Compact Hardened Managed Ethernet Switch

Sales of this product has been discontinued. Please contact us to discuss alternatives.

ML1200 - Legacy

Compact Hardened Managed Ethernet Switch

Sales of this product has been discontinued. Please contact us to discuss alternatives.

GE Vernova's MDS WiYZ™ is an intelligent data acquisition and networking platform combining wireless connectivity for sensors, I/O, instruments and meters with comprehensive network infrastructure solutions for IP/Ethernet and serial, machine-to-machine and backhaul communication to host systems and devices.

MDS WiYZ

Intelligent Data Acquisition

GE Vernova's MDS WiYZ™ is an intelligent data acquisition and networking platform combining wireless connectivity for sensors, I/O, instruments and meters with comprehensive network infrastructure solutions for IP/Ethernet and serial, machine-to-machine and backhaul communication to host systems and devices.

Versatile
  • Battery or line powered Remotes
  • Single, sensor or multiple analog & digital I/O
  • I/O Extension to regenerate remote signals
  • Poll data using Modbus
  • Collect, time-stamp and store data
  • FTP for transfer data files
  • Configurable data sampling & transmission rates
  • Bridge communication to RTUs, Meters and Controllers
  • Bridge between wired & multiple WiFi, MDS and cellular wireless options
Reliable
  • Rugged NEMA 4X, IP 65 housings
  • -40 to 70° C temperature ranges
  • Class 1, Division 2 rated environments
  • Self-healing mesh networking
Cost Effective
  • Battery powered Remotes reduce cost
  • Ultra-low power operation reduces solar power infrastructure cost
  • Outdoor, hardened components eliminate extra enclosure, accessory and integration costs
  • Self-creating mesh networking reduces path analysis and deployment costs
  • Multiple sensor and I/O capacity
Secure
  • 128-bit encryption and authentication
  • Password protected access and lockdown
  • Frequency hopping 2.4 GHz mesh network
WiYZ Application Advantages
WiYZ Application Advantages
Sensors and I/O Signals
  • Use WiYZ Remotes with level, pressure, flow and temperature sensors to remotely monitor important parameters
  • Connect digital signals for status monitoring and control
  • Regenerate signals from sensors and I/O to RTUs and controllers
System Communication
  • Interface data to host systems using Modbus
  • Transfer data files to Enterprise systems using ftp
  • Bridge IP/Ethernet and serial communication to remote controllers and multi-variable
Gateway Connectivity
  • Enterprise connectivity using public cellular communication
  • Connect multiple WiYZ networks to SCADA systems using MDS point-to-multipoint wireless
  • Connect to your plant's WiFi infrastructure

The WiYZ Gateway is a powerful and flexible device facilitating wired and wireless connectivity to host systems and Enterprise 
networks. The WiYZ Gateway supports up to 4 wireless connectivity options for bridging communication between Mesh, Cellular, WiFi and MDS wireless.

The WiYZ Gateway establishes and maintains the ISA 100 mesh network. It also collects data from WiYZ Remotes. Data can be locally stored on the gateway in between transmissions to Enterprise networks resulting in significant savings in cellular communication costs. Alternatively, the gateway supports Modbus for direct polling of sensor and I/O data in real time. The WiYZ Gateway operates as a multi-device hub and bridges IP/Ethernet and serial communication (either wired or wireless) anywhere, between remotes, controllers and PLCs and host systems.

  • Configurable data transmission periods
  • Storage of time stamped data in between data transmissions
  • Security implementation including encryption and password access
MDS WiYZ
MDS Wireless standards labels

MDS WiYZ Remotes are packed with features and functionality to match up with a diverse range of remote monitoring and control requirements. Each Remote accommodates 2 Analog Inputs, 2 Analog Outputs, 2 Digital Inputs and 2 Digital Outputs. One RS232 port is used for configuration. A second RS232/RS485 port is available for connection to an external device.

  • Configurable sample periods allow remotes to periodically sample sensor and I/O data, and transmit back to the gateway at specified intervals, conserving battery power and reducing network traffic.
  • Condition-based data transmission allows remote to transmit data only when there is a change of state for a Digital Input
  • I/O extension can be implemented to regenerate sensor and I/O signals between devices
MDS WiYZ
MDS Wireless standards labels

MDS WiYZ Device Manager

Use the web based WiYZ Device Manager for convenient, intuitive configuration and maintenance of WiYZ devices. Device Manager is resident in the WiYZ Gateway and can be accessed via the Ethernet port or over the air via any of the backhaul options. The WiYZ Device Manager provides a comprehensive set of tools and utilities such as configuration wizards, device profiles for repetitive configuration tasks and utilities for saving device configurations and upgrading firmware.

  • Access over-the-air or using Gateway Ethernet port
  • Device profiles simplify repetitive setup tasks
  • Built-In Wizards guide users through multi-step configuration processes
  • View I/O Data and Status information from WiYZ Remotes or other devices on the WiYZ network
  • View data logged on Gateway in trend graph formats
  • View device status and performance information
  • Simple Maintenance Menus for firmware upgrade and saving radio configuration
  • Menus for broadcasting firmware upgrades to all Remotes
  • Network Configuration Features
  • Setup bridging over multiple wireless option
  • Monitor network status and health
MDS WiYZ Device Manager

Wireless I/O Extension

Use the MDS WiYZ I/O Extension feature to regenerate I/O signals at meters, RTUs and controllers when direct wiring is too expensive or impractical. Gas wellhead pressure values can be monitored by a WiYZ remote located at the wellhead and regenerated by another WiYZ remote into an RTU or Flow meter.

Wireless I/O Extension
  • Use WiYZ to measure pressures at a gas wellhead
  • Connect pressure instruments or transducers directly to a WiYZ Remote
  • Transmit pressure values to a WiYZ remote at RTU or Flow meter
  • Regenerate the pressure values as 0-5 V or 0-20 mA signals to RTU
  • Connect 1-2 Analog and 1-2 Digital signals per remote
  • Use WiYZ Remote’s internal battery power at locations without power
  • Eliminate need to run signal wire between wellhead and meter site

Remote Data Collection & Network

Collect process data from remote assets using IP/Ethernet to local PLC or controller for monitoring and control applications where it is cost prohibitive to run signal wire or when power is unavailable. Use WiYZ to directly connect sensors, transducers or I/O from instruments and meters. WiYZ Remotes automatically form a mesh network around obstructions to the WiYZ Gateway.

Remote Data Collection & Network
  • Use WiYZ to automatically create a mesh data acquisition network for remote assets
  • Collect level, pressure and status data from remote devices and send to Gateway
  • Connect PLC or Controller to WiYZ serial or IP/Ethernet port
  • Use Modbus to poll data collected at WiYZ Gateway
  • Use WiYZ Remote battery power at locations without power or DC power at both Remote and Gateway
  • Use WiYZ to power transducers and instruments

Cellular or MDS eNET Backhaul

When Operations centers and Enterprise networks need long range access to remote sites, use the Cellular infrastructure or MDS eNET option. The WiYZ Gateway operates not only as the access point to the MDS Mesh network, but also supports WiFi for local drive-up data access.

Cellular or MDS eNET Backhaul
  • Collect data from WiYZ gateway using Modbus TCP polling
  • Transfer data that is logged and timestamped in the Gateway via ftp to host systems.
  • Use the WiYZ Gateway to create a local IP/Ethernet network for other metering devices and controllers
  • Use GSM/GPRS, CDMA or MDS eNET to communicate with remote WiYZ networks
  • Use WiYZ for drive up WiFi access to remote data and network

Substation Network Infrastructure

When a utility uses WiFi at a substation to collect data from IEDs or RTUs and monitor status/condition information the WiYZ Gateway can operate as the WiFi access point to bridge wireless Ethernet and serial data onto the Cellular network or private MDS eNET network. The WiYZ Gateway also supports wired Ethernet and serial connectivity to interface other devices and systems.

Substation Network Infrastructure
  • Use the WiYZ Gateway to bridge WiFi enabled IEDs or controllers onto cellular infrastructure or IP/Ethernet hub
  • Optionally connect Ethernet and serial devices to the WiYZ Gateway
  • Use WiYZ Remotes to monitor other substation status points
  • Use GE Vernova MDS eNET to monitor other devices remote from the substation

Facility Data Acquisition and Networking

When process facilities need to automate data collection from remote assets, metering devices and controllers WiYZ has the versatility not only to form a mesh network around obstructions and interference but also to provide wireless serial and IP/Ethernet connectivity. The WiYZ Gateway can operate as a WiFi remote for connection to an existing WiFi network or create a MDS eNET network for a comprehensive network infrastructure.

Facility Data Acquisition and Networking
  • Collect data from multiple WiYZ Gateways and Remote clusters monitoring status, pressure level and temperature parameters
  • Provide IP/Ethernet and serial communication to remote controllers
  • Bridge remote data onto facility WiFi networks
  • Use GE Vernova MDS eNET to for license free communication to plant control and monitoring systems

The MDS LEDR Series provides full duplex and scalable bandwidth in both subrate and fullrate models. Designed to connect to industry-standard sources, the LEDR Series is available in protected configurations with displays, integrated web servers, and management systems.

MDS Backhaul LEDR Series

Scalable, Long Range Licensed Point-to-Point Solutions

The MDS LEDR Series provides full duplex and scalable bandwidth in both subrate and fullrate models. Designed to connect to industry-standard sources, the LEDR Series is available in protected configurations with displays, integrated web servers, and management systems.

JPAX family is a purpose-built communications solution specifically designed for utility operations, providing the required security and dependability through layers of redundancy. The platform is based on MPLS-TP (Multi-protocol Label Switching with Transport Profile) technology that maintains deterministic performance through packet based communications providing utilities with increased efficiency and ease of integration.

JPAX family

Packet-Switched Networking Solution for Teleprotection with Hybrid+ Transport Capabilities

JPAX family is a purpose-built communications solution specifically designed for utility operations, providing the required security and dependability through layers of redundancy. The platform is based on MPLS-TP (Multi-protocol Label Switching with Transport Profile) technology that maintains deterministic performance through packet based communications providing utilities with increased efficiency and ease of integration.

JunglePAX WAN ports supports standard MPLS

Both JunglePAX 10G WAN ports (1 & 2) now optionally support standard MPLS mode in addition to Hybrid mode as a user configurable option. Additionally, two out of four 1G WAN ports (4 & 6) now operate in standard MPLS mode (not user-configurable).

Use of standard MPLS mode allows for interoperability with foreign MPLS equipment and Ethernet microwave radio devices. Note that foreign MPLS and Ethernet radio devices generally don’t support the IEEE 802.3ae standard, which is used by JunglePAX as a basis for hybrid mode implementation. The 1G WAN ports 3 and 5 continue to support Hybrid mode only. Use of Hybrid mode continues to be advantageous in standalone JPAX network applications as it allows native, non-packetized TDM services and MPLS services to coexist on the same fiber.

The WAN ports in standard MPLS mode allows for tunneling JunglePAX NMS information through foreign packet-based devices/networks to ensure that all JunglePAX nodes are visible regardless of whether they are optically connected to each other or via foreign packet-based devices/network.

JunglePAX WAN ports support standard MPLS JunglePAX WAN ports support standard MPLS

Native TDM and TDM over Packet: xTDM offers the best of both worlds

Introducing the xTDM Access Card for the JunglePAX Hybrid Packet & TDM platform that offers the best of both worlds. This add-on unit offers the flexibility to support both native TDM over Hybrid WAN ports as well as emulated T1/E1 signals over MPLS, making it extremely flexible for all customer applications.

This release also allows for establishing packetized point-to-point Nx64k services between xTDM-8A cards T, or T1E1-4A/CBUS-4A ports at the far end. Point-to-point Nx64k services between local xTDM-8A card and JIF-Share/CMUX/CDAX card residing at remote JMUX/TN1U/TN1Ue nodes are also supported via Evolution units.

t1/e1-cbus

The xTDM Access Card key features:

  • Up to 8 x bulk T1E1 services or up to 4 x CBUS ports (via future 90308-02 card)
  • Two ports per each RJ-45 connector, requiring the use of splitter cables to gain access to the even numbered ports
  • Supports transport of bulk T1/E1 over MPLS or SONET/SDH
  • Supports transport of Nx64kbps services over MPLS
  • Future supports for 1+1 redundant hardware configuration if two cards are installed in adjacent slots
  • Services can be established to existing T1E1-4A units

Evolution Module - Optically connecting JMUX and JPAX for simplified interoperability

GE Vernova’s new Evolution Module (B86900-01) enables migration to MPLS ring-by-ring or node-by-node AND offering an upgrade opportunity to modernize hardware while preserving highly dependable SONET/SDH delay performance for critical services through deployment of JunglePAX Hybrid Mode. Evolution and Hybrid work together to ensure ongoing security and dependability across both SONET/SDH and MPLS planes.

1 Gigabit of Ethernet data can now be passed over the same 1G+ fiber link as SONET VT1.5 or SDH TU-1’s to enable full interoperability between JMUX/TN1U and JPAX.

Evolution Modules Tying Lentronics Multiplexer and JunglePAX networks together via dual-home Evolution Modules. Showing TDM services that bypass packetization to create end-to-end TDM services with SONET/SDH equivalent performance

Advanced Network Management System for JPAX

GE Vernova's EnerVista INSIGHT Advanced NMS solution employs Smart Tile technology, replacing the existing Telenium Traffic Manager, to assist users build MPLS Tunnels, SONET/SDH VTU’s and Services. This approach employs a wizard-based engine that walks users through each of the unique build processes using a combination of maps, graphical services tools and optimizers to quickly achieve their desired outcomes.

Schedule a demonstration today to see the new GE Vernova EnerVista INSIGHT version 8.8.

EnerVISTA 8.8 image EnerVista 8.8
WAN Encryption for improved confidentiality

Encryption of all MPLS traffic carried over the WAN is now supported. This is a licensed feature, allowing users to encrypt individual fiber optic segments on any of the 12 WAN JunglePAX ports. After enabling Encryption on both sides of a WAN link, public/private keys will automatically roll based on the administrator’s configuration (30 min to 200 hrs), or keys can be manually renewed on each segment via the Web User Interface.

Purpose-Built for Teleprotection and Superior Performance

  • High speed protection switching within 3ms
  • Low end-to-end service latency within <1ms over SONET/SDH transport layers
  • Designed with layers of redundancy for improved security and dependability
  • ‘AAA’ secured and encryption for improved reliability

Single Solution Converging and Simplifying Operations

  • Flexible design for deployment across backhaul, aggregation and access networks
  • One box solution for mission critical OT and IT, capable of connecting multiple and diverse applications
  • Integrated and application-driven software simplifies network management
  • Network-wide Summary and Status Information dashboard for simplified health and integrity validation

Ruggedized with modular design lowering total cost of ownership

  • Industrially hardened with no cooling fans for longer life in harsh environments
  • Offers integrated application-specific access modules designed for critical production relaying applications
  • Certified to IEEE 1613 and IEC 61850-3 substation hardening requirements
  • Processes 24 Gb/s of traffic across the extended -20°C to + 60°C operating temperature
  • Flexible redistribution of service ports

JunglePAX Overview

The JunglePAX platform is designed for utilities with critical utility communications in mind. GE Vernova’s JPAX offers a truly converged solution with security and dependability for all applications whether they are critical Teleprotection circuits or for less time-sensitive business IT needs. Security and Dependability ensure data will be delivered and received on time when an actual data packet is sent, and data will not be falsely received when no data was sent. Both are key performance requirements to ensure utility communications reliably operate at all times. JunglePAX equipment is

  • Purpose built for teleprotection and superior performance
  • Single solution converging and simplifying operations
  • Ruggedized and Modular Design Lowering Total Cost of Ownership
JunglePAX Overview The JunglePAX solution can be applied to the overall power infrastructure from the Core (Backhaul) network to Aggregation and Access Networks, providing an application-defined approach to utility networking that assures service quality, security and perfo

Hybrid+ Mode, for critical teleprotection where 1ms latency is too slow

JunglePAX Hybrid+ technology offers the best of both worlds by preserving SONET/SDH performance in a packet-switched network. This is achieved by adding an independent SONET/SDH layer alongside the MPLS-TP layer (without impacting its capacity) over the same optical WAN link. Use of this layer is optional and is intended for TDM-based relaying applications (C37.94, RS-232 Mirrored Bit, G.703 64k etc.) that are extremely delay sensitive.

lentronics JPAX Hybrid Tech

Hybrid+ Technology found only in JunglePAX permits migration from SONET/SDH to Packet-transport technologies without compromising application performance, equipment reliability and network-wide availability.

 

Modernizing optical communications infrastructure without performance impact

Hybrid+ Technology found only in JunglePAX permits migration from SONET/SDH to Packet-transport technologies without compromising application performance, equipment reliability and network-wide availability.

Modernizing optical

What is Hybrid Transport Mode and why is it important?

  • Watch the full session here
  • Summary here
  • See the performance results here

Teleprotection Application

Utilities are concerned about the impact on critical infrastructure and damage or injury associated with a fault condition on the transmission network. Teleprotection is a critical utility application that enables protection devices to communicate in a coordinated, reliable and expeditious way. Distance or directional comparison relays that send tripping signals require deterministic communications with low propagation delay edge (substation) to edge (substation), often as low as within 8ms. The faster the tripping signal can be transmitted across network, the quicker the dangerous energized state can be removed. Due to their importance, tripping signals cannot tolerate network disturbances affecting availability, capacity, physical communication failures, maintenance related outages or security vulnerabilities.

JunglePAX Solution for Teleprotection

The JunglePAX platform has been designed for teleprotection applications with layers of redundancy to ensure there is no single point of weakness, industry leading protection switching within 3ms, and low end-to-end service latency within 1ms excluding propagation delay.

Below is a teleprotection application example, which walks through the sequence of events that the JunglePAX platform would perform to ensure that critical teleprotection circuits are delivered securely and dependably across the network.

Application Defined Networking

The Lentronics JunglePAX is ideal for power utility operations and IT applications, supporting the following typical applications:

Critical Operational Traffic (OT)

  • Teleprotection

Essential Operational Traffic (EOT)

  • SCADA
  • Maintenance & Emergency Voice
  • Asset health and status

Critical Information Traffic (CIT)

  • Surveillance & Intrusion detection
  • Metering

Essential Information Traffic (EIT)

  • Business service backhaul
  • Connecting field offices and mobile users with operational data
Application Example: Transmission Cable Fault

1 - Transmission cable fault There is a transmission cable fault affecting the primary communication path

2 - Fault detected Fault is detected by the protection relay

3 - Tripping signal A tripping signal is sent to the JunglePAX platform

4 - Fault detected and transmitted The JunglePAX in Substation 1 detects the primary transmission path fault

5 - Teleprotection signal received The JunglePAX in Substation 2 detects the loss of the primary communications path and switches to the protected communications path within 3ms

6 - Protection action Protection relay initiates the action to clear the fault

Application Example JunglePAX provides reliable inter-substation relay communications during primary communications path failures

JunglePAX Components

The JunglePAX comprises of replaceable and hot swappable interface cards which ensure that the platform is easy to maintain. The flexible mix of client service cards provides utilities with a solution that addresses changing communications requirements.

JunglePAX  View

Technical Specifications

MULTI-SERVICE PLATFORM
 Purpose-built, modular in design with layers of redundancy
 Hot swap of all redundant components without service interruptions
 Utility hardened ensure security and dependability
 Non-blocking architecture
WIDE AREA NETWORK (WAN) OPTIONS
Optical WANCapacity24Gbps
 Number of 10G Optical WAN ports2, SFP+, (up to 80km)
 Number of 1G Optical WAN ports4, SFP
NETWORK MANAGEMENT
ManagementDevice managementembedded Management System (eMS)
 Network managementOptional Advanced NMS
 High availability mode1+1 protected
 Console portUSB
 Inbound / Outbound interfacesCLI, WebUI (HTTPS), SNMPv3 *, NetConf
PERFORMANCE
 CORE Hardware protection1+1, 20G bypass
 ProcessorsDual, Dedicated separately for Data (DP) & Management (eM) plane
 Transport ProtocolMPLS-TP, RFC 5654
 EncapsulationWAN-Interface Sublayer (WIS) (on/off)
 Quality of serviceIEEE 802.1p/q with priority queues and priority scheduling
 Node transit delay< 30 μs
SwitchingCapacity66G
 FabricRedundant
BackplanePassiveYes
Client servicesTDM and EthernetTDM: Emulated TDM over PSN (CESoPSN,SAToP)
Ethernet: E-Line, E-Tree and E-LAN Ethernet Virtual Connections, configurable max frame size (up to 12,000 bytes), 32k MAC addresses per node
PacketizerT1/E1/CBUS TDM ports8
SynchronizationWAN Synchronization methodSyncE
 Internal ModesHeadend with SSM, Freerun
 Accuracy4.6ppm
 External modes2KHz, 10MHz, 1PPS, GPS *
 QualitySSM, ESMC *
TimingTiming ProtocolsNTP, IEEE 1588v2 (telecom and power) *
 Accuracy1us, Grandmaster (1588v2) *
OAMFault DetectionLDI, 256 HW-assisted BFD per CORE
 Protection Switching1+1: <3 ms on fiber break, ~0 ms on CORE module extraction
1:1: <16 ms on fiber break, <50 ms on CORE module extraction
SECURITY
SecurityEtherWAN encryption engine6 independent encryption engines, Optionally enabled on each WAN port *
 EncryptionAES 256
 AuthenticationSHA 256
 Key distributionPublic/Private, User configurable rolling key frequency *
 Access ControlRole-based
 User AuthenticationRADIUS
 AccountingSyslog (local)
 Federal Information Processing Standard140-2
CERTIFICATION
Industry ComplianceSAFETY, UL, EU, CSAUL 60950-1, ETSI EN/IEC 60950-1, CAN/CSA C22.2, RCM (Australia)
 Conducted and Radiated emissionsFCC Part 15B, CISPR/EN 55022, EN 300 386, VCCI, AS/NZS CISPR 22, CNS13438, and KN 22
 ImmunityEN 55024, EN 300 386 and KN 24
 Power SubstationIEEE 1613 (no cooling fans)
 HardeningIEEE 1613 (no cooling fans), SWC, EMI, RFI & ESD
EnvironmentalOperating Temperature-20°C to + 60°C
 Storage Temperature-40°C to +70°C, IEC60068-2
 Humidity, %RH5 - 95%, non-condensing
 Altitude3000m
 EarthquakeNEBS ITL GR-63-CORE Issue 4*
 RoHSRoHS / WEEE
POWER MANAGEMENT
PowerDC48/130 VDC (ungrounded or +ve grounded), isolated inputs, hot swappable
 AC120/240 VAC, 50/60 Hz, hot swappable
 RedundantYes
 Consumption160W, Overcurrent protection at 180W per power supply
ACCESS CARD INTERFACES
Access Card interfacesNumber of Access slots16
 Hot swappableYes
 4 x GigE slots3
 EF-4A4 x 1G/FE fiber ports, SFP, per-port configurable native VLAN ID
 EC-4A4 x 10/100/1000 Mbps copper ports, RJ-45, per-port configurable native VLAN ID
 GigE slots6, using EF-4A and EC-4A units
 TDM slots4 (16 if xTDM-8A cards are used)
 T1E1-4A4 x T1/E1 ports, RJ-48c, G.704, G.706, G.826
E1 formats: PCM30/CAS, PCM31/CCS, Unframed
 CBUS-4A card4x CBUS ports, RJ-48C
 xTDM-8A8 x T1/E1 ports (G.704, G.706, G.826) or 4 x CBUS ports, RJ-48c *
 64kbps slots10
 C3794-1A1 x IEEE C37.94, mmf/smf, N x 64 kbps (N=1…12), SFP, LC connector
 C3794-4A4 x IEEE C37.94, mmf/smf, N x 64 kbps (N=1…12), SFP, LC connector
 DR-1A1 x RS-232/V.24/V.28 (up to 38.4 kbps) or 1x G.703 64 kbps codirectional
 DR-4A4 x RS-232/V.24/V.28 (up to 38.4 kbps) or 1 x G.703 64 kbps codirectional
 G703D-4A4 x G.703 64 kbps codirectional
 DTT-2A2 x DTT Tx/Rx @48VDC. 130VDC, 250VDC

* future release

IT and OT applications have traditionally operated independently over disparate networks, each serving the utility networking groups differently. IT and OT-centric applications can remain separated (i.e., metering from protection) although converged application can share the same space, generating opportunities for utilities to improve OPEX and CAPEX through elimination of redundancy and simplification initiatives.

More components within utility systems are becoming intelligent and requiring new communication connections and functions, generating demand for:

  • Real time control in energy delivery support for heterogeneous networks and integration of previously segmented and disparate networks
  • Lower utility operational costs through economy of scale, and convergence of operation and information technologies
  • A converged network is required, with:
    • Increased system capabilities,
    • Ability to ensure the performance of critical and time-sensitive applications,
    • Simplified and secure technology

GE Vernova and Ribbon Communications have partnered producing an optimized proposition for utilities requiring more from their network. This solution will protect people and critical assets, scaling across the entire communications landscape with information assurance as traffic flows securely across network boundaries.

Edge to core data process

The MDS Intrepid™ P2MP high capacity point-to-multipoint backhaul solution is ideal for commercial-grade applications where longer distance and higher capacity with multiple sites is necessary. Intrepid P2MP provides highly secure, time sensitive and mission critical communications, and backhauls this information back to a central point.

MDS Intrepid P2MP

High Capacity Point-to-Multipoint Wireless Backhaul 5.4 and 5.8GHz Unlicensed Bands

The MDS Intrepid™ P2MP high capacity point-to-multipoint backhaul solution is ideal for commercial-grade applications where longer distance and higher capacity with multiple sites is necessary. Intrepid P2MP provides highly secure, time sensitive and mission critical communications, and backhauls this information back to a central point.

Application Examples

Advanced & Rugged Commercial-Grade Equipment for Unlicensed

Implementing a private communications network while leveraging the cost benefits of an unlicensed band requires a solution that utilizes the latest technology to obtain the maximum signal range while supporting high data capacity. Intrepid P2MP's implementation of full 2x2 MIMO technologies on both the base station and subscriber units provide optimum performance in difficult, frequency dense and NLOS/nLOS systems. The use of scalable OFDM modulation provides robust communications at the highest bandwidth and throughput possible during path disturbances and fading events.

Asymmetrical data bandwidth permits more data throughput for the uplink rather than the downlink – a requirement for high definition video and one-way high data rate deployment. The MDS Intrepid P2MP provides Quality of Service for data prioritization and Service Level Performance.

Application Example: Video Security – Transportation and Public Safety

Transportation and Public Safety are using more and more high-definition video security system. Below is an example of a secure wireless backhaul system for a high capacity video security system requiring software adjustable asymmetric upload traffic assignment and loading.

Application Examples
Application Example: Oil & Gas Facilities

Below is an example of an oil well-head application utilizing the MDS Mercury™, Intrepid P2MP and Intrepid Ultra as a complete and universal solution for SCADA and video traffic at well-head sites.

Water & Wastewater Facilities
Application Example: Water & Wastewater Facilities

Below is an example of a wireless network utilizing Intrepid P2MP and Intrepid Ultra to aggregate data from devices that monitor vital flow, pressure and temperature measurements, and video surveillance.

wireless network utilizing

System Components

MDS Intrepid P2MP provides high capacity and scalable solutions for deployment within multipoint communication networks. By selection of the base station's sector angle (60, 90 or 120 degrees) multiple subscriber systems can installed within a given area to optimize efficiency and maximize sector throughput up to 200 Mbps aggregate. Time-Division Duplexing (TDD) synchronizes Intrepid P2MP base stations to accommodate multiple co-location systems and coverage overlap without introducing self-inflicted interference. MDS Intrepid P2MP is optimized as an Ethernet bridge for IP traffic operating with 10/100/1000Base T at the base station and with 10/100BaseT at subscriber units.

MDS Intrepid P2MP System Components
Base Station Unit
  • 200Mbps / Sector
  • 60, 90, or 120 Degree Sector
  • Asymmetric throughput
  • Up to 32 Subscribers
  • 4-level QoS for SLA
  • Ethernet Only Bridge
  • Single Ethernet port
  • 10/100/1000BaseT
  • PoE supplied
  • OFDM/ MIMO
  • Max Output: +25 dBm
  • -35°C to 60°C
  • IP67 all weather
Subscriber Units
  • Three Subscriber Units
  • - 10 , 20, or 50 Mbps
  • Asymmetric throughput
  • Ethernet Only Bridge
  • Single Ethernet port
  • 10/100BaseT
  • PoE supplied
  • OFDM/ MIMO
  • Max Output: +25 dBm
  • -35°C to 60°C
  • IP67 all weather
PoE & Accessories
  • Indoor and Outdoor Units
  • 120/240 VAC
  • -20 to -60 VDC
  • Indoor PoE: 10/100/1000BaseT
  • Outdoor PoE: 10/100BaseT
  • Plus Accessories:
  • 25-100 Meters UTP Cables
  • PoE Surge Arresters
  • HSS
  • GPS Sync
  • Antennas

Technical Specifications

High Capacity Point-to-Point Wireless Backhaul
Up to 38 GHz Licensed

GE Vernova's MDS™ Intrepid HC products offer a long-distance, high capacity point-to-point licensed wireless backhaul solution ideal for industrial and commercial-grade applications. MDS Intrepid HC MX and Intrepid HC OIP provide highly secure, time sensitive and mission critical communications backhauled to a centralized location. Offered in the traditional FCC/ETSI microwave frequencies between 6 GHz and 38 GHz, these devices can be used globally in developed and developing countries.

MDS Intrepid HC MX MDS Intrepid HC OIP

High Capacity Point-to-Point Wireless Backhaul
Up to 38 GHz Licensed

GE Vernova's MDS™ Intrepid HC products offer a long-distance, high capacity point-to-point licensed wireless backhaul solution ideal for industrial and commercial-grade applications. MDS Intrepid HC MX and Intrepid HC OIP provide highly secure, time sensitive and mission critical communications backhauled to a centralized location. Offered in the traditional FCC/ETSI microwave frequencies between 6 GHz and 38 GHz, these devices can be used globally in developed and developing countries.

MDS Intrepid HC MX - TDM to IP Migration

The MDS Intrepid HC MX operates in the licensed 6 to 38 GHz frequency bands and offers throughput capacity between 8 and 350 Mbps. It provides a flexible combination of native TDM and native Ethernet interfaces and supports STM-1 interfaces. The MDS Intrepid HC MX can be configured for non-protected (0+1), protected (1+1) or space diversity deployments. The rich feature set and interface support of native Ethernet and TDM provide maximum throughput with minimal latency.

Key Benefits
Key Benefits

• Operates in the secure FCC/ETSI licensed bands between 6 and 38 GHz 

• Provides scalable throughput options from 8 to 350 Mbps Native Ethernet and TDM implementation 

• Native Ethernet and TDM implementation provide separation of service and lowest service latency possible 

• Multiple deployment configurations maximize equipment and RF redundancy and minimize infrastructure cost

MDS Intrepid HC MX Application Advantages
MDS Intrepid HC MX Application Advantages
Reliable Communications
  • Hitless and errorless Adaptive Code Modulation(ACM) with modulations from QPSK to 256 QAM
  • Adaptive power and exceptionally high system gain
  • Full hardware / interface redundancy and network level resiliency

 

 

Flexible Deployment
  • Various channel size options facilitate the best combination of range and speed
  • Integrated carrier Ethernet switching and TDM cross-connect
  • Future capacity growth and additional functionality enabled with license keys and using the same hardware
Prioritized and Secure
  • Quality of Service (QoS) ensures critical communications receive highest priority
  • AES 128/256 encryption for high security

MDS Intrepid HC OIP

MDS Intrepid HC OIP - Ethernet Bridge Radio


The MDS Intrepid HC OIP operates in the licensed 7 to 38 GHz frequency bands and offers throughput capacity of up to 350 Mbps. As an all-outdoor radio terminal, supported by an outdoor PoE unit, the MDS Intrepid HC OIP eliminates the need for rack space within shelters, cabinets, and enclosures. The radio mates directly to the back of its associated antenna, minimizing visual impact. Power to the radio is provided by the PoE unit over the same Cat5e Ethernet cable that provides data to the unit.

Key Benefits
  • Operates in the secure FCC/ETSI licensed bands between 7 and 38 GHz
  • Provides scalable throughput options of up to 350 Mbps
  • Software-configurable capacity licenses allow system capacity upgrade without the need for hardware upgrade
  • Supports SyncE and IEEE 1588 v2 synchronization to allow for critical time synchronization of equipment across the system
  • Optical fiber and electrical RJ45 gigabit Ethernet provide both interface options for GigE communications
  • Jumbo packets of up to 9600 bytes offer the highest performance in GigE environments\
  • Q-in-Q, VLAN, QoS with 8 queues support the latest in VLAN requirements
  • 50 ms switching for ring protection (ITU-T G.8032) minimizes data interruption and delay

 

 

MDS Intrepid HC OIP Application Advantages

Reliable Communications

  • Hitless and errorless Adaptive Code Modulation(ACM) with modulations from QPSK to 256 QAM
  • Adaptive power and exceptionally high system gain
  • Full hardware / interface redundancy and network level resiliency

 

Flexible Deployment

  • Various channel size options facilitate the best combination of range and speed
  • Integrated carrier Ethernet switching and TDM cross-connect
  • Future capacity growth and additional functionality enabled with license keys and using the same hardware

 

 

Prioritized and Secure

  • Quality of Service (QoS) ensures critical communications receive highest priority
  • AES 128/256 encryption for high security

 

Energy
  • Substation SCADA, LAN/WAN and cellular/carrier
  • Fiber extensions, voice/PBX, video surveillance
Oil & Gas
  • Pump on/pump off SCADA control, WAN networks for remote offices
  • Disaster recovery, video surveillance, voice/PBX

 

Heavy Industrial Transportation
  • Two-way radio repeater control, mobile command vehicles
  • Leased line replacement, disaster recovery, video surveillance
Water & Wastewater
  • Water monitoring SCADA and LAN/WAN
  • Fiber extensions, video surveillance, building connectivity

Gridcom DIP.net bridges the gap between conventional protection communications and the emerging packet network environment in the electrical substation. The product’s interface modularity both at substation side and at communication network side facilitates grid transition whichever be the path and pace adopted for the power network. Gridcom DIP.net is an efficient, modern, and reliable communication solution for transferring critical messages and commands for managing the grid to prevent failure and network damage.

Gridcom DIP.net

IEC 61850 Teleprotection for Transmission and Distribution Grids providing prompt, dependable, and secure transmission of commands and control signals across the grid

Gridcom DIP.net bridges the gap between conventional protection communications and the emerging packet network environment in the electrical substation. The product’s interface modularity both at substation side and at communication network side facilitates grid transition whichever be the path and pace adopted for the power network. Gridcom DIP.net is an efficient, modern, and reliable communication solution for transferring critical messages and commands for managing the grid to prevent failure and network damage.

Gridcom DIP.net is the optimal software solution for ensuring critical communications in evolving power system automation architecture for advanced substation-to-substation exchanges. Designed upon proven teleprotection principles while hosting advanced automation technologies, the Gridcom DIP.net is a versatile interface between the electrical substation and the telecom network.

Ready for Future Network

The flexible I/O cross-connect and multiple configuration capabilities provide protection engineers with extensive flexibility and numerous design possibilities without external relaying cubicle logics. Transmission of critical information over an area becomes easier to design, deploy and maintain.

Smooth Migration The transition toward the digital substation can be performed smoothly with a modular teleprotection. Gridcom DIP.net not only provides IEC 61850 MMS and GOOSE interfaces for your future substation, but also optional I/0 modules for wiring to your legacy protection and control devices.

Network Quality Monitoring

Gridcom DIP.net provides a dedicated set of link and network quality monitoring features according to protection service requirements in order to detect communication impairments and assess the acceptability of the communication.

Interface Modularity

Gridcom DIP.net bridges the gap between conventional protection communications and the emerging packet network environment in the electrical substation. The product’s interface modularity both at substation side and at communication network side facilitates grid transition whichever be the path and pace adopted for the power network

Key Benefits

Easy to Use

Deployment and maintenance interventions are substantially facilitated through an adapted mechanical design as well as an advanced set of functional tools embedded in the firmware of the device.

Interoperability

Taking into account the evolution of IEC 61850 in time, Gridcom DIP.net assures interoperability with earlier versions of the standard already deployed in substations, as well as the present edition and provides for easy upgrades in the future

Cyber Security

Bringing remote management capability into the substation may introduce vulnerability in the system. Powerful authentication and encryption protocols incorporated into Gridcom DIP.net provide secure remote access for operations.

Protection Metrics

The performance criteria expected by protection engineering can be set more easily with a comprehensive set of thresholds and alarm settings.

example of transition towards IEC 61850 substation
Example of transition towards IEC 61850 substation

Hardware Specifications

TP COM COMMUNICATIONS INTERFACE
  • Six (6) IEC61850 Fast ETH 10/100 Mbps RJ45 SFP ports
  • Two (2) direct OF and/or IEEE C37.94 SFP ports
  • One or two V11, E1/T1, G703 64 kbps and analog extension boards with RJ45 connector and 3 Alarm Output Relays 8 Pin Connector
  • CAN BUS Electrical Iterface RJ45 port for connection between modules
  • RJ 45 Management port
  • Five (5) LED indicating system status
  • IRIG-B Synchronization interface
TP I/O INPUT-OUTPUT INTERFACE MODULE
  • Four (4) digital acquisition inputs
  • Four (4) NO restitution heavy duty outputs
  • Six (6) restitution heavy duty outputs (4 NO/NC, 2 NO)
  • CAN BUS Electrical Iterface RJ45 port for connection between modules
  • Five (5) LED indicating system status
TP OG OPTICAL INTERFACE MODULE
  • Two (2) IEC61850 Fast ETH 10/100 Mbps RJ45 SFP ports
  • Two (2) direct OF and/or IEEE C37.94 SFP ports
  • CAN BUS Electrical Iterface RJ45 port for connection between modules
  • Five (5) LED indicating system status
  • IRIG-B Synchronization interface
PS-1, PS-2 POWER SUPPLY MODULE
  • PS-1 Range : 30 - 60 VDC
  • PS-2 Range : 80 - 370 VDC; 85 - 277 VAC (50/60 Hz)
  • CAN BUS Electrical Iterface RJ45 port for connection between modules
  • Two (2) LED indicating system status
  • One (1) NO/NC alarm output contact

* when power supply >48VDC and redundancy is required

Built for critical ethernet communications

Unparalleled network security and performance for mission critical applications, creating up to four distinct Ethernet WANs, each with its own configurable, dedicated bandwidth and tightly controlled access privileges. 

Ether-1000 Unit

Built for critical ethernet communications

Unparalleled network security and performance for mission critical applications, creating up to four distinct Ethernet WANs, each with its own configurable, dedicated bandwidth and tightly controlled access privileges. 

e-terrapowercom is a broadband power line modem with integrated switch designed for communications on medium and low voltage grids. The solution is based on broadband PLC technology with additional networking capabilities, to build reliable and cost-effective communication networks utilizing existing power cables. e-terrapowercom provides a ruggedized design with superior performance allowing for a diverse range of applications such as metering, automation, asset monitoring, video surveillance and IP telephony.

e-terrapowercom

Broadband power line communication

e-terrapowercom is a broadband power line modem with integrated switch designed for communications on medium and low voltage grids. The solution is based on broadband PLC technology with additional networking capabilities, to build reliable and cost-effective communication networks utilizing existing power cables. e-terrapowercom provides a ruggedized design with superior performance allowing for a diverse range of applications such as metering, automation, asset monitoring, video surveillance and IP telephony.

GE Vernova Advantage

Compact and rugged design for harsh environments Compact and rugged design for harsh environments
Suitable for a variety of environmental conditions Suitable for a variety of environmental conditions
Superior transceiver design with proven field performance providing high signal power resulting in optimal performance
  • Up to 200Mbps* throughput and low latency data channel
  • Superior signal amplifier design for long distance coverage going up to several hundred meters without repeaters
  • Configurable frequency bands for optimal spectrum reuse
  • Flexible modulation with configurable notches to prevent interferences with other systems
Flexible switching features enabling a variety of applications
  • Built-in Ethernet switch reducing deployment costs by eliminating the need for additional network infrastructure
  • Integrated GUI for configuration and maintenance
  • Embedded monitoring and measurement tools for quicker deployment and simplified maintenance
  • Fast deployment mode utilizing default pre-configurations
  • Cyber security features to prevent local and remote unauthorized access
Ruggedized design for harsh environments with lower cost of ownership
  • Industrial hardened IP-40 enclosure with no cooling fans for extended operating life
  • Wide range built-in AC and DC power supply
  • DIN mountable and compact footprint design for small cubicles and voltage cell
  • EMC certified for high voltage environments and class II electrical safety

* Maximum bandwidth depending on signal noise ratio and external factors

Utility Application Example

Delivering cost effective communications solution for utilities on medium voltage networks

e-terrapowercom uses power cables as a medium for digital communication necessary for automation and control of the power grid. The solution delivers a transparent IP network with Quality-of-Service (QoS) to prioritize critical applications, and uses Virtual LANs (VLAN) to separate data streams of each distinct service. In order to improve asset control and maintenance, IP video cameras and telephones can be deployed in key substations due to the exceeding bandwidth provided. The communication system can be rolled out over a large number of substations starting from High Voltage (HV) substation to several kilometers over the grid, as it does not require heavy civil works and additional infrastructure.

Utility Application Example

Industry Application Example

A flexible and cost-effective alternative for telecom infrastructure for industrial applications

Industries can take advantage of the power grid built to supply energy to production and machinery to create IP communication channels, using the e-terrapowercom solution. This data channel can provide backhauling for operating local networks, telemetry on remote devices, and supervision of the assets connected to the control center. In addition, environments like underground facilities often have limited radio coverage and Broadband Power Line enables connecting such areas.

Industry Application Example

E-terrapowercom Components

Long Range Version

The e-terrapowercom is also available in a long range version, which has a higher power density in shorter frequency channel to attain longer distances or overcome noisier environments. The maximum bandwidth is reduced and it is dedicated to specific cases.

Coupling Options

The e-terrapowercom modem is connected to the electrical grid through inductive or capacitive coupling devices. Inductive is used over insulated cables while capacitive requires a connection to a live part of the grid. Inductive is easy and fast to install, especially in cubicles and small rooms. Capacitive is mainly dedicated to overhead lines.

E-terrapowercom overview diagram

Technical Specification

 BPLLong Range
Maximum raw bandwidth200 Mbps40 Mbps
Frequency range2 to 34 MHz1 to 17 MHz
Frequency modes1616
ModulationOFDMOFDM
Encryption3DES / AES 128bits3DES / AES 128bits
BPL power spectral density-35 dBm/Hz-30 dBm/Hz
Internal filtersSelectableSelectable
Networking
ModeLayer-2 / Layer-3
FeaturesReal-time monitoring
Remote ping (ICMP)
Static NAT
MAC address filtering
VLAN Access / Trunk
DHCP client
DHCP server
QoS 
IPSec client
SNMP v3
NTP client
Web GUIHTTP / HTTPS
Network standardsIEEE 802.3
IEEE 802.1p
IEEE 802.1q
Hardware
Ports2x BPL 50 Ohm
4x FEth RJ-45 auto-sensing
AC power cord connector
DC terminal block
Operation temperature-20°C to 65°C 
5% to 95% non-condensing
Weight680 g
Dimensions (W x H x D)60 x 146 x 150 mm
DIN mountTop hat rail
Ingress Protection LevelIP-40
Electrical
AC Operating voltage80 to 265 Vac 50/60Hz
DC Operation voltage24 to 40 Vdc
Power consumption6 W (Peak 12 W)
Standards
EMCIEC 61000-6-2:2005
IEC 61000-6-4:2006
IEC 61000-6-5:2001
ANSI C37.90.1/2/3
Operation environmentIEC 60721-3-3: 3K5 / 3M4
SafetyEN 60950 (LV Directive) / Class II

GE Vernova’s Lentronics™ Cyber Secured Service Unit (CSSU) protects Lentronics Multiplexers against cyber threats, specifically those that target the reliability of the Bulk Electric System (BES). The CSSU is an essential security appliance that takes the place of a legacy Service or IP Service Unit, to better protect against malicious and unintentional network changes. It utilizes defense-in-depth strategies, allowing utilities to meet demanding security standards such as NERC CIP.

Cyber Secured Service Unit

Improved Cyber Security for Lentronics SONET/SDH Multiplexers

GE Vernova’s Lentronics™ Cyber Secured Service Unit (CSSU) protects Lentronics Multiplexers against cyber threats, specifically those that target the reliability of the Bulk Electric System (BES). The CSSU is an essential security appliance that takes the place of a legacy Service or IP Service Unit, to better protect against malicious and unintentional network changes. It utilizes defense-in-depth strategies, allowing utilities to meet demanding security standards such as NERC CIP.

Overview

The Lentronics Cyber Secured Service Unit protects Lentronics multiplexers from unauthorized user access and remote equipment configuration. In addition, non-authenticated software clients will be actively rejected along with failed user authentication attempts. The use of strong privacy policies help prevent man-in-the-middle attacks.

Each CSSU communicates with adjacent CSSUs over the SONET/SDH overhead to facilitate:

  • Centralized user authentication
  • Distribution of a common, network-wide security policy
  • Distribution of common security settings, including digital certificates
  • Upgrade of the units operating firmware to apply any future patches
  • Distribution of the current time

This extends the electronic security perimeter around each NMS access point, securing all sites, particularly remote locations containing critical assets belonging to critical BES Cyber Systems.

Cyber Secured Service Units Perform Centralized and Localized User Authentication
Lentronics CSSU provides local and centralized user authentication with a single cyber security policy

Security
  • Supports OpenSSL
  • Supports Transport Layer Security (TLS)
  • Strong AES 256 encryption
  • X.509 Digital Certificates
  • Digitally signed communications to EMS clients (Lentronics VistaNET)
  • Digitally signed firmware to authenticate trusted source operating code
Access Control
  • Integrates with central authentication server (RADIUS) for centralized user administration
  • Supports dual RADIUS servers and gateways
  • Authenticates users locally if RADIUS is absent
  • Integrated Access Control List (ACL) for local authentication and authorization
  • Distributes ACL between sites over SONET/ SDH overhead
  • Enforces user authentication
  • Optional unit password to control craft console port access
Connectivity
  • Encrypted front and rear Ethernet ports
  • Supports concurrent network management sessions
  • Secured console port
  • Inter-Ring Tie port to bridge NMS domains
Utility Hardened
  • Meets IEEE 1613 and IEC 61850-3 environmental specifications
  • Reliable operation in extreme temperature from -4°F to +140°F (-20°C to +60°C)
  • Meets Earthquake risk Zone 4 shock and vibration specification

Access Control

A Cyber Secured Service Unit can be deployed in one of two operational modes, Legacy or Secure. Legacy mode (CSSU-L) offers a consistent set of features that supports interoperability with pre-existing Service or IP Service Units.

Secure mode (CSSU-S) is a licensed component that must be applied to all CSSUs within a ring, or across the entire management domain. In this case, a network-wide security envelope is formed to protect and control assets through Authentication, Authorization, Accountability, Privacy and Integrity.

Updating the CSSUs Access Control List: Example of Revoking Users Access
Example of Revoking Users Access

VistaNET Administrator Creates a New Policy

  • User X: Access Rights Expired
  • Applies new security policy to connected CSSU

SONET/SDH Overhead

  • CSSU synchronizes the new security policy to all connected CSSUs

Enforcing Security

  • Each CSSU enforces the new security policy

Access Control Enforced

  • Access is denied for User X
  • Any damage caused by User X is contained to the local site where physical access was breached

Technical Specifications

Technical specifications, encryption, authentication and security standards for the Lentronics CSSU * Equipped with CSSU-S code

Order Code

Part NumberDescription
B86434-11Cyber Secured Service Unit, Legacy Mode for JungleMUX, TN1U and TN1Ue Multiplexers
Ethernet 10/100BaseT via RJ-45 front connector, providing a gateway for Network Management
Serial 9.6kb RS232 via RJ-11 front connector, supporting network management or local unit setup only
B86434-11/AActivated Cyber Secured Service Unit, to operate in Secured Mode for JungleMUX, TN1U and TN1Ue Multiplexers 
Ethernet 10/100BaseT via RJ-45 front connector, providing a secure gateway for Network Management
Serial 9.6kb RS232 via RJ-11 front connector, local unit setup
86434/AActivation code to upgrade from CSSU-Legacy to CSSU-Secure operating mode
86434-75TN1Ue CSSU paddleboard equipped with rear Ethernet 10/100BaseT, Major/Minor Form C relay, Power alarm input, Protected NMS Tie ports (new tie format) and Contact IN terminals
86434-81TN1U CSSU paddleboard equipped with rear Ethernet 10/100BaseT, Major/Minor Form C relay, Power alarm input, Protected NMS Tie ports (new tie format) and Contact IN terminals
86434-92JungleMUX CSSU paddleboard equipped with rear Ethernet 10/100BaseT, Major/Minor Form C relay, Power alarm input, Protected NMS Tie ports (new tie format) and Contact IN terminals

* Equipped with CSSU-S code