smartDEN
IP-16R-MT
User Manual
7 July 2020
-
50
-
10. Security considerations
The
smartDEN IP-16R-MT
runs a special firmware and do not have a general-
purpose operating system. There are no extraneous IP services found on general-
purpose operating systems (e.g. fingerd, tcp_wrapper, etc.) that can possibly be
exploited by an unauthorized agent. In particular, the
smartDEN IP-16R-MT
does not
run protocols such as Telnet and FTP which may have the potential for security
breech. The only exception from this is the Modbus-TCP protocol, that can be
disabled.
Web-browser access
A challenge-response authentication is used in login process. When the password is
entered, it is transmitted across the network in encrypted form, so eavesdropping on
the data transmission will not reveal the password. Subsequent transmissions of the
password to "login" onto the device are encrypted and "safe". The only case when
the password is transmitted across the network "in the open", is when it is being
changed and submitted in
General
Setting
form. Therefore, you must set passwords
in the secure environment where you can make sure that no one is "eavesdropping".
Modbus-TCP communication
Modbus-TCP does not implement encryption. Modbus-TCP communication should
be used in trusted networks and disabled if not used.
XML/JSON operation
A challenge-response authentication can be used in login process. The password
can be transmitted by custom application across the network in encrypted form.
Web and XML/JSON access can be restricted by IP Address (range of IP
Addresses) or by MAC Address.