Manual

Table Of Contents
Software User Guide 61
Network Tab
EnableFirewall(Required):Specify whethertoenablethefirewallserviceonthisdevice.Therecommendedsetting
forthisfieldisYes
.
Note:Disablingthefirewallwillcompromisesecurityandroutingfunctionsoftheunit.
AllowPing:ToallowICMPechoresponses(Ping)fromexternaldevicesthroughuntrustedinterfacesonthisunit,
selectYes;otherwiseselectNo.TherecommendedsettingforthisfieldisYes
.
Torestrictaccessviaaconfiguredwhitelist,selectawhitelistnameforthelistofnamesavailableinthedropdown
menu.Note:Thissettingwillnot
overrideanyfirewallrulesdefinedonotherpages,suchasserviceaccessorredirect
rules.
PingWhitelistName:Selectthedesiredwhitelistfromthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACLRules>Subnet>WhitelistRulesscreen.
AllowSSH:ToallowexternaldevicestoconnecttotheSSHServer,viaport
22,throughuntrustedinterfacesonthis
unit,selectYes;otherwiseselectNo.TherecommendedsettingforthisfieldisYes
.
TorestrictaccessviaaconfiguredWhitelist,clickthecheckboxmarkedUseWhitelistandthenselectaWhitelistname
fromthelistofnamesavailableinthedropdownlistboxprovided.Whitelistsmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:Settingthisoptionto
YesdoesnotenabletheSSHserver,itjustallowsittobeaccessibleviathefirewallwhenit
isenabled.TheSSHServermaybeenabledviatheServices>SSH/TELNETServerscreen.
IftheSSHServerisconfiguredtouseaportotherthan22,arulespecificallyforthealternate
portwillneedtobe
addedviatheNetwork>Firewall>PortAllow/ForwardingRules>ServiceAccessRulesscreen.
Note:Thissettingwillnotoverrideanyfirewallrulesdefinedonotherpages,suchasserviceaccessorredirectrules.
SSHWhitelistName:Selectthedesiredwhitelistforthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
AllowTelnet:ToallowexternaldevicestoconnecttotheTELNETSer ver,viaport23,throughuntrustedinterfaceson
thisunit,selectYes;otherwiseselectNo.The
recommendedsettingforthisfieldisNo.
Torestrictaccessviaaconfiguredwhitelist,clickthecheckboxmarkedUseWhitelistandthenselectawhitelistname
fromthelistofnamesavailableinthedropdownlistboxprovided.Whitelistsmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:SettingthisoptiontoYes
doesnotenabletheTelnetServer,itjustallowsittobeaccessibleviathefirewallwhen
itisenabled.TheTelnetServermaybeenabledviatheServices>SSH/TelnetServerScreen.
Note:Thissettingwillnotoverrideanyfirewallrulesdefinedonotherpages,suchasserviceaccessorredirectrules.
TelnetWhitelistName:Selectthedesiredwhitelistforthedropdownmenu.Whitelistsarecreate dintheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
AllowModb us:ToallowexternaldevicestoconnecttotheMODBUSServer,viaport502,throughuntrustedinter
facesonthisunit,selectYes;otherwiseselectNo.
TherecommendedsettingforthisfieldisNo.
Torestrictaccessviaaconfiguredwhitelist,clickthecheckboxmarkedUseWhitelistandthenselectawhitelistname
forthelistofnamesavailableinthedropdownlistboxprovided.White listmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:SettingthisoptiontoYes
doesnotenabletheMODBUSserver,itjustallowsittobeaccessibleviathefirewall
whenitisenabled.TheMODBUSServermaybeenabledviatheAutomation>ModBus>Forwardingscreen.
ModbusWhitelistName:Selectthedesiredwhitelistforthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACLRules>
SubnetWhitelistRulesscreen.