47
645M 4G/LTE CELLULAR ROUTER
MN032003EN March 2017 www.eaton.com
Figure 49 . : Port forwarding example
4.4 Port forwarding
NAT functionality is only useful for traffic flows that are initiated
by the 645M or by a device that is physically connected to the
645M. Port forwarding can be enabled to allow remote devices
connecting through the Internet to initiate traffic flows with a
local device connected to a 645M router.
In the example configuration shown below, a host from the
Internet can create either a TCP or UDP connection with the
local host at 192.168.1.250 on port 7000 by sending a packet
to the cellular IP address of the 645M at port 8010. When
the 645M receives a packet destined for port 8010 it will look
through the Port Forwarding table to see if a matching rule
exists. It finds the rule that instructs it to forward this packet to
port 7000 of IP address 192.168.1.250. The 645M then modifies
the destination IP address and port number before forwarding
the packet onto the local area network.
Port forwarding is useful for field applications that use polling
that is initiated by a polling master. The port forwarding function
allows the polling master to establish a data connection through
the Internet. The incoming polling message is forwarded by the
645M to the appropriate PLC or RTU on the 645M’s local
area network.
4.5 DMZ
Alternately, DMZ can be enabled on the 645M router. When
DMZ is enabled, all traffic destined to the 645M’s cellular IP
address that is received from the Internet is forwarded to the
DMZ host. The IP address of the DMZ host is specified by
the user. Using DMZ can eliminate the need to specify many
individual port forwarding rules. However, by exposing all the
ports on the local device, the local device may become more
susceptible to attacks.
If specific Port Forwarding rules exist in the IP Mapping Table,
they will take precedence over the DMZ host.
4.6 Friendly IP address
Friendly IP addresses can be used with either port forwarding
or DMZ to provide an additional layer of security. When Friendly
IP addresses are used, the 645M will only forward packets
to the LAN if the source IP address of the received packet
matches either the specific IP address or range of IP addresses
specified in the Friendly IP address field.
This feature can be disabled by entering 0.0.0.0 in the friendly
IP address field. In this case, packets from any host on the
Internet can be forwarded to the LAN when either DMZ or Port
Forwarding is enabled.
4 Ip addressing