HEROS functions | Firewall
Setting
Meaning
Interface
Select the interface
Selection of the
eth0
interface usually corresponds to X26 of the MC main
computer.
eth1
corresponds to X116.
You can check the interfaces in the network settings on the Interfaces tab. For
main computer units with two Ethernet interfaces, the DHCP server for the
machine network is active for the second, non-primary, interface by default. With
this setting the firewall cannot be activated for
eth1
because the firewall and
DHCP server mutually exclude each other.
Report other inhibited packets
Activate the firewall with a high security level
All services except for SSH are blocked.
Inhibit ICMP echo answer
When this option is set, the control no longer responds to a PING request
Service
This column contains the short names of the services that are configured with
this dialog. For the configuration it is not important here whether the services
themselves have been started.
DNC
designates the service the DNC server provides via the RPC protocol
for external applications that were developed with the RemoTools SDK (port
19003)
For more detailed information, consult the RemoTools SDK
manual.
LDAPS
includes the server on which the user data and the user
administration configuration are saved.
LSV2
includes the functionality for
TNCremo
, Teleservice, and other
HEIDENHAIN PC Tools (port 19000)
When user administration is active, you can set up only secure
network connections via SSH. The control automatically disables
the LSV2 connections via the serial interfaces (COM1 and COM2)
and the network connections without user identification.
OPC UA
designates the service provided by the
OPC UA NC Server
(port
4840)
SMB
only refers to incoming SMB connections, i.e. if a Windows share is
created on the NC. Outgoing SMB connections (i.e. if a Windows share is
connected to the NC) cannot be prevented.
SRI
refers to the connections that are used in conjunction with the acquisition
of operating states through the
State Reporting Interface
option.
SSH
stands for the Secure Shell protocol (port 22). As of HEROS 504, LSV2
can be executed securely via this SSH protocol while user administration is
active.
"User authentication from external applications",
VNC
protocol means access to the screen contents. If you block this service,
the screen content can no longer be accessed, not even with the Teleservice
programs from HEIDENHAIN (e.g. to create a
screenshot
) If this service is
blocked, the HEROS VNC configuration dialog shows a warning that
VNC
is
disabled in the firewall.
10
HEIDENHAIN | TNC 620 | User's Manual for Setup, Testing and Running NC Programs | 01/2022
403
Summary of Contents for TNC 620
Page 4: ...Contents 4 HEIDENHAIN TNC 620 User s Manual for Setup Testing and Running NC Programs 01 2022...
Page 6: ...Contents 6 HEIDENHAIN TNC 620 User s Manual for Setup Testing and Running NC Programs 01 2022...
Page 24: ......
Page 25: ...1 Basic information...
Page 43: ...2 First steps...
Page 55: ...3 Fundamentals...
Page 126: ......
Page 127: ...4 Tools...
Page 165: ...5 Setup...
Page 245: ...6 Testing and running...
Page 311: ...7 Special functions...
Page 316: ......
Page 317: ...8 Pallets...
Page 339: ...9 MOD functions...
Page 368: ......
Page 369: ...10 HEROS functions...
Page 470: ......
Page 471: ...11 Operating the touchscreen...
Page 488: ......
Page 489: ...12 Tables and overviews...