Structure and functions
4
System dimensions and compatibility list
15
Building Technologies
A6V10854379_a_en
CPS Fire Safety
25.01.2019
5
NK8000 Security
To ensure the system security and prevent physical damages and attacks that may
compromise the system integrity and confidentiality, make sure to install NK823x
units according to the following criteria:
⚫
NK823x units must be updated to latest Kernel and firmware versions.
⚫
NK823x units must be must be installed in locked cabinets (for example, a
control panel housing or the dedicated NE8001 cabinet).
⚫
Cabinets must be installed in locked rooms with constant surveillance and
restricted access to authorized personnel only.
⚫
Most of the communication protocols used between the NK823x units and the
management station, and between the NK823x units and the subsystems, are
open and unprotected protocols (e.g. BACnet, Modbus TCP, IEC 60870-5-104
etc.). Therefore, the networks where NK823x units are connected to must be
protected from unauthorized data access, use, disclosure, disruption,
modification, and destruction. This concerns all networks that are somehow
vulnerable due to external connections (WAN, Internet), open technologies
(wireless networks), or any other risk of fraudulent access.
To achieve the required level of security, the protective measures must include:
–
The use of firewalls on the Intranet to filter external traffic and select the
allowed ports.
NOTE: The list of ports used by the management system can be found in
the
Application & Planning
document (A6V10063710).
–
The use of Virtual Private Networks (VPN) or other equivalent solutions to
establish a secure (encrypted) tunnel between the NK823x LAN and the
management station across public or unprotected networks.
⚫
In the NK8237 unit download, the secure (default) option must be selected. Do
not use the FTP modes. For more information, refer to section Configuring IP
⚫
The built-in NK823x firewall and routing capabilities only provide a basic level
of protection for gateway purposes. For this reason, the use of NK823x as
firewall for protecting subsystems, management stations, and customer
networks is not recommended. In installations with a critical infrastructure and
higher security requirements, the use of up-to-date, professional and properly
configured firewalls is highly recommended.