WALL IE, Industrial Ethernet Bridge and Firewall | Version 1 | 15.05.2017
19
5
Packet filter functionality
The packet filters define the of access between the production network (WAN) and the automation
cell (LAN) in both directions. For example, it can be configured that only certain participants from the
production network may exchange data with defined participants
from the automation cell.
The following filter criteria on layers 3 and 4 are available:
•
IPv4 addresses
•
Protocol (TCP/UDP)
•
Ports
The packet filters are available in both the "WAN to LAN" direction and in the direction "LAN to
WAN".
5.1
Creation of rules in the packet filter
In the "Packet Filter" menu, select "WAN to LAN" or "LAN to WAN", depending upon which
communication direction you wish to restrict.
With the "
Default Action
" option you can set how the standard action of the packet filter should
work.
In the "Accept" setting, all frames are generally permitted and only special packets are filtered.
In the "Reject" or "Drop" settings, all frames are generally prohibited and only the frames indicated in
the filter rules are accepted. "Reject" hereby rejects frames with an error message. "Drop" rejects frames
without error messages.
Whitelisting can be realized with "Accept," blacklisting with "Reject" or "Drop."
With the option "
ICMP Traffic
", you can allow the passage of ICMP packets - e.g. a "Ping".