Siemens Remote Services
Siemens Remote Services
Siemens Remote Services
n
a
h
c
e
D
Planning Guide
System
10021770
10140720
10094012
10093973
10093962
10093961
10093902
10093864
10093858
10093754
07728392
07728350
07727717
07555373
07555365
07555357
07414803
07413078
07412807
07152494
07152478
07152460
07151066
07129534
07009165
07008605
07008530
07007755
05917054
05904656
05904649
05904466
05904441
05904433
05903872
05902064
05895151
05895003
05894873
05568386
04815549
03844581
© Siemens AG 2005
The reproduction, transmission or use
of this document or its contents is not
permitted without express written
authority. Offenders will be liable for
damages. All rights, including rights
created by patent grant or registration
of a utility model or design, are
reserved.
Disclaimer
The installation and service of equipment described herein is to be performed by qualified
personnel who are employed by Siemens or one of its affiliates or who are otherwise
authorized by Siemens or one of its affiliates to provide such services.
Assemblers and other persons who are not employed by or otherwise directly affiliated
with or authorized by Siemens or one of its affiliates are directed to contact one of the
local offices of Siemens or one of its affiliates before attempting installation or service pro-
cedures.
General remarks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Abbreviations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Connection Concept . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Project Manager Tasks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
"SRS Final Configuration" Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Ordering Information. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Router Selection Criteria. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Modem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Order Form (do not order by e-mail). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Network Switch. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Integration of the Router into the LAN Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
LAN Side. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
WAN Side . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Technical Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Cisco 801/805 Routers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Cisco 1721 Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Cisco 1603 Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Router Pix Firewall 501 xDSL (IPSEC). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Connection Configuration Package for the Central Service Contractor . . . . . . . . . . 20
Security Mechanisms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
CHAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Call-back . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
NAT (Network Address Translation) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Encryption (IPSEC). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Fire Wall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
User Administration and Monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Contact Partners for the Project Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
General SRS Process: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Technical Router Details: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Abbreviations 0
As of February 1, 2004, a simplified process was established for connecting AX, CT, MR,
and SP modalities. All other modalities continue to use the previous process.
Project Manager tasks for the AX, CT, MR and SP modalities:
• The SRS Checklist is now part of the System Checklist and therefore have to be filled
out together (the Serial Number is no longer required).
• If the customer requires connection via his router/firewall or an SRS router already ex-
ists, nothing further needs to be done.
• Plan/order the required connections (ISDN/analog; Ethernet, Power): connect the rout-
er in accordance with the installation instructions (the router is shipped along with the
system)
Project Manager tasks / procedure for all other modalities:
- If an SRS router already exists or the customer requires connection via his router/fire
wall, continue with the last point.
- Plan/order the required connections (ISDN/Analog; Ethernet; Power).
- Order the appropriate router from CSML Material Logistics (see "order form", Page 2-
3), including an analog modem, if required. For details, see Page 2-2.
- Connect the router in accordance with the installation instructions (should be ready
by the time the system is delivered).
- Return the SRS Checklist to the central service contractor for the final router configu-
ration (see the Checklist) or to your local USC, depending on who is to perform the fi-
nal configuration.
NOTE Until further notice, the final router configuration will be performed
exclusively by the central service contractor.
Support from the central service contractor is required if the cus-
tomer has a fire wall.
Ordering Information 0
• ISDN or analog (please note: analog routers are considered the "exception", ISDN rout-
ers are the preferred choice).
• Number of medical systems / components (<=5 / >5; see overview below)
• Data encryption (general and patient-related)
NOTE For the core countries in Europe as well as the USA and Canada,
only order routers with encryption.
For other countries, the customer’s wishes must be observed.
Number of Encryption
Technology Router Part No.
Systems
ISDN >5 No RDIAG Router 1603/1721 ISDN 73 82 802
RDIAG Router 1603/1721 ISDN
ISDN >5 Yes 73 82 810
IPSEC
ISDN <=5 No RDIAG Router 801 ISDN 73 82 869
ISDN <=5 Yes RDIAG Router 801 ISDN IPSEC 73 82 877
Analog1 >5 No RDIAG Router 1603/1721 Analog 73 82 828
RDIAG Router 1603/1721 Analog
Analog1 >5 Yes 73 82 836
IPSEC
Analog1 <=5 No RDIAG Router 805 Analog 73 82 844
RDIAG Router 805 Analog
Analog1 <=5 Yes 73 82 851
IPSEC
RDIAG Router Pix Firewall 501
DSL any Yes 84 00 793
IPSEC
1. In cases where there is an analog router connection, a country-specific modem also has to be or-
dered.
Modem 0
Countries not listed must obtain the modem locally. Only the Multitech model MTX 2834
ZDX modem is permitted.
Tab. 1
Tab. 2
Delivery Date:
Account No. to be charged:
Remarks "No charge in accordance with SRS Planning
Guide of 06/01"
Modification (Serial No.)
Misc.
Tab. 3
SAP Number:
Anticipated delivery date ex. CSML
Remarks
Network Switch 0
If a local LAN is not available, a small LAN (8 connections) can be set up using a
SWITCH.
NOTE Routers and modems are not invoiced if they are used exclusively
for remote service.
If the routers are used for other purposes, the country organiza-
tions will be charged for any costs incurred.
Prerequisites
• Both areas, i.e., the system and the router, have to access the same IP network.
• Power cables (two cables are included in the router package shipment: 110/240V;
50/60Hz). Plug-in connectors for Europe and USA are included. For other connections,
the plug-in connectors have to be purchased locally.
LAN Side 0
WAN Side 0
• DSL with DSL modem: The DSL cable is part of the Pix Firewall package.
• ISDN: The ISDN cable is part of the router package (3m 10 BaseT, twisted pair, 1:1 ca-
ble).
• Analog (if ISDN not possible, a direct analog connection must be provided for dialing).
NOTE There is a toll-free 0800 number available to dial the RDIAG server.
This is possible only if IDD is supported by the provider.
In TK systems, have the country-specific area code enabled (e.g.:
Europe int. - 008000; Germany - 0800).
Europe
Germany, UK and others; NET3 ISDN switches basic-net3 Euro ISDN S0
Norway NET3 switches (phase 1) basic-nwnet3
France VN2 ISDN switches vn2
France VN3 ISDN switches vn3
Japan
Japan NTT ISDN switches ntt
North America
AT&T basic rate switches basic-5ess
NT DMS-100 basic rate switches basic-dms100
National ISDN-1 switches basic-ni1
New Zealand
New Zealand Net3 switches basic-nznet3
DSL Requirements
Bandwidth
If anti-virus pattern distribution is enabled, the bandwidth should be at least 768/128k
upstream/downstream.
IP address requirements
An Internet routeable IP address is required.
It has to be static and always be the same IP address.
The address must not be translated anywhere in the provider's network and be not part of
the
addresses intended for private use.
Flat Rate
A connection that is always on is required for SRS. For financial reasons, a flat rate with-
out any volume and time limit is required.
Technical Specifications 0
Physical Specifications
• Dimensions (H x W x D)
- 5.1 x 24.6 x 21.1 cm (2.0 x 8.3 x 9.9 inches)
• Weight
- 0.66 kg
Environmental Specifications
• Temperature
• Relative humidity
Power Supply
• External tabletop power supply:
• Weight
• Power Supply
• Operating Specifications
Physical Specifications
• Dimensions (H x W x D)
- 5.56 x 22.02 x 28.32 cm (5.56 x 11.15 x 8.67 inch)
• Weight
- 0.82 kg
Environmental Specifications
• Temperature
• Relative humidity
- At operating temperature: 10% to 85%
Power Supply
Switch 0
• Type
- ATI AT FS708 10/100Mbps Auto Negotiation
MDI/MDI-X Switch for Port 8
• Dimensions
- 249mm x 114mm x 38mm / 1.95 kg, without fan
Hardware Requirements
Power
Range Line Voltage: 100V to 240V AC
Nominal Line Voltage: 100V to 240V AC
Current: 0.051 Amps (at 115V)
Frequency: 50-60 Hz, single phase
Power cord: The device is delivered with a standard power cord for Europe and the U.S.
If your country uses a different power cord, it has to be supplied locally.
- The interface between the customer fire wall and the remote server is clarified and
configured.
• VPN
VPN (Virtual Private Network)
- Access via Internet must be available or established. The connection via Internet is
possible using VPN technology. At this time, connection is made via the customer’s
own systems (router, fire wall, etc.). These must support VPN. IPSEC is used as the
VPN Protocol. In the future, VPN via ADSL will be offered in some countries. When it
becomes available, it will be absolutely necessary for the Internet provider to have a
static address.
• PIX
Siemens DSL Router or VPN Router
Basically, different networks have different security requirements. Each network has to be
considered inbdividually to ensure that a reasonable security policy is implemented. If the
local network (LAN) is accessible to the public via appropriate access nodes, there is a
significantly increased risk of unauthorized data access. To minimize this risk, access
products such as ISDN routers use standardized protocols for authentication and encryp-
tion.
• Analog
- Call-back
- Authentication of PPP CHAP
- IPSEC Encryption
• ISDN
- Calling Line Identification (CLI)
- Analog / ISDN
- Authentication CHAP
- IPSEC Encryption
CLI 0
Calling line identification (CLI) (also: caller ID) permits an incoming call to be checked for
its origin telephone number. Thus, a criterion for access to the nbetwork may be estab-
lished (in this case: D-channel of the ISDN). CLI requires a switching station that supports
call number transfer (with Euro ISDN Standard).
CHAP 0
CHAP is used to authenticate the two partners when a connection is established. The
passwords are transferred in encrypted format. Two procedures are available: "local“ and
"remote“ authentication relative to the caller. Many manufacturers support only remote
authentication, i.e. the caller authenticates himself only with the called party. With local
authentication, the party called must also authenticate himself with the caller.
Call-back 0
If the router is called, it first attempts to authenticate the partner via PPP CHAP (see stan-
dard options). If the partner is recognized, the connection is terminated and a call-back is
initiated. This prevents a stolen password from being used from any telephone line.
If certain IP address ranges that SIEMENS must use for the RDIAG server are specified
by the customer, IP address translation (NAT) is also required. NAT (Network Address
Translation) makes it possible for "private“ networks with unofficial address ranges to link
to e.g. the Internet. Translation of the addresses is done directly in the components (rout-
ers) that connect the two networks to each other. The particular LAN is hidden to the out-
side by the router, all data appears to come from the router itself. This requirement for
NAT usually exists when the customer is operating a fire wall.
Encryption (IPSEC) 0
With this option, the entire data stream that goes over public lines is encrypted. The
IPSEC standard with a code length of 128 bits is always used. Components from the
same manufacturer have to be used on both ends because the standard currently permits
limited interpretation, and thus limited implementation parameters for manufacturers.
Fire Wall 0
Special requirements, which are listed in the SRS Final Configuration checklist, exist for
operation of RDIAG through a fire wall system. (Chapter 5.3 - Customer Administrated
Routers).
Siemens' central remote server can determine at any time when and which users have
logged into the system. For more information please contact the SRS Helpdesk.
With every access, three independent security levels have to be passed with the network
versions:
1. Router: Our specialist in the UPTIME Service Center requires the user name, the pass-
word, and (depending on what has been agreed) a call-back to pass this requirement.
2. Fire wall (optional): Only known users and procedures (Telnet, HTTP, FTP, etc.) can
pass through this security level. Every access and even every attempt at access is doc-
umented without exception.
3. System Access: Before reaching the unit, the user name and password are requested
multiple times. In this regard, the procedure and the routine correspond to that for the
modem version.