The Anybus Defender Compact comes with automatic learning mode functionality that can map the traffic going through (in bridge mode) and create rules . These are then availible for review by an admin before you can activate the protection of your device or environment.
APPLICABLE PRODUCTS
- Anybus Defender Compact 1004 — ABD1004-NATFW
- Anybus Defender Compact Manager
VERSIONS USED IN THIS ARTICLE
- Anybus Defender Compact Firmware 1.4.1
- Anybus Defender Compact Manager 1.2.8
When Learning Mode is active, all traffic is allowed to pass through the Defender Compact. The device monitors the communication (for example from FlexEdge to Modbus devices) and records the traffic so firewall rules will be generated "automatically". The type of devices passing their data is important during testing because each device generates unique network traffic depending on the service it uses, including its IP address, protocol, and port.
NOTE: Learning mode with the Pin only works on devices that are in factory default state. After connecting with GUI and reviewing rules, the learning mode will be disabled and the pin will not be effective anymore and can be safely removed.
Setup
The Anybus Defender Compact’s physical packaging includes a two-pin connector that can be used when preparing the device for learning mode. The User manual on configuring connectors can be found here Anybus_Defender_Compact-Manual_env2 - The User manual explains which terminals to connect at page 19 to 21.
This article explains configuring the Anybus Defender Compact in learning mode through its firmware (Anybus Defender Compact).
Start by Connecting the Defender Compact
NOTE: Make sure your Defender Compact is in Factory Default mode.
To install the Defender compact for learning in a live network, take the following steps:
- Connect the provided pin between + and I/O 1
- Install Power to the unit
- Install the Defender between machine lines, or between devices and network that need to be protected from each other. One side on WAN port and other side on one of the LAN ports
Traffic shall now be allowed without restrictions through the device. To view the recorded traffic and activate filtering you need to connect with Anybus Compact Manager.
Create a new project
Install Anybus Compact Manager and create a new project.
And activate the device by going online
Connect to the device - via USB
When device is connected, navigate to “Packet filter” and Download Network data. When packet filter is inactive, the device captures incoming traffic, and it is then displayed what devices are connected to the compact. The Anybus Defender should learn what traffic is passing it, including modbus traffic passing from Flex Edge to Modbus as in our example setup. Select to "Download Networkdata".
The process will load until finished. Meanwhile Anybus Defender is capturing traffic passing through and from source to Compact - NAT/FW.
Once finished loading, certain devices or single IP Addresses can be found and activated if selected. First, the ip address of the FlexEdge is configured in packet filter. The ip address of the FlexEdge becomes present in Firewall Rules.
This will automatically create rules under “Packet filter” -> “Rules” that applies after traffic learnt in the Compact - NAT/FW. Compact - NAT/FW now allows traffic passing from LAN to WAN. The images below explains with arrows and signs what IP addresses are allowed to pass.
Your configuration is now complete, after uploading and activating the configuration the firewall will now deny all traffic except what is explicitly allowed by the rules.