Quick start
This guide sets up one central service and one node, and sends a first study from a modality to a PACS. The central service and the node can share one server at small volumes.
modality ──DICOM (11112)──► node ──DICOM──► PACS │ │ HTTPS 5080: configuration, heartbeats, history ▼ central service ── database ▲ browsers (web console)Before you start
Section titled “Before you start”- A server (or two) sized as in Plan and size.
- The files for your platform from the download page.
- A database: PostgreSQL 18 or later, or SQL Server 2019 or later. The central service creates its own database and schema on first start.
- The network paths below.
- For each sender: its calling AE title and IP address. For each destination: host, port and called AE title.
| From | To | Port | Why |
|---|---|---|---|
| Browsers | central service | TCP 5080 | Web console |
| Node | central service | TCP 5080 | Configuration, heartbeats, history |
| Central service | database | 5432 (PostgreSQL) or 1433 (SQL Server) | Database |
| Modalities and other senders | node | TCP 11112 (or 104) | Incoming DICOM |
| Node | each destination | its DICOM port | Outgoing DICOM |
1. Install the central service
Section titled “1. Install the central service”Run Routes.Central.msi. It asks for the database (SQL Server or PostgreSQL), the port (5080), an HTTPS certificate
thumbprint, and who may administer, view and search the history.
- SQL Server: the service connects with Windows authentication as its account, by default the computer account
(
CONTOSO\CENTRAL01$, orNT AUTHORITY\SYSTEMwhen SQL Server is on the same server). Give that login thedbcreatorrole, or create an emptyRoutesdatabase and make itdb_owner. - PostgreSQL: enter a connection string such as
Host=db01;Database=routes;Username=routes;Password=…, for a user that may create the database, or owns an empty one. - HTTPS: a certificate from a CA your nodes and browsers trust is best. Without one, the service makes a self-signed certificate and shows its thumbprint for the node installers; browsers warn until it is trusted.
Unattended:
msiexec /i Routes.Central.msi /qn SQLSERVER="sql01" SQLDATABASE="Routes" HTTPPORT=5080 CERTTHUMBPRINT="<thumbprint>" ADMINGROUPS="CONTOSO\PACS-Admins"Check that it runs: Get-Service RoutesCentral, and its log in %ProgramData%\Routes\Central\Logs.
Unzip routes-docker-<version>.zip and go to its routes-docker folder:
cp .env.example .env # set POSTGRES_PASSWORD and ENROLLMENT_KEY (openssl rand -base64 24)docker compose up -ddocker compose exec central cat /data/initial-admin-password.txtThis runs PostgreSQL, the central service and one node. The console is at https://<host>:5080; sign in as admin
with the password shown. The node enrolls by itself with the key from .env, so you can skip step 3.
Unpack routes-central-<version>-linux-x64.tar.gz to /opt/routes/central (it includes everything it needs), and give
it a PostgreSQL connection in /etc/routes/central.env:
Routes__Central__DatabaseProvider=PostgreSqlRoutes__Central__ConnectionString=Host=db01;Database=routes;Username=routes;Password=…Run it as a systemd service under its own user. On first start it creates the admin account, with a random password
in /var/lib/routes/central/initial-admin-password.txt.
2. Sign in and review the settings
Section titled “2. Sign in and review the settings”-
Open
https://<central server>:5080/. On Windows, browsers sign you in with your Windows account (add the address to the Local Intranet zone if you are asked for a password). On Linux and Docker, sign in asadminand choose your own password. -
Open Configuration › Settings and review the listen ports (the port your senders will use, such as
104or11112), the router AE title (ROUTES), and how long history, dead letters and the resend cache are kept. Save. -
Open Configuration › Node enrollment and copy the central address, the enrollment key and, for a self-signed certificate, its thumbprint. Treat the key as a password.
3. Install the node
Section titled “3. Install the node”Give the node a data volume sized for its queues and resend cache, and exclude its data folder from real-time antivirus scanning if your policy allows. Then:
msiexec /i Routes.Node.msi /qn CENTRALURL="https://central01.contoso.local:5080/" APIKEY="<enrollment key>" CENTRALTHUMBPRINT="<thumbprint>" DATADIR="D:\Routes"CENTRALTHUMBPRINT is only needed for a self-signed central certificate.
The compose file already runs a node. To add another, copy the node service with another name and port.
Unpack routes-node-<version>-linux-x64.tar.gz to /opt/routes/node, and put its settings in /etc/routes/node.env
(readable by root only):
Routes__Node__CentralUrl=https://central01.contoso.local:5080/Routes__Node__ApiKey=<enrollment key>Routes__Node__CentralCertificateThumbprints=<thumbprint>To listen on port 104, give the program the capability: setcap 'cap_net_bind_service=+ep' /opt/routes/node/Routes.Node.
Within a few seconds the node appears on the Nodes tab as Running, listening on the ports from Settings.
4. Configure the first route
Section titled “4. Configure the first route”-
Destination. Configuration › Destinations › Add destination: name
PACS, hostpacs01.contoso.local, port104, called AE titlePACS01. Save, then click Echo to check the connection. Make sure the PACS accepts the router: add its AE title (ROUTES) and the node’s address to the PACS’s allowed senders. -
Source. Configuration › Sources › Add source: name
CT scanners, calling AE titlesCT*, and the scanners’ network, such as10.20.30.0/24. The address range stops anyone else from sending asCT1. -
Route. Configuration › Routes › Add route: name
CT to PACS, sourceCT scanners, destinationPACS. -
Check it. Configuration › Route tester: enter calling AE title
CT1and the address10.20.30.15. It shows which route matches, and why the others do not.
5. Send a test study
Section titled “5. Send a test study”-
On the modality, add the router as a storage destination: the router’s DNS name, the listen port, AE title
ROUTES. Press Echo or Verify first. -
Send a small study. Without a modality, any DICOM sender will do, such as
storescu -aec ROUTES -aet CT1 routes.contoso.local 11112 *.dcm. -
Watch it arrive on Monitoring, then find it in History by accession number or patient ID: each instance shows as Delivered to the PACS, with the transfer syntax it was sent in.
Next steps
Section titled “Next steps”- Set up alerts (email, Teams or Slack) on the Alerts tab, and backups of the database.
- Add a second node and a load balancer for redundancy.
- Explore what routes can do: header conditions, tag edits, groups with failover, holding studies until complete, prior studies, DICOMweb and cloud destinations, AI workflows and HL7.
