background image

OPERATING GUIDE

31-00140-01

SmartVFD Security Guide

INTRODUCTION AND 
INTENDED AUDIENCE

This manual contains security-related information to 
guide the contractor install, operate, and securely 
maintain it.

SYSTEM OVERVIEW

The following is a system diagram of the SmartVFD in an 
example installation.  

Fig. 1. 

Some key elements of the diagram are:

Lonworks network:

 Lonworks (LON) network provides 

access to the Honeywell SmartVFD controller so it can 
communicate and share information.

BACnet network:

 The BACnet MS/TP or BACnet IP 

network provides access to the Honeywell SmartVFD 
controller. 

Modbus RTU or N2 network: 

Modbus RTU or N2 bus 

networks provide access to the Honeywell SmartVFD 
controller so it can communicate and share information.

HVFDCDMCA Commissioning Kit:

 Required for direct 

access commissioning of the SmartVFD. Connects to PC 
via USB and connects to SmartVFD via RJ45 using a 
communication bus. 

Drive Care Tool:

 PC software designed to allow user 

access to all of the VFD parameters. It is used in 
conjuction with the HVFDCDMCA Commissioning Kit 
hardware to connect a PC to the SmartVFD.

Building Management System: 

The Building 

Management System is not specifically defined, but can 
be any management system that accepts one of the 
communication types already described and used by the 
SmartVFD.

The SmartVFD has multiple communication protocol 
options. Typically only one communication protocol is 
chosen to interface with the SmartVFD in any given 
installation.

SYSTEM DESIGN AND 
PLANNING

This section contains information on activities that need 
to happen when the system is being planned by the 
contractor.

Physical Security of Components

It is important to have a plan for physical security of 
system components. It is recommended that the 
contractor identify the security needs of the building 
owner and provide guidance for implementation in 
addition to the requirements of the building owner.

It is recommended that the organization responsible for 
providing security for network assets be involved in the 
planning. The Building owner/Customer's IT groups needs 
to approve and connect the SmartVFD to the system so 
that the IT system will work with the SMARTVFD.

Physical security controls, such as a locked cabinet or 
equipment room that restricts physical access to the 
SMARTVFD are necessary to prevent system tampering, 
power interruption, and other security issues.

Ensure that SMARTVFD components requiring high 
reliability are protected with secure power sources and 
emergency power systems. Honeywell recommends 

RS485 BACNET MSTP OR

MODBUS RTU OR N2 NETWORK 

ETHERNET BACNET IP

OR MODBUS TCP 

LON – LONWORKS BUS 

BUILDING

MANAGEMENT 

SYSTEM (JACE

OR OTHER) OR 

IP ROUTER

PC

PC

PC

HVFDSDMCA

COMMISSIONING

KIT

SMARTVFD

CLOUD

MCR37280

Summary of Contents for SmartVFD

Page 1: ...scribed and used by the SmartVFD The SmartVFD has multiple communication protocol options Typically only one communication protocol is chosen to interface with the SmartVFD in any given installation SYSTEM DESIGN AND PLANNING This section contains information on activities that need to happen when the system is being planned by the contractor Physical Security of Components It is important to have...

Page 2: ...rough the use of an access code settable on the keypad parameter P8 1 and P8 2 Access to the SmartVFD directly by PC via the Drive Care Tool software and the HVFDCDMCA hardware kit requires no password Any PC application accessing the SmartVFD via the BMS or router should be protected with a robust password See APPENDIX 3 SECURITY MAINTENANCE TASKS on page 3 PCs used to access the SmartVFD Each PC...

Page 3: ...ion best practices for SmartVFD SMARTVFD Communication Bus Lon BACnet MS TP etc Security of the bus also means that the bus is electrically reliable for communications It is important the bus is installed with one wire type consistent throughout the whole gateway to controller connection as to eliminate reflections from bus wire impedance mismatches Shielded wire is not recommended for normal inst...

Page 4: ...est real time protection for your system Configure the virus scanner to run on demand scans during regular scheduled maintenance to catch any malicious files or programs which may be dormant on the computer Configure both on access and on demand scanning to Scan the boot sectors of all disks Move infected files to a quarantine directory and notify the user that an infected file was found Allow the...

Page 5: ...tronger password that is also easier for the user to remember For example My dog Fido has 50 fleas is a much stronger password and much easier to remember than X 9d8oc Ek Enforce password history set to 24 passwords remembered This prevents reuse of the same password too quickly Password must meet complexity requirements set to enabled improves encryption and makes guessing harder Suggest requirin...

Page 6: ...will reject any incoming connections by default Exceptions must be put into the firewall to allow incoming connections to succeed If not manually configured on first usage the Windows firewall will prompt the user to add a firewall exception Use the following configuration settings The firewall is on The firewall is on for all network locations Home or work Public or Domain The firewall is on for ...

Page 7: ...accessible fit locks or remove the DVD drives Disable unused USB ports to prevent USB drives or other uncontrolled devices from being connected to the system Such devices may be used to introduce a virus or other malware Also disable or physically protect the power button to prevent unauthorized use Set the BIOS to boot only from the operating system s root partition drive Set a BIOS password ensu...

Page 8: ... M S 01 18 Printed in United States By using this Honeywell literature you agree that Honeywell will have no liability for any damages arising out of your use or modification to the literature You will defend and indemnify Honeywell its affiliates and subsidiaries from and against any liability cost or damages including attorneys fees arising out of or resulting from any modification to the litera...

Reviews: