Page 1
Released Product Manual 35095 (Revision -, 3/2018) Original Instructions Security Appliance Moxa EDR-810 Router/Firewall/VPN/NAT Configuration and Service Manual...
Page 2
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Read this entire manual and all other publications pertaining to the work to be performed before installing, operating, or servicing this equipment. Practice all plant and safety instructions and precautions. Failure to follow instructions can cause personal injury and/or property damage.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Warnings and Notices Important Definitions This is the safety alert symbol used to alert you to potential personal injury hazards. Obey all safety messages that follow this symbol to avoid possible injury or death.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Electrostatic Discharge Awareness Electronic controls contain static-sensitive parts. Observe the following precautions to prevent damage to these parts: Discharge body static before handling the control (with power to the control turned off, contact a grounded surface and maintain contact Electrostatic while handling the control).
(LAN) and either a security DMZ or a customer WAN. The MOXA EDR-810 is similar to, and often used in combination with, the TofinoXe to create cyber secure MicroNet Plus control systems.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Chapter 3. Installation and Connections The device is DIN-rail mounted (wall mount optional) and supports dual 12/24(0.32 A)/48 Vdc input voltage power supplies. Additional details and mounting dimensions are available in the Industrial Secure...
Moxa EDR-810 Router/Firewall/VPN/NAT Chapter 4. Configuring the Router: The Moxa EDR-810 appliance (P/N 10-004-483) is pre-configured with the Woodward Cyber Secure configuration file 10-004-485 (10-004-485.ini). Custom configurations (*.ini) can be installed as described in the following procedures of this section Table 4-1 Default Configuration Comparisons compares parameters between the various configurations for the device.
Page 12
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT The DHCP server is enabled by the firmware default configuration and disabled by the Woodward standard cyber secure configuration. Before proceeding to establish a connection on a network without a DHCP server, the service computer must be assigned an IP address on the same subnet (e.g.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Status/Overview Screen The green bar in the router administration page contains pertinent information about the router status: LAN IP WAN IP Firmware version System Configuration Load/Save a Configuration Navigate to System->System File Update->Local Import/Export Load a saved configuration: ...
Page 14
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Save a configuration: Select Configuration File Click Export Browse… to the directory/folder you wish to save the file in and click save SIEM Log File Configuration Navigate to System->Warning Notification->System Event Settings...
Page 15
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Navigate to System->Warning Notification->Syslog Server Settings Click Apply after any revisions Navigate to System->Setting Check Click Apply after any revisions Woodward...
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Verify Port configuration Navigate to Quick Settings Profiles -> WAN Routing Quick Setting to view the port configuration. WAN ports will be marked in Red and labeled WAN. Clicking on the ports will set the port to either WAN or LAN.
Page 17
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Setting the LAN IP address Navigate to Interface->LAN to set the LAN IP Address. Verify the following settings: VLAN ID: 1 IP Address: This IP address will be the network gateway and should be used on the MicroNet CPU as the gateway setting (e.g.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Configuring NAT Navigate to NAT->NAT Setting Verify following settings: Enable: Not Checked (default) NAT mode: 1-1 Host IP: IP Address of the MicroNet CPU (e.g. 10.0.101.1) Interface: WAN Interface IP: IP Address of the WAN IP (10.0.10.10) ...
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Configure Firewall Security Policy Setup Navigate to Firewall->Policy Setup Revise settings as necessary and click apply Click Apply after any revisions Denial-of-Service (DoS) Navigate to Firewall->DoS Defense Revise settings as necessary and click apply...
Page 20
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Modbus TCP Policy Navigate to Firewall->Modbus TCP Policy Global Setting: Check Drop Multiple Function Policy Setting: Check Enable, Action = ACCEPT, Slave ID = 0, All other settings = ALL Click Apply after any revisions...
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Configure Network Security Navigate to Security->RADIUS Select RADIUS State = Enable Enter 1 RADIUS Server = 10.0.100.110, RADIUS Port = 1812 Click Apply after any revisions Woodward...
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Chapter 5. Product Support and Service Options Product Support Options If you are experiencing problems with the installation, or unsatisfactory performance of a Woodward product, the following options are available: Consult the troubleshooting guide in the manual.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Replacement/Exchange: Replacement/Exchange is a premium program designed for the user who is in need of immediate service. It allows you to request and receive a like-new replacement unit in minimum time (usually within 24 hours of the request), providing a suitable unit is available at the time of the request, thereby minimizing costly downtime.
Page 24
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT When shipping the item(s), attach a tag with the following information: Return authorization number Name and location where the control is installed Name and phone number of contact person Complete Woodward part number(s) and serial number(s)
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Replacement Parts When ordering replacement parts for controls, include the following information: The part number(s) (XXXX-XXXX) that is on the enclosure nameplate The unit serial number, which is also on the nameplate Engineering Services Woodward offers various Engineering Services for our products.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Technical Assistance If you need to contact technical assistance, you will need to provide the following information. Please write it down here before contacting the Engine OEM, the Packager, a Woodward Business Partner, or...
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Glossary Acronym/Term Definition/Description Local Area Network - The network behind the router (private/protected zone or access-controlled) Network Address Translation - A routing method which modifies network address information of data packets to map one IP address space into another.
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT Revision History New Manual — Woodward...
Page 29
Released Manual 35095- Moxa EDR-810 Router/Firewall/VPN/NAT We appreciate your comments about the content of our publications. Send comments to: icinfo@woodward.com Please reference publication 35095-. ÌB35095è:è-´ » ´ ¹ µ ¸ Î PO Box 1519, Fort Collins CO 80522-1519, USA 1041 Woodward Way, Fort Collins CO 80524, USA...
Need help?
Do you have a question about the EDR-810 and is the answer not in the manual?
Questions and answers