59 (148)
•
Stopped
The Bluetooth module driver has been stopped.
Firewall
Your Anybus Edge device features a Firewall which improves the system's security by analysing
network traffic and blocking unallowed traffic.
The Anybus Edge device Firewall has a blocking policy. This means that while outgoing
connections are generally allowed, incoming connections will be generally blocked except if
there is a rule allowing the specific connection.
At the top of the settings form you can enable the Firewall and configure the maximum number
of rules. This determines the number of connections (incoming and outgoing) that can be
handled simultaneously.
When enabling the Firewall, always make sure that you defined some static rules that
allow you to access the web server etc. in order to be able to disable the Firewall if
needed. If you enable the Firewall without any appropriate rules, you will be unable to
access your device in any way. You will need to reset the device to factory settings in this
case.
Dynamic Rules
Dynamic rules are created by the Firewall for outgoing connections. You have to configure how
many minutes dynamic rules will be valid (time to live).
Static Rules
You can add up to 50 static Firewall rules. Static rules allow access to a specific service on
your Anybus Edge device from the network. Each rule consists of the following parameters:
Network interface
Determines the network interface from which you want to accept connections. You may e.
g. want to allow access to the device's web server only from the local area network. So
you would choose the Ethernet interface here. If you do not care about the network
interface, select
Any
.
Service
This selection provides a set of predefined services which you may want to allow to be
connected to. If the desired service is not on the list, choose
Other
in order to manually
specify the service's protocol and port(s) (see below).
Protocol
This parameter will show up only if you choose
Other
for the
Service
field. It determines
which base protocol (TCP or UDP) the service you want to allow uses.
Minimum/maximum port
These parameters will show up only if you choose
Other
for the
Service
field. They
determine the port(s) the service you want to allow runs on. You can specify a single port
(set minimum and maximum to the same value) or a port range (e.g. 10000 to 10005). Or
you can set both parameters to 0, which means that you want to allow connections on
any port (wildcard).
Minimum/maximum
source IP address
Determines the IP addresses you want to allow to connect to the specified service. You
can specify a single IP address (set minimum and maximum to the same value) or an IP
address range (e.g. 192.168.0.1 to 192.168.0.10). Or you can set both parameters to
0.0.0.0, which means that you want to allow connections from any IP address (wildcard).
Event Log Messages
The Firewall is implemented inside the NAT service module. Event Log messages are documented
in the
section.
Network Address Translation
The HMS Hub firmware is able to perform network and port address translation (aka NAT/PAT)
in order to route traffic between a local (internal) and a global (external) network. This feature
can for example be used to allow another device connected to the Anybus Edge device's
Anybus Edge Gateway Reference Guide
SCM-1202-154 1.0 en-US