ABB COM600 series 5.0 Cyber Security Deployment Manualline page 20

Substation management unit
Hide thumbs Also See for COM600 series 5.0:
Table of Contents

Advertisement

20
COM600 series 5.0
Cyber Security Deployment Guideline
To access Windows Firewall:
1. Login to COM600 using a user account that has administrative priveleges.
2. Go to Control Panel.
3. Click Windows Firewall.
4. Click Advanced Settings to open the Windows Firewall settings window.
5. Select
Inbound Rules to further configure rules affecting incoming connection
requests.
Outbound Rules to further configure rules affecting outgoing connection
requests.
The table below shows a brief summary of the inbound rules available by default.
Rule name
CALServer-UDP
CALServer- TCP
DNP-TCP
DNP-UDP
DNP-TCP-TLS
HTTP
HTTPS
IEC 61850
IEC 870-5-104
MODBUS-TCP
SPA-TCP
Rule description
Allows UDP connection on port 514. This rule allows incoming
syslog messages which are further processed by CAL Server
in COM600.
Allows TCP connection on port 1468. This rule allows incoming
syslog messages which are further processed by CAL Server
in COM600.
Allows TCP connection on port 20000. This rule allows
incoming DNP messages which are further processed by a
DNP slave in COM600.
Allows UDP connection on port 20000. This rule allows
incoming DNP messages which are further processed by a
DNP slave in COM600.
Allows TCP connection on port 19999. This rule allows
incoming DNP messages using TLS which are further pro-
cessed by a DNP slave in COM600.
Allows TCP connection on port 80. This rule allows incoming
HTTP traffic for COM600 WebHMI.
Allows TCP connection on port 443. This rule allows incoming
secure HTTP traffic for COM600 WebHMI.
Allows TCP connection on port 102. This rule allows incoming
MMS messages which are further handled by IEC 61850 Proxy
Server in COM600.
Allows TCP connection on port 2404. This rule allows incoming
IEC-104 messages which are further handled by IEC104 Slave
in COM600.
Allows TCP connection on port 502. This rule allows incoming
Modbus messages which are further handled by Modbus Slave
in COM600.
Allows TCP connection on port 7001. This rule allows incoming
SPA messages which are further handled by SPA client pro-
cess in COM600.
1MRS758267

Advertisement

Table of Contents
loading

Table of Contents