Pepperl Fuchs VisuNet RM Shell 5 Users guide

VisuNet RM Shell 5
Manual
With regard to the supply of products, the current issue of the following document is applicable: The General Terms of Delivery for Products and Services of the Electrical Industry, published by the Central Association of the Electrical Industry (Zentralverband Elektrotechnik und Elektroindustrie (ZVEI) e.V.) in its most recent version as well as the supplementary clause: "Expanded reservation of proprietor­ship"
Worldwide
Lilienthalstr. 200
68307 Mannheim
Germany
Phone: +49 621 776 - 0
E-mail: info@de.pepperl-fuchs.com
North American Headquarters
Pepperl+Fuchs Inc.
1600 Enterprise Parkway
Twinsburg, Ohio 44087
USA
Phone: +1 330 425-3555
E-mail: sales@us.pepperl-fuchs.com
Asia Headquarters
Pepperl+Fuchs Pte. Ltd.
P+F Building
18 Ayer Rajah Crescent
Singapore 139942
Phone: +65 6779-9091
E-mail: sales@sg.pepperl-fuchs.com
https://www.pepperl-fuchs.com
VisuNet RM Shell 5
Contents
1 Introduction................................................................................................................ 6
1.1 Note................................................................................................................. 6
1.2 Content of this Document............................................................................. 6
1.3 Target Group, Personnel ............................................................................... 6
1.4 Symbols Used ................................................................................................ 7
2 VisuNet RM ShellAn Overview.............................................................................. 8
2.1 Update Architecture ......................................................................................9
2.2 Factory Reset ................................................................................................ 9
2.3 Program Features ........................................................................................ 10
2.4 Licencing ...................................................................................................... 12
2.5 Installation.................................................................................................... 12
2.5.1 First Start Wizard ............................................................................. 13
2.6 VisuNet RM Shell User Roles...................................................................... 27
3 VisuNet RM Shell 5 User Interface .........................................................................28
3.1 Unified Write Filter ....................................................................................... 31
4 About App................................................................................................................. 33
4.1 Hardware ......................................................................................................34
4.2 Licenses and Terms of Use......................................................................... 34
4.3 Software........................................................................................................ 35
5 Profiles Management App ...................................................................................... 36
5.1 Connection Features ...................................................................................39
5.2 RDP Settings ................................................................................................ 47
5.3 Raritan KVM Settings ..................................................................................50
5.4 VisuNet Desktop Sharing Settings............................................................. 52
5.5 VNC Settings ................................................................................................ 61
5.6 Web Browser Settings (Chrome)................................................................ 64
5.7 Web Browser Settings (Internet Explorer) ................................................ 64
6 App Management..................................................................................................... 66
6.1 Wedge App ................................................................................................... 69
6.2 Process Explorer App ................................................................................. 71
7 System Settings App............................................................................................... 72
2020-12
3
VisuNet RM Shell 5
Contents
7.1 General Settings ..........................................................................................74
7.2 Desktop Sharing ..........................................................................................79
7.3 Dialog Filter .................................................................................................. 81
7.4 Display Settings ...........................................................................................83
7.4.1 Configuring a Single Monitor ............................................................ 83
7.4.2 Configuring Multiple Monitors........................................................... 83
7.5 Emerson DRDC Settings .............................................................................85
7.6 Frontkey Settings......................................................................................... 86
7.7 Keyboard Settings .......................................................................................88
7.8 Network.........................................................................................................89
7.9 Pointing Device Settings .............................................................................91
7.10 Proxy Settings ..............................................................................................92
7.11 Scheduler......................................................................................................94
7.12 Security.........................................................................................................95
7.13 Touch Settings..............................................................................................98
7.14 Update...........................................................................................................99
7.15 VisuNet CC Settings ..................................................................................103
7.16 Wedge Configuration for Scanners With Serial Interface......................104
8 System Tools App ..................................................................................................108
8.1 Clean Lock..................................................................................................108
8.2 Network Adapter Information ...................................................................109
8.3 Network NSLookup Tool ............................................................................109
8.4 Network Ping Tool ......................................................................................110
9 Factory Reset .........................................................................................................111
9.1 Change Password ......................................................................................114
9.2 Image Management ...................................................................................115
9.3 Network Settings........................................................................................117
9.4 Device Info..................................................................................................118
10 How-Tos...................................................................................................................119
10.1 Connecting an RM / BTC with a PC via RDP............................................119
10.2 Increasing RDP Reactivity and Performance ..........................................127
10.3 Configuring Auto-Logoff from Session (Session Timeout) with RDP ..127
4
2020-12
VisuNet RM Shell 5
Contents
10.4 Configuring a Multi-Monitor (Extended Desktop) Setup with RDP and
Box Thin Client BTC................................................................................... 127
10.5 Installing McAfee Endpoint Security .......................................................128
10.6 Pairing a Bluetooth® Device..................................................................... 131
10.7 Importing Host Certificates ...................................................................... 134
10.8 Enable TLS 1.0 (for Raritan DKX2-101 or older Webservers)................ 144
11 Appendix ................................................................................................................147
11.1 Open Network Ports .................................................................................. 147
11.2 Shell freezes on RDP log-on screen ........................................................ 147
11.3 Pepperl+Fuchs SE End User License Agreement (EULA).....................147
2020-12
5
VisuNet RM Shell 5
Introduction
1 Introduction
1.1 Note
This manual revision was released with VisuNet® RM Shell version 5.5 but also covers all pre­vious versions of VisuNet RM Shell 5.
1.2 Content of this Document
This document contains information required to use the product in the relevant phases of the product life cycle. This may include information on the following:
Product identification
Delivery, transport, and storage
Mounting and installation
Commissioning and operation
Maintenance and repair
Troubleshooting
Dismounting
Disposal
Note
For full information on the product, refer to the further documentation on the Internet at www.pepperl-fuchs.com.
The documentation comprises the following parts:
This document
Datasheet
In addition, the documentation may comprise the following parts, if applicable:
EU-type examination certificate
EU declaration of conformity
Attestation of conformity
Certificates
Control drawings
Instruction manual
Other documents
1.3 Target Group, Personnel
Responsibility for planning, assembly, commissioning, operation, maintenance, and dismount­ing lies with the plant operator.
Only appropriately trained and qualified personnel may carry out mounting, installation, com­missioning, operation, maintenance, and dismounting of the product. The personnel must have read and understood the instruction manual and the further documentation.
Prior to using the product make yourself familiar with it. Read the document carefully.
6
2020-12
VisuNet RM Shell 5
Introduction
1.4 Symbols Used
This document contains symbols for the identification of warning messages and of informative messages.
Warning Messages
You will find warning messages, whenever dangers may arise from your actions. It is mandatory that you observe these warning messages for your personal safety and in order to avoid prop­erty damage.
Depending on the risk level, the warning messages are displayed in descending order as fol­lows:
Danger!
This symbol indicates an imminent danger.
Non-observance will result in personal injury or death.
Warning!
This symbol indicates a possible fault or danger.
Non-observance may cause personal injury or serious property damage.
Caution!
This symbol indicates a possible fault.
Non-observance could interrupt the device and any connected systems and plants, or result in their complete failure.
Informative Symbols
Note
This symbol brings important information to your attention.
Action
This symbol indicates a paragraph with instructions. You are prompted to perform an action or a sequence of actions.
2020-12
7
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2 VisuNet RM ShellAn Overview
Pepperl+Fuchs VisuNet Remote Monitors (RMs) and Box Thin Clients (BTC) are industrial­grade thin client solutions that provide a simplified, modern user interface for operators. The firmware of an RM, called VisuNet RM Shell (RM Shell), enables users to easily access appli­cations that run on a host system (e.g., workstation PC or server) via Ethernet.
With RM Shell, the latest versions of common remote protocols, such as RDP 10 or VNC are supported. With these protocols, the RMs / BTCs can be easily integrated into all major pro­cess control systemswhether they are virtualized or conventional workstation-based setups.
Further, RM Shell has a tailored user interface, which only shows the important system aspects that are relevant for the configuration of the RM / BTC. This makes the integration of an RM / BTC into the process control system simpler than ever before. Configuring a new RDP connec­tion, for example, can be done in a few steps. This is achieved via a consistent, touchscreen­optimized design across all protocol editors.
RM Shell also helps increase process stability. It ensures a stable connection to the process control host system and an error-free display of the process pictures.
The auto-connect function can be used to configure RMs / BTCs in such a way that they auto­matically establish a connection to a designated host system, without any further intervention from the user. While temporarily interrupted connections are automatically reestablished, backup hosts can be specified in RM Shell to which an RM / BTC can automatically connect if a host system fails.
In addition to support for remote protocols, RM Shell also offers a restricted web browser fea­ture, which can be enabled via an optional professional license key. This allows fixed addresses to web applications like web-based Manufacturing Execution Systems (MES) to be defined. Users with administrator rights can restrict operator access to these pre-defined web­sites. This increases system security and reduces the risk of malware infiltration.
This manual describes the features and functions of RM Shell in detail.
2020-12
8
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2.1 Update Architecture
The RM Shell architecture consists of two partitions.
The main elements of partition C are the RM Shell as well as Device Drivers and Service Appli­cations. All components are based on Windows 10 IOT LTSC 2019 or Windows 10 IOT LTSB
2016.
Updates regarding Windows security patches, functional updates or RM Shell security updates effect partition C. Only single components are affected and will be overwritten depending on the update. Whenever a factory reset is performed all data of partition C will be overwritten.
The Factory Reset Update is an own package which will be provided and imported via Shell.
Figure 2.1 Architecture of the RM Shell
2.2 Factory Reset
With Factory Reset Version No. 6.0 and newer, the image is no longer available locally on Parti­tion D which increases the storage and speed. With Factory Reset Version >6.0 and RM Shell version >5.3 it is possible to capture your own backup image. We strongly recommend to cre­ate your own backup image and store it on your network drive.
Feature Description Notes
Pepperl+Fuchs Factory Reset Image
Backup Image Own captured Backup Image, which
2020-12
Available for each specific device. The Pepperl+Fuchs default settings will be applied back to your device. With Factory Reset 6.0 and newer the image wont be stored on the device any more.
can only be applied on the same device with the identical serial num­ber. The backup image can be used to restore a specific state of a device.
Get in contact with your local sales support Caution! After applying the Pep­perl+Fuchs image the setup of the device needs to be performed locally! The RM Shell first start wiz­ard will guide you through the most important initial configuration steps. Please refer to the First Start Wizard Chapter in the RM Shell Manual for further information.
Has to be captured by the customer in the RM Shell Factory Reset or via VisuNet CC - Device Backup in advance. Note: VisuNet CC might not be able to find the device when changes of the computer name or the Network settings have been done after cap­turing the image.
9
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2.3 Program Features
Feature Description Notes
Operating system Based on Microsoft® Windows® 10
Modern, simpli­fied user interface
Easy Set-up Designed to be used intuitive.
Auto-connect Allows you to configure the RM to
Connection loss detection
Backup connec­tion
Centralized man­agement of all RMs
Remote Protocols and Clients
MS RDP Latest version of Microsoft Remote
VNC VNC client, compatible with multiple
Restricted web browser, based on Internet Explorer
Restricted web browser, based on Chrome
Desktop Sharing Displays the desktop of other RMs
Raritan KVM Client allows you to directly connect
DRDC Allows you to directly connect from a
Security
Unified write filter Unified write filter Protects the drive
Scheduler Enables 24/7 use of unified write fil-
IoT Enterprise LTSC 2019 or Micro­soft® Windows® 10 IoT Enterprise LTSB 2016
Touch-optimized, modern UI
Additional an initial setup wizard guides you through the most import­ant steps when configuring an RM for the first time
automatically connect to host sys­tems after startup
The RM detects network failures or if a host is unavailable
In case of a network or host failure, an RM can automatically connect to a backup host system
RMs can be managed and config­ured centrally via VisuNet Control Center.
Desktop Protocol
VNC servers (e.g., TightVNC and UltraVNC)
Fast HTML browser that uses Inter­net Explorer to render websites. Operators can be restricted to visit­ing only specified websites.
Fast HTML5 browser that uses the Google Chrome. Operators can be restricted to visiting only specified websites.
with enabled Desktop Sharing Server
to Raritan Dominion KX IV-101 KVM­over-IP-Switch
VisuNet Remote Monitor to a virtual­ized Emerson DeltaV system
from persistent storage of malicious software
ter without buffer overflow. Periodic reboots can be planned to occur when device is not in use
Improved feature in RM Shell 5
Improved feature in RM Shell 5
Optional CC license feature. Please find further information at pepperl-fuchs.com/hmi
Optional PRO license feature
Optional PRO license feature
Optional PRO license feature
Optional PRO license feature
Optional DRDC license feature
New feature in RM Shell 5
New feature in RM Shell 5
10
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Feature Description Notes
Antivirus soft­ware support
Dialog filter Closes application windows that are
Firewall Windows firewall protects RMs from
USB pen drive lock
Updates Pepperl+Fuchs provides regularly
Capture Backup Image
Apply Backup Image
Additional Security Features
Security Alerts Pepperl+Fuchs investigates all
Thin Client Soft­ware Update Ser­vice
Advanced Features
Administrator access to Win­dows® Explorer
Clean lock Allows you to temporarily lock the
Network test tools A set of network test tools (e.g., ping
Task Switcher Switch between multiple remote
Extended desk­top support for industrial Box Thin Client BTC
Wireless LAN configuration support
Administrators can install third-party virus protection software. Windows defender is activated by default
not whitelisted and blocks user access to the file system
network attacks
USB lockdown prevents access of storage media like USB sticks on the RMs
updates in terms of security patches and functional updates.
Capture your individual device set­tings of the RM/BTC as a backup image and apply when required back on to the device.
Apply your individual device settings of the RM/BTC which were earlier captured as a backup image and overwrite the full windows partition.
reports of security vulnerabilities affecting Pepperl+Fuchs products and services.
Let us inform you when either secu­rity or functionality updates are avail­able.
Allows administrators to install third­party applications and adjust advanced system Settings. Systems can be integrated in the domain.
input devices (e.g., touchscreen) when cleaning the device to avoid accidental inputs
tool) provide support while commis­sioning an RM
connections and apps that are run­ning on the RM.
Remote profile connections can be assigned to different monitors that are connected to the industrial Box Thin Client BTC
Wireless LAN connections can be managed in RM Shell (requires built­in wireless LAN adapter)
New feature in RM Shell 5
New feature in RM Shell 5
Please check for updates regularly or use our Thin Client Software Update Service to be informed by Pepperl+Fuchs.
New feature of RM Shell 5.3 and newer, and Factory Reset 6.0 Note: RM Shell 5.3 (or newer) in combination with Factory Reset 6.0 (or newer) is required.
New feature of RM Shell 5.3 and newer, and Factory Reset 6.0 Note: RM Shell 5.3 (or newer) in combination with Factory Reset 6.0 (or newer) is required.
Cyber Security and Reporting, Subscribe to our RSS feed to stay updated on Cyber Security Informa­tion from Pepperl+Fuchs
https://www.pepperl­fuchs.com/global/en/33314.htm
New feature in RM Shell 5
2020-12
11
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Feature Description Notes
Process explorer Allows you to diagnose an RM and
Desktop Sharing Server
2.4 Licencing
Ordering Information
When purchasing Pepperl+Fuchs RMs or BTCs RM Shell is already installed and the scope of delivery includes RM Shell licenses.
Part No. Model Number
548289 VISUNET-RM-SHELL5-PRO
548294 VISUNET-RM-SHELL5-DRDC
548284 VISUNET-RM-SHELL5-CC
monitor how much RAM, storage, and CPU are being used by local processes.
Clone an RM and display its desktop on other RMs
Note
License Bundles
Contact your local Pepperl+Fuchs sales representative for information about license bundles.
2.5 Installation
A Wizard guides you through the first steps of the installation of the RM Shell. After completing the First Start Wizard the RM Shell will be started in the Operator Role.
12
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2.5.1 First Start Wizard
When you start a device with VisuNet RM Shell for the first time, the first-start wizard appears on your screen. This wizard guides you through the most important initial configuration steps.
Configure your basic system settings and click "Next." Accept the terms and conditions on the next window to start using VisuNet RM Shell.
Figure 2.2
If your VisuNet RM Shell 5 is based on Windows® 10 IoT Enterprise 2019 LTSC, you also must perform the following steps:
2020-12
13
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Set the correct Region
1.
Click "Set Region" to enter the advanced Microsoft® settings.
Figure 2.3
2020-12
14
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2.
Navigate to the "Region" tab on the left side
Figure 2.4
2020-12
15
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
3.
Pick the required region from the drop-down list.
Figure 2.5
4.
Close the dialog
16
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Add Keyboard Layout
Click "Set Language and Keyboard" (2.) to enter the advanced Microsoft® settings, then navi­gate to "Language"
1.
Select the installed language "English (United States)" and click the "Options" button:
Figure 2.6
2020-12
17
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
2.
Under the "Keyboards" section, click the Add a keyboard button
Figure 2.7
18
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
3.
Select the new keyboard layout
Figure 2.8
2020-12
19
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
4.
Remove the US keyboard layout in the last step
Figure 2.9
5.
Close the dialog.
6.
The input language in the First Start Wizard will not change, since only the keyboard layout is affected by this change.
The Wizard guides you through the following:
20
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Computer Name
Changes the computer name of your Windows® device as well.
The updated computer name is only applied after a restart.
Figure 2.10 Computer Name
2020-12
21
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Setup Network
All information about the local RM / BTCs network adapter hardware is shown.
You can edit the network adapter name according to your needs.
Use this option to enable/disable DHCP (Dynamic Host Configuration Protocol).
With DHCP, you can integrate the RM / BTC into an existing network without further manual configuration. Settings like IP Address, Subnet Mask, Default Gateway, and DNS Server are addressed then assigned automatically to the RM / BTC. However, you can set up all these parameters manually by disabling the DHCP option.
22
Figure 2.11 Setup Network
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Setup Touchscreen
Select the right touch settings, if your RM is equipped with a touch screen option. For further information refer to Chapter 7.13.
Figure 2.12
2020-12
23
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Password Settings
Engineer Password: no default password is set. To ensure the highest level of security, the
Administrator and Engineer user roles must be password protected.
Administrator Password: no default password is set. To ensure the highest level of security, the Administrator and Engineer user roles must be password protected.
Windows® Password: accesses the Windows® password. The Windows® password is dis- played in encrypted form only.
Tip
We highly recommend changing the Windows® password.
Factory Reset Password: Change the Factory Reset password. The password is hidden via dots and must have at least 6 characters. The field cannot be blank.
24
Figure 2.13 Password Settings
Note
In case of restoring a backup or clone image or if you changed the password in the Factory Reset UI the Factory Reset Password option will not appear.
2020-12
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
License Agreement
You have to accept the License agreement to proceed further.
Figure 2.14 License Agreement
Note
Correct Information
Ensure that you set the correct information on this wizard. The information should be valid for the location where the VisuNet RM Shell will be installed. The correct time is required for encrypted communication and to ensure reliable communication.
After completing the First Starting Wizard, the VisuNet RM Shell will be started in the Operator Role. To configure further settings switch to the Administrator role.
2020-12
25
VisuNet RM Shell 5
VisuNet RM Shell—An Overview
Figure 2.15
VisuNet RM Shell does not come with any pre-created connection profiles. For this reason, the profiles list is empty when you start VisuNet RM Shell for the first time.
26
2020-12
VisuNet RM Shell 5
full
user rights
limited
user rights
A
E
O
VisuNet RM Shell—An Overview
2.6 VisuNet RM Shell User Roles
The VisuNet RM Shell security concept is based on 3 user roles that are structured hierarchi­cally. Each user role has different rights.
Figure 2.16 Concept of user rights: O(perator), E(ngineer) and A(dministrator)
User Role Description
Operator (O) Operators are standard users. They can only
Engineer (E) Engineers are responsible for RM setup and
Administrator (A) Administrators have all rights of operators and
execute predefined profiles. Operators have no access to RM settings.
integration. They have acces to profiles, sys­tem settings, and applications (create, edit, and delete profiles).
engineers. In addition, administrators can access Windows®Explorer to install third-
party applications and drivers and adjust advanced settings outside of RM Shell.
Warning!
Password Protection
To ensure the highest level of security, the Administrator and Engineer user roles must be pass­word protected. Access to the Administrator and Engineer user roles should be permitted only to employees who are familiar with the administration of thin clients. There is no factory default password setting for any of the user roles.
The passwords can be set in the first start wizard. In the administrator role, the passwords can be adjusted or set in the Security Settings
Note
Compatibility of Third-Party Software
RM Shell is qualified to work with software that is shipped with Pepperl+Fuchs VisuNet devices. Pepperl+Fuchs does not guarantee the functionality of third-party software. Customers are responsible for ensuring compatibility with any third-party software.
2020-12
27
VisuNet RM Shell 5
1
5
4
2
6
3
VisuNet RM Shell 5 User Interface
3 VisuNet RM Shell 5 User Interface
Home Screen Features (Administrator Role, after individual profiles have been created)
The home screen is divided into 6 basic areas:
Figure 3.1 RM Shell 5 home screen
1 System functions
2 Unified write filter status
3 User-role information
4 Fly-in messages
5 Profiles
6 Applications
28
2020-12
VisuNet RM Shell 5
VisuNet RM Shell 5 User Interface
1. System Functions
Icon Description
RM Shell Task Switcher The RM Shell Task Switcher allows you to switch between open connection profiles and applications running on an RM / BTC. To open the Task Switcher, click the icon or press the hotkey CTRL+Alt+SCROLL on the keyboard. The Task Switcher shows a window overview of all open remote connections and apps. You can change the application by selecting one of the displayed remote connections or apps. Use the number keys 1 to 9 to switch within the profiles. Click 0 to return to the VisuNet RM Shell Home screen.
Switch user role Choose between Operator, Engineer, or Administrator
Touchscreen keyboard Shows the touchscreen keyboard on the screen.
Preconfigured power options, such as:
Protect disk and restart
Restart
Shutdown (Some devices need a power
reset to be able to boot again)
Turn off display
The power options can be set by the Engineer and Administrator user roles. The Operator user role is only allowed to run the preconfig­ured options.
2. Unified Write Filter Status
This area of the home screen indicates whether the unified write filter is enabled. For more information on the unified write filter, see chapter 3.1.
3. User-Role Information
When an Administrator or Engineer user is logged in, the signed-in user role is indicated at the top of the home screen. If an Operator user is logged in, this information is not displayed.
4. Fly-In Messages
At the top-right corner of the home screen, fly-in messages show error messages or status information when certain events occur. Click on the fly-in messages to make them disappear. The messages automatically disappear after 30 seconds.
5. Profiles
This section shows all profiles that have been created locally. Every profile is represented by a tile that displays the profile type (e.g., "RDP," "VNC"), profile name (e.g., "RDP - 2"), and con­nection status (e.g., "connected," "disconnected").
The following symbols indicate the different profile types:
2020-12
29
VisuNet RM Shell 5
VisuNet RM Shell 5 User Interface
RDP
Desktop Sharing
1
VNC
Web Browser URL (Chrome)
Web browser URL (IE)
Raritan KVM
1. PRO license required to unlock feature
1
1
1
Profile status information is indicated at the bottom-left corner of each profile tile:
Status Description
Idle Initial status after a profile has
been created
Disconnected Profile is not connected to a
host
Connected Profile is connected to a host
PC. A green status bar at the top of the profile tile is visible.
30
2020-12
Loading...
+ 122 hidden pages