Cyber security
Product manual 2TMD041800D0002
│
152
11.3
Deployment guideline
Please do not install it within a public place and to ensure that physical access to the devices is
granted only to trusted personal.
All devices need to work in security mode by default and. all devices in one system shall be
signed by a public CA at commissioning stage, normally management software works as CA.
It’s suggest compatible mode only be used when device need to communicate with previous
generation products. In this mode, data transmission between devices are not encrypted, it may
lead to data leaks and has the risk of being attacked.
When user decide to remove the device from system, user shall reset the device to factory
setting in order to remove all the configuration data and sensitive data in the device. This will
prevent sensitive data leak.
It is recommended to apply "MAC filter" and "Rate limiter“ in the switch to prevent DOS attack.
11.4
Upgrading
Device supports firmware updating via SD card, in this mode, a signature file will be used to
verify the authentication and integrity of firmware.
If Internet services available, device will connect to MyBuilding sever to get new firmware
automatically, but needs to be confirmed by end user every time. A signature file will be used to
verify the authentication and integrity of firmware.
11.5
Backup/Restore
Some configurations of device can be exported to SD card for backup purpose, and on later
use, imported it again to restore configuration.
When connect to management device, user can backup and restore configurations on
management device side, this feature is enable or disable by a local setting item.
11.6
Malware prevention solution
The device H8236 is not susceptible to malware, because custom code cannot be executed on
the system. The only way to update the software is by firmware upgrading. Only firmware
signatured by ABB can be accepted.
11.7
Password rule
The user needs to change the engineering password when entering the engineering settings for
the first time. This engineering password is not allowed continuously increasing or decreasing
numbers (e.g. 12345678, 98765432). And three consecutive identical numbers are also not
allowed. (e.g. 123444, 666888)
Your passwords could not known by the others to guarantee the security.
Summary of Contents for Welcome IP H8236 02 Series
Page 1: ...2TMD041800D0002 26 07 2019 Product manual ABB Welcome IP H8236 IPTouch 7 H8236 02 IPTouch 7 ...
Page 4: ...Table of contents Product manual 2TMD041800D0002 4 ...
Page 21: ...Mounting Installation Product manual 2TMD041800D0002 21 Installation 1 4 5 3 2 ...
Page 27: ...Commissioning Product manual 2TMD041800D0002 27 2 Accept licensing terms ...
Page 28: ...Commissioning Product manual 2TMD041800D0002 28 3 Select country 4 Set date and time ...
Page 82: ...Commissioning Product manual 2TMD041800D0002 82 ...
Page 99: ...Commissioning Product manual 2TMD041800D0002 99 Enter the user name and password and click OK ...