Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

ION Setup and Port Forwarding Rules

Power Monitoring and Energy Automation NAM

This forum is created for the exchange of information and open dialogue regarding electrical power monitoring and energy automation products and services. Participants will have access to downloadable material as well as chat opportunities with subject matter experts.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Power Distribution NEMA
  • Power Monitoring and Energy Automation NAM
  • ION Setup and Port Forwarding Rules
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Charles_Murison
Picard Charles_Murison Picard
5
Michael_Neas
Ensign Michael_Neas Ensign
3
Robert_Lee
Admiral Robert_Lee Admiral
2
sesa29811
Crewman sesa29811 Crewman
1
View All
Related Products
product field
PowerLogic
PowerLogic ION8650 series

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Solved Go to Solution
Back to Power Monitoring and Energy Automation NAM
Solved
Bill_Mulkey
Crewman Bill_Mulkey
Crewman

Posted: ‎2022-02-05 10:04 AM

0 Likes
6
5708
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-05 10:04 AM

ION Setup and Port Forwarding Rules

Can ION Setup be configured to take into consideration Port Forwarding rules on routers? 

 

Scenario:

A Wireless Router with WAN IP of 10.10.10.10 and LAN IP of 192.168.1 is connected to two ION 8650 meters via ethernet.

Both meters are configured via ION Setup with IP addresses of 192.168.1.101 and 192.168.1.102, respectively. 

ION number 1 is set to listen for SSH/SFTP traffic on port 22.

ION number 2 is set to listen for SSH/SFTP traffic on port 22.

 

When connecting remotely to the meter via SSH/SFTP, a WAN IP address of 10.10.10.10 is used.

The router, by default, listens for SSH/SFTP traffic on port 22 and a port forwarding rule must be used to forward the traffic to the meters.

 

The Port Forwarding Rules look like this for SSH/SFTP:

ION-1 --- 10.10.10.10:2201 ---> 192.168.3.101:22

ION-2 --- 10.10.10.10:2202 ---> 192.168.3.102:22

 

It appears that ION Setup utilizes the value read from the meter configuration and uses that value when attempting a connection to the meter certificate server. Currently, there is no way to update ION Setup to use a different port after the connection is made and a third party application must be used to remotely manage SSL certificates in the meters. 

 

Maybe a new Protocol Tab under Device Properties in Network Viewer mode that sets the ports to be used for that particular meter could be implemented?

Labels
  • Labels:
  • ION 8650
  • Utility Metering
  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic

Accepted Solutions
Robert_Lee
Admiral Robert_Lee Admiral
Admiral

Posted: ‎2022-02-22 10:48 AM

In response to Bill_Mulkey
1 Like
1
5651
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-22 10:48 AM

Hi Bill,

 

I've gone ahead and made the preliminary changes to the next update of ION Setup which should be released next week so you should be able to try it out then.

 

After installation, if you use RegEdit with an admin level account, you should see a new registry key located in:

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Schneider Electric\ION Setup\3.2

SFTPPortNumber

default value should be 22

You should be able to modify it to common port number that your routers use and I would recommend that you leave the meter's programmed one to 22 (or if you have to modify it, switch it to match the one used by the router).  Any other number will likely make ION Setup connect to the wrong port number.

If this becomes an issue down the road, we'd likely have to make a change to the UI someplace to allow individual port designation which will likely get very messy.

As for the enterprise handling of certificates, Schneider is indeed looking how that can be easily managed at the corporate level and it is very unlikely ION Setup will be doing this.

It is more likely that this will become a future enhancement to EcoStruxure Cybersecurity Admin Expert (CAE) Security Administration Tool.  That team is aware of our need for an enterprise wide solution for certificate management and are looking into how to best handle that for metering products.

https://www.se.com/ww/en/product-range/63515-ecostruxure-cybersecurity-admin-expert/

See Answer In Context

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Replies 6
N4th4n13L
Lieutenant JG N4th4n13L Lieutenant JG
Lieutenant JG

Posted: ‎2022-02-06 02:17 PM

0 Likes
1
5697
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-06 02:17 PM

Hi Bill,

 

Have you tried changing the IP Port on the meter? If you set SSH/SFTP to listen to IP Port 2201 on the meter, ION Setup will detect the change. Set the Meter IP Port to match the IP Port setup in your port forwarding rules.

 

What I can't confirm is if ION Setup uses the IP address used to connect, or if it's reading the IP Address for the communication module when it tries to setup the SFTP connection.

 

The IP port setup can be viewed in the Ethernet connection modules under Setup Registers. Depending on how your GUI is setup, these values are present. We can also work with you to adjust the files so that it shows up in the setup assistant.

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Bill_Mulkey
Crewman Bill_Mulkey
Crewman

Posted: ‎2022-02-07 08:30 AM

In response to N4th4n13L
0 Likes
0
5692
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-07 08:30 AM

The issue is that our Port Forwarding rules are not setup like that. In order to support that, I would need unique configurations at every site that has more than one meter, not to mention the need to update the rules on 7000+ routers to make this work. The SSH/SFTP is really the only protocol that has this issue and it is because IONSetup isn't aware of the Port Forward rules.

 

Maybe a new Wizard could be added under Tools-->Diagnostics-->Tools for Certificate Management that would allow for the connection with a custom port number?  

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Robert_Lee
Admiral Robert_Lee Admiral
Admiral

Posted: ‎2022-02-09 09:36 AM

2 Likes
3
5685
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-09 09:36 AM

I'll best try and describe the issues here and possible future solutions. Presently the latest ION Setup is designed as a convenience to read how to transfer various files (web/IO upgrade, CID, COMTRADE, etc.) and in those instances where FTP/SFTP are utilized, it would communicate to the device and determine what IP Port the device is using. This allows when the device is set to a different port # than the expected standard port and will allow software to learn that port # directly from the device and connect using that port.

Ex. You can remap the SFTP port # the device uses to say port 44 instead of 22 for SSH and ION Setup would then open port 44 for SSH use.

However, this does NOT help in the instances I think you are speaking of when an intermediate device (router) is used to port forward to another port # which is located behind say a firewall.

Ex. ION Setup PC <=> Port X => Router <=> Port Y <=> Meter.

So to try and address this we need to tackle 2 issues.

In the instance where only the PC <=> Router requires a specific port # to be used, we could add a new default SFTP (or FTP) registry entry to allow users to specify which port # to use.

Ex. SFTPPortNumber = 44

That would allow where a router is being used to port forward.  However, I would likely have to put in some restrictions on its use to that the device could not be set to a different port # other than either the default port or the identical port #.  In the above example, the device SFTP port # would have to be either the default 22 or set to 44.  The reason being is at some point, ION Setup would have to use the assigned port # given to the meter where there is no port forwarding.

Another drawback with the above solution would be that all sites for that ION Setup would have to use the identical port # (i.e. all of you N routers in your system would have to be using the same port forwarding port #).

The only other means to do this would to be allow to individually assign each device a specific SFTP/FTP port # to be used from the software side.

Alternatively a user could use any SFTP/FTP software to do the transfers themselves although it isn't as convenient and in some cases like upgrade there is no feedback via those client software.

If everyone thinks the above is an acceptable solution, I'll try and implement something in an upcoming update.

By the way, we've also implemented a custom solution for the exact same issue for the ION Port but have done so for each device.  In the network viewer, you will now be able to specify the protocol type when specifying a custom port number (ex. if say you have port forwarding on port 5500 => 7700, you will be able to specify whether that 5500 is ION or the upcoming TLS if supported by the firmware).

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Bill_Mulkey
Crewman Bill_Mulkey
Crewman

Posted: ‎2022-02-18 04:34 AM

In response to Robert_Lee
0 Likes
2
5667
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-18 04:34 AM

@Robert_Lee Thanks for the detailed reply. Currently, our only solution is to utilize a third party sftp/ftp file transfer utility or directly connect to the ethernet port.

 

With the myriad of possible network configurations, it would probably be best for the end user to manage this from the router side and have a numerical equivalent port to port forwarding rule to support the sftp/ftp data connections.

 

I would like to point out, that at some point, TLS certificate management at an Enterprise level will become an issue and there is currently no way, that I am aware of, to manage this via PME or other Schneider supported applications. Is there any ongoing conversation about supporting TLS certificate management at an Enterprise level? 

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Robert_Lee
Admiral Robert_Lee Admiral
Admiral

Posted: ‎2022-02-22 10:48 AM

In response to Bill_Mulkey
1 Like
1
5652
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-02-22 10:48 AM

Hi Bill,

 

I've gone ahead and made the preliminary changes to the next update of ION Setup which should be released next week so you should be able to try it out then.

 

After installation, if you use RegEdit with an admin level account, you should see a new registry key located in:

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Schneider Electric\ION Setup\3.2

SFTPPortNumber

default value should be 22

You should be able to modify it to common port number that your routers use and I would recommend that you leave the meter's programmed one to 22 (or if you have to modify it, switch it to match the one used by the router).  Any other number will likely make ION Setup connect to the wrong port number.

If this becomes an issue down the road, we'd likely have to make a change to the UI someplace to allow individual port designation which will likely get very messy.

As for the enterprise handling of certificates, Schneider is indeed looking how that can be easily managed at the corporate level and it is very unlikely ION Setup will be doing this.

It is more likely that this will become a future enhancement to EcoStruxure Cybersecurity Admin Expert (CAE) Security Administration Tool.  That team is aware of our need for an enterprise wide solution for certificate management and are looking into how to best handle that for metering products.

https://www.se.com/ww/en/product-range/63515-ecostruxure-cybersecurity-admin-expert/

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Bill_Mulkey
Crewman Bill_Mulkey
Crewman

Posted: ‎2022-03-07 04:52 AM

In response to Robert_Lee
0 Likes
0
5633
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-03-07 04:52 AM

@Robert_Lee 

Downloading the latest .exe now. Appreciate the fast response and the information on the EcoStruxure Cybersecurity Admin Expert. It looks very promising from an enterprise security management perspective.

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of