The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  ·...

32
1 The Secure Solution for Remote Access, Data Collection and M2M-Communication 2016 / 2017

Transcript of The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  ·...

Page 1: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

1

The Secure Solution for Remote

Access, Data Collection and

M2M-Communication

2016 / 2017

Page 2: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

2

fast secure versatileMachines and production lines

of your customers are only a

mouse click away.

Dial-ups only towards the portal,

never the other way around.

Monitoring of utilization and material

consumption for condition-based

maintenance.

Page 3: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

3

GERMAN TECHNOLOGY

SECURELY CONNECTED WORLDWIDE

Page 4: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

4

PRODUCT OVERVIEW

mbCONNECT24

mbNET

mbNET.mini

mbSPIDER

mbSECBOX

Accessories

Model overview

CONTENTS

6

18

22

23

24

25

28

Secure remote maintenance with the remote service portal

Data backup and virus detection

Industrial router designed for universal use

Global-SIM, antennas, cables and more accessories

Overview of hardware and sotware functions

Data management, remote monitoring and web visualization

Small router, great performance

SYMBOL KEY CONNECTIONS:

WAN

LAN

RS-232/RS-485

MPI/PROFIBUS

mobile communication

WLAN

FirewallRegistered trademarks of

Siemens: TIA Portal, S7-300, S7-400, S7-1200, S7-1500, SIMATIC, S7, STEP 7

Beckhof: TWINCAT

3S-Smart Sotware: CoDeSys

Page 5: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

5

MB CONNECT LINE YOUR FORERUNNER FOR THE DIGITAL TRANSITION

As independent medium-sized business we are pacemaker when

it comes to solutions for professional communication via internet.

Speciically it’s about the secure connection of machines and

plants for remote maintenance, data collection and M2M-commu-

nication. In the early years industrial modems played the major

role. In the meantime the internet became the backbone of the

worldwide communication and therefore also the base of the

remote service building kit of MB connect line. Today we are facing

the continuous digitalization of the complete chain from the plan-

ning and development to the production up to the transportation

to the end-user. In this case we deliver solutions that are convinc-

ing not only because of their functionality but also when it comes

to the protection of data against unauthorized access, manipula-

tion and reconnaissance.

The foundation of our success as supplier of future technology

are very well skilled specialists. Besides ofering various training

MB connect line GmbH was founded in 1997 and focused on “Made in Germany” from the beginning.

The headquarter is located in the Bavarian town Dinkelsbühl. North American customers are being sup-

ported by our US-subsidiary MB connect line Inc. which is located in Warrenville, Illinois.

opportunities to our employees, we are an active training company of

the Chamber of Industry and Commerce and as cooperation partner

of the Duale Hochschule Heidenheim we ofer several dual study

programs in information technology.

Our accociation work and memberships e.g. at the Cluster Mecha-

tronik & Automation Bayern e.V., at the TeleTrusT – Federal Associa-

tion IT-Security e.V. and at the European Cyber Security Organization

(ESCO) also show that the subject internet security is very important

to us.

Siegfried Müller

CEO

Company proile

MADE IN GERMANY

Our products are produced exclusively in Germany, which guarantees

the highest quality and safeguards jobs in Europe.

Page 6: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

6

THE ECOSYSTEM

mbCONNECT24

• worldwide accessibility via internet

• serves as central connector between user, units and

plant components

• secure, encrypted connections to the machines and to

the users

• as basis for secure remote maintenance, data collection,

M2M-communication and networking via internet

Remote Service Portal

• simple management via web interface

• project based management of your machines and devices

• role based user management with highly scalable access

authorizations (also on IP- or Port-level)

• comprehensive functions for reporting, task management

and messaging

• various server solutions, public and private

• encrypted SSL/TLS-connections

• 2-factor authentication

• Secure Remote Password Protocol (SRP)

• IP Black/Whitelisting

• certii ed and audited security

• Security-by-Design

Server Management Maximum Security

Page 7: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

7mbCONNECT24

Your machines and

equipmentIP transparent access (mbDIALUP)

Diagnosis, coni guration and programming via internet

Use of existing engineering tools such as Siemens Step7, TIA,

RSlogix or Codesys, as if you were on the spot

Direct MPI/PROFIBUS interface and driver for SIMATIC sot ware

Remote diagnosis with program- and i rmware-updates

Several users can access the router at the same time

Web based access (mbWEB2go)

Supports webserver, RDP and VNC directly in standard browsers

Optimized for smartphones and tablets

No client- or additional sot ware required

Web based visualization

Easy link of indicating and operating element with process data

(drag&drop)

Reading and writing of system- and process-data via standard

browser

Editor for Dashboards and widgets

Access to visualization pages via external static links

Data management

Comprehensive reports (manual or time-controlled)

Data export as PDF, CSV or HTML

Connection to enterprise systems (ERP, SCADA)

External data base connection (mySQL)

API-Access to live- and logging-data

Your options

M2M-communication

PLC

LAN

PLC

LAN

Remote access

PLC

LAN

Data logging and alarming

PLC

LAN

Page 8: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

8

For remote access, collect and display data, web-based visualization,

monitoring and alarming, as well as M2M communication on a secure

platform.

The server with the remote service

portal as central connecting component

between users and machine and displays

the management interface.

VPN

HTTPS

SIEMENS, Rockwell,RSLogix, Beckhof Twincat,Schneider Electric, Mitsubishi, …

You have access to web-

server as well as VNC- and

RDP-support via smart-

phone or tablet without

specii c sot ware.

The service staf con-

nects with the portal via

client-sot ware

(mbDIALUP) to have a

IP transparent access to

all devices behind the

router.

Via webbrowser you can

visualize equipment, read

operating data or manage

the process, look on the

surveillance camera or on

the webserver of the PLC.

TCP/UDP

The modular system – functional principle

Functional Principle

Terminalserver technologies, such as VNC or RDP, usually require a

appropriate client on the user side, e.g. with Java or Flash.

mbWEB2go solves this via server-sided Proxy which translates the

graphic outputs of VNC and RDP, so that access is possible directly

via standard browser.

The mbWEB2go principle is based on a HTML5 web application and

therefore doesn’t need special plug-ins or additional installations.

Through the minimum resource requirements it’s ideal for smart-

phones and tablet computers.

Webbased access

HTTPS

HTTPS

mbWEB2go is a service in the remote-service-portal and acts as PROXY – between RDP, VNC, webserver and browser

Browser

mbCONNECT24

Page 9: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

9

VPN

PLC

LAN

Motion

RS-232/485

Security through:

• Encrypted connections (SSL/TLS)

• Only outbound connections

• Regular security audits

The router allows the IP transparent

access to PLC, HMI and other end devices.

Additionally it serves as a i rewall and

collects data from control systems or

sensors.

Connection to end devices with serial

interface, Ethernet, MPI/PROFIBUS and

USB.

PLC

MPI/Proi bus

PLC

USB

Webbased Access (mbWEB2go)

Mobile and secure web access via HTTPS

Works with every standard browser

Access to web server and IP-cameras

Supports RDP- and VNC-protocols without special

clients or apps

HTML5-capable standard browser is sui cient

Independent from operating system on the end device

Allows the monitoring and visualization independent from

stationary PCs

PLC

LAN

HMI

LAN

mbCONNECT24

Web Server

VNC Server

RDP Server

Page 10: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

10

Central switchboard

The Center – Remote Service Portal

Varieties of the Remote Service Portal

mbCONNECT24

• Switchboard for users and devices (routers, data modems)

• All users and devices only connect to the server (so called

outbound connections)

• Central management of all projects, users and machines

• Role-based user management

• Finely scalable access rights for participants behind the router

• Provides encrypted data connections between the locations

• Organizes devices and users in projects

• Provides ei cient workflow with integrated messaging system

and task planer

• Machines and units will be equipped with an industrial router

mbNET or a data modem mbSPIDER, which register on the

portal.

• Machines and units establish a VPN-connection to the portal:

permanent with power supply, program-controlled if required or

if required by key switch or at the push of a button, router with

modem via SMS.

• The routers and data modems don’t require a i x IP-address

because the end devices always register themselves on the

portal (also no SIM with i x IP).

• Access control for each device connected to the router.

• Connection of external devices, with which you connect your own

OpenVPN-capable devices with the portal.

• Templates simplify the job with recurring coni gurations.

mbCONNECT24

Public Cloud

mymbCONNECT24.mini

Private Cloud

mymbCONNECT24.virtual

Private Cloud

• Start with a free, ready to use

environment

• Upgrade to higher scope of

performance possible

• For small to medium sized projects

(up to 250 units)

• Complete solution

• Serverhardware with installed

Portal-Sot ware

• Ready to use

• For small to medium sized projects

(up to 100 units)

• Hardware independent virtual

machine

• Runs with your hardware

(inhouse or hosted)

• Widely scalable in functionality and

scope of performance

Interesting Facts

Page 11: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

11mbCONNECT24

Security at its maximum

• Thanks to the encrypting over the security protocol TLS/SSL

• The compliance with highest standards also allows the use in

business critical applications.

• Because only outbound connections are being used, a smooth

integration in the existing IT is guaranteed without security

concerns.

• The existing security strategies remain untouched

• Therefore securing of the authentication, integrity and coni den-

tiality of the transferred information.

• 2-factor authentication (with SMS or Google-Auth)

• With Secure Remote Password (SRP) technology

• Regular tool-based and manual penetration test

Customize

Adapt the layout of the portal with your logo or company colors.

Scalable up to individual front foil of router and data modem.

Top 10 Facts

1. Secure and transparent access to control systems,

machines and units

2. Use of existing engineering tools, such as Siemens Step7,

TIA-Portal, RSlogix or CoDeSys, as if you were on site

3. Direct MPI/PROFIBUS interface and driver for

SIMATIC Sot ware

4. WAN connection via Port 80,443 or 1194 and PROXY’s,

China Gateway, one clear IP-address per server

5. No specii c IT-knowledge required

6. Several users can connect to a router at the same time

and can access the IP network simultaneously (Limitation

through licenses and bandwidth)

7. Fast commissioning through coni guration transfer via i le

(USB stick)

8. Of line coni guration management of the routers (central

data management on the server). No coni guration on the

router necessary

9. Personalized and limited access rights via project

management on the portal

10. Scalable server solutions

Project Management

• Practical project structure in which the sites and Machinery is

directly illustratable

• Project-related management and coni guration of the end

devices

• A project is the highest authority – all units (data modems and

routers) are assigned to exactly one project

• As soon as a unit has been created in the project, the interfaces

and connected components can be dei ned and managed.

Project

Device

PLC

MPI/Proi bus

PLC

LAN

HMI

LAN

Motion

RS-232/485

HMI

RS-232/485

Interfaces

System

LAN

Serial COM

MPI/Profibus

USB

PLC

USB

Page 12: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

12

Access possibilities for remote maintenance and data collection

Transparent Access (mbDIALUP)

Possibilities of connection for internet and site-sided:

ETH 3G 4G WIFI ETH serialS7-MPI/

PB USBRemoteaccess

Datacollection

mbNET ✔ ✔ ✔ ✔ ✔ ✔ ✔ in prep ✔ ✔

mbNET.mini ✔ ✔ ✔ ✔ ✔ - - ✔ ✔ -

mbSPIDER ✔ ✔ - ✔ ✔ ✔ - - - ✔

Internet Site

VCOM, tunnels virtual COM-

Ports on COM-interface of

the mbNET

SEARCHoverIP, Multicast for

common PLC-programming

environment

TCP/IP Ethernet-Protocols

mbNET.S7 „Adapter“

STEP7-Classic

and TIA Portal for MPI/

PROFIBUS

USBoverIP, tunnels virtual

USB-Port on USB-interface

of mbNET

RS-232

RS-485

Beckhof

Wago, …

STEP 7 Classic

TIA Portal

Rockwell

Schneider Electric

USB

VCOM

mbNET-S7

USBoverIP

TCP/IP

TCP/IP

SEARCHoverIP

mbCONNECT24

RS-232/485

PLC

MPI/Proi bus

Page 13: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

13

S7 Ethernet

S7-MPI/PB

ModbusTCP

ModbusRTU

RockwellEthernetIP KNX

OnBoard I/O’s

mbNET ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini - - - - - - ✔

mbSPIDER ✔ - ✔ ✔ ✔ ✔ ✔

Data sources for the data collection

PLC

LAN

PLC

LAN

HMI

LAN

Motion

LAN

Motion

RS-232/485

PLC

MPI/Proi bus

PLC

USBEthernet

Serial RS-232/485

Ethernet

Serial RS-232/485

MPI/Proi bus

USB

Ethernet

mbCONNECT24

Page 14: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

14

Item no. Product Name Account Devices

Standard VPN clients

Active connec-tions

Several ac-tive connec-tions to one unit

mb-WEB2go connec-tions

Number of users

Number of user groups

Num-ber of clients

max. 250 max. 5

0610 mbCONNECT24 V2 Basic 1 50 - 1 - 2 25 5 1 ✔

0620 mbCONNECT24 V2 PRO Remote 1 250 - 3 ✔ 50 250 250 250 ✔ ✔

0630 mbCONNECT24 V2 PRO Data 1 250 - 1 ✔ 50 250 250 250 ✔ ✔

0640 mbCONNECT24 V2 PRO Individual 1 250 lic 1+ ✔ 50 250 250 250 ✔ ✔

0619 Standard VPN clients, 25 pcs. +25 ✔

0612 Active connections, 1 pc. +1 ✔

0613 Data point storage, 1M ✔

0614 Dashboards, 250 pcs. ✔

0615 Alarm events, 250 pcs. ✔

0641 Tasks for taskmanager, 5 pcs. ✔

0616 Access to customer-database API ✔ ✔

0617 Integration of external data point storage ✔ ✔

0611 Upgrade data consumption, 2GB p.m. ✔

0618 mbSMS, 250 pcs.

max. 5 max. 20k max. 20k max. 250 max. 500

0910 mymbCONNECT24.virtual FREE 1 5 1 1 - 1 5 1 1 ✔ ✔

0911 mymbCONNECT24.virtual PRO 1+ 10+ 1+ 2+ ✔ 10+ 1k 250 1k ✔ ✔

0920 Account licenses, 1 pc. +1

0925 Device licenses, 25 pcs. +25

0930 Standard VPN clients, 25 pcs. +25

0935 Active connections, 1 pc. +1

0940 Active mbWEB2go connections, 10 pcs. +10

0945 M2M connectiongroups, 1 pc.

0950 Data points per unit, 25 pcs.

0955 Data point storage, 1M

0960 Dashboards, 50 pcs.

0965 Alarm events, 50 pcs.

0966 Tasks for taskmanager, 5 pcs.

0970 Customizing Advanced ✔

0975 Access to customer-database API ✔

0980 Integration of external data point storage ✔

0618 mbSMS, 250 pcs.

max. 110 max. 5

0690 mymbCONNECT24.mini V2 1 10+ - 5 ✔ 25 250 250 1k ✔

0696 Device licenses, 25 pcs. +25

0886 Tasks for taskmanager, 5 pcs. ✔

0667 Customizing Advanced ✔

0668 Access to customer-database API ✔

0618 Integration of external data point storage

mbCONNECT24

Functional overview

lic License GB Gigabyte k Thousand (kilo) M Million (Mega) TB Terabyte 1+ expandable +1 extended by oneLegend

Page 15: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

15

Reports

M2M connec-tion groups

Data points per unit

Data point storage

Dash-boards

Alarm events

Tasks for taskma-nager

Custo-mizing Basic

Custo-mizing Advanced

Customer database API

External data point storage

Data consump-tion mbSMS

SotwareUpdate/Upgrade

max. 5M max. 260 max. 260 max. 11 max. 12GB

View - 10 50k 10 10 1 - - - - 2GB 10+ ✔

✔ Export - 10 50k 10 10 1 - - ✔ - 6GB+ 10+ ✔

✔ Export - 250 5M 250 250 10 - - ✔ - 6GB+ 10+ ✔

✔ Export - 250 50k+ 10+ 10+ 1+ ✔ - lic lic 2GB+ 10+ ✔

+1M ✔

+250 ✔

+250 ✔

+5 ✔

✔ ✔

✔ ✔

+2GB ✔

+250

max. 500 max. 250 max. 5M max. 20k max. 20k max. 101

Export 1 5 50k 10 10 1 ✔ - - - ✔ 0+ -

✔ Export 1+ 25+ 1M+ 25+ 25+ 10+ ✔ lic lic lic ✔ 0+

+1

+25

+1M

+50

+50

+5

+250

max. 5M max. 250 max. 250

✔ Export 5 250 5M 250 250 10 ✔ lic lic lic - 0+

+250

mbCONNECT24

✔ included compulsory / mandatory

Page 16: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

16 mbCONNECT24

Glossary

Account An account has to be seen like a customer’s account

Active connections

An active connection describes the active tunnel of a user to his site. The connection establishment of

the individual units to the portal respectively the dial-up of the user to the platform remain unafected.

We are talking about an “active connection” when the user actively chooses a site and activates the

VPN tunnel to this site.

Alarm EventThe deinition of rules in terms of speciic data points forms the basis of the alarm management, the

number of entered alarms (Alarm Event) per account is limited.

Clients

Users are being organized with clients, i.e. I classify the users in my organization, e.g. according to

departments. Background here is also the simpliied management, through a “hierarchic structuring” a

false granting of accesses to external installations is almost impossible.

Connection Reports

The system mbCONNECT24 protocols all actions, such as active connections, Web2Go connections,

SMS sending… The export of this data can be made in various formats (PDF, HTML, csv) according to

user, device or also depending on the project. These reports serve as valuable basis for invoicing or

controlling your activities..

Customer-Database APIThe portal can provide data for external applications, the data will be provided via syntax and authenti-

cation deined by MB.

Customizing Advanced

Besides the logo on the top right, the label mbCONNECT24 “top let” can be replaced by an own

label. Furthermore the colors can be changed independently according to your wishes. Also the color

adaption of the used VPN-Client-Sotware mbDIALUP can be done. The same applies for the program

mbCHECK, which checks the local installations for the integration in the portal.

Customizing BasicAllows the integration of own logos in mbCONNECT24. The position of the logo is „top right“ in the page

display, the MB connect line logo will be replaced by it.

Dashboards

Besides the reading of machine data respectively their protocolling, these data can also be visual-

ized. With the help of graphic elements (widgets), own visualizations (dashboards) can be created on

mbCONNECT24. Each dashboard can be arranged individually for user or application purposes. The

maximum number of diferent dashboards per account is limited.

Data Point Storage

Concerns the total number of all protocolled data, independent from which type or readout interval of

the single data points. In the end ater reaching the maximum the irst data record will be overwritten,

so called “rolling memory”, basically FIFO.

Data points per unit

With various types of end devices MB connect line ofers the possibility to readout data of machine

components. This data can be stored for analyzing on the portal mbCONNECT24. The readout of the

data will be made by the end devices. Because of the limited capacity of the end device and deined

ressources of the particular accounts, the maximum number of the single data points per device is

limited. In the end this efects the number of the diferent “data points” on the machine, the frequency

of a readout of the particular data point is not afected by this.

Devices and Projects

Describes the amount of possible units in the account. Here the number for max. units is valid indepen-

dent from the projects, whereas the number is alike. An example: 50, i.e. max. 50 units and 50 projects,

therefore you can advise each unit to a project.

External

Data Point Storage

The data point storage usually is integrated in mbCONNECT24, i.e. the provision of memory capacity is

not necessary, therefore the memory capacity for protocolling is limited. The connection of an external

data point memory allows a data storage independent from mbCONNECT24 respectively an own ad-

ministration of the data. Furthermore the external data memory allows an easier pick-up of the machine

data for external systems. Depending on customer requirements an external data memory might be

required to meet internal requirements concerning data protection and data security.

The following explanation is valid correspondingly for all mbCONNECT24 versions, i.e. also

mymbCONNECT24.mini, -.virtual etc.

Page 17: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

17mbCONNECT24

Guaranteed bandwidth

The complete bandwidth on the server is devided due to the system by the before mentioned number

of accounts of each customer. MB connect line guarantees a bandwidth for the single account, inde-

pendently from this the bandwidth will be influenced by the complete system of each customer by the

local existing infrastructure of the user, respectively the local conditions at the machine installation.

Therefore the mentioned guaranty refers to the service provided by MB, all further influential variables

are not in the range of influence of MB connect line.

M2M connectiongroups

Through the centralized connection of the components via mbNET router to the portal mbCONNECT24,

a connection among the individual units is possible. It’s important to take care of a well matched

assignment of the individual IP addresses of all components before connecting the individual units. The

M2M-function will be activated in a project and is therefore valid for all units in the project. The network

of components is called a M2M-connectiongroup, no matter how many end devices interconnect in this

group.

mbSMS

mbSMS refers to the SMS sending from mbCONNECT24, i.e. the portal is the sender and no mobile de-

vice is necessary for sending the SMS. This allows e.g. information about alarms or messages via SMS.

For mymbCONNECT24 an own SMS-gateway can be used. We support the gateway of www.smstrade.de

mbWEB2go connections

Compared to the active connections with dial-in of the user via VPN, an access to the mbCONNECT24

portal in the WEB2go technology is being made via HTTPS. Therefore the installation of the VPN-client

(mbDIALUP) on the user’s computer is not necessary, a current browser (e.g. Firefox) is suicient for the

connection. Depending on the goal, WEB2go can be implemented for many applications suiciently

and eventually easier respectively more efective in the work flow. Generally all applications that allow

access via HTTP, HTTPS, VNC, TELNET, SSH can be addressed via WEB2go. Besides the easier dial-in,

these accesses can also be made available on the portal for users without user account. The approval

via “direct LINK” or also via “QR-Code” is the easiest access control on the market. The number of the

WEB2go connections is independent from the number of active connections.

Part No. Part number of the product

Several active connections

to one unit

In the past the number of active connections to one unit has been limited to 1 due to the system.

Through further development it’s technically possible that several users can connect with the same site

simultaneously. Therefore several active connections are required for the multiple connection establish-

ment of diferent users. In the end due to the multiple connections on the device, diferent users might

access a single installation. In practice this multiple access has to be known to the users and has to be

coordinated safely in the process.

SotwareupgradesIncludes further developments of mbCONNECT24, i.e. new features, displays and dialogues will be

realized within the scope of further development in future versions.

Sotwareupdates

Includes security updates, which will be solved extraordinarily respectively a new version will be in-

stalled in the system mbCONNECT24 ater becoming known. Furthermore this also includes the provi-

sion of adapted irmware on the MB end devices, e.g. mbNET.

Standard-VPN-Clients

(External devices)

The used technology OpenVPN allows the integration of diferent platforms, i.e. also devices that have

not been produced by MB, can be embedded via VPN client. In this case it’s reasonable to involve the

MB contact person to assure an efective procedure leading to the goal.

Tasks for Taskmanager

With the task manager you can create tasks in the mbCONNECT24 account, that activate service

time-controlled within the account. This includes e.g. the sending of any report (connections, data

points) via E-Mail. The number of tasks per account is limited.

UserEach person receives a personal name and password from the administrator, with which every person

will be authenticated. On the platform this is called as single user.

User groups

When creating a user the administrator has to deine the rights for the use of the system. Through the

deinition of those rights the entries will be easier and mistakes will be avoided. Therefore ater prior

deinition of diferent user groups the single user can be assigned to a user group. In the IT this is the so

called “role”, i.e. what am I allowed to do? E.G. create units, delete or only establish a connection.

User/unit

Component settings

(Firewall behind the unit)

User that connect to a mbNET via VPN, generally have the complete access to all components that

are connected to the router. The user can therefore access all components, a user-dependent access

control in the machine net via router is only feasible with the mentioned extension (irewall behind the

unit). Therefore despite existing VPN-tunnel to the user, the access to certain network areas can be

limited.

Page 18: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

18

INDUSTRIAL ROUTER

SPECIFICALLY DESIGNED FOR UNIVERSAL USE

Thanks to a variety of interfaces and device drivers, you enjoy

enormous flexibility with the mbNET industrial router for the

maintenance of diferent control systems, drives, operating panels,

frequency converters and other components.

integrated 4-port switch (4 x Ethernet 100 Mbit)

secure connection via VPN (PPTP, IPSec, L2TP, OpenVPN)

Internet connection via Ethernet, WAN interface or modem

(analog, 2G, 3G, 4G or WiFi)

2 x RS-232/485 interface selectable onboard,

optional: 1 x MPI/PROFIBUS up to 12 Mbit/s,

1 x RS-232/485 switchable

over 90 drivers for various control system types

2 SIM card slots with failover functionality

(3G and 4G versions)

4 digital inputs, 2 digital outputs

the network connections can be initiated from anywhere

with the text message control function

slim metal case with IP20 for DIN rail mounting

Access to the Internet can be made through the intranet (corporate

network), through the integrated modem (analog, 2G, 3G or 4G)

or through a broadband connection (DSL). A suitable mbNET indus-

trial router is available for almost every local infrastructure.

The industrial routers mbNET are speciically designed for industrial use. They enable a secure and

reliable connection of machines and equipment via the Internet.

They support various security protocols, so they are universally compatible. But the routers’ full perfor-

mance is achieved when they are connected to the remote service platform mbCONNECT24. The inte-

grated irewall ensures maximum access protection by allowing remote access only to identiied and

authenticated users.

The compact

solution

mbNET.mini

• Page 22

mbNET

Enhancement for

3G / 4G networks

Antennas

• Page 27

Page 19: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

19

PRODUCT VERSIONS:

PRODUCT VERSIONS:

mbNET with two serial interfaces

mbNET with serial and MPI/Profibus interface

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232 RS-485

MPI/Proibus VPN*

MDH810 8810-UL 1× analog 56 kbit 56 kbit 4× 2× - ✔

MDH814 8814-UL 1× 3G 5,76 Mbps 21 Mbps 4× 2× - ✔

MDH850 8850-UL-EU 1× 4G 50 Mbps 100 Mbps 4× 2× - ✔

MDH850 8850-UL-AT&T 1× 4G 50 Mbps 100 Mbps 4× 2× - ✔

MDH811 8811** 1× WLAN 54 Mbps 54 Mbps 4× 2× - ✔

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232 RS-485

MPI/Proibus VPN*

MDH830 8830-UL 1× analog 56 kbit 56 kbit 4× 1× 1× ✔

MDH834 8834-UL 1× 3G 5,76 Mbps 21 Mbps 4× 1× 1× ✔

MDH855 8855-UL-EU 1× 4G 50 Mbps 100 Mbps 4× 1× 1× ✔

MDH855 8855-UL-AT&T 1× 4G 50 Mbps 100 Mbps 4× 1× 1× ✔

MDH831 8831** 1× WLAN 54 Mbps 54 Mbps 4× 1× 1× ✔

mbNET

The mbNET industrial router from MB connect line has the largest range of performance and features.

The diferent models: mbNET.easy, mbNET.basic and mbNET.mini are optimized for diverse applications

and provide a budget friendly solution when the mbNET’s full scope of performance and features is not

required. All models ofer secure VPN encryption.

* IPSEC, PPTP, L2TP, OpenVPN

** Not UL listed

Page 20: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

20

PRODUCT VERSIONS:

mbNET with LAN

mbNET.basic

PRODUCT VERSIONS:

mbNET with LAN and WAN

mbNET

Your benefits:The entry-level model mbNET.basic is used for the remote main-

tenance of Ethernet devices or networks. The units have a LAN

interface as well as a USB port for coni guration. Depending on the

device model, an additional WAN interface is available for access

via the company’s intranet or an integrated modem (analog, 2G,

3G, 4G) from anywhere you have an Internet connection.

Applications range from connection to simple machines, to com-

plete packaging and production lines even up to mobile transport

systems.

mbNET.basic 4G provides data rates up to 100 Mbit/s download

and 50 Mbit/s upload. With this, large amounts of data and

high-resolution video streams are transferred reliably.

easy dial-in router

integrated 4-port switch (4 × Ethernet 100 Mbit/s)

i rewall, DynDNS, DHCP, Internet call back, OpenVPN

2 SIM card slots with Failover functionality

(3G and 4G versions)

4 digital inputs, 2 digital outputs

the network connections can be initiated from anywhere

with the text message control function (3G and 4G versions)

slim metal case with IP20 for DIN rail mounting

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232RS-485

MPI/Proi bus VPN

MDH816 8816-UL 1× - - - 4× - - OpenVPN

MDH849 8849-UL 1× 3G 5,76 Mbps 21 Mbps 4× - - OpenVPN

MDH859 8859-UL-EU 1× 4G 50 Mbps 100 Mbps 4× - - OpenVPN

MDH859 8859-UL-AT&T 1× 4G 50 Mbps 100 Mbps 4× - - OpenVPN

MDH841 8841** 1× WLAN 54 Mbps 54 Mbps 4× - - OpenVPN

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232RS-485

MPI/Proi bus VPN

MDH815 8815-UL - analog 56 kbit 56 kbit 4× - - OpenVPN

MDH819 8819-UL - 3G 5,76 Mbps 21 Mbps 4× - - OpenVPN

MDH858 8858-UL-EU - 4G 50 Mbps 100 Mbps 4× - - OpenVPN

MDH858 8858-UL-AT&T - 4G 50 Mbps 100 Mbps 4× - - OpenVPN

** Not UL listed

Page 21: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

21mbNET.

PRODUCT VERSIONS:

mbNET.easy with LAN and WAN

mbNET.easy

Your benefits:The functionality of the industrial routers mbNET.easy intentionally

focuses on the essentials: IP-based communication, access pro-

tection and data security. With this, you receive an economically

attractive and easy-to-use solution for remote maintenance, data

collection and networking via Internet.

The connection takes place through the remote service platform

mbCONNECT24. Through a variety of interfaces and device drivers,

the mbNET.easy fulills all requirements for access to remote main-

tenance. Connection to the S7-world is possible, as well as access

to over 90 control systems, drives and other components from

various manufacturers.

The industrial router mbNET.easy is also available as a starter kit.

In addition to the router, you receive two network cables, an MPI/

Proibus cable, an A/C power adapter, the USB stick mbMEM with

the sotware mbCHECK and mbDIALUP, as well as a demo version of

the mbNET S7 driver.

The mbNET.easy can only be operated with mbCONNECT24.

integrated 4-port switch (4 × Ethernet 100 Mbit/s)

1 × WAN interface

1 × MPI/PROFIBUS up to 12 Mbit/s, 1 × RS-232/485 switchable

4 digital inputs, 2 digital outputs

secure connection to the remote service platform

mbCONNECT24, mymbCONNECT24

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232 RS-485

MPI/Proibus VPN

MDH835 8835-UL 1× - - - 4× 1× 1× OpenVPN

Page 22: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

22 mbNET.mini

SMALL ROUTER

GREAT PERFORMANCE

The mbNET.mini is a very compact industrial router for DIN-rail mounting. It of ers secure IP-based ac-

cess to Ethernet devices and networks through the remote service platform mbCONNECT24. Therefore,

it is not only suitable for remote maintenance applications but also for tasks such as alerts and M2M

communication.

integrated Ethernet switch (3-port with LAN / WAN, otherwise 4-port)

1 × WAN or 1 × 3G / 4G modem, WiFi

3G / 4G version supports GPRS, EDGE, UMTS, HSPA+, LTE

2 digital inputs for connection to the remote service platform

or for sending alerts via text message or e-mail

OpenVPN security protocol

ideal for M2M applications

solid metal case for DIN rail mounting

USB over IP capable

Secure connection to the Remote Service Platform mbCONNECT24

The industrial router mbNET.mini is available in several versions. The

WAN version uses the existing network or a broadband connection

(DSL) to connect to the Internet and of ers a 3-port switch. The 3G/4G

version allows connection over the mobile communication network and

includes a 4-port switch. Enhancement for

3G / 4G networks

Antennas

• Page 27

PRODUCT VERSIONS:

mbNET.mini with LAN and WAN

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232RS-485

MPI/Proi bus VPN

MDH860 8860 1× - - - 3× - - OpenVPN

MDH861 8861 - 3G 5,76 Mbps 21 Mbps 4× - - OpenVPN

MDH862 8862 EU - 4G EU 50 Mbps 100 Mbps 4× - - OpenVPN

MDH862 8862 AT&T - 4G AT&T 50 Mbps 100 Mbps 4× - - OpenVPN

MDH863 8863 - WLAN 54 Mbps 54 Mbps 4× - - OpenVPN

Page 23: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

23

DATA MANAGEMENT

REMOTE MONITORING AND WEB VISUALIZATION

The mbSPIDER is a programmable data modem for continuous logging of counter readings, measure-

ments, logic states and analog values. The logged values are visualized via the integrated web server or

via the remote service platform mbCONNECT24 – barrier free via smartphone or standard browser.

Enhancement for

3G networks

Antennas

• Page 27

The mbSPIDER is programmed in a free script language. Together with an integrated

database, FTP server/client functionality, as well as web visualization, you can collect,

evaluate and visualize any data. Sending of messages and alerts via text message and

e-mail is also possible.

1 Ethernet port 100 Mbit/s usable as LAN and WAN

for possible dataconnection see page 13

1 RS-232/-485 interface

2 digital and 4 analog inputs, 1 relay output

secure connection to remote service platform mbCONNECT24

Link the supplied widgets (display and control elements) with the database for

visualization. HTML or programming knowledge is not necessary.

The web visualization is optimized for smartphones and tablet PCs and can be

displayed with any standard browser. Dispensing with special clients or apps is

intentional.

PRODUCT VERSIONS:

mbSPIDER with serial interface, LAN and WAN

Name Item no. Case WAN/

LAN Modemmax.

Uploadmax.

DownloadRS-232RS-485

MPI/Proi bus VPN

MDH900 8900 Plastic 1× - - - 1× - OpenVPN

MDH901 8901 Plastic 1× WLAN 54 Mbps 54 Mbps 1× - OpenVPN

MDH905 8905 Plastic 1× 2G 235 Kbps 235 Kbps 1× - OpenVPN

MDH906 8906 Plastic 1× 3G 5,76 Mbps 21 Mbps 1× - OpenVPN

MDH910 8910 Metal 1× WLAN 54 Mbps 54 Mbps 1× - OpenVPN

MDH911 8911 Metal 1× WLAN 54 Mbps 54 Mbps 1× - OpenVPN

MDH905 8915 Metal 1× 2G 235 Kbps 235 Kbps 1× - OpenVPN

MDH916 8916 Metal 1× 3G 5,76 Mbps 21 Mbps 1× - OpenVPN

mbSPIDER

Page 24: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

24

DATA BACKUP AND

VIRUS DETECTION

permanent backup of dynamic PLC data such as recipe settings,

setpoints, etc. (DB)

detection of tampering in OB, FC, FB, SFC, SFB, SDB

alert by text message or e-mail if there are changes in the

components

simple restoration of saved data without the manufacturer's

sot ware

2 digital outputs for status signaling

4 digital inputs for operating functions

The i rst step saves the complete program memory (OB, FC, FB,

DB, SFC, SFB, SDB), the order numbers and the serial numbers in

a reference backup. On the basis of this reference data, the device

continuously monitors the static memory area of S7-300 and

S7-400 control systems. Dynamic PLC values and recipe data or

control parameters can be restored at any time.

The mbSECBOX is a security solution for the S7-300 and S7-400 control systems from Siemens. It was

specially developed for virus detection and data backup at the PLC level. The mbSECBOX immediately

detects malware such as Stuxnet and other attacks on S7 control systems and alerts you before any

damage is done.

PRODUCT VERSIONS:

mbSECBOX with serial interface, LAN and WAN

mbSECBOX

Enhancement for

3G networks

Antennas

• Page 27

Name Item no. WAN Modemmax.

Uploadmax.

Download LANRS-232RS-485

MPI/Proi bus VPN

MDH874 8874-UL 1× 3G 5,76 Mbps 21 Mbps 4× - 1× -

Page 25: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

25

ACCESSORIES

Item no. End device Description Length

8256 AIOVision AVTCE 210.2 RS-232 connection cable 2.5 m

8201 Allen Bradley PLC5xx Channel RS-232 connection cable 2.5 m

8200 Allen Bradley SLC503/4 Channel RS-232 connection cable 2.5 m

8202 AMK - X77 RS-232 connection cable 2.5 m

8239 Atlas Copco DMC 30515P RS-232 connection cable 2.5 m

8238 Automata SCS 6130-001-1 V2.0, SW ST 3.06 RDMX RS-232 connection cable 2.5 m

8205 B&R BRITGR31-0 V1.4 RS-232 connection cable 2.5 m

8206 B&R mini Bradol or storage module RS-232 connection cable 2.5 m

8204 B&R2000 PLC RS-232 connection cable 2.5 m

8266 Baumüller BmaXX 4400 RS-232 connection cable 2.5 m

8260 Bosch CL 400 RS-232 connection cable 2.5 m

8207 Bosch CLx X31/PG(RS232) RS-232 connection cable 2.5 m

8259 Bosch Rho 3.0 RS-232 connection cable 2.5 m

8248Control Techniques frequency converter SE and

GPSRS-485 connection cable 4.0 m

8244 Danfoss frequency converter VLT5xxx RS-232 connection cable 2.5 m

8208 Danfoss VLT2xxx RS-232 connection cable 2.5 m

8240 Ebelt operation station BeSt 2xx RS-232 connection cable 2.5 m

8234 Elau Pac Controller MAx 4 RS-232 connection cable 2.5 m

8243Emotron frequency converter of the U-series with

option card RIO RS-232 connection cable 2.5 m

8209 EPIS control system Epis EMD RS232 connection cable 2.5 m

8203Eurotherm (ASB) servo controller Apollo 3G type

DER.A3 and K(L)KER.A3RS-232 connection cable 2.5 m

8232 GE_Fanuc PLC 352 RS-232 connection cable 2.5 m

8246 Galileo Micro Inovation Touchpanel GF0/1 RS-232 connection cable 2.5 m

Connection cables

Global SIM – worldwide independence

Your benei ts:

full support for GSM service (data up to max. 3G, text

messages, CSD)

no minimum contract period

always the best network – with worldwide coverage

simple administration of all SIM cards via professional MyM2M portal

clear prepaid rate model protects from unforeseen costs

Name Item no. Description

GLOBAL SIM A001371 Mini SIM card (25 x 15 mm) with full support for GSM services (data up to max. 3G, text messages, CSD)

Accessories

Page 26: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

26 Accessories

Item no. End device Description Length

8245 Hitachi SJ, L100 frequency converter RS-232/RS-422 interface

conversion cable 2.5 m

8236 Indramat CLC motion control card RS-232 connection cable 2.5 m

8237 Indramat DKC/PPC Ecodrive 03 servo control system RS-232 connection cable 2.5 m

8267 Indramat Indardrive control system RS-232 connection cable 2.5 m

8211 KEB frequency converter F4 Operator Panel RS-232 connection cable 2.5 m

8212 KEBA Kamro PLC with TCP/IP connection (CPU CU 201) RS-232 connection cable 2.5 m

8263 Keyence PLC RS-232 connection cable 2.5 m

8249Kollmorgen-Seidel frequency converter Servostar 600

seriesRS-232 connection cable 2.5 m

8213 Kuhnke PLC RS232 RS-232 connection cable 2.5 m

8214Lauer operator panel PCS 090, 095, 900, 950, 9000,

9100 and LCA 300RS-232 connection cable 2.5 m

8215 Lenze converter RS-232 connection cable 2.5 m

8216 Locon Deutschmann NSW RS-232 connection cable 2.5 m

8273 mbSPIDER Y-cable RS-232/RS-485 0.25 m

8233 Mitsubishi FRE type SC FRPCRS-485/RS-232 interface

conversion cable 2.5 m

8258 Mitsubishi Melsec PLC A2SH RS-232 connection cable 2.5 m

8265 MotomanNX100/ XRC RS-232 connection cable 2.5 m

8217 NPOS RS-232 connection cable 2.5 m

8218 Omron PLC RS-232 connection cable 2.5 m

8270 Parker Compax SL Hauser C3 servo control system RS-485 connection cable 10 m

8255 Parker Compax SL Hauser C3 servo control system RS-232 connection cable 2.5 m

8261 Phönix Interbus Module IBS BA DSC/i-T. RS-232 connection cable 2.5 m

8271 Pilz PSS Mini Touch 270 Monochrom RS-232 connection cable 2.5 m

8220 PLC Direct DL105, 205, 305, 405 RS-232 connection cable 2.5 m

8221 Primo Compact Mayr axis control system RS-232 connection cable 2.5 m

8222 Proline 90, 95, 900 RS-232 connection cable 2.5 m

8223 Promicon System 90E RS-232 connection cable 2.5 m

8231 RS232/485 adapter RS-232 connection cable 2.5 m

8224 SEW 232 M SEW-Movidyn/Movitrac (IPOS or USS11 A) RS-232 connection cable 2.5 m

8274SEW X-Terminal, SEW-Movidyn, Drive MKS51xxx,

Movitrag, MovidriveRS-232 connection cable 2.5 m

8235 Siemens operator panel OP7/17 RS-232 connection cable 2.5 m

8262Siemens HMI serial - OP170B, TP170A, TP170B, Mobile

Panel 170, TP270, OP270, MP270, MP270B, MP370RS-232 connection cable 2.5 m

8268 Siemens S7 200 PPI connection cable 2.5 m

8264 Siemens S7 300/400 MPI/Proi bus connection cable 1.2 m

8269 Siemens S7 300/400 MPI/Proi bus connection cable 3.0 m

8272 Siemens S7 300/400 MPI/Proi bus connection cable 7.0 m

8225 Siemens Simatic S5 PLC TTY-/RS-232 converter cable 2.5 m

8227 Stöber frequency converter FDS 4xxx RS-232 connection cable 2.5 m

8228 Stromag amplii er module CDC003.1/X14 RS232 RS-232 connection cable 2.5 m

8257 Sütron operation material BTxx RS-232 connection cable 2.5 m

8229 Sütron operation material BTxxN RS-232 connection cable 2.5 m

8230TSX 37 / TSX57 TSX SCP CC1030 of the TSX SCP 111 RS

232MP PCMCIA card RS-232 connection cable 2.5 m

8247 TSX LES 64 RS-232 connection cable 2.5 m

8252 Vectron frequency converter VCB 230/400 RS-232 connection cable 2.5 m

Page 27: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

27

WIFI and mobile communication antennas

USB stick

Network adapter

Item no. Short description

5104 mbMEM 4 GB, MLC Flash, 0 °C – +60 °C

A008045mbMEM Industrial Grade 2 GB, SLC Flash, Linux format ext3,

-40 °C – +85 °C

Accessories

Ri = directional antenna

Ru = beam antenna

For more antennas please ask.

Item no. Short description Description

9149 A/C power adapter 24 V Output 24 VDC / 1A Input 100-230 VAC

Item no. Type* FrequencyTransmission method**

Thermal endurance

Connec-tion

Cable length

Amplii ca-tion factor Mounting

Dimen-sions in mm

A001006 oa699 – 960/

1710 – 2690 MHz

GSM, 2G, 3G,

4G-40 °C to +85 °C

SMA –

male250 cm 2.2 dBi max. Magnet foot 31 × 72

A001007 oa900/

1,800 – 2,100 MHzGSM, 2G, 3G -40 °C to +85 °C

SMA –

male500 cm 5 dBi Magnet foot 31 × 308

A001008 oa900/

1,800 – 2,100 MHzGSM, 2G, 3G -40 °C to +85 °C

SMA –

male1,250 cm

-16 dBi with

12 m cableMagnet foot 31 × 72

A001013 oa700 – 960/

1,710 – 2,700 MHz

GSM 2G, 3G,

4G -40 °C to +80 °C

SMA –

male500 cm 2 dBi to 4 dBi Wall mounting 46 × 164

A001014 oa700 – 960/

1,710 – 2,700 MHz

GSM 2G, 3G,

4G MIMO***-40 °C to +80 °C

2 ×

SMA –

male

2 × 200

cm

2.5 dBi to

4 dBi

Wall mounting

& screen clip137 × 151

A001017 oa

650 – 960/

1,710 – 2,170/

2,500 – 2,700 MHz

GSM 2G, 3G,

4G MIMO***-20 °C to +70 °C

2 ×

SMA –

male

2 × 500

cm

8.2 dBi to

9.3 dBi

Wall mounting,

mast mounting

260 ×

260 × 80

A001374 oa2.4 GHz/

5.1 – 5.9 GHzWIFI -40 °C to +85 °C

SMA –

female250 cm

2.4 GHz

2 dBi/ 5 GHz:

5 dBi

Magnet &

patch mounting15 × 53

A001373 oa

824 – 894/

1,800 – 2,100/

2,400/

5,100 – 5,900 MHz

WIFI -40 °C to +85 °CSMA –

female500 cm 2.4 GHz 5 dBi Magnet foot 31 × 233

A001015 Extension cable for mobile communication antennas (GSM, 2G, 3G, 4G) 500 cm

A001016 Extension cable for mobile communication antennas (GSM, 2G, 3G, 4G) 1000 cm

*** MIMO (Multiple Input Multiple Output) denotes the use of multiple transmitter and

receiver antennas for improving the quality and the data rate

** Please refer to the respective provider for information about the transmission frequency

* da = directional antenna; oa = omnidirectional antenna

Subject to change

Page 28: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

28

MODEL OVERVIEW

HARDWARE FUNCTIONS

Model overview

Model number Item

Remote access (VPN & Web2go)

Data collection(on portal server)

Data security(backup & virus detection) LAN MP/DP

RS232 RS485

USB over IP

MDH835 8835-UL ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH830 8830-UL ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH831 8831 ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH834 8834-UL ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH8855 8855-UL-EU ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH855 8855-UL-AT&T ✔ ✔ - 4x 1x 1x - ✔ ✔

MDH810 8810-UL ✔ ✔ - 4x - 2x - ✔ ✔

MDH811 8811 ✔ ✔ - 4x - 2x - ✔ ✔

MDH814 8814-UL ✔ ✔ - 4x - 2x - ✔ ✔

MDH850 8850-UL-EU ✔ ✔ - 4x - 2x - ✔ ✔

MDH850 8850-UL-AT&T ✔ ✔ - 4x - 2x - ✔ ✔

MDH815 8815-UL ✔ ✔ - 4x - - - ✔ ✔

MDH816 8816-UL ✔ ✔ - 4x - - - ✔ ✔

MDH841 8841 ✔ ✔ - 4x - - - ✔ ✔

MDH819 8819-UL ✔ ✔ - 4x - - - ✔ ✔

MDH849 8849-UL ✔ ✔ - 4x - - - ✔ ✔

MDH858 8858-UL-EU ✔ ✔ - 4x - - - ✔ ✔

MDH858 8858-UL-AT&T ✔ ✔ - 4x - - - ✔ ✔

MDH859 8859-UL-EU ✔ ✔ - 4x - - - ✔ ✔

MDH859 8859-UL-AT&T ✔ ✔ - 4x - - - ✔ ✔

MDH860 8860 ✔ - - 3x - - ✔ ✔ ✔

MDH861 8861 ✔ - - 4x - - ✔ ✔ ✔

MDH862 8862 EU ✔ - - 4x - - ✔ ✔ ✔

MDH862 8862 ATT ✔ - - 4x - - ✔ ✔ ✔

MDH863 8863 ✔ - - 4x - - ✔ ✔ ✔

MDH900 8900 - ✔ - 1x - 1x - ✔ ✔

MDH901 8901 - ✔ - 1x - 1x - ✔ ✔

MDH905 8905 - ✔ - 1x - 1x - ✔ ✔

MDH906 8906 - ✔ - 1x - 1x - ✔ ✔

MDH910 8910 - ✔ - 1x - 1x - ✔

MDH911 8911 - ✔ - 1x - 1x - ✔

MDH915 8915 - ✔ - 1x - 1x - ✔

MDH916 8916 - ✔ - 1x - 1x - ✔

MDH874 8874-UL - - ✔ 4x 1x - - ✔

Basic functionsInterfaces to machine communication

Page 29: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

29

for wired Internet Type

max. Upload

max. Download Connection

Supply voltage (DC)

Digital IN

Digital OUT

Analog AnalogUSB for memory medium

DIN rail mounting

✔ ✔ 1x - - - - 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x analog RJ11 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x WiFi SMA (male) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x analog RJ11 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x WiFi SMA (male) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ - analog RJ11 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x - - 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x WiFi SMA (male) 10-30V 4x 2x - - ✔ ✔

✔ ✔ - 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ - 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ - 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x 4G 50 Mbps 100 Mbps SMA (female) 10-30V 4x 2x - - ✔ ✔

✔ ✔ 1x - - - - 10-30V 2x - - - ✔ ✔

✔ ✔ - 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 2x - - - ✔ ✔

✔ ✔ - 4G EU 50 Mbps 100 Mbps SMA (female) 10-30V 2x - - - ✔ ✔

✔ ✔ - 4G ATT 50 Mbps 100 Mbps SMA (female) 10-30V 2x - - - ✔ ✔

✔ ✔ - WiFi SMA (male) 10-30V 2x - - - ✔ ✔

✔ 1x - - - - 10-30V 2x 1x „Relay“ 2x 2x ✔ ✔

✔ 1x WiFi SMA (male) 10-30V 2x 1x „Relay“ 2x 2x ✔ ✔

✔ 1x 2G 235 Kbps 235 Kbps SMA (female) 10-30V 2x 1x „Relay“ 2x 2x ✔ ✔

✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 2x 1x „Relay“ 2x 2x ✔ ✔

✔ 1x - - - - 10-30V 2x 1x „Relay“ 2x 2x ✔ -

✔ 1x WiFi SMA (male) 10-30V 2x 1x „Relay“ 2x 2x ✔ -

✔ 1x 2G 235 Kbps 235 Kbps SMA (female) 10-30V 2x 1x „Relay“ 2x 2x ✔ -

✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 2x 1x „Relay“ 2x 2x ✔ -

✔ 1x 3G 5,76 Mbps 21 Mbps SMA (female) 10-30V 4x 2x - - - ✔

Interfaces to portal server Electrical connections

INTEGRATED MODEM

Subject to change

WANinterface

IN (0-10 V) IN (4-20 mA)

Model overview

Page 30: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

30

MODEL OVERVIEW

SOFTWARE FUNCTIONS

Model overview

SeriesModel number Item

Con-struc-tion

OpenVPN

VPN-Ipsec

VPN-L2PT

VPN-PPTP

Tool-box

FTP-/ SFTP- Server

SMTP Client

DNS Server

DHCP Server LAN

DHCP Server WAN

SMB for USB Port

mbNET.easy MDH835 8835-UL Metal mb 24 - - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH830 8830-UL Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH831 8831 Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH834 8834-UL Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH8855 8855-UL-EU Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH855 8855-UL-AT&T Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH810 8810-UL Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH811 8811 Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH814 8814-UL Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH850 8850-UL-EU Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH850 8850-UL-AT&T Metal ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH815 8815-UL Metal ✔ - - - ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH816 8816-UL Metal ✔ - - - ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH841 8841 Metal ✔ - - - ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH819 8819-UL Metal ✔ - - - ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH849 8849-UL Metal ✔ - - - ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH858 8858-UL-EU Metal ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH858 8858-UL-AT&T Metal ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH859 8859-UL-EU Metal ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET MDH859 8859-UL-AT&T Metal ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini MDH860 8860 Metal mb 24 - - - - - ✔ - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini MDH861 8861 Metal mb 24 - - - - - ✔ - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini MDH862 8862 EU Metal mb 24 - - - - - ✔ - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini MDH862 8862 ATT Metal mb 24 - - - - - ✔ - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbNET.mini MDH863 8863 Metal mb 24 - - - - - ✔ - - - - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH900 8900 Plastic mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH901 8901 Plastic mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH905 8905 Plastic mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH906 8906 Plastic mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH910 8910 Metal mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH911 8911 Metal mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH915 8915 Metal mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSPIDER MDH916 8916 Metal mb 24 - - - ✔ ✔ - - - - - ✔ ✔ ✔ ✔ ✔ ✔

mbSECBOX MDH874 8874-UL Metal - - - - - ✔ ✔ - - - - ✔

Page 31: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

31

Portal functions

via mbCONNECT24FTP-/SFTPServer for USB Port

Firewall with IP ilter 1:1 NAT and Port Forwar-ding

PPP modem (analog/ISDN/mobile)

PPoE/PPTP WAN

DynDNS

mb-NETdns

Alarm manage-ment E-mail, SMS (Mul-tiplex inputs)

I/O mana-ger

LUAinter-preter

Routing WAN-LAN, VPN-LAN

Local conigu-ration inter-face via int. webser-ver

Protokoll of the webser-ver Routing

mb-WEB-2go

Internet SMS

✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ ✔ ✔ - ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ - - ✔ - - - ✔ - HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ - - ✔ - - - ✔ - HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ - - ✔ - - - ✔ - HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ - - ✔ - - - ✔ - HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ ✔ - - ✔ - - - ✔ - HTTP/ HTTPS ✔ ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - - - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - - - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ ✔ - ✔ - - - - - ✔ - ✔ HTTP - ✔ ✔

✔ ✔ - - - - - - - - - - ✔ HTTP/ HTTPS - - -

Subject to change

Model overview

Page 32: The Secure Solution for Remote Access, Data Collection and M2M-Communication€¦ ·  · 2017-07-27The Secure Solution for Remote Access, Data Collection and M2M-Communication ...

MB connect line GmbH ofers universal solutions for worldwide

remote maintenance of machines and equipment. The specialists

at MB connect line can draw on years of experience and extensive

know-how.

MB connect line GmbH

Winnettener Str. 6

91550 Dinkelsbühl

Germany

Tel. +49 (0) 98 51 / 58 25 29 0

Fax +49 (0) 98 51 / 58 25 29 99

MB connect line Inc.

4320 Winield Road, Suite 200

Warrenville, IL 60555

USA

Tel. +1-630-797-0093

[email protected]

[email protected]

www.mbconnectline.com

Follow us:

EN: facebook.com/mbconnectlineinc

DE: facebook.com/mbconnectline

EN: twitter.com/mbconnectlineen

DE: twitter.com/mbconnectline © 2

016

MB

Co

nn

ect

Lin

e G

mb

H.

All

rig

hts

re

serv

ed

| Te

xt a

nd

ph

oto

cre

dit

s: M

B C

on

ne

ct L

ine

Gm

bH

, fo

toli

a,

shu

tte

rsto

ck,

Sie

me

ns

AG

| m

bC

ON

NE

CTL

INE

_E

N_

11_

16_

O |

Layo

ut:

H1QN

.de