Network and IT Guidance Technical Bulletin - Johnson Controls

Network and IT Guidance Technical Bulletin

Building Technologies & Solutions 2019-12-20

LIT-12011279 Release 10.1

stnetnoC

Contents

Document introduction................................................................................................................. 9 Summary of changes.......................................................................................................................... 9 Related documentation.................................................................................................................... 10

Network and IT considerations.................................................................................................. 11 Computer hardware configuration requirements........................................................................ 11 Metasys device IP address assignment (DHCP or manual).......................................................... 11 Metasys device hostname resolution (DNS or hosts file).............................................................. 15 DNS implementation considerations.............................................................................................. 15 DHCP implementation considerations........................................................................................... 15 Microsoft Active Directory service overview.................................................................................. 16 Support for Active Directory service (including single sign-on capability)...................... 17 Implementation considerations............................................................................................ 18 Metasys Server and SCT considerations............................................................................... 19 Child device considerations................................................................................................... 20 Information obtained from Active Directory services........................................................ 20 Enabling exact or alternate UPN authentication for a Metasys Server............................. 20 Enabling exact or alternate UPN authentication for SCT................................................... 21 Service account....................................................................................................................... 21 User account rules.................................................................................................................. 23 User creation and permissions............................................................................................. 24 User management in Metasys UI.......................................................................................... 24 RADIUS Overview............................................................................................................................... 25 Situations when Metasys system login screen appears for RADIUS users....................... 26 RADIUS errors.......................................................................................................................... 27 Syslog overview................................................................................................................................. 28 Metasys system use of Syslog packet format...................................................................... 30 Web site caching................................................................................................................................ 31 Microsoft Message Queuing (MSMQ) technology........................................................................ 31

Network and IT Guidance Technical Bulletin

i

Contents

Introduction............................................................................................................................. 31 Recovery................................................................................................................................... 32 Message queue troubleshooting.......................................................................................... 33 Metasys system and virtual environments..................................................................................... 33 Monitoring and managing (SNMP)................................................................................................. 34 Time management (Simple Network Time Protocol [SNTP])....................................................... 35 Email (SMTP)...................................................................................................................................... 35 Encrypted email................................................................................................................................. 36 Communication to pagers, email, printer, SNMP, or Syslog destination................................... 36 Remote access to the Metasys system using a VPN...................................................................... 37 Metasys system architecture............................................................................................................ 37 Protocols, ports, and connectivity for the Metasys system........................................................... 38 Protocols and ports tables..................................................................................................... 38 Connectivity and protocol diagrams.................................................................................... 48 ZigBee channels...................................................................................................................... 58 Spanning trees........................................................................................................................ 58 Field bus considerations................................................................................................................... 58 Pre-boot Execution Environment (PXE).......................................................................................... 59 Network reliability requirement...................................................................................................... 59 Metasys system security considerations........................................................................................ 59 General security recommendations..................................................................................... 59 Metasys access security......................................................................................................... 59 Secure Sockets Layer (SSL)/Transport Layer Security (TLS)............................................... 70 Metasys for Validated Environments (MVE)......................................................................... 73 Metasys server considerations........................................................................................................ 73 ADX-specific features.............................................................................................................. 73 ADX split configuration.......................................................................................................... 73 Metasys Network with an ADX............................................................................................... 74

Network and IT Guidance Technical Bulletin

ii

Contents

ADSADX log folder.................................................................................................................. 74 Windows Internet Explorer web browser............................................................................ 75 Anti-spyware considerations................................................................................................. 75 Backup considerations for the Metasys Server.................................................................... 75 Supported operating system, SQL Server software, and IIS versions........................................ 76 Supported network engine models and releases with security attributes................................ 77 Internet Information Server (IIS) anonymous access considerations (Metasys Server and SCT)........................................................................................................................ 77 General information............................................................................................................... 77 Enabling and disabling anonymous access on the default web site................................ 78 Databases........................................................................................................................................... 80 Microsoft SQL database considerations.............................................................................. 80 Historical data storage........................................................................................................... 82 Data backup/restore............................................................................................................... 82 Site Management Portal UI.............................................................................................................. 82 Metasys Advanced Reporting System UI.............................................................................. 82 Java software and private JREs.............................................................................................. 83 Web browser recommendations.......................................................................................... 83 Launcher download options and proxy settings................................................................ 83 Pop-up add blockers............................................................................................................... 86 Sleep power option on Windows 8.1 and Windows 7 computers..................................... 87 Disabling User Account Control............................................................................................ 87 Metasys dial-up networking.............................................................................................................. 88 Metasys Application Programming Interface (API)....................................................................... 88 Network Interface Cards (NICs)....................................................................................................... 89 Appendix: Network and IT terminology.................................................................................... 89 Active Directory Service.................................................................................................................... 89 Active Directory Service Domain/Domain Controller.................................................................... 89 Active Directory Service Schema..................................................................................................... 89

Network and IT Guidance Technical Bulletin

iii

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download