Manual Hirschmman
Manual Hirschmman
GUI Application
HiView 4.2
Manuals and software are protected by copyright. All rights reserved. The copying, reproduction,
translation, conversion into any electronic medium or machine scannable form is not permitted,
either in whole or in part. An exception is the preparation of a backup copy of the software for
your own use.
The performance features described here are binding only if they have been expressly agreed
when the contract was made. This document was produced by Hirschmann Automation and
Control GmbH according to the best of the company's knowledge. Hirschmann reserves the right
to change the contents of this document without prior notice. Hirschmann can give no guarantee
in respect of the correctness or accuracy of the information in this document.
Hirschmann can accept no responsibility for damages, resulting from the use of the network
components or the associated operating software. In addition, we refer to the conditions of use
specified in the license contract.
You can get the latest version of this manual on the Internet at:
https://www.doc.hirschmann.com
Contents
1 Introduction 5
1.1 Password change during first time log on 6
3 Using HiView 13
3.1 Devices Tab 14
3.1.1 Adding a device 15
3.1.2 TLSv1 and TLSv1.1 algorithm handling 15
3.1.3 Tile view 16
3.1.4 Table view 18
3.1.5 Removing a device 19
3.1.6 Device access 19
3.1.7 Connecting to Industrial HiVision 23
3.2 Discovery Tab 25
3.2.1 Discovery Tab Visibility 25
3.2.2 HiDiscovery v2 25
3.2.3 Network Adapter 26
3.2.4 Signaling a Device 27
3.2.5 First time log on (Password change) 27
3.2.6 IP address management 28
3.2.7 Device access 28
8 Maintenance 41
B Index 48
C Further support 49
1 Introduction
Application Example
As the administrator of a large data network, you sometimes have to visit
sites within your data network.
With a USB stick in your pocket, on which you have previously copied
HiView with your settings, you have barrier-free access to the graphical
user interface of Hirschmann Ethernet devices.
Forget difficulties such as the incompatibility of browsers, Java versions
or Java plug-ins, installation with entries in the registry or the changing
cache content of browsers on different computers.
You can find detailed information about changing the password in “First time
log on (Password change)” on page 27.
2.1.1 Hardware
Processor
x86 compatible CPU, min. 1 GHz
RAM
at least 1 GB, 2 GB recommended
HiView requires approx. 200 MB free RAM.
For every open window, HiView requires an additional 500 MB RAM
To start Industrial HiVision, HiView requires an additional 2 GB RAM
Disk space
1 GB free.
Monitor resolution
at least 1024x768 pixels.
2.2 Installation
To start the HiView application, double click the HiView program symbol.
The first time you start the HiView application, HiView asks you to accept
the license conditions.
After you have accepted the license conditions, HiView creates the
configuration file HiView[2.0].cfg.
Among other things, the configuration file also contains the languages of the
application interface that you can select.
Note: When you restart the application, HiView opens the last saved
configuration.
Note: When you restart the application, HiView opens the last saved
configuration.
2.3 Deinstallation
Delete the directory where you extracted the application files with the
command rm -rf
3 Using HiView
After you start it the first time, HiView displays the following program window:
Figure 1: HiView program window after you start it the first time
The Devices tab displays your devices as either a tile or a list item. You can
verify the reachability and configure the devices displayed in the dialog. The
dialog allows you to configure the devices using a web browser, telnet or
SSH.
If you use HTTPS to connect to a device and get the message, “Secure
connection failed, please try again using a URL prefix and
port.”, then update the device software.
After you update the device software, proceed as follows:
Make a new certificate.
Use an up-to-date hash algorithm to make the new certificate.
Upload the new certificate on the device.
If you can not use HTTPS to connect to your device, then you can try to
access the device with HTTP.
To disable the TLSv1 and TLSV1.1 algorithms, perform the following steps:
Close the HiView application.
Using a text editor, save a text file as security.properties to your
installation directory:
Enter the following text into the security.properties file:
reenableUnsecureTLSAlgorithms=false
Save the security.properties file.
Restart the HiView application.
The Tile view is the HiView default setting. If you want to switch from Tile
View to Table view, proceed as follows:
To display the Table view, select Preferences > View > Table view.
Every tile represents one device and displays the device symbol, the device
name and the device address.
The more often you establish a connection to the device, the further forward
HiView places the device in the Tile view.
To display the Tile view, select Preferences > View > Tile view.
Every table row represents one device and displays the device symbol, the
device name and the device address. Furthermore, HiView indicates with a
check mark in the “Open” column if the graphical user interface of the device
is open.
The more often you establish a connection to the device, the further up the
list HiView places the device in the Table view.
Certificate Fingerprints
If HiView does not have an HTTPS certificate fingerprint on record for a
device, then HiView displays the “Confirm HTTPS Certificate“ dialog. The
dialog contains the fingerprint of the HTTPS certificate. HiView also
displays the “Confirm Applet Signature Certificate“ dialog when a
fingerprint for an applet signing certificate is not on record. To help
prevent a man-in-the-middle attack, verify that the dialog contains the
correct fingerprint.
If you do not know the fingerprint of the HTTPS certificate, then you can
use HiView to get the fingerprint. To get the fingerprint of the HTTPS
certificate, perform the following steps:
In a controlled environment, connect the isolated device, for which you
wish to get the fingerprint, directly to your PC.
Open the GUI of the device.
When the fingerprint of the certificate is not recorded in the
ssl_known_hosts file, HiView displays the “Confirm HTTPS
Certificate“ dialog.
Copy the fingerprint to a secure location.
If you do not know the fingerprint of the applet signing certificate, then you
can use HiView to get the fingerprint. To get the fingerprint of the applet
signing certificate, perform the following steps:
In a controlled environment, connect the device, for which you wish to
get the fingerprint, directly to your PC.
Open the GUI of the device.
In the “Confirm HTTPS Certificate“ dialog, click either the “Accept“ or
the “Accept Permanently“ button. The “Confirm Applet Signature
Certificate“ dialog opens.
Copy the fingerprint to a secure location.
If HiView does not display the “Confirm HTTPS Certificate“ dialog, then
HiView accepted the fingerprint permanently in a previous session. To
display the “Confirm HTTPS Certificate“ dialog again, perform the
following steps:
Close the GUI of the device.
Open the <Installation directory>/ssl_known_hosts text file.
Comment out the line that contains the IP address and fingerprint of
the device.
In HiView, reopen the GUI of the device. The “Confirm HTTPS
Certificate“ dialog opens.
If HiView does not display the “Confirm Applet Signature Certificate“
dialog, then HiView accepted the fingerprint permanently in a previous
session. To display the “Confirm Applet Signature Certificate“ dialog
again, perform the following steps:
Close the GUI of the device.
Open the <Installation directory>/known_applet_signatures
text file.
Comment out the fingerprint lines.
In HiView, reopen the GUI of the device.When HiView did not record
the fingerprint of the HTTPS certificate in a previous session the
“Confirm HTTPS Certificate“ dialog opens.
In the “Confirm HTTPS Certificate“ dialog, click either the “Accept“ or
the “Accept Permanently“ button. The “Confirm Applet Signature
Certificate“ dialog opens.
After the network administrator gets the fingerprint of the certificate, the
network administrator uses a secure channel to send the fingerprint to the
remote client. The remote client compares the fingerprint received from
the network administrator to the fingerprint in the dialog. To help you verify
the fingerprint, HiView lets you copy and paste the fingerprint in the
“Fingerprint to verify“ field.
The buttons in the dialog let you perform the following actions:
“Accept“
HiView accepts the certificate, but does not record the fingerprint for
future reference. HiView opens the dialog for confirmation each time
you access the device.
“Accept Permanently“
HiView records the fingerprint for future reference.
“Cancel“
The dialog closes without making a connection to the device. The
fingerprint is not recorded for future reference.
Note: If you use your computer to connect to the device through a firewall,
enter a rule in the firewall that allows the data traffic through port 161.
Displaying a certificate
Hirschmann devices usually have certificates for the Web application (jar
file). Depending on the device you access, the connection also has a
certificate.
To view the certificates of HiOS devices, with a software version lower
than 7.0, select in the graphical user interface of the device Tools >
Retrieve Product.
To view the certificates of the HiOS devices, with software version 7.0
or higher, open the certificate in the web browser.
Note: You can find the default port values in the Industrial HiVision
manual, chapter A.5 “Ports used“.
When you changed the Project Data Server > Port from the default port
value, perform the following steps:
In the “URL“ field, enter the following information: Web Server > Protocol
://Management Station IP Address:Web Server > Port?project-
data-port=Project Data Server > Port.
For example, https://10.0.1.159:11194?project-data-
port=10000.
Press the “Return“ key.
Note: The Web server port value that Industrial HiVision uses is version-
dependent. You find the port that Industrial HiVision uses in the settings
under Preferences > Advanced > Services.
Starting with Industrial HiVision version 7.0 you find the current port number
in the Preferences > Advanced > Services Access dialog.
The Discovery tab allows you to search for devices in your network. The tab
also allows you to specify the IP parameters for the devices. The tab also
allows you to configure the devices using a web browser, Telnet or SSH.
The Discovery tab is compatible with devices that support HiDiscovery v2.
Classic Switches since version 09.0.01
HiOS since version 05.0.00
HiSecOS since version 03.0.00
3.2.2 HiDiscovery v2
HiDiscovery v2 is a primary setup tool based on the SNMPv2 protocol. After
you select the network adapter and click the Refresh button, the Discovery
tab displays a line for every device that responds to a HiDiscovery v2 inquiry.
Note: If you change the network interface parameters of the computer, then
restart HiView.
To set the LEDs to flashing for the selected device, mark the Signal
checkbox.
To stop the flashing, unmark the Signal checkbox.
Example configuration
To change the default password on a device proceed as follows:
Open the Discovery tab.
Select a device which has a marked checkbox in the Password
Change column.
Right-click on a selected device.
In the context menu select the Change Password option.
In the Change Password > New password field, type in the password
that you want to use to access the device.
You can use the following methods to verify your password:
– Mark the Show Password checkbox. The New password field
displays the password in plain text.
– Type in the same password in the Confirm password field.
Click the OK button.
Note: You can change the password on several devices at the same time.
For security reasons, it is recommended that each device has a different
password.
Configure
The Configure function opens the Discovery Configuration dialog which
allows you to specify the IP parameters and name of a device.
GUI
The GUI function opens the graphical user interface of the device which
allows you access to the device configuration.
Note: If you use your computer to connect to the device through a firewall,
enter a rule in the firewall that allows the data traffic through port 161.
SSH/Telnet
The “SSH/Telnet“ function allows you to remotely login to the Command
Line Interface (CLI) of the device using an encrypted network protocol.
HiView attempts to connect to a device using SSH first. When HiView
cannot connect to a device using SSH, HiView attempts to connect to the
device using Telnet.
To help provide secure communications, use SSH and disable Telnet on
the device.
The prerequisite for an SSH connection is that the SSH server using
SSHv2 is enabled in the device.
Ping
The Ping function allow you to test the reachability of a device in an IP
network. The function also measures the round trip time of the ICMP echo
request and reply.
When you install the HiView program, the Applet Launcher is added to the
installation directory. You can find the Applet Launcher in the HiView
installation directory.
You can use the Applet Launcher in conjunction with other external
programs. Calling the Applet Launcher from an external program lets you
open the Graphical User Interface (GUI) of a device.
HiView for example, uses the Applet Launcher to open the Graphical User
Interface of a device. After you open a supported device with HiView, it stores
the device information and displays the device.
Note: The Applet Launcher is also available for Linux users. To start the
Applet Launcher with the Linux operating system, open the HiView root
directory and start the AppletLauncher.sh.
After you press the Return key, the command window displays the Usage
line and descriptions of the available arguments. On the Usage line the
arguments in brackets, “[]” are optional.
– IP address
This is the only mandatory argument. This value is the IP address of
the device.
– Port
The TCP web port of the device for example, 80 = HTTP, 443 =
HTTPS. If you changed the web port of the device, then enter the web
port in the command. Otherwise, this argument is optional.
– ?Param=Value[&Param=Value]
The URL query project-data-port parameter is used to connect to
Industrial HiVision. See “Connecting to Industrial HiVision” on
page 23.
-user
This argument is optional. Enter the login user name for the device. This
argument is used for the auto-login function. Use this argument only in
combination with the password argument.
-password
This argument is optional. Enter the login password for the device. This
argument is used for the auto-login function. Use this argument only in
combination with the user argument.
-locale
This argument is optional. This argument is used to specify the GUI
language of the device. The possible values are en for English, and de for
German.
4.1.2 Auto-Login
You can use the Applet Launcher to automatically login to the device.
The following example describes how to enter arguments in the command
line to automatically login to a device. The web port on the device was also
changed.
In the following example, these values are used:
The protocol with which the Applet Launcher communicates with the
device is https.
The IP address of the device is 123.456.78.90.
The web port was changed to 5000.
The user name is admin.
The password is private.
The desired GUI language is English.
To automatically login to a device, enter the values in the command line as
follows:
AppletLauncherCmd.exe -address https://123.456.78.90:5000 -
user admin -password private -locale en
5 Saving an individual
configuration
8 Maintenance
The HiView Devices tab has been tested and is compatible with the following
devices and software versions:
Note: The * symbol entered next to the version means the software version,
and later versions, support the HiDiscovery v2 protocol.
EAGLE20
05.4.00*
05.3.02
MACH100 L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH100GE L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH1000 L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH1000GE
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH1000GE L3P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH3000
3.46
MACH4000 L2P/L3E
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH4000 L3P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MACH40XG L2P/L3E/L3P
09.1.00*
09.0.16*
09.0.04*
08.0.11
MS20/30 L2E
09.1.00*
09.0.16*
09.0.04*
08.0.11
MS20/30 L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
Octopus OM L2E
09.1.00*
09.0.16*
09.0.04*
08.0.11
Octopus OM L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
Octopus OS L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
PowerMice L2P/L3E/L3P
09.1.00*
09.0.16*
09.0.04*
08.0.11
RS20/30/40 L2E/L2P
09.1.00*
09.0.16*
09.0.04*
08.0.11
RSB
05.3.09*
05.3.03
RSR
09.1.00*
09.0.16*
09.0.04*
08.0.11
BRS
08.1.00*
07.4.01*
EAGLE20 Ruggedized
03.3.00*
03.0.00*
02.0.01
01.0.00
EES (EES-PRP)
07.1.00*
07.0.06*
06.1.00*
06.0.02*
05.0.03
04.0.04
03.0.04
EES-HSR, EES-MRP
02.0.03
GRS1020/30
08.1.00*
07.0.06*
06.1.00*
06.0.02*
05.0.03
04.0.04
MSP30
08.1.00*
07.0.06*
06.1.00*
06.0.02*
05.0.03
04.0.04
03.0.04
MSP40
08.1.00*
07.0.06*
06.1.00*
B Index
A Storage medium 37
Applet signature certificate 19 System requirements 8
B T
Barrier-free 5 Table view 18
BAT devices 15 Technical questions 49
Tile view 16
C TLS Protocols 15
Cache 15, 37 Training courses 49
Certificate 22
Configuration file 10, 11 U
UDP Port 26
D Update 41
Device Password 27 URL 15, 23
Disk space 8 USB stick 5, 10, 11, 12
F W
FAQ 49 Windows 10, 12
Fingerprint Verification 19
Firewall 26 Z
Zip file 10, 11, 12
H
HTTPS certificate 19
I
IP Address 28
J
Java error 14
L
Language 10, 11
License conditions 10, 11
Linux 11
M
Memory space 37
Monitor resolution 8
P
Portable 5
Processor 8
Product certificate 22
Program window 15, 19
R
RAM 8
S
SD Card 10, 11, 12
Stand-alone 5
C Further support
Technical questions
For technical questions, please contact any Hirschmann dealer in your area
or Hirschmann directly.
You find the addresses of our partners on the Internet at
http://www.hirschmann.com.
A list of local telephone numbers and email addresses for technical support
directly from Hirschmann is available at
https://hirschmann-support.belden.com.
This site also includes a free of charge knowledge base and a software
download section.