49
Rev Version 1.4.1
Rev Version 1.4.1
If the MAC Address filter list is a whitelist, the message is accepted. If the MAC Address filter list is a blacklist,
the message is dropped.
•
The MAC Address filter checks the source address of the message only.
•
The IP Address filter checks both the source address and the destination address of the message. If either
address match, then the rule is activated.
•
ARP filtering applies only to ARP request packets (typically these are broadcast packets) that are sourced
from the Ethernet interface and destined for the wireless interface. ARP requests from devices on the wireless
network will always be passed to the Ethernet interface. ARP response packets will always be passed.
Figure 54 Filtering
When configuring a whitelist, it is important to add the addresses of all devices connected to the WI-MOD-xxx-E-
5W wired Ethernet port, that communicate over the wireless link. It is particularly important to add the address of
the configuration PC to the whitelist. Failure to add this address will prevent the configuration PC from making any
further changes to configuration. Design of the filter may be simplified by monitoring network traffic and forming a
profile of traffic on the wired network. Network analysis software, such as the freely available
“Wireshark” program,
will list broadcast traffic sent on the network.
Filter Example
In the example shown in Figure 55, device B needs to communicate with device E via modems C and D. The filtering
requires that modem C has device B in its whitelist. IP filtering checks both source and destination IPs, therefore,
any traffic from device E will be passed back into the LAN via modem C because the destination matches the IP for
device B. This works because device B is a Modbus master and it initiates all communications. If the
communications were being initiated from each end (a non-polling system) you would need to configure a filter list
for each modem to allow the communications to be passed from each end.
With this filter configuration device A will not be able to access device E because device A is not present in the
whitelist in modem C.
Figure 55 Filter Example