11
A B B A B I L I T Y
T M
ED G E I N D US T R I A L G AT E WAY
70
11.3.2 Device firewall
Network security in ABB Ability
TM
Edge Industrial Gateway is accomplished by defining a set of rules used
by device. Internal firewall is a software application which allows or blocks any software program
executing within ABB Ability
TM
Edge Industrial Gateway from establishing a connection on the network.
The network connection can be an outgoing connection initiated from ABB Ability
TM
Edge Industrial
Gateway or an incoming connection to ABB Ability
TM
Edge Industrial Gateway. The outgoing connection
rules are defined by creating outbound rules and the incoming connection rules are defined by creating
inbound rules.
The rules specify whether to allow or block a connection based on some defined criteria.
The table below shows a brief summary of the rules available:
The port 5003 can be firewalled using Provision Tool. User can add Local view (web server) to be available in eth0
and limit incoming connections by source IP address (Configuration → Gateway Connectivity → To Web Server)
—
11.4 Time service
Time used in ABB Ability
TM
Edge Industrial Gateway can be synchronized using NTP client to an NTP
Server like Google NTP Server.
User can configure maximum three NTP Servers using Provisiong Tool. By default, one of the NTP time
servers is shipped along with the ABB Ability
TM
Edge Industrial Gateway (with time.google.com).
User can configured all the three NTP Servers using CCT tool.
Time Synchronization is performed at every Powerup of ABB Ability
TM
Edge Industrial Gateway & there
after everyone hour.
Rule name
Rule description
HTTPS
Allows TCP connection on port 5001 & 5003. This rule allows incoming secure HTTPS traffic
for ABB Ability
TM
Edge Industrial Gateway.
MODBUS-TCP
Allows TCP connection on port 502. This rule allows incoming
Modbus messages which are further handled by Modbus Slave in ABB Ability
TM
Edge Industrial Gateway.
NTP
Allows UPD connection on port 123. This rule allows incoming
NTP messages which are further handle by NTP client in ABB Ability
TM
Edge Industrial Gateway.
Reject ALL incoming SSH
Rejects all TCP connection on port 22. This rule rejects all incoming TCP traffic for SSH for
ABB Ability
TM
Edge Industrial Gateway.
Allow outbound DNS
Allows UDP connection on port 53. This rule allows incoming DNS requests for name resolution.
—
Figure 27
—
Note: It is recommended
to set the NTP
synchronization to local
network stratum 1 clock
Содержание Ability
Страница 1: ... USER MANUAL ABB AbilityTM Edge Industrial Gateway ...
Страница 2: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 2 ...
Страница 4: ......
Страница 6: ......
Страница 12: ......
Страница 16: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 16 ...
Страница 21: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 21 3 ...
Страница 22: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 22 4 ...
Страница 28: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 28 5 ...
Страница 34: ...6 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 34 ...
Страница 44: ...7 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 44 ...
Страница 48: ...8 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 48 ...
Страница 54: ...9 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 54 ...
Страница 58: ...1 0 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 58 ...
Страница 61: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 61 1 0 ...
Страница 62: ...1 1 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 62 ...
Страница 76: ...1 2 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 76 ...
Страница 80: ...1 3 ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 80 ...
Страница 84: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 84 1 4 ...
Страница 88: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 88 1 5 ...
Страница 94: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 94 1 6 ...
Страница 99: ...ABB ABILIT Y TM EDGE INDUSTRIAL GATEWAY 99 1 6 ...