Security considerations when using the FactoryTalk AssetCentre software
When using one or more of the following Rockwell Automation software products, you need to configure endpoint firewall rules, and allow the Rockwell Automation services and the dependent services to run on the computer.
- FactoryTalk AssetCentre Server
- FactoryTalk AssetCentre Client
- FactoryTalk AssetCentre Agent
- FactoryTalk Services Platform
- RSLinx Classic
- RSLinx Enterprise (renamed toFactoryTalk Linxstarting from version 6.00)
Firewall rules
To run the FactoryTalk AssetCentre software on a Microsoft Windows operating system, you must configure the endpoint firewall rules to allow the following to communicate on the network:
- Services
- Ports
- Internet Control Message Protocol
Service dependencies
To run the FactoryTalk AssetCentre software on a Microsoft Windows operating system, you must allow the Rockwell Automation services and the dependent services to run on the computer.
Secure communication with TLS and SSL protocols
Windows implements SSL and TLS through S-channel Security Support Provider (SSP). The
S-channel SSP implementation of the TLS and SSL protocols uses algorithms from a cipher
suite to create keys and encryption information. Starting from FactoryTalk AssetCentre
version 9.00, the operating system's capability is used to automatically filter out the
insecure ciphers.
- For all cipher suites listed for different operating systems, refer to Cipher Suites in TLS/SSL (S-channel SSP).
- If you have a preference on the cipher suites and need to customize the priorities in group policy, refer to Prioritizing S-channel Cipher Suites.
- To enable or disable specific ciphers in the registry, refer to How to restrict the use of certain cryptographic algorithms and protocols in Schannel.dll.
For information on the security considerations when using other Rockwell Automation products, including:
- Ports, services, and firewall rules necessary for FactoryTalk AssetCentre components, see Configuring Firewalls for FactoryTalk AssetCentre (publication FTAC-RM001). Additional information for Rockwell Automation software, firewall rules, and service dependencies, see
- TCP/UDP ports used by Rockwell Automation products, seeKnowledgebase Document ID: BF7490 - TCP/UDP Ports Used by Rockwell Automation Products.
- 21 CFR Part 11 requirements addressed by FactoryTalk AssetCentre, see Guidelines for Applying FactoryTalk AssetCentre in a 21 CFR Whitepaper.
Provide Feedback