Other operations
Other blocked JOBS
This list allows prohibiting additional S7 function codes or code ranges belonging to the JOB
operation set. It is possible to Add or Delete elements to or from this list by clicking on the relevant
buttons.
Other blocked USERDATA groups
This list allows prohibiting whole sets or ranges of whole sets of USERDATA operations. It is
possible to Add or Delete elements to or from this list by clicking on the relevant buttons.
Support
Disable intrusion
prevention
When this option is selected, the scan of the S7 protocol will be disabled and traffic
will be authorized if the filter policy allows it.
Log each S7 request Enables or disables the logging of S7 requests.
OPC UA
OPCUA parameters
Maximum client
message size (bytes)
This value makes it possible to restrict the maximum size that an OPC UA client is
allowed to send. It has to be between 8192 and 2147483647 (default value: 65535).
Maximum server
message size (bytes)
This value makes it possible to restrict the maximum size that an OPC UA server is
allowed to send. It has to be between 8192 and 2147483647 (default value: 65535).
Prohibit "None"
security code
If this option is selected, you will prevent the circulation of unencrypted and unsigned
OPC UA traffic.
Managing OPC UA services
Public services
This table lists the codes and associated OPC UA services that have been predefined on the
firewall. These codes are classified by operation set: Attribute, Discovery, Method, Monitored Item,
Node Management, Query, Secure Channel, Session, Subscription and View.
Predefined OPC UA services are allowed by default (Analyze action). The buttons Block by
service set, Analyze by service set and Modify all services allow modifying the action (Analyze
/ Block) applied to the selected service set or to all OPC UA services listed in the table.
Other allowed services
This list allows authorizing additional OPC UA function codes blocked by default by the firewall. It
is possible to Add or Delete elements to or from this list by clicking on the relevant buttons.
Support
Disable intrusion
prevention
When this option is selected, the scan of the OPC UA protocol will be disabled and
traffic will be authorized if the filter policy allows it.
Log every OPC UA
query
Enables or disables the logging of OPC UA requests.
Page 287/448 sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
SNS - USER CONFIGURATION MANUAL V.3
PROTOCOLS