Skip to content

nomos System Manager ​

The nomos System Manager is a service from nomos system with which you, as an integrator, look after all your controllers in one place: you see their state, check their security, set up monitoring, back them up automatically and receive reports by email. nomos runs a separate instance for each integrator. The controllers connect to it over the Support VPN.

INFO

Management is something different: there, one controller on site looks after other controllers. The System Manager is a service run by nomos for all of an integrator's controllers, connected over the Support VPN.

Getting access ​

Contact nomos system support (support@nomos-system.com, see Help & support). nomos sets up your System Manager and gives you its address and your access.

The System Manager's web interface is not publicly reachable, only over the VPN: your computer connects with a WG profile (WireGuard). You receive the first one with your access from nomos; you issue further ones yourself under Admins.

You sign in under Sign in with Username and Password; with two-factor authentication turned on, you also enter the code from your authenticator app. You invite other people from your company under Admins.

If the Controllers page shows One-time Setup, link the System Manager to your nomos Cloud account as an integrator: Next, then Start. The linking opens in a new window.

Connecting a controller ​

  1. nomos provides the VPN profile for your System Manager as a file. There are different profiles; use the one you received from nomos.
  2. Upload the profile on the controller under Software Update with Manual Upload and confirm Install update? with Install.
  3. Turn on the Support VPN on the controller: click On at the top right and confirm Turn on the support VPN? with Turn on.
  4. The controller connects to the System Manager over the Support VPN and appears there under Controllers with the status Not authenticated.
  5. Click Authenticate in its row and enter the Username and Password of an administrator of the controller.

The System Manager then creates its own administrator account "nomos system Manager" on the controller and works with it from then on; it does not store your password. End controller session removes this account from the controller again. Security, monitoring and backups are only available for authenticated controllers that are online.

Controller list ​

The Controllers page lists all connected controllers:

  • Status – Online, Offline or Not authenticated.
  • IP – the controller's address in the VPN.
  • Serial Number, Description and Tags.
  • Score – the result of the security check (0–100).
  • Actions – Details opens the detail view, Authenticate the sign-in to the controller. Open opens the controller's Configuration, nomos App or Node-RED in a new window, as well as any custom interfaces the controller provides.

The search field finds controllers by IP, serial number and description. Offline controllers only appear with Show Offline Controller. With Tags Filter you show only the controllers with a particular tag.

INFO

Open calls the controller at its VPN address. Your computer has to reach it, for example through a WG profile.

Controller details ​

A click on the row or on Details opens the detail view with the tabs Overview, Security, Monitoring and Backup; for a controller that is not authenticated, also Authentication.

Under Overview you maintain the controller's Description and Tags and apply them with Save. Tags group controllers, for example by customer or region; the list, statistics and email reports can be filtered by them. Next to them are details such as Name, Product, Version, Hardware, Uptime and Last seen, the Utilisation of CPU, RAM and Storage, and the controller's Port Forwardings.

Software update ​

If a newer version is available for the controller, the button Update to ‹version› appears next to Version. After the confirmation Update the controller to version ‹version›? the controller installs the update. You start updates in the System Manager per controller; automatic updates are set up on the controller under Software Update.

Security ​

The Security tab shows the controller's security check, the same as on its Security page: the score with Condition and a table with ID, Severity and Description of the findings. Solution opens the matching page in the controller's configuration, Check again runs the check again. From a score of 75 a controller counts as OK, from 50 it has warnings, below that problems.

Below it, under Automatic E-Mail Report, you set up the controller's own report, the same as on its Security page: Weekly on a weekday or Monthly on a day of the month, at the Time on the controller, to the email addresses entered.

The System Manager's Security page summarises all controllers, in one card for all and one per tag: the Overview counts the authenticated controllers that are online with Problems, with Warnings and OK. In the Automatic E-Mail Report tab you set up a joint report for all controllers or for those with one tag:

  1. Tick Enable automatic Report.
  2. Choose Weekly with a weekday or Monthly with a day (1st to 28th) and the time. It applies in the Time on the System Manager; the time zone is shown.
  3. Enter at least one recipient under E-Mail and click Save.

The report gives the number of controllers that are online, how many of them are not authenticated or have problems or warnings, and below that the findings of each controller. It is in German if your browser was set to German when you saved, otherwise in English.

Monitoring ​

A monitoring reports by email or push notification when devices of a controller are no longer reachable. It is stored on the controller and runs there, even when the System Manager is not connected. Once a monitoring is set up, the finding CVE-24-0005 disappears.

  1. In the Monitoring tab, choose Add... under Selection.
  2. Enter a name under Name and leave Enabled ticked.
  3. Under When following Devices, choose the devices, grouped by platform, or One of all. You exclude individual devices under except following Devices.
  4. Under is unreachable for, set how long a device has to be unreachable before it is reported: in minutes (at least 5) or hours.
  5. Under then send a Notification to, enter email addresses or choose a Push Notification Device, that is a mobile device of the controller with push notifications. At least one recipient is required.
  6. Click Add.

You choose an existing monitoring under Selection, change it and apply it with Save, or delete it with Remove. Next to it, a chart shows how many of the monitored devices were unreachable over time.

Backups ​

The System Manager creates backups on the controller, downloads them and keeps them; it then deletes them from the controller. They also count for the check CVE-24-0006.

On the Backups page, under Automatic Backup, you set up the schedule for all authenticated controllers: Enable automatic Backup, Weekly or Monthly, the time in the Time on the System Manager and the Maximum Number of Backups (2 to 60) kept per controller; the System Manager deletes older automatic backups. A backup is only created if the controller is connected to the System Manager at the selected time. The Backup Browser above lists all kept backups by serial number; a click downloads one.

In a controller's Backup tab you override the schedule for this controller with the same settings. Below are two lists:

  • Local Backups – the backups in the System Manager: Download, Restore and Delete.
  • Remote Backups – the backups on the controller: Download, Restore, Import (copies it to the System Manager) and Delete.

WARNING

Restore overwrites all settings of the controller. It applies the backup and restarts.

Statistics ​

The Statistics page shows, for all controllers and per tag, Total, Online, Offline, Not authenticated and, as Condition, the average score of the authenticated controllers.

Admins ​

Under Admins you manage the accounts of your System Manager. The list shows for each account the username, email, whether two-factor authentication (TOTP) is turned on, the WG profile and the last login.

  • Invite – in the Invite admin dialog, enter a name under Username and optionally an email address. The System Manager creates an activation link that is valid for 24 hours. Pass it on to the person through a separate channel; with it they set their password (at least 12 characters).
  • Reset – resets the account's password and two-factor authentication and creates a new activation link.
  • Issue WG profile – creates a WireGuard profile for the person. With it, their computer reaches the System Manager and the connected controllers, for example for Open or the ETS. The profile is shown only once: scan the QR code or download it. Re-Issue replaces it, Revoke invalidates it.
  • Delete – removes the account.

Settings ​

Under Settings you turn on Two-Factor Authentication (TOTP) for your own account. Under Notification Recipients you enter up to five email addresses of your company; they are pre-filled as recipients for new security reports, monitorings and email reports.