Converts RS232 serial data connections into AES encrypted IP packets
Flexible Serial Data Extensions over IP Packet or MPLS Networks
Overview & Applications
The Black•Tube CEP RS232 converts RS232 serial data connections into AES encrypted IP packets, extending the serial data over very cost effective Ethernet or MPLS based LAN/WAN/MAN wired and wireless networks. Synchronous, Asynchronous, Isochronous or HDLC serial data is encrypted then encapsulated into IP packets. This facilitates the interconnection of Serial Data over IP between Serial Bulk Encryptors (KIV7/OMNI), Data Terminals, Data Acquisition Systems, WAN Routers and Bridges
and SCADA RTUs.
Layer 1 with Isochronous Support
In Layer 1 operating mode every bit is encapsulated into an IP packet. The size and frequency of the IP packets can be set with data bit rates from 75 bits to 256 kilobits per second. Isochronous serial protocols, such as Conitel, are transported synchronously to maintain message alignment. A configured number of incoming packets are buffered in order to compensate for the packet delivery jitter introduced by the network. The size of the Tube bit buffer is configurable to accommodate the peak amount of jitter.
Asynchronous Over IP
Asynchronous characters from the RS232 interface with 5 to 8 data bits, baud rates from 1.2 to 38.4 kilobits, 1 or 2 stop bits that are with or without parity are efficiently encapsulated into IP packets. The encapsulation supports block mode transfers to minimize the bandwidth required. Additionally the latency is controlled by setting the Tube Bytes per packet.
HDLC Over IP
In Layer 2 operating mode HDLC Data frames, such as those used by Wide Area Networking protocols PPP and Frame Relay or proprietary Data Links, are transported within IP packets as HDLC over IP. The Serial to Packet conversion only occurs when HDLC frames are active.
SCADA Protocol Transparency
The Black•Tube CEP transports Bit or Byte orientated SCADA protocols transparently because of its unique TDM circuit emulation capability. RTU transmit data is encapsulated into IP packets at 64,000 samples per second and de-encapsulated at the
Assured Delivery Protocol
| Protector OPTION -PRO The protector option utilizes the second LAN interface as a redundant path for the interconnection of the IP encapsulated RS232 data. The extension of the RS232 has a fault tolerant link that is configured to always on, or with switch over criteria. |
Applications
Black•Tube CEP RS232 Utility Applications
NERC -CIP mandates control center redundancy. RTUs must be accessible from, and be able to connect to, multiple control centers. Black•Tube CEP continuously monitors connectivity to the active control center and automatically switches to the active backup control center (1 to 4 supported).
- Meets NERC mandates for control center redundancy - Preserves investment in RTU and Central site SCADA - Facilitates control center redundancy with IP flexibility - Supports up to four redundant control centers ⁻ Redundant and diverse connectivity |
Black•Tube CEP Multidrop |
In order to minimize the number of analog telephone circuits required to connect Data Center Front End SCADA controllers to Substation Remote Terminal Units Multi-Drop communication protocol was implemented. The CEP Multi-Drop feature allows a single RS-232 SCADA host connection to communicate with up to 8 remote terminals over a packet based network
The Black•Tube CEP transparently supports Multi-Drop by simultaneously transmitting IP packetized Front End SCADA messages to up to eight remote Black•Tube CEPs. The Black•Tube CEP connected to the addressed RTU detects a control signal and sends the SCADA response back to the Serial interface connected to the Front End polling port.
Black•Tube CEP Management
Management Module
Black•Tube CEP isolates management and data plane functionality with the use of two separate processor modules. Management processor access is limited to encrypted sessions via SSH, or SNMPv3, that employ AES 256 bit keys and sophisticated NIST passwords. These sessions may be established after authentication via TACACS+ or Radius. | The independent Linux based management plane of the Black•Tube CEP ensures Critical Infrastructure Data is isolated from management network access. The Management Module uses internal serial ports to connect to the Data Plane processor. Administration and User Logs are available with Syslog. |
NERC CIP Compliance |
The Black•Tube CEP installations achieve NERC CIP compliance with a combination of internal and external functions.
Internally the Management Module software has the sophistication to implement comprehensive policies and privileges for administrator and user accounts. Administrator policy includes removal, disabling or renaming.
Interoperability with external functions such as Syslog, Network Timing Protocol, TACACS+ and Radius with its support for RSA SecureID delivers trusted compliance.
Electronic Security Perimeter | CIP-005 Requirement | IPTube CEP Solution |
|
R2.2 - Enable only needed ports R2.4 - Strong Technical Controls R3.2 - Unauthorized Access R5.3 - Access Logging |
• Each Port may be enabled or disabled • RSA's SecureID two-factor Authentication • Alert messages via Syslog or TACACS+ • Syslog of Access and Command interactions |
System Security Management | CIP-007 Requirement | IPTube CEP Solution |
Access control is Authenticated, Authorized and Accounted for with Radius or TACACS+. Security Patches managed proactively. | R2.1-3 - Ports and Services R3 - Security Patch Management R5.3 - Secure Passwords R6.4 - Security Status Logs |
• Kernel and application upgrade alerts • Require minimum length, strength, frequency • Syslog and AAA via TACACS+ |
Technical Specifications
Black•Tube CEP RS232 Technical Specifications | ||
LAN Network Interface:
RS232 Interface Control Signal Extension: RS232 Over IP Protocol:
| Management:
|
How To Order
Black•Tube CEP RS232
Ordering Information



Black•Tube CEP RS232 Optional Features
Protection: Option Pro
The protector option utilizes the second LAN interface as a redundant path for the interconnection of the IP encapsulated RS232 data. The extension of the RS232 has a fault tolerant link that is configured to always on, or with switch over criteria.
How to Order – Black•Tube CEP RS232 | ||
Part No. | Description | Notes |
CEP-007-2232-0x | Black•Tube CEP RS232 | Specify # of RS232 Ports Enabled (1 to 3) |
CH-CEP-007-2232-0x | Chassis Slot Card: Black•Tube CEP RS232 | Specify # of RS232 Ports Enabled (1 to 3) |
Base Option | Specify as suffix | |
-EXT | Extended Temperature | -40C to 70C |
-PRO | Protector Option | Fault Tolerant Network Interconnect |
-Y | Serial Redundancy | Serial Interface hardware redundancy |
Power Options | Specify as suffix | Hot Standby Configuration 2nd Power Suffix |
-HSPDC | Connector for Dual DC Supply | |
-WIREDC | Power Supply Module 12/26 VDC Screw Term | |
-N48VDC | Power Supply Module Negative 48 Volt DC | Isolated Negative 48 Volt Power |
Rack Mount Option | Specify as suffix | |
-RACKMNT | 19" Wide Rack Mount Brackets | Enclosure Nut Serts Installed |
Wall Mount Option | ||
-WALLMNT | Right Angle Wall Mount Brackets | Enclosure Nut Serts Installed |