smartDEN IP-16R-XX User Manual
13 Apr 2021
11. Security considerations
The smartDEN IP-16R-XX runs a special firmware and do not have a general-
purpose operating system. There are no extraneous IP services found on general-
purpose operating systems (e.g. fingerd, tcp_wrapper, etc.) that can possibly be
exploited by an unauthorized agent. In particular, the smartDEN IP-16R-XX does not
run protocols such as Telnet and FTP which may have the potential for security
breech. The only exception from this is the integration protocol, that can be disabled.
Web-browser access
A challenge-response authentication is used in login process. When the password is
entered, it is transmitted across the network in encrypted form, so eavesdropping on
the data transmission will not reveal the password. Subsequent transmissions of the
password to "login" onto the device are encrypted and "safe". The only case when
the password is transmitted across the network "in the open", is when it is being
changed and submitted in General Settings form. Therefore, you must set
passwords in the secure environment where you can make sure that no one is
"eavesdropping".
SNMP communication (for smartDEN IP-16R only)
SNMPv1 does not implement encryption. Authentication of clients is performed only
by a "community string", which is transmitted in clear text. SNMP communication
should be used in trusted networks and disabled if not used.
Modbus-TCP communication (for smartDEN IP-16R-MT only)
Modbus-TCP does not implement encryption. Modbus-TCP communication should
be used in trusted networks and disabled if not used.
MQTT communication (for smartDEN IP-16R-MQ only)
Within the current module implementation the MQTT does not implement any
encryption. This communication should be used in trusted networks and disabled if
not used.
XML/JSON operation
A challenge-response authentication can be used in login process. The password
can be transmitted by custom application across the network in encrypted form.
Web and XML/JSON access can be restricted by IP Address (range of IP
Addresses) or by MAC Address.