This document describes how to block all the unused services/servers like HTTP, FTP, IPtoSerial,... on an Ewon Flexy/Cosy131 device.
This can be needed when, for instance, HTTP and FTP servers cannot be used onsite because not matching the onsite security policies.
APPLICABLE PRODUCTS
Ewon : Flexy
Ewon : Cosy131
IN THIS ARTICLE
Block HTTP & FTP servers
For this, first make sure your device runs the firmware 14.9 or above.
From this version, a new COM parameter is available called "ClosedDevice".
You can access it either by using the tabular edition of the device web interface, by a comcfg.txt configuration file pushed via FTP or USB/SD card or through BASIC/JAVA programming.
The ClosedDevice parameter is a bitwise value that allows you to block the access to the web server (HTTP) and or the FTP server on the different Ewon IP interfaces (LAN, WAN & VPN).
Here is the table of the possible values :
Bit Setting |
Decimal Value |
Description |
0 |
0 |
No additional protection (default) |
1 |
1 |
Close FTP Server on LAN interface |
2 |
2 |
Close HTTP Server on LAN interface |
1 + 2 |
3 |
Close FTP and HTTP Servers on LAN interface |
4 |
4 |
Close FTP server on WAN interface |
1 + 4 |
5 |
Close FTP server on LAN & WAN interfaces |
8 |
8 |
Close HTTP server on WAN interface |
2 + 8 |
10 |
Close HTTP server on LAN and WAN interfaces |
4 + 8 |
12 |
Close FTP & HTTP servers on WAN interface |
16 |
16 |
Close FTP server on VPN interface |
1 + 16 |
17 |
Close FTP server on LAN & VPN interfaces |
4 + 16 |
20 |
Close FTP server on WAN & VPN interfaces |
1 + 4 + 16 |
21 |
Close FTP server on LAN, WAN & VPN interfaces |
32 |
32 |
Close HTTP server on VPN interface |
2 + 32 |
34 |
Close HTTP server on LAN & VPN interfaces |
8 + 32 |
40 |
Close HTTP server on WAN & VPN interfaces |
2 + 8 + 32 |
42 |
Close HTTP server on LAN, WAN & VPN interfaces |
16 + 32 |
48 |
Close FTP & HTTP servers on VPN interface |
1 + 2 + 4 + 8 + 16 + 32 |
63 |
Close all protocols on all interfaces |
The HTTP & FTP servers ports blocked by the ClosedDevice parameters are the ones configured in the COM parameters "IpsHttpP1", "IpsHttpP2" and "IpsFtpP"
NOTE : A reboot of the device is required to apply properly the blocking of the selected service.
Block IPtoSerial services
By default, the IptoSerial (aka Serial gateways) services like ModbusTCP to Modbus RTU, Siemens ISOTCP to MPI,... are opened.
If there are not used and you want to block them on all IP interfaces, just set the respective ports to 0 and reboot your device.
You can access it either through the menu IOServers > Global Settings or via the tabular edition of the device web interface, by a config.txt configuration file pushed via FTP or USB/SD card or through BASIC/JAVA programming
Block Ebuddy connections
To block the Ebuddy UDP port 1507, you can set the COM parameter "CfgProtoDis" to 0