Emerson Smart Firewall > Smart Firewall configuration worksheets

Worksheet for Smart Firewall configuration

It is recommended that you print and complete this worksheet and keep it for your records.

Note

Ensure that no DNS information is configured for the Network Interface Card (NIC).

Table: Worksheet for firewall configuration

Static IP addressing for the Internal network. The firewall administrator assigns network addresses.

What is the range of IP addresses assigned to the DeltaV workstations' third NIC?

Note

Enter these IP addresses in the worksheet for internal workstation names and IP addresses.

____.____.____.____ to ____.____.____.____

(example: 192.168.1.100 to 192.168.1.200)

What is the subnet mask used for this network?

_____._____._____._____

(example: 255.255.255.0)

What is the IP address of the firewall's gateway? This will also be the address of the web UI.

______.______.______.______

Note

This address should be selected from the range of addresses assigned to the internal network. Typically it is the first address in the range.

Dynamic IP addressing for the Internal network. The firewall assigns network addresses.

Will the firewall serve the IP address to the internal workstations (DHCP)?

If the answer is yes, provide the parameters in the following rows.

Y______ N______

What is the starting IP address that is used to generate the network addresses for the DeltaV workstations?

______.______.______.______

Note

This must be the first address in the subnet. Typically it is XXX.XXX.1.1

What is the subnet mask for this address?

____.____.____.____

(example: 255.255.255.0)

How many workstations will have IP addresses assigned?

Note

To prevent unauthorized connections this should be the same number of DeltaV workstations that will be assigned addresses.

______ (maximum number of workstations)

Does the firewall's external interface have a dedicated IP address assigned by the IT department? (recommended)

If the answer is yes, provide the addresses in the following rows.

Y______ N______

What is the external network address?

This is also the gateway address used to reach the DeltaV workstations, the address used as the gateway parameter in the route add command, and the gateway used to configure a router.

______.______.______.______

What is the external network subnet mask?

______.______.______.______

What are the IP addresses of DNS servers (2 maximum)?

Note

Emerson strongly recommends that DNS servers are not used. This helps to prevent a user from entering a URL in an internet browser on a DeltaV workstation to access the internet.

______.______.______.______

______.______.______.______

What is the IP address of the gateway?

For the Smart Firewall this is the address of the router located on the plant network to which the Smart Firewall is connected. Typically, this is the same address as the default gateway on the computers on that network. The gateway is optional and required only if the DeltaV workstations communicate with computers other than those on the network directly connected to the firewall.

______.______.______.______

Will users on the external network have read only access to the firewall?

Y______ N______

If firewall events are logged to a remote (syslog) server, what is the server's IP address?

This address can be entered during initial configuration even if the remote syslog server software is not yet installed so it can easily access the firewall during firewall installation.

______.______.______.______

What is the network address of the NTP server (if used)

______.______.______.______