EasyManuals Logo

GE D30 User Manual

GE D30
686 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #226 background imageLoading...
Page #226 background image
5-16 D30 LINE DISTANCE PROTECTION SYSTEM – INSTRUCTION MANUAL
PRODUCT SETUP CHAPTER 5: SETTINGS
5
Figure 5-2: Login screen for CyberSentry
When the "Server" Authentication Type is selected, the D30 uses the RADIUS server and not its local authentication
database to authenticate the user.
When the "Device" button is selected, the D30 uses its local authentication database and not the RADIUS server to
authenticate the user. In this case, it uses built-in roles (Administrator, Engineer, Supervisor, Operator, Observer, or
Administrator and Supervisor when Device Authentication is disabled), as login accounts and the associated passwords
are stored on the D30 device. In this case, access is not user-attributable. In cases where user-attributable access is
required, especially for auditable processes for compliance reasons, use server authentication (RADIUS) only.
No password or security information is displayed in plain text by the EnerVista software or the UR device, nor are they ever
transmitted without cryptographic protection.
When CyberSentry is enabled, Modbus communications over Ethernet is encrypted, which is not always tolerated by
SCADA systems. The UR has a bypass access feature for such situations, which allows unencrypted Modbus over Ethernet.
The Bypass Access setting is available on the
SETTINGS  PRODUCT SETUP  SECURITY  SUPERVISORY screen. Note that
other protocols (DNP, 101, 103, 104, EGD) are not encrypted, and they are good communications options for SCADA
systems when CyberSentry is enabled.
When using the rear RS485 port and CyberSentry, registers can be read with a maximum buffer of 64 bytes. Settings may
not be written, so use another port.
CyberSentry settings through EnerVista
CyberSentry security settings are configured under Device > Settings > Product Setup > Security.
Only (TCP/UDP) ports and services that are needed for device configuration and for customer enabled features are
open. All the other ports are closed. For example, Modbus is on by default, so its TCP port 502, is open. But if
Modbus is disabled, port 502 is closed. This function has been tested and no unused ports have been found open.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the GE D30 and is the answer not in the manual?

GE D30 Specifications

General IconGeneral
BrandGE
ModelD30
CategoryRelays
LanguageEnglish

Related product manuals