
L-VIS User Manual
302
LOYTEC
Version 6.2
LOYTEC electronics GmbH
NOTE:
A maximum of 64 MB of swap space may be allocated on an external storage media to
extend the available memory of the device and allow larger projects to be loaded. Note that
the first boot after a new swap space was activated will take some time to set up the
memory. Subsequent reboots of the device will not be affected. Also note that removing the
media during run time while a swap space is active will cause the device to malfunction.
15.9 Security Hardening Guide
This guide contains security-relevant information for operating the product on IT networks.
For devices operated solely on a field bus network like FT-10 without any connection to a
TCP/IP network, most of the following steps do not apply.
15.9.1 Device Installation
To run the device with a minimum set of enabled services and maximum security, follow
the steps below during device installation and configuration:
In the project settings, set up a PIN code for access level 15 and either check the
option
Lock pages in setup menu
or
Hide setup menu
.
Download the final project to the device and test it (access via the configuration
software will be disabled later on in the process).
Open the Web UI of the device and change the default admin password.
Browse to the port configuration, open the
Ethernet
tab and disable FTP, Telnet,
SSH, and possibly RNI (LVIS-3E1xx) or BACnet/IP (LVIS-ME2xx) services.
On the installed device, open the command page of the setup menu and execute
the command
Disable HTTP Server
. The device will reboot with the web service
disabled. Note that this will also disable the OPC XML-DA server.
15.9.2 Ports
This Section lists all ports which may be used by the device. The port numbers listed here
are default settings for their respective services. If not stated otherwise, the port numbers
can be changed.
Required Ports:
1628 udp/tcp: This is the data exchange port for CEA-852 (LON over IP). It is
required for global data point connections and possibly for control network
communication if the device is an LVIS-3E1xx and the IP852 interface is
enabled. The port can be changed.
Optional ports not necessary for the primary product function:
21 tcp: This port is opened by the FTP server. The port can be changed and
disabled.
22 tcp: This port is opened by the SSH server. The port can be changed and
disabled.
23 tcp: This port is opened by the Telnet server. The port can be changed and
disabled.
80 tcp: This port is opened by the Web server and the OPC XML-DA server. It
can be disabled if OPC XML-DA is not required. The port can be changed.
1629 udp/tcp: This is the configuration server port of CEA-852. Exactly one
device in the system needs this port open. Other devices register with the