background image

EAGLE 20

Release 09 04/2012

25

Configurable Firewall rules:

Incoming/outgoing data traffic

Modem access

External Management access

IP Masquerading, 1-to-1 NAT, Port Forwarding

IP Spoofing Protection

VPN functions

The EAGLE 20 supports the following Virtual Private Network (VPN) 
functions:

Multipoint VPN: Router Mode

VPN protocols: IPsec

Encryption algorithms:

DES-56

3DES-168

AES-128, AES-192, AES-256

Authentication:

Pre-shared key (PSK)

X.509v3 certificates

Hashing algorithms: MD5, SHA-1

NAT-T support

2.5.2

Operating modes

This device helps protect the internal network from the influences of the 
external network. These influences can include unauthorized access 
attempts, as well as interfering network events such as overloads.

State on delivery

On delivery, the device works in the Transparent Mode. In this mode, no 
network settings (e.g., for subnetworks) are required for operation. 

The firewall has been preconfigured so that the IP data traffic from the 
internal network is possible; however, traffic from the external network to 
the internal network is not possible. Thus, already the delivery state helps 
protect against unauthorized accesses from the external network.

Transparent Mode

The Transparent Mode is a transparent bridge mode. In this mode, the 
device works as a 2-port bridge, whereby only IP and ARP frames 
corresponding to the firewall rules are transmitted.

Summary of Contents for EAGLE 20 MM/MM

Page 1: ...US V 24 IP ADDRESS V 24 R EAGLE 20 USB 24V P1 FAULT 24V P2 0V 0V g 2 Aufkleber MAC Adresse 1 P 2 1 FAULT LS DA 2 1 k STATUS V 24 IP ADDRESS V 24 R EAGLE 20 USB 24V P1 FAULT 24V P2 0V 0V g 2 Aufkleber...

Page 2: ...features described here are binding only if they have been expressly agreed when the contract was made This document was produced by Hirschmann Automation and Control GmbH according to the best of th...

Page 3: ...up 16 2 1 Installing the device 16 2 1 1 Overview of installation 16 2 1 2 Unpacking and checking 16 2 1 3 Terminal block for supply voltage and signal contact 17 2 1 4 Connecting the terminal block...

Page 4: ...l injury if the instructions are not followed This is the safety alert symbol It is used to alert you to potential personal injury hazards Obey all safety messages that follow this symbol to avoid pos...

Page 5: ...voltage connections and to the signal contact with SELV circuits with the voltage restrictions in accordance with IEC EN 60950 1 The supply voltage is electrically isolated from the housing Use undam...

Page 6: ...distance of up to 5 cm 1 97 in from the device and relative air humidity specified in the technical data Install the device in a location where the climatic threshold values specified in the technica...

Page 7: ...an therefore cause material damage and or injuries Only appropriately qualified personnel should work on this device or in its vicinity These personnel must be thoroughly familiar with the warnings an...

Page 8: ...ustrial sector Interference immunity EN 61000 6 2 2005 Emitted interference EN 55022 2010 Warning This is a class A device This device can cause interference in living areas and in this case the opera...

Page 9: ...ent The device creates and uses high frequencies and can radiate same and if it is not installed and used in accordance with this operating manual it can cause radio transmission interference The use...

Page 10: ...ther information that you need to install the device The following manuals are available as PDF files on the CD ROM supplied Installation user manual Configuration user manual Web based Interface refe...

Page 11: ...rts the following network modes Transparent Mode Router Mode PPPoE Mode The Industrial ETHERNET Firewall is used everywhere that security sensitive network cells require a connection from the internal...

Page 12: ...e special requirements of industrial automation They meet the relevant industry standards provide high operational reliability even under extreme conditions and also long term reliability and flexibil...

Page 13: ...The device conforms to the specifications of standard ISO IEC 8802 3u 100BASE TX ISO IEC 8802 3 100BASE FX The device contains the function units such as Firewall VPN function Management function volt...

Page 14: ...port and 1 FX port Figure 3 Interfaces of the EAGLE 20 TX MM and EAGLE 20 TX SM 1 Port 1 INTERNAL port 100BASE TX RJ45 connector Autonegotiaton autopolarity autocrossing 2 Port 2 EXTERNAL port 100BAS...

Page 15: ...autocrossing 1 2 4 Device variants with 2 FX ports Figure 5 Interfaces of the EAGLE 20 MM MM 1 Port 1 INTERNAL port 100BASE FX DSC connector Multimode 2 Port 2 EXTERNAL port 100BASE FX DSC connector M...

Page 16: ...install and configure a EAGLE 20 Industrial ETHERNET Firewall product Unpacking and checking Connect the terminal block for voltage supply and signal contact and connect the supply voltage Install th...

Page 17: ...supply of the main voltage the device reports a loss of power You can avert this message by applying the supply voltage via both inputs or by changing the configuration in the Management Figure 6 Pin...

Page 18: ...the link status of at least one port The report of the link status can be masked by the Management for each port In the default state link status monitoring is deactivated The temperature of the devic...

Page 19: ...wisted pair connection These connections are RJ45 sockets 10 100 Mbit s TP ports enable the connection of terminal devices or independent network segments according to the IEEE 802 3 10BASE T 100BASE...

Page 20: ...d from the optical connections or from the ends of the connected optical fibers that are connected to the optical connections LIGHT EMITTING DIODE CLASS 2 M wave length 650 nm power 2 mW in accordance...

Page 21: ...EXTERNAL port to the external network e g the Internet This network is used to set up the connections to the external device or external network 2 2 Display elements After the operating voltage is ap...

Page 22: ...e Glowing green Device is ready for operation Slowly flashing yellow The device is in Router Redundancy Backup Mode Glowing yellow The device is operating in the Router Redundancy Master Mode and ther...

Page 23: ...ion Entry via the HiDiscovery protocol via the application HiDiscovery or Industrial HiVision via the internal port Auto Configuration Adapter Web Interface Further information on the basic settings o...

Page 24: ...device Figure 9 Pin assignment of the V 24 interface and the DB9 connector Note You will find the order number for the terminal cable which is ordered separately in the Technical Data chapter see on...

Page 25: ...es of the external network These influences can include unauthorized access attempts as well as interfering network events such as overloads State on delivery On delivery the device works in the Trans...

Page 26: ...n the Router and Transparent modes an additional network access option to the internal network is provided over the V 24 interface of the EAGLE 20 via PPP In this case communication is possible with t...

Page 27: ...b browser https 192 168 1 1 Result The HTTPS connection to the EAGLE 20 is set up A security message is displayed Confirm the security message with Yes To login enter Login admin Password private case...

Page 28: ...t when it is operated normally Operate this device according to the specifications see Technical data Relays are subject to natural wear This wear depends on the frequency of the switching operations...

Page 29: ...mbly Disassembling the device In order to remove the device from the DIN rail move the screwdriver horizontally under the chassis in the locking gate pull this down without tilting the screwdriver and...

Page 30: ...Back up fuse Nominal rating 3 15 A for each voltage input Characteristic slow blow Insulation voltage between operating voltage connections and housing 800 V DC Protective elements limit the insulati...

Page 31: ...erference EN 55022 Class A Yes FCC 47 CFR Part 15 Class A Yes Germanischer Lloyd Classification and Construction Guidelines VI 7 3 Part 1 Stability Vibration IEC 60068 2 6 Test FC test level according...

Page 32: ...ption at 24 V DC Power output at 24 V DC Power consumption at 24 V AC Power output at 24 V AC TX TX 6 9 W 23 5 Btu IT h 7 2 W 24 6 Btu IT h TX MM MM TX TX SM 8 1 W 27 6 Btu IT h 8 1 W 27 6 Btu IT h MM...

Page 33: ...Name EN 61000 6 2 Generic norm immunity in industrial environments EN 55022 IT equipment radio interference characteristics EN 60950 1 Safety for the installation of IT equipment EN 61131 2 2008 Progr...

Page 34: ...certification indicator appears on the housing However with the exception of Germanischer Lloyd ship certifications are only included in the product information under www hirschmann com IEEE 802 1AB...

Page 35: ...et ap belden com Hirschmann Competence Center The Hirschmann Competence Center is ahead of its competitors Consulting incorporates copmprehensive technical advice from system evaluation through networ...

Page 36: ......

Reviews: