Check out our White Paper Series!
A complete library of helpful advice and survival guides for every aspect of system monitoring and control.
1-800-693-0351
Have a specific question? Ask our team of expert engineers and get a specific answer!
Sign up for the next DPS Factory Training!

Whether you're new to our equipment or you've used it for years, DPS factory training is the best way to get more from your monitoring.
Reserve Your Seat TodayRail signal and communications equipment lives in an electrical environment unlike almost any other. Wayside cabinets and bungalows sit beside traction power, long runs of track circuit, and grounding schemes that were designed around the railroad's own safety systems rather than around the monitoring gear bolted into the rack. A remote telemetry unit (RTU) that is perfectly well-behaved in a telecom central office can, in that environment, become an unintended path to ground.
This article covers three requirements that come up repeatedly when railroads and transit agencies standardize on a new monitoring platform: ground isolation, fail-safe remote power cycling, and cybersecurity hardening. It is written for rail communications and signal engineers planning a replacement of end-of-life monitoring units across a large installed base.

Ground isolation means the RTU's power return and signal circuits are electrically separated from its metal chassis, so that mounting the unit in a grounded rack does not tie the railroad's power system to chassis ground through the monitoring equipment.
Most commercial monitoring hardware bonds power ground and chassis ground together, which is the normal and correct practice in a telecom facility. In rail environments that bond can be a problem. Signal and wayside power systems are often deliberately floating or referenced in specific ways, and an unplanned bond can introduce ground loops, interfere with fault detection on the power system, or conflict with the railroad's own grounding standards.
The practical symptom engineers describe is revealing: a unit behaves as expected on the bench, then reveals an unwanted ground path once it is mounted, because the ground is not only at the grounding lug. It also travels through the mounting ears and the rack itself.
That is why ground isolation has to be addressed as a property of the whole installed unit, not just the lug:
On some RTU models, ground isolation is available as a factory build option. Specifying that option in writing, and making sure it appears plainly on the quote and the unit documentation, is the cleanest path for new purchases.
For a railroad with close to a hundred units already deployed, replacing every unit just to gain ground isolation is an expensive answer. The natural question is whether existing units can be converted during a repair cycle.
Sometimes the answer is yes, but it is model-specific, and it should never be improvised. The right sequence:
This is ordinary groundwork for any legacy upgrade path, and it matters more in rail than elsewhere because the grounding requirement is a safety and standards question, not a preference.
Remote power cycling means using an RTU control output to interrupt power to a device that has locked up and cannot be reached any other way - a radio, a modem, a network switch at a remote site. It saves truck rolls, which in rail often means saving a trip that requires track access.
Two design problems come up immediately.
RTU relays are signaling relays, not power relays. Onboard control relays are typically rated for light loads - enough to drive an indicator or the coil of another relay, not the supply current of a piece of wayside equipment. The standard answer is an interposing relay: the RTU relay drives the coil of a larger relay, and the larger relay switches the device power. A relay expansion chassis with larger contacts - on the order of 10 amps per circuit - mounted beside the RTU keeps this tidy and serviceable. Alternatively, a purpose-built remote power distribution unit handles switching and control in one device.
An RTU reboot must not reboot everything else. This is the requirement that is easy to miss. If the controlled devices are powered through a relay that must be energized to stay on, then any moment when the RTU restarts, loses power, or is swapped out will drop power to every device it controls. That turns routine RTU maintenance into a site-wide outage.
The fail-safe design is the opposite arrangement:
Done this way, the RTU can fail, reboot, or be pulled from the rack without affecting the equipment it protects. Where a site already uses a hinged amphenol breakout panel on the back of the RTU, the control wiring to an interposing relay chassis is usually simpler than running conductors back to a 66 block.
Transit and rail operators are increasingly subject to formal cybersecurity initiatives, and monitoring equipment is squarely in scope. Much of the installed base across the industry predates current expectations, which is exactly why replacement programs are an opportunity to raise the bar rather than simply swap boxes.
| Capability | What to Require |
|---|---|
| SNMP | SNMPv3 with authentication and encryption, and the ability to reject SNMPv1 and v2c requests entirely. |
| Web interface | HTTPS with current TLS rather than plain HTTP. |
| Command-line access | SSH rather than Telnet. |
| Authentication | Centralized authentication such as RADIUS, so credentials are managed in one place rather than on every unit. |
| Firmware | An actively maintained platform with updates available, so findings from future scans can be addressed. |
Two practices make the evaluation concrete. First, run the candidate unit through the same vulnerability scanner your security team uses for everything else, and review the findings with the manufacturer before approval. Second, if your team has identified a specific concern, report it to the manufacturer directly and early - responsible disclosure gets it fixed, and the response tells you a great deal about the vendor you are about to standardize on. DPS Telecom documents its monitoring security approach for teams working through exactly this kind of review.
A fleet replacement across dozens or hundreds of wayside locations is as much a procurement exercise as a technical one. A few practices keep it moving:
Where sites report into a central system, a central alarm master gives the operations center one consolidated view while each unit keeps local control of its relays.
Because the chassis also bonds to ground through its mounting ears and the rack. True isolation requires the power and signal circuits to be separated from the chassis internally, so mounting the unit in a grounded rack does not create a path.
Sometimes, depending on the model and hardware revision. Ask the manufacturer for a documented modification and whether it is supported in the field, on the bench, or only at the factory. Do not improvise board changes.
Usually not. Onboard relays are rated for light loads. Use the RTU relay to drive the coil of a larger interposing relay, or use a remote power distribution unit designed to switch device power.
Wire device power through normally closed contacts so devices stay powered when the relay is de-energized, energize only to force a reboot, and verify the RTU's outputs stay de-energized through its own restart.
SNMPv3 with the ability to reject older SNMP versions, HTTPS with current TLS, SSH instead of Telnet, centralized authentication such as RADIUS, and an actively maintained firmware platform.
Yes. A single unit validated in a representative cabinet confirms grounding, relay behavior, and scan results before it becomes the standard across every location.
If your railroad is replacing a large base of end-of-life monitoring units and needs ground isolation, fail-safe remote power cycling, and a security posture that survives your team's scans, those requirements are best settled on one evaluation unit before the fleet order. DPS Telecom can review your grounding requirements, recommend an interposing relay design for your cabinets, and document the configuration clearly on the quote your management will see. Get a Free Consultation, or call 1-800-693-0351 or email sales@dpstele.com.
Andrew Erickson
Andrew Erickson is an Application Engineer at DPS Telecom, a manufacturer of semi-custom remote alarm monitoring systems based in Fresno, California. Andrew brings more than 19 years of experience building site monitoring solutions, developing intuitive user interfaces and documentation, and opt...