Windows
Routes comes as two installers, Routes.Central.msi and Routes.Node.msi, on the download
page. Both are self-contained: the servers need no .NET runtime. They run on Windows Server 2019, 2022 and 2025 (64-bit), and on Windows 10 and 11 for testing.
The central service
Section titled “The central service”Run Routes.Central.msi on the server that will hold the configuration and serve the console. It asks for:
| Page | Setting | Notes |
|---|---|---|
| Database | SQL Server or PostgreSQL | See The database. |
| SQL Server instance | localhost, sql01 or sql01\INSTANCE. The service connects with Windows authentication as its service account. |
|
| PostgreSQL host, port, user, password | Default localhost, 5432, user routes. |
|
| Database name | Default Routes. Created on first start when the account may create databases. |
|
| Settings | Port | The web console and node API. Default 5080; the firewall is opened for it. |
| HTTPS certificate thumbprint | A certificate in LocalMachine\My. Empty: a self-signed certificate is made. See HTTPS and certificates. |
|
| Administrators | Windows groups or users, ; separated, such as CONTOSO\PACS-Admins. |
|
| Viewers | May look at the console but change nothing. Empty: any signed-in user. | |
| History viewers | May search the history, which holds patient names and IDs. Empty: administrators only. |
When it finishes, the service is running at https://<server>:5080/.
Unattended installs
Section titled “Unattended installs”Every setting is also an installer property:
# SQL Server, Windows authentication as the computer accountmsiexec /i Routes.Central.msi /qn SQLSERVER="sql01" SQLDATABASE="Routes" HTTPPORT=5080 CERTTHUMBPRINT="<thumbprint>" ADMINGROUPS="CONTOSO\PACS-Admins" VIEWERGROUPS="CONTOSO\Radiology-IT" HISTORYGROUPS="CONTOSO\PACS-Support"
# PostgreSQLmsiexec /i Routes.Central.msi /qn DATABASEPROVIDER=PostgreSql PGHOST="db01" PGUSER="routes" PGPASSWORD="<password>" SQLDATABASE="routes" ADMINGROUPS="CONTOSO\PACS-Admins"
# Any connection string (SQL authentication, an Always On listener)msiexec /i Routes.Central.msi /qn CONNECTIONSTRING="Server=router-ag;Database=Routes;MultiSubnetFailover=True;Integrated Security=true;TrustServerCertificate=true" ADMINGROUPS="CONTOSO\PACS-Admins"| Property | Default | Meaning |
|---|---|---|
DATABASEPROVIDER |
SqlServer |
SqlServer or PostgreSql. |
SQLSERVER |
localhost |
SQL Server instance. |
SQLDATABASE |
Routes |
Database name (both servers). |
PGHOST, PGPORT, PGUSER, PGPASSWORD |
localhost, 5432, routes |
PostgreSQL connection. |
CONNECTIONSTRING |
A full connection string; overrides the above. | |
HTTPPORT |
5080 |
Console and node API port. |
CERTTHUMBPRINT |
HTTPS certificate in LocalMachine\My. |
|
HTTPSMODE |
SelfSigned |
Without a certificate: SelfSigned, or Http behind a TLS-terminating proxy only. |
ADMINGROUPS, VIEWERGROUPS, HISTORYGROUPS |
Who may administer, view, and see patient data. | |
AUTHENTICATION |
Windows |
Windows, OpenIdConnect or Local. See Console sign-in. |
OIDCAUTHORITY, OIDCCLIENTID, OIDCCLIENTSECRET, OIDCROLECLAIMS |
For an identity provider. | |
SECRETPROTECTION |
Machine |
How stored secrets are encrypted. See Several central servers. |
INSTANCENAME |
computer name | This server’s name in the console. |
SERVICEACCOUNT, SERVICEPASSWORD |
LocalSystem | Run the service as another account. |
LOGDIR |
%ProgramData%\Routes\Central\Logs |
Log folder. |
Running as a service account
Section titled “Running as a service account”By default the service runs as LocalSystem, which SQL Server sees as the computer account (CONTOSO\CENTRAL01$), or
as NT AUTHORITY\SYSTEM when SQL Server is on the same server. To use a dedicated domain account instead:
msiexec /i Routes.Central.msi /qn SERVICEACCOUNT="CONTOSO\svc-routes" SERVICEPASSWORD="<password>" ...Give that account access to the database instead of the computer account. With several central servers, run them all as the same account (see Several central servers).
-
In the console, open Configuration › Node enrollment and copy the central address, the enrollment key and, with a self-signed certificate, its thumbprint.
-
On each node server, run
Routes.Node.msi. It asks for the central address, the enrollment key, an optional node name (default: the computer name) and the data folder. -
The node appears on the Nodes tab within seconds.
Unattended:
msiexec /i Routes.Node.msi /qn CENTRALURL="https://central01.contoso.local:5080/" APIKEY="<enrollment key>" CENTRALTHUMBPRINT="<thumbprint>" DATADIR="D:\Routes"| Property | Default | Meaning |
|---|---|---|
CENTRALURL |
The central service’s address. Several central servers: ; separated, nearest first. |
|
APIKEY |
The enrollment key. Used once: the node then gets a key of its own. | |
CENTRALTHUMBPRINT |
The central certificate’s thumbprint, when Windows does not trust it (self-signed). Several: ; separated. |
|
NODENAME |
computer name | The node’s name in the console. Must be unique. |
DATADIR |
%ProgramData%\Routes\Node\Data |
Queues, the resend cache and everything in transit. |
LOGDIR |
%ProgramData%\Routes\Node\Logs |
Log folder. |
SERVICEACCOUNT, SERVICEPASSWORD |
LocalSystem | Run the node as another account. |
The node’s listen ports are set centrally (Configuration › Settings), so its firewall rule is for the program, not a port: changing ports needs no reinstall.
What the installers set up
Section titled “What the installers set up”| Central service | Node | |
|---|---|---|
| Program folder | C:\Program Files\Symmetricare\Routes\Central |
C:\Program Files\Symmetricare\Routes\Node |
| Windows service | RoutesCentral (Symmetricare Routes Central Service) |
RoutesNode (Symmetricare Routes Node) |
| Settings | HKLM\SOFTWARE\Routes\Central |
HKLM\SOFTWARE\Routes\Node |
| Data | %ProgramData%\Routes\Central\Data |
%ProgramData%\Routes\Node\Data |
| Logs | %ProgramData%\Routes\Central\Logs |
%ProgramData%\Routes\Node\Logs |
| Event log source | Routes Central | Routes Node |
| Firewall | the console port | the node program |
The registry keys are readable by SYSTEM and Administrators only, since they can hold a connection string or client
secret. When they start, the node closes its data and log folders, and the central service its log folder, to ordinary local users (everyone under %ProgramData% could otherwise read them).
To change a setting later, edit its value under the registry key and restart the service. Upgrades keep every setting: the installer reads them back from the registry.
Checking it works
Section titled “Checking it works”Get-Service RoutesCentral, RoutesNodeGet-Content "$env:ProgramData\Routes\Central\Logs\*.log" -Tail 20If a service starts and stops again, its log says why. The usual causes are covered in Troubleshooting.
