5. Device Concept
UCX series – User's Manual
40
Applied firmware package: v1.2.0b9 | LDC software: v2.5.10b1
5.7.
Basic Network Security
DIFFERENCE:
The basic network security feature is available only from FW package v1.2.0.
These basic network security improvements help to prevent unauthorized access to the UCX series switchers:
▪
▪
Disable Network Services
▪
▪
The following table summarize the ports, protocols, features and the security options.
#new
Purpose/
function
Affected
software Protocol Port number
Port
disable
option
Encryption Authentication
Other
features
HTTP port
(
LW3 over
WS, REST
API)
LDC,
LDU2
TCP
80
FW update,
Welcome
Screen image
upload,
Log files,
User Scripts
Serial
messaging
HTTPS port
(
LW3 over
WSS, REST
API)
LDC,
LDU2
TCP
443
LW3
protocol
LDC
TCP
6107
Serial over
IP
(RS-232)
-
TCP
8001, 8002
mDNS /
Bonjour
(Device
Discovery)
LDC,
LDU2
UDP
224.0.0.251:
5353
Remote IP
LDC,
LDU2
UDP
230.76.87.82:
37421
INFO:
The ports are necessary to pass via a network switch/firewall for a proper working between the
device and the softwares.
ATTENTION!
Be careful when combining the security functions; improper settings may cause malfunction.
5.7.1.
Disable Ethernet Ports
Internal Ethernet connections can be limited by enabling/disabling the Ethernet ports depending on the
actual system configuration (e.g. Ethernet layer of the USB Type-C port can be disabled if necessary).
5.7.2.
HTTP/HTTPS
UCX series switc
h
er provides HTTP/HTTPS server services on its 80 (for HTTP) and 443 (for HTTPS) ports.
It makes possible to use the following services via HTTP/HTTPS:
#new
▪
LW3 over WebSocket (WS, WSS) for LW3 protocol or using LDC for device control
▪
REST API for device control
▪
Serial message sending with REST API
▪
Firmware update
▪
WelcomeScreen image upload
▪
UserScripts upload
▪
Logfiles download from the device
Basic Authentication
To limit user access for HTTP/HTTPS server services, basic authentication can be turned on 80 and 443
ports separately.
ATTENTION!
Authentication feature in UCX series is not equal with the Cleartext login feature in the
Advanced Control Pack in the TPS family extenders.
The picture below illustrates the successful authentication process: