FL MGUARD 1000 product family
22 / 52
PHOENIX CONTACT
108413_en_06
2.5.5
Firewall and device access
At the firewall, a distinction is made between incoming and
routed
data traffic:
–
Incoming data traffic
is the packets that are sent to the device (device access).
–
Routed data traffic
is the packets that are
routed
through the device, for example that
come in via net zone 2 (XF2) and go out via net zone 1 (XF1).
Firewall (for incoming data traffic) = device access
Firewall (for routed data traffic) = routing
Table 2
-
10
Default setting
: firewall for incoming data traffic
Service,
protocol
Incoming via
Port
Description
HTTPS
Net zone 2 (XF2)
TCP 443
Corresponding requests to the
web server of the device are per
-
mitted, i.e.:
– login and configuration via
web-based management
– login and configuration via
RESTful server (
Config API
)
SNMP
Net zone 2 (XF2)
UDP 161
Corresponding requests to the
SNMP server of the device are
permitted.
DHCP
Net zone 2 (XF2)
UDP 67
Corresponding requests to the
DHCP server of the device are
permitted.
DNS
Net zone 2 (XF2)
TCP 53
UDP 53
Corresponding requests to the
DNS server of the device are per
-
mitted.
NTP
Net zone 2 (XF2)
UDP 123
Corresponding requests to the
NTP server of the device are per
-
mitted.
ICMP
(IPv4)
Net zone 2 (XF2)
Ping requests (
ICMP requests
) to
the configured or assigned (per
DHCP) IPv4 addresses of the net
zones (in
router mode
) or the man
-
agement IP address (in
stealth
mode
) are permitted.
Access to all other network services and network protocols of the device are dropped by
the firewall.
Default setting
:
All packets that are sent from net zone 2 (XF2), i.e. from subnetwork 192.168.1.0/24, to
any target address are forwarded by the device (
routed
).
(Rule: 192.168.1.0/24 --> 0.0.0.0/0 = ACCEPT).
All other packets are rejected.
Summary of Contents for 1153079
Page 1: ...User manual UM EN FL MGUARD 1000 FL MGUARD 1000 Installation and startup...
Page 10: ...FL MGUARD 1000 product family 10 52 PHOENIX CONTACT 108413_en_06...
Page 28: ...FL MGUARD 1000 product family 28 52 PHOENIX CONTACT 108413_en_06...
Page 50: ...FL MGUARD 1000 product family 50 52 PHOENIX CONTACT 108413_en_06...
Page 53: ......