Security features
8.3 Device access control (IP filter) (PAC3220 only)
90
PAC3120 and PAC3220
Equipment Manual, 10/2019, L1V30425208F-01
8.3 Device access control (IP filter) (PAC3220 only)
This function is only available on the PAC3220.
The IP filter is a configurable access protection. When the IP filter is activated, Modbus TCP
write commands are only accepted if the remote station is located in the same subnet.
The IP filter can be activated on the device in the "Communication" submenu of the
"Settings" menu.
Note
Switching from standard port 502 to a user
-defined port makes it more difficult to scan for
Example
PAC3220 No. 1 with IP filter is located in subnet 1 (192.168.100.0/24).
PAC3220 No. 2 without IP filter is located in subnet 2 (192.168.98.0/24).
● Host 1 (IP: 192.168.100.87) in subnet 1 (192.168.100.0/24) has read and write access to
PAC3220 No. 1 (192.168.100.10/24), because Host 1 is located in the same subnet as
the PAC
device.
● Host 1 (IP: 192.168.100.87) in subnet 1 (192.168.100.0/24) has read and write access to
PAC
No. 2 (192.168.98.20/24) in subnet 2 (192.168.98.0/24), because the IP filter is not
activated on PAC No. 2.
● Host 2 (IP: 192.168.98.17) in subnet 2 (192.168.98.0/24) has read only access to PAC
No. 1 (192.168.100.10/24), because the IP
filter is activated on PAC No. 1 and Host 2 is
not located in the same subnet as PAC No. 1.