Table of Contents About the IEF-G9010 Series ......................... 6 Introduction ............................6 Main Functions ............................7 Getting Started ............................. 8 Getting Started Task List ........................8 Opening the Management Console ......................9 Changing the Administrator’s Password ....................10 The System Screens ..........................11 Device Information ..........................
Page 5
Terms and Acronyms The following table lists the terms and acronyms used in this document. Term/Acronym Definition Application Layer Gateway Comment Event Format CIDR Classless Inter-Domain Routing Deep Packet Inspection Engineering Workstation Human-Machine Interface Industrial Control System Information Technology Network Address Translation Security Dashboard Console Operational Technology Programmable Logic Controller...
1. About the IEF-G9010 Series Introduction The IEF-G9010 Series next generation firewalls are a highly integrated industrial multiport firewall with NAT and IPS functions. They are designed for Ethernet-based security applications in factory networks and provide an electronic security perimeter to protect critical cyber assets such as pump-and-treat systems in water stations, DCS systems in oil and gas applications, and PLC/SCADA systems in factory automation.
• Flexible Segmentation and Isolation The IEF-G9010 Series is the ideal solution to segment a network into easily manageable security zones. The firewall can isolate connectivity between the different facilities and production zones to increase security against outside attacks and to create highly secure isolated network zones that can contain threats if they occur.
2. Getting Started This chapter describes the IEF-G9010 Series and how to get started with configuring the initial settings. Getting Started Task List This task list provides a high-level overview of all procedures required to get the IEF-G9010-2MGSFP Series up and running as quickly as possible. Each step links to more detailed instructions later in the document.
The default IP address of the IEF-G9010 Series is 192.168.127.254 with subnet 255.255.255.0. Before connecting a PC/Laptop to the IEF-G9010 Series, the PC's IP address should be set to an IP address that is able to access the default IP address. After that, connect the PC and the IEF-G9010 Series using an Ethernet cable.
When you log in for the first time, the IEF-G9010 Series will request you to create a new admin account and change the default password for security reasons. Enter the new username and password and click Confirm. The system will return to the login screen. Use the new admin account and password to log in.
This widget shows the system boot time, device name, model, firmware version, and firmware build date and time. Secured Service Status This widget shows the status of the device’s security services, the current pattern version, and the sync status with SDC. IEF-G9010 Series User Manual...
This widget shows summary information for the WAN interface. LAN Interface Summary This widget shows summary information for the LAN1, LAN2, and DMZ interfaces. Throughput/Connection This widget shows the real-time throughput and connection usage of the device. IEF-G9010 Series User Manual...
The assets, listed on the screen, are automatically detected by IEF-G9010 Series devices. NOTE The term asset in this chapter refers to the devices or hosts that are protected by the IEF-G9010 Series. Enabling Active Query Active Query can detect inactive or dormant assets or passive assets on the network. Active Query is only available in Inline Mode.
The MAC address of the asset. IP Address The IP address of the asset. First Seen The date and time the asset was first seen. Last Seen The date and time the asset was last seen. IEF-G9010 Series User Manual...
The amount of traffic transmitted by this application. The amount of traffic received by this application. NOTE Click Manual Asset Info Refresh to refresh the displayed information. NOTE You can specify the refresh time from the [Refresh Time] drop-down menu. IEF-G9010 Series User Manual...
5. The Network Screens This chapter describes how to configure the physical ports and network interfaces of the IEF-G9010 Series. Port Settings The [Port Settings] tab allows you to enable or disable the ports and configure the port link speed.
The term Network Interface or Interface in this document refers to the logical interface that maps to one or more physical ports. NOTE The default web management console IP address is 198.168.127.254 and is bound to the LAN1 network interface. IEF-G9010 Series User Manual...
IP Address: Enter a valid IP address. b. Subnet Mask: Enter the subnet mask. c. (Optional) Enable VLAN ID: Use the toggle to enable or disable VLAN ID tagging. d. (Optional) VLAN ID: If VLAN ID is enabled, specify a VLAN ID. IEF-G9010 Series User Manual...
DHCP Relay: Configure the interface to act as a relay to a remote DHCP server. Configure the following additional settings: Relay Server Address: Enter the IP address of the remote DHCP server. Click Ok. Configuring the DMZ Network Interface Steps Go to [Network] > [Network Interface]. The Network Interface tab will appear. IEF-G9010 Series User Manual...
Page 20
In the [Network Settings] section, configure the following settings for the interface: a. IP Address: Enter a valid IP address. b. Subnet Mask: Enter the subnet mask. c. (Optional) VLAN ID: If VLAN ID is enabled, specify a VLAN ID. IEF-G9010 Series User Manual...
Configure the following additional settings: Relay Server Address: Enter the IP address of the remote DHCP server. Configuring the WAN Network Interface Steps: Go to [Network] > [Network Interface]. The Network Interface tab will appear. IEF-G9010 Series User Manual...
Page 22
(Optional) DNS Server 1,2: Enter the primary and secondary DNS server. (Optional) Enable VLAN ID: Use the toggle to enable or disable VLAN ID tagging. (Optional) VLAN ID: If VLAN ID is enabled, specify a VLAN ID. IEF-G9010 Series User Manual...
Refer to the following sections for more information. Gateway Mode When in Gateway Mode, the IEF-G9010 Series acts as a gateway with NAT functionality connecting multiple different network segments while actively analyzing, filtering, and taking actions on all traffic that passes through it.
Bridge Mode When in Bridge Mode, the IEF-G9010 Series sits in the direct communication path between the source and the destination, actively analyzing, filtering, and taking actions on all traffic that passes through it. Selecting the Operation Mode The Operation Mode screen can be accessed by going to [Network] > [Operation Mode].
Page 25
When switching from Gateway to Bridge Mode, the Port Mapping, Network Interface, NAT Rules, ALG, and Static Route functions will be unavailable and cannot be configured. NOTE Policy enforcement rule configurations are not compatible between Gateway and Bridge Mode. Therefore, policy enforcement rules must be reconfigured after switching operation modes. IEF-G9010 Series User Manual...
Page 26
In Bridge Mode, the LAN1 network settings and LAN1 DHCP Service for Gateway Mode are view-only. NOTE Policy enforcement rule configurations are not compatible between Gateway and Bridge Mode. Therefore, policy enforcement rules must be reconfigured after switching operation modes. IEF-G9010 Series User Manual...
Go to [NAT] > [NAT Rule]. The NAT Rule tab will appear. Do one of the following: a. Click Add to create a new rule. b. Click on the name of an existing NAT rule to edit it. IEF-G9010 Series User Manual...
IP address from your local network to outgoing traffic. The following table shows an example: Original Destination IP Mapped Destination IP 172.1.1.5 192.168.100.5 172.1.1.20 192.168.100.20 172.1.1.50 192.168.100.50 172.1.1.69 192.168.100.69 Steps: Go to [NAT] > [NAT Rule]. The NAT Rule tab will appear. IEF-G9010 Series User Manual...
Go to [NAT] > [NAT Rule]. The NAT Rule tab will appear. Do one of the following: a. Click Add to create a new rule. b. Click on the name of an existing NAT rule to edit it. IEF-G9010 Series User Manual...
Without an ALG, client applications like FTP would be unable to transfer files when the FTP client is located within a NAT network. Use the [ALG Settings] tab to configure the following settings: Enable or disable the FTP, SIP, and H.323 ALG • IEF-G9010 Series User Manual...
Configuring ALG Settings Steps: Go to [NAT] > [ALG]. The ALG Settings tab will appear. Use the toggles to enable or disable the FTP, SIP, and H.323 ALG. Click Save. IEF-G9010 Series User Manual...
The Static Route tab will appear. Do one of the following: a. Click Add to create a new static route. b. Click on the name of an existing static route to edit it. Configure the following settings: IEF-G9010 Series User Manual...
Page 33
Metric: Enter a metric for the route. This determines which static route to use based on the specified metric. A lower number represents a higher priority. Click Ok. On the Routes overview page, click Save to save your settings. IEF-G9010 Series User Manual...
Go to [Object Profile] > [IP Object Profile]. Do one of the following: a. Click Add to create a new profile. b. Click on the name of an existing profile to edit it. Configure the following settings: IEF-G9010 Series User Manual...
No:x: In the [Service Object List] section, specify the protocol type and port range (TCP, UDP), type and code (ICMP), or protocol number (Custom). Click the button to add another entry. You can add up to 8 entries. Click OK. IEF-G9010 Series User Manual...
Modbus CIP S7COMM S7COMM_PLUS PROFINET SLMP FINS MELSOFT SECS/GEM TOYOPUC IEC61850-MMS • General protocols, including: HTTP FTP SMB RDP MQTT IEF-G9010 Series User Manual...
Page 37
Protocol Filter Profile Name: Enter a name for the profile. b. (Optional) Description: Enter a description for the profile. In the [ICS Protocol] section, select the protocols you want to include in the protocol filter profile. IEF-G9010 Series User Manual...
Page 38
Advanced Settings for TOYOPUC Enable the Drop Malformed function. Refer to Enabling the Drop Malformed Option for an ICS Protocol. In the [General Protocol] section, select the protocol(s) you want to include in the protocol filter profile. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for the Modbus Protocol The device features more detailed configurations for the Modbus ICS protocol. Through the [Advanced Settings] pane, you can further specify the code/function, unit ID, and address/addresses range against which the function will operate. IEF-G9010 Series User Manual...
Page 40
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 41
Enter the address or address range against which the function will operate. Click Add. Repeat the above steps to add more protocol definition entries. vii. Click OK. In the [General Protocol] section, select the protocol(s) you want to include in the protocol filter profile. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for the CIP Protocol The device features more detailed configurations for the CIP ICS protocol. Through the [Advanced Settings] pane, you can further specify the Object Class ID and Service Code against which the function will operate. IEF-G9010 Series User Manual...
Page 43
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 44
[Custom Service Code] field. Click Add. Repeat the above steps to add more protocol definition entries. vii. Click OK. In the [General Protocol] pane, select the protocols you want to include in the protocol filter. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for S7Comm The device features more detailed configurations for the S7Comm ICS protocol. Through the [Advanced Settings] pane, you can further specify the function code, function group code, and sub-function code against which the function will operate. IEF-G9010 Series User Manual...
Page 46
Go to [Object Profile] > [Protocol Filter Profile]. Do one of the following: a. Click Add to add a protocol filter profile. b. Click on the name of an existing profile to edit it. Configure the following settings: IEF-G9010 Series User Manual...
Page 47
EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. b. Select the [S7Comm] protocol to configure advanced settings for this protocol: Click [Settings] besides [S7Comm] and select [Advanced Matching Criteria]. IEF-G9010 Series User Manual...
Page 48
[Custom Sub-function Code] field. vii. Click Add. Repeat the above steps to add more protocol definition entries. viii. Click OK. In the [General Protocol] pane, select the protocols you want to include in the protocol filter. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for S7Comm Plus The device features more detailed configurations for the S7Comm Plus ICS protocol. Through the [Advanced Settings] pane, you can further specify the function code against which the function will operate. IEF-G9010 Series User Manual...
Page 50
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 51
From the [Function List] drop-down menu, select a function for this protocol. Click Add. Repeat the above steps to add more protocol definition entries. iii. Click OK. In the [General Protocol] pane, select the protocols you want to include in the protocol filter. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for SLMP The device features more detailed configurations for the SLMP ICS protocol. Through the [Advanced Settings] pane, you can further specify the command code against which the function will operate. IEF-G9010 Series User Manual...
Page 53
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 54
From the [Command Code List] drop-down menu, select a function for this protocol. iii. Click Add. Repeat the above steps to add more protocol definition entries. Click OK. In the [General Protocol] pane, select the protocols you want to include in the protocol filter. Click OK. IEF-G9010 Series User Manual...
Advanced Settings for MELSOFT The device features more detailed configurations for the MELSOFT ICS protocol. Through the [Advanced Settings] pane, you can further specify the command code against which the function will operate. IEF-G9010 Series User Manual...
Page 56
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 57
From the [Command Code List] drop-down menu, select a function for this protocol. Click Add. Repeat the above steps to add more protocol definition entries. iii. Click OK. In the [General Protocol] pane, select the protocols you want to include in the protocol filter. Click OK. IEF-G9010 Series User Manual...
The device features more detailed configurations for the TOYOPUC ICS protocol. Through the [Advanced Settings] pane, you can further specify the command code, preset sub-command code, and custom sub- command code against which the function will operate. IEF-G9010 Series User Manual...
Page 59
Admin Config: Firmware update commands sent from EWS to PLC, Project update (i.e., PLC code download) commands sent from EWS to PLC, and administration configuration relevant commands from EWS to PLC. Others: Private commands, un-documented commands, or particular protocols provided by an ICS vendor. IEF-G9010 Series User Manual...
Page 60
If you want to specify a custom sub-command code, select [Custom Sub-cmd Code] and input a service code in the [Custom Sub-cmd Code] field. Click Add. Repeat the above steps to add more protocol definition entries. Click OK. IEF-G9010 Series User Manual...
ICS Threats Others The IPS protocol risk level: • Information Medium High Critical The default action for IPS patterns: • All Actions Accept and Log Deny and Log IEF-G9010 Series User Manual...
Page 62
The preset action when responding to intrusion Keyword The keyword(s) used for searching the pattern rule Steps: Go to [Object Profile] > [IPS Profile]. Click Add to add an IPS profile. The [Create IPS Profile] screen will appear. IEF-G9010 Series User Manual...
Page 63
Accept and Log: When an intrusion is detected, the intrusion will be accepted and logged for monitoring. Deny and Log: When an intrusion is detected, the intrusion will be rejected and logged for monitoring. When you are done configuring the pattern rule, click Save. IEF-G9010 Series User Manual...
If the rule action is set to Prevention and Log, the security node blocks subsequent anomalous packets until the end of the detection period. After the detection period, the security node will continue to allow anomalous packets to go through until the threshold is reached again. IEF-G9010 Series User Manual...
Service object profiles: For more information, see Configuring Service Object Profiles. • Protocol filter profiles: For more information, see Configuring Protocol Filter Profiles. • Steps: Go to [Security] > [Policy Enforcement]. The [Policy Enforcement Rule List] screen will appear. IEF-G9010 Series User Manual...
Page 66
LAN2 interface. If you select [LAN to LAN], then the policy enforcement rule will apply to traffic from the LAN1 interface to the LAN2 interface or from the LAN2 interface to the LAN1 interface. IEF-G9010 Series User Manual...
Before creating policy enforcement rules, make sure the required objects and profiles are created. IP object profiles: For more information, see • Configuring IP Object Profiles. Service object profiles: For more information, see • Configuring Service Object Profiles. IEF-G9010 Series User Manual...
Page 68
Select the source and destination IP or IP object profile from the drop-down menu. Single IP iii. IP Range IP Subnet IP Object NOTE If you select Object, you will need to select the IP object from a previously created IP object profile. IEF-G9010 Series User Manual...
Page 69
Accept: Allow network traffic that matches this rule. Deny: Block network traffic that matches this rule. iii. Advanced Filter: The node will act based on the selected protocol filter and protocol filter action. Click Save to save the configuration. IEF-G9010 Series User Manual...
NOTE When more than one policy enforcement rule is matched, the IEF-G9010 Series takes the action of the rule with the highest priority and ignores the rest of the rules. The rules are listed in the table by priority with the highest priority rule listed in the top row of the table.
This chapter describes how to view the pattern information and how to import a DPI (Deep Packet Inspection) pattern to the IEF-G9010 Series device. The DPI pattern contains signatures to enable the intrusion prevention feature on the device. The intrusion prevention feature detects and prevents behaviors related to network intrusion attempts or targeted attacks at the network level.
IP Protocol Name The IP protocol name of the connection. Action The action performed based on the policy settings. The number of detected network packets within the detection period after Count the detection threshold was reached. IEF-G9010 Series User Manual...
The ICMP type if the selected protocol is ICMP. VLAN ID The VLAN ID of the connection. IP Protocol Name The IP protocol name of the connection. Action The action performed based on the policy settings. IEF-G9010 Series User Manual...
The time the log entry was created. Event Type The log event description. Interface The network interface which received the asset information. Asset MAC Address The source MAC address of the asset. Asset IP Address The source IP address of the asset. IEF-G9010 Series User Manual...
Steps: Go to [Logs] > [System Logs]. The following table describes the log’s fields. Field Description Time The time the log entry was created. Severity The severity level of the log. Message The log event description. IEF-G9010 Series User Manual...
The Administration Screens This chapter describes the administrative settings for the IEF-G9010 Series device. Account Management NOTE Log in to the management console using the default administrator account (“admin”) to access the Accounts screens. The system uses role-based administration to grant and control access to the management console. Use this feature to assign specific management console privileges to user accounts and present them with only the tools and permissions necessary to perform specific tasks.
Click Change Password. The [Change Password] screen will appear. Configure the following settings: a. Old password: Enter your current password. b. New password: Enter your new password. c. Confirm password: Enter your new password again. Click Save. IEF-G9010 Series User Manual...
Configuring Password Policy Settings The IEF-G9010 Series provides the following password policy settings to enhance web console access security: Password complexity • Password complexity settings are used to enforce stronger passwords. For example, you can require users to create passwords that must be at least eight characters long and must contain a combination of both uppercase and lowercase letters, numbers, and symbols.
In the [Access Control List] pane, configure the following setting: a. Use the toggle to enable or disable access control for the specified management clients. b. Provide the IP address(es) that are allowed to manage the device. IEF-G9010 Series User Manual...
Telnet protocols are used for connecting to the command line interface (CLI). The Sync Setting Screen The IEF-G9010 Series can be managed by Moxa’s SDC (Security Dashboard Console). Use this screen to register the IEF-G9010 Series to an SDC instance.
The Syslog Screen The IEF-G9010 Series maintains Syslog events that provide a summary of security and system events in. Common Event Format (CEF). Configure the Syslog settings to enable the device to send system logs to a Syslog server. Configuring Syslog Settings Steps: Go to [Administration] >...
Click the calendar to select the date and time. Set the hour, minute, and second. iii. Click Apply. From the [Time Zone] drop-down list, select the time zone. Click Save. NOTE SDC synchronizes the system time with its managed instances. IEF-G9010 Series User Manual...
We recommend the following actions: Always back up the current configuration before importing a configuration file. • Import or export configurations while the IEF-G9010 Series is idle, as this will affect the device’s • performance. Backing Up a Configuration Steps: Go to [Administration] >...
[Partition Name], [Partition Status], [Firmware Version], and [Firmware Build Date]. NOTE The IEF-G9010 Series can have up to two firmware versions installed at any time. Each firmware is installed on its own separate partition. At any given point in time, one partition will be designated as [Running], which indicates it is the currently active firmware.
Click Ok to reboot the device and make the [Standby] partition the [Running] partition. The Reboot System Screen Use the [Reboot System] screen to reboot the system. Rebooting the System Steps: Go to [Administration] > [Reboot System]. In the [Reboot System] window, click Reboot to reboot the system. IEF-G9010 Series User Manual...
NOTE If multiple pattern files exist in the folder, the newest will be selected in subsequent steps. Plug the USB disk device into the IEF-G9010 Series device’s USB port. IEF-G9010 Series User Manual...
Page 89
Data Transfer Indication IPS/IDS LED Blinking amber/green (Every 0.5 seconds) If any error occurs during an action, the LED will indicate this state. Action COLOR/STATE Error Indication (While an action was in Fault LED Solid red progress) IEF-G9010 Series User Manual...
Page 90
10. If the USB disk device is unplugged, the LEDs will return to their state prior to the USB device being plugged in, and a system log will be generated. IEF-G9010 Series User Manual...
Need help?
Do you have a question about the IEF-G9010 Series and is the answer not in the manual?
Questions and answers