In Bridge mode the Defender will function transparently, with the same IP subnet on each side. There is no routing function, essentially the Defender functions as a switch, but can still inspect and block traffic.
This can for instance be used to inspect traffic between an HMI and a PLC, or between a Remote Access Gateway and a PLC. Functions such as traffic filtering, traffic inspection with Industrial Profiles or Intrusion Detection are possible.
APPLICABLE PRODUCTS
Anybus Defender 4000 Series and up, with NAT, DPI or PRO licenses.
PRE-REQUISITES
2 ethernet ports available to connect together.
With Siemens Managed switches have to be present between Defender and Siemens equipment answering to DCP traffic.
VERSIONS USED IN THIS ARTICLE
- Anybus Defender 2.5.2-2025111723
HOW TO: Enable Bridge mode
Choose two or more Ethernet ports to use as switch, if you don’t already have the ports activated go to:
Interfaces -> Assignments -> Available network ports
Make sure you enable the ports that you want to use to Bridge. Example click the OTP1 name and enable the port. And Save.
Then, Go to Interfaces -> Assignments -> Bridges -> Add
In Member Interfaces hold Ctrl and click the interfaces you want to add to the bridge, you can also add a Description. IN this example LAN and OPT1. You can also Bridge WAN and LAN if this is the use-case.
Go back to Interfaces -> Assignments and Add the bridge at Available network ports and enable it.
You could add an IP address to LAN, OTP1 or BRIDGE to allow access to the Defender, but it is not necessary to make it work like a switch.
Adding Firewall Rules
You will need to add rules under Firewall->Rules on either LAN or OTP1. Rules are applied on traffic that originates on that port. E.g. Traffic from LAN -> OPT1 hits the LAN rules, traffic from OPT1 -> to LAN hits the OPT1 interface rules. You do not need to create rules for return traffic.
Example, you want the IP 192.168.0.12 on LAN to be able to ping 192.168.0.15 on OTP1, here is how it would look.
Special Note: Siemens PROFINET DCP (Discovery and Basic Configuration Protocol)
In a Siemens Profinet network DCP discovery is supported when the PLC is connected via a managed ethernet switch to the Defender in Bridge Mode. E.g. do not connect the devices directly to the Defender's ports. To allow DCP traffic to pass correctly, install a managed switch between the Defender and the PLC. Without the managed switch, PLC discovery via DCP will fail. This is because the device adds VLAN-0 tag on the response traffic that needs to be removed by a L2 switch.