FEC920: USER GUIDE
Page 7
A
September 18
2.7.5 SNTP
The
FEC920
can support SNTP for network time synchronisation.
To mitigate threats:
1.
Physically protect access to subnet(s) in use.
2.
Firewall to block UDP port 123.
2.7.6 ModBus
The
FEC920
supports ModBus, which can be configured to act as Master via TCP and Slave via serial or TCP.
To mitigate threats:
1.
Physically protect access to subnet (or serial cabling) in use.
2.
Firewall to block TCP port 502 (or alternate non-standard port if so configured).
2.7.7 HTTP (Web Server)
To mitigate threats:
1.
Physically protect access to subnet(s) in use.
2.
Firewall to block TCP port 80.
2.7.8 UHH Navigator
To mitigate threats:
1.
Physically protect access to subnet(s) in use.
2.
Firewall to block TCP port 50010.
2.7.9 Ethernet IP
To mitigate threats:
1.
Physically protect access to subnet in use.
2.
Firewall to block TCP port 2222. This port is opened when Ethernet IP option is enabled.
2.7.10 BACnet
To mitigate threats:
1.
Physically protect access to subnet in use.
2.
Firewall to block UDP port 47808. This port is opened when BACnet option is enabled.
2.8 DECOMMISSIONING
When a
FEC920
instrument is at the end of its life and being decommissioned,
Siemens
advises reverting all
parameters to their default settings using the Engineer Password ‘reset’ or via iTools (see Section 6.1.6 and
Section 9 for instructions). This can help to protect against subsequent data and intellectual property theft if the
controller is then acquired by another party.
A5E45696052A Rev-AA