4.DeviceConcept
HDMI-TPS-RX110AY series – User's Manual
28
Appliedfirmwarepackage:v1.5.0b3 | LDCsoftware:v2.5.9b2
4.9.
Basic IT Security
DIFFERENCE:
ThisfeatureisavailableonlyinHDMI-TPS-RX110AY-PlusmodelfromFWpackagev1.5.0b3.
These entry-level network security improvements help to prevent unauthorized access to the Lightware
device:
#new
▪
Cleartext login
▪
IP Port Block
▪
MAC Filtering
The
Cleartext Login
tool allows setting a password for login, thus, the device will not accept any command
coming from an interface (RS-232, Ethernet, etc…), only the device type and the serial number can be queried
withoutlogin.YoucansetallaffectedTCP/IPportsindividuallytoenableordisable.
The
IP Port Block
feature is an additional protection for the Cleartext login. There are TCP/IP ports in
Lightwaredeviceswhicharenotprotectedbythelogin,soyoucandisablethemifnecessary.Example:due
totheworkingmethodoftheLW2communication,theCleartextlogindoesnotprovideprotectionwhenLW2
command is sent to the device, that is why the TCP port no.10001 shall be blocked manually.
Another level of security is the
MAC Filtering
tool. You can create an ’allowlist’ of network devices based on
theMACaddresswhichareallowed:
▪
Controlling the device (Send option), or
▪
Queryingparameters(Receiveoption)to/fromtheLightwaredevice.
Below table shows the protection levels of these features.
ATTENTION!
Be careful when combining these functions; improper settings may cause malfunction.
MostofthesefeaturesareavailableinLDC,seethe
section.
IP Port
Function
MAC Filter
Cleartext Login
IP Port Block
80
HTTPPost&Get
-
81
LW3control(miniweb)
-
6107
LW3protocol
-
800x
Command injection (RS-232)
-
900x
Command injection (IR)
-
10001
LW2protocol
-