How to restrict access to a subdevice using firewall policies

When you use a
FactoryTalk® Remote Access
Manager
runtime or device with several controllers from different vendors as subdevices and you want each vendor to access only their controller, you can limit their access to specific subdevices by adjusting the firewall settings.
  1. Access
    FactoryTalk® Remote Access
    Manager
    .
  2. Access
    Explorer
    Domain view
    .
  3. Create a new firewall policy:
    1. Right-click the domain tree and select
      Create firewall policy
      .
    2. Name the firewall policy and select
      Save
      .
  4. In the domain tree, navigate to the
    Policies
    and select the new policy you created.
  5. Select the plus button in the
    Firewall Rules
    section to define the firewall rules.
  6. In the dialog window set the firewall rules:
    1. In the
      MAC Address
      drop-down menu, select
      Any
      .
    2. In the
      Ethernet Type
      drop-down menu, select
      IPv4
      .
    3. In the
      IP Address
      drop-down menu, select
      Single
      and below provide the IP address of the device.
    4. In the
      IP Protocol
      drop-down menu, select
      Any
      .
    5. Select
      Save
      .
  7. Select the device you want to set the firewall policies for.
  8. Navigate to
    Firewall
    pane and select the plus button.
  9. In the dialog window appears set the firewall policy:
    1. In the
      Select firewall policy
      drop-down menu, select the firewall policy you created.
    2. Select the user you are setting the firewall policy for.
    3. Select
      Allow
      .
  10. In the
    Firewall
    pane, clear the
    Inherit firewall policies
    checkbox and in the
    Default action
    drop-down menu, select
    Deny
    .
    The selected user can only access the subdevice defined in the rule.
  11. Repeat steps 3 to 10 for all the users and devices you want to allow or restrict access to.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal