Cisco IE-4000 Software Configuration Manual page 991

Industrial ethernet switch
Hide thumbs Also See for IE-4000:
Table of Contents

Advertisement

Configuring MODBUS TCP
Understanding MODBUS TCP, page 987
Configuring the Switch as the MODBUS TCP Server, page 988
Displaying MODBUS TCP Information, page 989
Understanding MODBUS TCP
Use Modicon Communication Bus (MODBUS) TCP over an Ethernet network when connecting the switch to devices such
as intelligent electronic devices (IEDs), distributed controllers, substation routers, Cisco IP Phones, Cisco Wireless
Access Points, and other network devices such as redundant substation switches.
MODBUS is a serial communications protocol for client-server communication between a switch (server) and a device
in the network running MODBUS client software (client). You can use MODBUS to connect a computer to a remote
terminal unit (RTU) in supervisory control and data acquisition (SCADA) systems.
The client can be an IED or a human machine interface (HMI) application that remotely configure and manage devices
running MODBUS TCP. The switch functions as the server.
The switch encapsulates a request or response message in a MODBUS TCP application data unit (ADU). A client sends
a message to a TCP port on the switch. The default port number is 502.
MODBUS and Security, page 987
Multiple Request Messages, page 988
MODBUS and Security
If a firewall or other security services are enabled, the switch TCP port might be blocked, and the switch and the client
cannot communicate.
If a firewall and other security services are disabled, a denial-of-service attack might occur on the switch.
To prevent a denial-of-service attack and to allow a specific client to send messages to the switch (server), you can
use this standard access control list (ACL) that permits traffic only from the source IP address 10.1.1.n:
interface Ethernet0/0
ip address 10.1.1.1 255.255.255.0
ip access-group 1 in
!
access-list 1 permit 10.1.1.0 0.0.0.255
To configure quality of service (QoS) to set the rate-limit for MODBUS TCP traffic:
interface FastEthernet0/1
ip address 10.1.1.1 255.255.255.0
ip access-group 1 in
rate-limit input access-group 101 8000 8000 8000 conform-action transmit exceed-action drop
Cisco Systems, Inc.
www.cisco.com
987

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ie-5000Ie-4010

Table of Contents