatch User’s Guide (B0860AJ)
for more information.
Additionally, the DAS Mailbox file on each 70 Series workstation on the node or network must
be updated accordingly.
Uninstall Notes
If the RW_DasExec DAS software must be uninstalled for any reason use the following proce-
dure:
1. Login to the proper account for installation:
a. For a secure system, use the IA Installer account. Typically, the name is IAInstaller.
b. For a standard system, use the fox account.
2. Open a command prompt and navigate to
d:\opt\fox\bin\remote\tools\DAS\install. For stations with I/A Series v8.8,
open this command prompt as an administrator.
3. Execute the script uninstall_70.cmd. This script may take some time to execute
especially if the RW_DasExec service is pending on completion of a data acquisition
task before it can be stopped and removed.
4. On secure I/A Series systems, if the IA Installer account is not named IAInstaller, the
following occurs:
a. A dialog box asks if the I/A Installer account has been renamed.
b. If Yes is selected, another dialog box prompting for the IA Installer account name
appears. Enter the new account name, and click OK.
10
1. 70 Series DAS Installation for I/A Series Workstations B0860AY – Rev A
11
B0860AY – Rev A 1. 70 Series DAS Installation for I/A Series Workstations
12
2. Verify the FIST Host
This chapter describes how to verify the correct addresses for the FIST host.
Be aware of the following:
The FIST host text file designates which I/A Series workstation will transfer the FIST
configuration file to the RemoteWatch Server. This file is required for RemoteWatch
applications.
Only one station on the system is designated as the FIST host.
As with the RemoteWatch Mailbox file, verify that the station listed in the Fist-
Host.txt file exists.
Fisthost.txt is located on 70 Series workstations in the folder:
D:\opt\fox\bin\remote\tools\DAS\cfg
13
B0860AY – Rev A 2. Verify the FIST Host
14
3. Verify Data Transfer to the
RemoteWatch Server
This chapter describes how to verify that data has been transferred successfully to the
RemoteWatch Server.
NOTE
Due to timing issues with mailbox stations, it may take another DAS collection
before all of the stations have folders in D:\resource_das\data. If only some of
the stations have folders, check back in 1-2 hours to verify that the rest of the sta-
tions have sent their data.
If the folders don't exist, the following tips may help troubleshoot the issue:
To force a DAS collection on the I/A station, pause and continue the RW_WinExec
service. Enter the following commands on the I/A Series station at a command
prompt:
net pause RW_DasExec
net continue RW_DasExec
It takes several minutes for a collection to run and transfer files to the server.
The data files are archived on the I/A Series station into a 7z archive file and then
transferred to the server. To verify that the archive was received on the server, check for
any *.7z files in D:\ftproot using the following commands on the server at a com-
mand prompt:
D:
cd \ftproot
dir /s *.7z
If no files are listed, then there is a problem with the connection between the station
and the server.
The D:\ftproot\resource_das\data\7z_input folder must exist on the server
for the files to be processed correctly. Verify that the folder exists and if it doesn't, cre-
ate it.
15
B0860AY – Rev A 3. Verify Data Transfer to the RemoteWatch Server
The Invensys® File Services must be installed and running on the RemoteWatch
Server. Try restarting the service by running the following two commands on the
server at a command prompt:
net stop ISFService
net start ISFService
For further troubleshooting guidance, contact the GCS Support Center.
16
Appendix A. I/A Series Secure
Environment Remote Watch Server
Communications Setup
This appendix describes how to setup the RemoteWatch Server communications in a secure
I/A Series environment.
Each station designated as a RW Mailbox station MUST BE able to communicate with the RW
Server. Each I/A Series station with DAS installed has the name PS_DAS assigned to the IP address
of the RW Server that was specified during installation.
After installation of an I/A Series Secure system, the following conditions may exist that prevent
data transfer to the RemoteWatch Server:
The second network interface on the 70 Series station is disabled and has no IP
configuration
Communication can only occur when a RW server is connected to the same second
subnet as the 70 Series station
The McAfee® HIPS package, when fully enabled, prevents RW data files from being
sent to the RW Server.
! WARNING
Before connecting an I/A Series system to a network other than the I/A Series con-
trol network, the security of this connection must be reviewed by the customer to
insure that the customer security requirements are not compromised in anyway.
17
B0860AY – Rev A Appendix A. I/A Series Secure Environment Remote Watch
! WARNING
A syntax error during the entering of the route add command could affect I/A Series
station operation and require an I/A Series station reboot.
It is suggested that the route add command be implement and verified without the persistence
option (-p) being specified. Once the command is verified to provide the proper routing, the
command can be re-issued with the -p option specified to make the change persist between
reboots.
For maximum security the route add command should specify a netmask 255.255.255.255. The
format of a route add is:
route add {RWS_IP} MASK 255.255.255.255 {2ND_NET_IP} METRIC 20
where: {RWS_IP} is replaced by the IP address of the RW Server
{2ND_NET_IP} is replaced with the 70 Series station second network IP address.
18
Appendix A. I/A Series Secure Environment Remote Watch Server Communications Setup B0860AY – Rev A
4. Log into the McAfee ePolicy Orchestrator 4.0.0 Console using the admin account.
19
B0860AY – Rev A Appendix A. I/A Series Secure Environment Remote Watch
20
Appendix A. I/A Series Secure Environment Remote Watch Server Communications Setup B0860AY – Rev A
21
B0860AY – Rev A Appendix A. I/A Series Secure Environment Remote Watch
7. On the resulting page, the firewall rule is defined. Leave the default values except for
the following three fields:
a. For the Name field, enter: RW DAS
b. For the Remote address field, enter: Single and the IP Address of the Remote
Watch Server
c. For the Remote Service, enter: ftpdata (20)
Then, click OK.
8. After adding the rule, click Save in the lower-right hand corner to bring you back to
the main interface.
9. From the top menu, select the Systems icon and then System Tree from the sub-
menu below it. Expand the nodes in the tree view on the left side of the screen to find
the I/A Series stations (typically found in the I/A Computers node). Check the box
22
Appendix A. I/A Series Secure Environment Remote Watch Server Communications Setup B0860AY – Rev A
next to all of the stations that have DAS installed or will have DAS installed in the
future.
Figure 3-6. Select I/A Series Stations to Receive the New RW DAS Rule
23
B0860AY – Rev A Appendix A. I/A Series Secure Environment Remote Watch
11. From the resulting More Actions menu, click Wake Up Agents.
24
Appendix A. I/A Series Secure Environment Remote Watch Server Communications Setup B0860AY – Rev A
12. On the Wake Up McAfee Agent screen, click OK to accept the default values as shown.
25
B0860AY – Rev A Appendix A. I/A Series Secure Environment Remote Watch
26
Index
D
DAS 11
installation 1
software version 11
uninstall 10
DAS Installation
70 Series 1
Data transfer
RemoteWatch server 17
F
FIST Host 13
G
Global Customer Support Center vii
I
Installation
prerequisites 1
N
Nodebus 9
R
RemoteWatch Mailbox 13
Revision information vii
RW_DasExec_Pkg 2
RW_DasExec_Service viii, 10
RW_WinExec viii
RW_WinExec_Service viii
T
The MESH control network 9
V
Verifying data collection 15, 17
27
Invensys Operations Management
5601 Granite Parkway Suite 1000
Plano, TX 75024
United States of America
http://www.iom.invensys.com