Phoenix Contact FL MGUARD 1000 Series Bedienungsanleitung

User manual
UM EN MGUARD NT
FL MGUARD 1000
Web-based management
mGuardNT 1.3.x

2020-07-09
PHOENIX CONTACT GmbH & Co. KG • Flachsmarktstraße 8 • 32825 Blomberg • Germany
phoenixcontact.com
108420_en_03
FL MGUARD 1000 – Web-based management – mGuardNT 1.3.x
Designation Version Order No.
FL MGUARD 1102 1153079
FL MGUARD 1105 1153078
For further information see mGuardNT 1.3.x firmware Release Notes.
User manual
This user manual is valid for:
UM EN MGUARD NT, Revision 03

Table of contents
108420_en_03 PHOENIX CONTACT 3 / 72
Table of contents
1 For your safety ...........................................................................................................................5
1.1 Identification of warning notes ............................................................................... 5
1.2 Qualification of users ............................................................................................. 5
1.3 Intended use.......................................................................................................... 5
1.4 Modifications to the product .................................................................................. 5
1.5 IT security.............................................................................................................. 5
1.6 About this user manual .......................................................................................... 7
1.7 Support.................................................................................................................. 7
2 mGuardNT basics ......................................................................................................................9
2.1 Device properties and scope of functions.............................................................. 9
2.2 Network ............................................................................................................... 11
2.3 Firewall ................................................................................................................ 11
2.3.1 Easy Protect Mode ............................................................................... 12
3 Using the web-based management .........................................................................................13
3.1 Establishing a network connection to the device ................................................. 13
3.2 User login ............................................................................................................ 13
3.3 User logout .......................................................................................................... 14
3.4 Help regarding the configuration.......................................................................... 15
3.4.1 Page structure and function ................................................................. 15
3.4.2 Icons and buttons ................................................................................. 16
3.4.3 Entering and changing values .............................................................. 17
3.4.4 Error messages .................................................................................... 17
3.4.5 Working with tables .............................................................................. 18
3.4.6 Resetting the device configuration to factory settings .......................... 19
3.4.7 Creating a snapshot ............................................................................. 19
3.4.8 Input: netmask and network ................................................................. 21
3.4.9 CIDR (Classless Inter-Domain Routing) ............................................... 22
4 Menu: Password ......................................................................................................................23
5 Menu: Device access ...............................................................................................................25
6 Menu: Network .........................................................................................................................27
6.1 Network >> Interfaces ......................................................................................... 27
6.1.1 Interfaces ............................................................................................. 27
6.1.2 Routes ................................................................................................. 34
6.1.3 NAT ..................................................................................................... 35

Product designation
4 / 72 PHOENIX CONTACT 108420_en_03
6.2 Network >> DHCP server .................................................................................... 42
6.3 Network >> DNS ................................................................................................. 45
7 Menu: Network security ...........................................................................................................47
7.1 Network security >> Firewall................................................................................ 47
7.1.1 Network security >> Firewall >> Firewall .............................................. 47
7.1.2 Network security >> Firewall >> Test mode alarms ............................. 53
7.2 Network security >> Firewall Assistant ................................................................ 55
8 Menu: Time and date ...............................................................................................................57
9 Menu: Firmware update ...........................................................................................................61
10 Menu: Support .........................................................................................................................63
10.1 Support >> Ping................................................................................................... 63
10.2 Support >> TCP Dump ........................................................................................ 64
11 Menu: Logs ..............................................................................................................................67
12 Appendix ..................................................................................................................................69
12.1 Using the RESTful Configuration API .................................................................. 69
12.2 Using smart mode ............................................................................................... 69

For your safety
108420_en_03 PHOENIX CONTACT 5 / 72
1 For your safety
Read this user manual carefully and keep it for future reference.
1.1 Identification of warning notes
1.2 Qualification of users
The use of products described in this user manual is oriented exclusively to:
– Electrically skilled persons or persons instructed by them. The users must be familiar
with the relevant safety concepts of automation technology as well as applicable stan-
dards and other regulations.
– Qualified application programmers and software engineers. The users must be familiar
with the relevant safety concepts of automation technology as well as applicable stan-
dards and other regulations.
1.3 Intended use
– The devices are security routers for industrial use, with integrated stateful packet in-
spection firewall. They are suitable for distributed protection of production cells or indi-
vidual machines against manipulation.
– The devices are designed for use in industrial environments.
– The devices are intended for installation in a control cabinet.
1.4 Modifications to the product
Modifications to hardware and firmware of the device are not permitted.
– Incorrect operation or modifications to the device can endanger your safety or damage
the device. Do not repair the device yourself. If the device is defective, please contact
Phoenix Contact.
1.5 IT security
For Phoenix Contact devices that can be integrated in an industrial network via Ethernet, or-
ganizational and technical measures must be taken in order to protect components, net-
works, and systems against unauthorized access and to ensure data integrity.
Phoenix Contact recommends that the following measures should be considered at the
very least.
This symbol together with the NOTE signal word warns the reader of actions
that might cause property damage or a malfunction.
Here you will find additional information or detailed sources of information.

mGuardNT firmware 1.3.x
6 / 72 PHOENIX CONTACT 108420_en_03
Perform threat analyses on a regular basis.
• In order to determine whether the measures you have taken still provide adequate pro-
tection for your components, networks, and systems, a regular threat analysis is man-
datory.
When planning systems, consider defense-in-depth strategies.
• Defense-in-depth strategies encompass several coordinated measures that include
operators, integrators, and manufacturers.
Make sure that your software/firmware is always up to date.
• Stay informed about updates for the products used. If possible, run provided updates
immediately to ensure maximum security for your product.
Deactivate unused communication channels.
• Check whether unused communication channels on the components you are using are
open (e.g., SSH, SNMP, FTP, BootP, DHCP, etc.). If possible, deactivate these chan-
nels.
Restrict access rights to the device.
• Restrict access rights for components, networks, and systems to those individuals for
whom authorization is strictly necessary.
Use strong passwords.
• Change default passwords during initial startup.
• If possible, use randomly generated passwords (password manager).
• Use strong passwords, e.g., at least ten characters long containing a mix of upper and
lower case letters, numbers, and special characters.
Use a firewall.
• Set up a firewall in order to protect your networks and the components and systems in-
tegrated in them against unauthorized network access.
• Use a firewall to segment a network or to isolate certain components (e.g., controllers).
Do not make components and systems available in public networks.
• Avoid integrating your components and systems into public networks.
• If you have to access your components and systems via a public network, use a VPN
(Virtual Private Network).

For your safety
108420_en_03 PHOENIX CONTACT 7 / 72
1.6 About this user manual
The following elements are used in this user manual:
1.7 Support
In the event of problems with your device or with operating your device, please contact your
supplier.
To get help quickly in the event of an error, make a snapshot of the device configuration im-
mediately when a device error occurs, if possible. You can then provide the snapshot to the
support team.
Bold Designations of operating elements, variable names or other accentuations
Italic – Product, module or component designations (e.g., tftpd64.exe, Config
API)
– Foreign designations or proper names
– Other accentuations
– Unnumbered list
1. Numbered list
•Operating instructions
⇒Result of an operation
For additional information on the device as well as release notes, user assistance and
software updates, visit: phoenixcontact.net/products.

mGuardNT basics
108420_en_03 PHOENIX CONTACT 9 / 72
2 mGuardNT basics
2.1 Device properties and scope of functions
Table 2-1 Device properties and scope of functions
Device properties FL MGUARD
1102 1105
HARDWARE
2 net zones (network interfaces) x x
Ethernet via RJ45 connections (transmission
speed: 10/100/1000 Mbps)
2 5
4-port Unmanaged Switch (RJ45) (bridge mode) - x
Service inputs and outputs (IOs) x x
NETWORK
Stealth mode x x
Router mode x x
Packet forwarding (router mode)
Security router x x
IP masquerading (NAT) x x
Port forwarding x x
1:1 NAT x x
Additional static routes x x
Network services (client/server)
DHCP x x
DNS x x
NTP x x
HTTPS (WBM/Config API) x x
FIREWALL
Stateful packet inspection firewall x x
Firewall (for continuous data traffic) x x
Device access (for incoming data traffic) x x
Integrity check of data packets to increase network security x x
Easy Protect Mode
Automatic protection of connected network clients without
configuration effort directly after connection of the device.
x x
Firewall Assistant
Analysis of data traffic for the automatic creation of firewall
rules.
x x

mGuardNT firmware 1.3.x
10 / 72 PHOENIX CONTACT 108420_en_03
Firewall test mode
Analysis of data traffic for the automatic extension of exist-
ing firewall rules.
x x
MANAGEMENT
Administration via web-based management (WBM) x x
Administration via RESTful Configuration API (Config API) x x
Firmware update via WBM and Config API x x
Smart mode
The access to certain management functions is imple-
mented via the Mode button on the device and without ac-
cess to a management interface.
x x
Support tools
TCP Dump (packet data analysis) x x
Ping (network analysis) x x
Log viewer (evaluation of log entries) x x
Support snapshot (status and error analysis) x x
Table 2-1 Device properties and scope of functions
Device properties FL MGUARD
1102 1105
Andere Handbücher für FL MGUARD 1000 Series
1
Inhaltsverzeichnis
Andere Phoenix Contact Netzwerk-Hardware Handbücher
Beliebte Netzwerk-Hardware Handbücher anderer Marken

Matrix Switch Corporation
Matrix Switch Corporation MSC-HD161DEL Bedienungsanleitung

B&B Electronics
B&B Electronics ZXT9-IO-222R2 Bedienungsanleitung

Yudor
Yudor YDS-16 Bedienungsanleitung

D-Link
D-Link ShareCenter DNS-320L Bedienungsanleitung

Samsung
Samsung ES1642dc Gebrauchsanweisung

Honeywell Home
Honeywell Home LTEM-PV Montageanleitung















