Manual

Table Of Contents
Software User Guide 62
Network Tab
AllowDNP3:ToallowexternaldevicestoconnecttotheDNP3Server,viaport20,000,throughuntrustedinterfaces
onthisunit,selectYes;otherwiseselectNo.TherecommendedsettingforthisfieldisNo
.
Torestrictaccessviaaconfiguredwhitelist,clickthecheckboxmarkedUseWhitelistandthenselectawhitelistname
forthelistofnamesavailableinthedropdownlistboxprovided.White listsmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:SettingthisoptiontoYes
doesnotenabletheDNP3Server,itjustallowsittobeaccessibleviathefirewallwhen
itisenabled.ThenDNP3Ser vermaybeenabledviatheAutomation>DNP3>PhysicalLinkLayerscreen.
DNP3WhitelistName:Selectthedesiredwhitelistforthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACL
Rules>SubnetWhitelistRulesscreen.
AllowWebInterfaceAccess:ToallowexternaldevicestoconnecttotheWebInterface,throughuntrustedinterfaces
onthisunit,selectYes;otherwiseselectNo.TherecommendedsettingforthisfeatureisYes
.
Torestrictaccessviaaconfiguredwhitelist,clickthecheckboxmarkedUseWhitelistandthenselectawhitelistname
fromthelistofnamesavailableinthedropdownlistboxprovided.Whitelistsmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:Thissettingwillnotoverrideanyfirewallrulesdefinedonotherpages,suchasserviceaccessorredirectrules.
WebUIWhitelistName:Selectthedesiredwhitelistforthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
AllowSNMPAgentAccess:ToallowexternaldevicestoconnecttotheSNMPAgent,viaport161,throughuntrusted
interfacesonthisunit,selectYes;otherwise
selectNo.TherecommendedsettingforthisfeatureisYes.
Torestrictaccessviaaconfiguredwhitelist,clickthecheckboxmarkedUseWhitelistandthenselectawhitelistname
fromthelistofnamesavailableinthedropdownlistboxprovided.Whitelistsmaybeviewed/definedviatheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
Note:SettingthisoptiontoYes
doesnotenabletheSNMPAgent,itjustallowsittobeaccessibleviathefirewallwhen
itisenabled.TheSNMPAgentmaybeenabledviatheServices>SNMPAgentscreen.
Note:Thissettingwillnotoverrideanyfirewallrulesdefinedonotherpages,suchasserviceaccessorredirectrules.
SNMPWhitelistName:Selectthedesiredwhitelistforthedropdownmenu.WhitelistsarecreatedintheNet
work>Firewall>ACLRules>SubnetWhitelistRulesscreen.
AllowIPSEC(Required):SpecifywhethertoallowESPdata,aswellasUDPport500tocommunicatewithexternal
devicesthroughuntrustedinterfaces.Therecommendedsettingfor
thisfieldisYes.
Note:ThisisnecessaryifyouareplanningtoconfigureanyIPSECtunnelsoriginatingfromthisdevice.
AllowNATTraversal(Required):SpecifywhethertoallowdataonUDPport4500onuntrustedinterface.Therecom
mendedsettingforthisfieldisYes
.
Note:ThisisnecessaryifyouareplanningtorunanyIPSECtunnelsthroughourdevice.Thiswouldsupportaunit
behindatrustedinterfacetomakeanIPSECconnectiontoahostbeyondanuntrustedinterface.
TrustedInterfaces:Identifiesthetrusted(internal)interface.Trafficfromthisinterfacewillbepermitted
outbound.
Defaultis“WAN/eth0”.