DeltaV system security > The DeltaV Security Administration application overview > The Windows firewall and a DeltaV workstation

Manage the firewall application rules

Important

The Windows firewall profiles should not be enabled without fully understanding the potential impact on communications between DeltaV and any applications external to DeltaV on the either the DeltaV 2.5 network or applications in networks above the 2.5 network.

With the Windows firewall enabled, all default Windows firewall rules are applied. The DeltaV rules are in addition to the default Windows firewall rules.

Important

Do not edit the DeltaV rules. If you need a specific rule, you must create a new rule and configure it as needed. Any rules created by you are your responsibility to test and validate with your DeltaV system.

You can create a new rule by copying the existing DeltaV rule and modifying it. Open the Windows Firewall with Advanced Security application and select the DeltaV rule (for example, OPC: OPC UA Server). Copy and paste the rule and rename it to something meaningful. Edit the rule's properties to change what is needed; for example, a different default OPC UA Server TCP port to match what you have configured in DeltaV Explorer (for that protocol). Enable the new rule as an incoming rule on non-DeltaV networks. You are still responsible for testing and validating this change works in your DeltaV system.

Before you can apply any of the rules found in DeltaV Security Administration, you must enable the Windows firewall for the appropriate profiles and network interface cards (NICS).

  1. Open the DeltaV Security Administration application.
    Start DeltaV InstallationDeltaV Security Administration.
  2. From the DeltaV Security Administration application, expand the Windows Firewall for DeltaV Workstations item in the hierarchy.
  3. Select Manage Firewall Rules.
  4. Select (place a checkmark for) any rules you want to enable.
    • Unchecked - not enabled; that is, inbound communication for this port is blocked.
      Note

      The rules are applied by port, so if a rule is not selected, then inbound communication on the port is blocked, unless another rule has that same port open.

    • Checked - enabled as an allow rule; that is, communication for this port is allowed.
  5. Click Apply Firewall Rules button.
The selected rules are now applied to the enabled Windows Firewall profiles for the network cards specified (in the Windows Firewall Advanced Settings).