Console settings
These settings apply to every node. They are kept in the database by the central service and changed in the console; nodes pick up a change within a few seconds, and listening ports are opened and closed without a restart. Every change is kept in the configuration history (Configuration › Version history) and the audit log.
Settings of sources, destinations and routes are described on their own pages under Features.
General
Section titled “General”Configuration › Settings, at the top.
| Setting | Default | Range | What it does |
|---|---|---|---|
| Listen ports | 11112 |
Every node listens on these ports for DICOM. Several are allowed, comma separated. | |
| Router AE title | ROUTES |
up to 16 characters | The calling AE title towards destinations that do not set their own. Senders may call the router by any AE title. |
| Max inbound associations per node | 200 | 1–5000 | Further associations are refused as transient (local limit exceeded). |
| Max PDU length (bytes) | 262144 | 4096–16777216 | Offered to senders and destinations. |
| Inbound idle timeout (s) | 300 | 5–86400 | An incoming association with no traffic for this long is closed. |
| Drain grace period (s) | 300 | 0–86400 | How long open incoming associations may continue after a node is drained. |
| Monitor retention (minutes) | 10 | 1–1440 | How long finished transfers stay on the Monitoring page. |
| Dead-letter retention (days) | 30 | 0–3650 | Dead letters older than this are deleted. 0 = keep until purged. |
| Quarantine (days) | 0 | 0–365 | Keep refused instances on the node for diagnosis. 0 = discard them. |
| Resend cache (hours) | 24 | 0–8760 | Keep delivered instances so they can be resent from the history. 0 = off. |
| Resend cache limit (GB per node) | 100 | 1–100000 | The oldest cached instances are removed first. |
| History retention (days) | 30 | 1–3650 | How long the per-instance history is kept in the database. |
| Audit log retention (days) | 2192 | 0–36500 | How long the audit log is kept: six years by default, as HIPAA asks of audit records; 0 = for ever. |
| Audit repository | none | The audit record repository (IHE ATNA) every audit entry also goes to, as host or host:port. See Security and audit. | |
| Audit repository protocol | TLS | TLS (RFC 5425, with the central server’s certificate), TCP or UDP. | |
| Audit source ID, enterprise site ID | Routes@ and the central server’s name; none |
How the messages name this system and the site. | |
| Trusted repository certificates | none | Thumbprints of the repository’s certificate, if the operating system does not trust its issuer. | |
| Minimum free disk (GB) | 10 | 0–100000 | Below this a node stops listening but keeps sending; it listens again with 25% more free (at least 2 GB more). Below half of it, instances on open associations are refused. 0 = off. |
| Accept private / unknown SOP classes | on | Accept SOP classes that are not in the standard’s storage list. | |
| Answer C-ECHO only from senders matching a route | off | Otherwise any system may verify the connection. | |
| Flush to disk before acknowledging | on | Each instance (and its place in the queues) is on the disk itself before the sender is told it is stored, so a power cut or crash loses nothing. Off is much faster on disks without a battery-backed write cache, but the last second or so of instances can be lost. | |
| Check daily for a newer release | on | Each central server asks Routes’ public releases once a day; the Nodes tab says when there is a newer one. Nothing is sent but the request, and nothing is downloaded or installed. Off for servers that may not reach the internet. | |
| Encrypt traffic kept on nodes | off | Instances, HL7 messages and the other records a node keeps that name patients are encrypted on its disk (AES-256) with the node’s own key. Can be turned on or off at any time: files already written stay as they are, and are read either way. See Security and audit. | |
| Changes need a second administrator’s approval | off | Two-person rule: configuration changes wait under Pending changes until another administrator approves them. See Security and audit. |
Quarantined instances, the resend cache and the history hold patient data. See Security and audit.
Transfer syntaxes
Section titled “Transfer syntaxes”| Setting | Default | What it does |
|---|---|---|
| Transfer syntaxes accepted from senders | any syntax the router knows, as the sender prefers | The rule for every source that does not set its own. |
| Transfer syntaxes sent to destinations | as received, then Explicit VR Little Endian, then Implicit VR Little Endian; lossy not allowed | The list for every destination that does not set its own. |
Both can have overrides for particular SOP classes. See Transfer syntaxes.
DICOM TLS
Section titled “DICOM TLS”| Setting | Default | What it does |
|---|---|---|
| TLS ports | none | Every node also listens on these ports for DICOM over TLS only, such as 2762. |
| Node certificate | automatic | From each node’s LocalMachine\My store: empty = a valid certificate issued to the node’s computer name; or a thumbprint, or text its subject contains. A node can override it with its own setting. |
| Senders must present a listed client certificate | off | Mutual authentication on the TLS ports: the sender’s certificate must be under Trusted certificates, or match Sender certificate subjects. |
| Trusted certificates | none | Thumbprints of senders’ or destinations’ certificates to accept although their issuer is not trusted; with client certificates required, the senders accepted. |
| Sender certificate subjects | none | With client certificates required: senders whose certificate the operating system trusts and whose subject contains one of these (CN=CT01). |
See DICOM TLS.
DICOMweb
Section titled “DICOMweb”| Setting | Default | Range | What it does |
|---|---|---|---|
| DICOMweb port | 0 (off) | 0–65535 | Every node serves /dicomweb on this port, such as 8443. |
| HTTPS with the node certificate | on | Otherwise plain HTTP (only behind a proxy that adds TLS). | |
| Largest upload (MB) | 10240 | 1–1048576 | One STOW-RS request can hold a whole study. |
| Requests at once per sender | 32 | 0–10000 | Per token or signed-in user, on each node; more are answered 429. 0 = no limit. |
| Requests per minute per sender | 6000 | 0–1000000 | A sustained rate; a minute’s worth may come at once. 0 = no limit. |
| Failed sign-ins before refusing | 20 | 0–100000 | From one address within 5 minutes; the address is then refused for 5 minutes. 0 = never. |
| Keep retrieved instances (minutes) | 30 | 0–1440 | WADO-RS answers later requests for the same instances from the node’s copy. |
| DICOMweb sign-in: identity provider | none | The OpenID Connect issuer whose access tokens nodes accept, for web viewers that sign users in. | |
| Accepted audiences | none | The aud values accepted in those tokens. |
|
| Group claims | groups;roles |
The claims holding the user’s groups or roles. | |
| User name claim | preferred_username |
Names the user in the audit log. | |
| Web viewers allowed (origins) | none | Sites whose pages may call DICOMweb from a browser (CORS). |
See DICOMweb.
HL7 and modality worklist
Section titled “HL7 and modality worklist”| Setting | Default | Range | What it does |
|---|---|---|---|
| HL7 port | 0 (off) | 0–65535 | Every node accepts HL7 v2 over MLLP on this port, such as 2575. |
| MLLP over TLS | off | With the node certificate. | |
| Require HL7 senders to present a certificate | off | Mutual TLS: senders must present a certificate listed below. Needs MLLP over TLS. | |
| HL7 sender certificates (thumbprints) | none | Accepted whoever issued them. | |
| HL7 sender certificate subjects | none | Also accepted: certificates the operating system trusts whose subject contains one of these, such as CN=RIS01. |
|
| HL7 senders (addresses) | none | Addresses and ranges HL7 may come from; required with an HL7 port. HL7 has no sign-in, so list them (any accepts every address). |
|
| Merges update | none | A patient ID map that HL7 merges add the prior ID to. | |
| Keep worklist items (days) | 7 | 1–3650 | After their scheduled date. |
| Keep HL7 messages (days) | 90 | 1–3650 | Messages received and the copies sent, in the history. |
| Complete an item when its study arrives | off | For modalities that do not send MPPS. | |
| HL7 status update receivers | none | Systems told when a worklist item’s status changes other than by the RIS: name, host, port, MLLP or TLS, receiving application and facility, and which sending applications’ orders. |
HL7 destinations, routes and lookup tables are under Configuration › HL7 routing. See Modality worklist and MPPS and HL7 routing.
Relevant prior studies
Section titled “Relevant prior studies”| Setting | Default | What it does |
|---|---|---|
| Body parts | the built-in list | One per line, Name: KEYWORD, KEYWORD, …. A name ending in * matches any body part. Built in: Head, Neck, Chest, Heart, Breast, Abdomen, Pelvis, Spine, Upper limb, Lower limb, Whole body. |
See Prior studies.
Console sign-in
Section titled “Console sign-in”Shown with local accounts only.
| Setting | Default | What it does |
|---|---|---|
| Every account must use two-factor sign-in | off | Each account sets up an authenticator app at its next sign-in. |
Logging
Section titled “Logging”| Setting | Default | What it does |
|---|---|---|
| Event log | Errors | The lowest level written to the Windows Application event log: Off, Errors, Warnings, Information. Sources Routes Central and Routes Node. |
| Syslog server | none | host or host:port (514 by default, 6514 for TLS). |
| Syslog protocol | UDP | UDP (RFC 5426), TCP (RFC 6587) or TLS (RFC 5425). |
| Syslog level | Warnings and errors | Errors, Warnings, Information or Debug and above. |
| Syslog facility | local0 (16) | local0 to local7. |
Log messages can name patients. Send them only where patient data may go, and prefer TLS.
OpenTelemetry
Section titled “OpenTelemetry”| Setting | Default | What it does |
|---|---|---|
| OTLP endpoint | none | The collector or monitoring service, as a URL: http://collector:4317 for gRPC, http://collector:4318 for HTTP (https:// when it has a certificate the operating system trusts). Empty = off. |
| Protocol | gRPC | gRPC or HTTP (protobuf). Over HTTP, /v1/traces, /v1/metrics and /v1/logs are added to the URL. |
| Headers | none | Sent with every export, often an API key: name=value, separated by commas. Kept like a password: never shown again, exported or kept in the version history. |
| Send metrics | on | The deployment’s metrics (sent by the leading central server) and each service’s runtime metrics. |
| Send traces | on | Instances received and delivered by nodes, held studies released, and console requests. |
| Share of traces (%) | 100 | Fewer for busy sites; a trace is kept or dropped whole. |
| Logs | Off | The lowest level sent: Errors, Warnings, Information or Debug and above. |
See Monitoring.
Alert rules and notifications
Section titled “Alert rules and notifications”On the Alerts page, for administrators. These are kept by the central service and never sent to nodes.
| Setting | Default | Range | Raises an alert when |
|---|---|---|---|
| Alerting enabled | on | ||
| Node offline after (min) | 2 | 0–1440 | a node has not been heard from for this long. Stopped drained nodes do not alert. |
| Destination unreachable after (min) | 5 | 0–1440 | a node cannot associate with a destination for this long. |
| Queue depth (instances) | 5000 | 0–10000000 | this many instances wait for one destination on one node. |
| Oldest queued instance (min) | 30 | 0–10080 | the oldest waiting instance has waited this long. |
| Disk free below (GB) | 20 | 0–100000 | a node’s data volume has less free space. |
| Remind every (hours) | 4 | 0–168 | an alert is still open; 0 = never remind. |
| Alert while dead letters exist | on | any destination has dead letters. | |
| Alert when a sender is turned away | on | a node refused a sender in the last hour (no route, or transfer syntaxes refused). |
0 turns a rule off.
| Notification | Default | What it does |
|---|---|---|
| Send to | none | Email addresses, comma separated. |
| From | none | The sender address. |
| SMTP server, SMTP port | none, 25 | |
| Use TLS (STARTTLS) | off | |
| SMTP user, SMTP password | none | Empty user = no authentication. The password is stored encrypted and never shown again. |
| Webhook URL | none | Receives a JSON POST with a text field and the alert list (Teams and Slack incoming webhooks accept it). Stored encrypted and never shown again. |
Scheduled usage reports are emailed with the same SMTP settings; see Monitoring, history and alerts.
