• Topic ID: id_11038905
  • Version: 2.0
  • Date: Nov 8, 2018 1:37:07 AM

Configure Product Network Filters

1 Overview

Product Network Filters (PNF) is a software tool that allows a site Network Administrator to control traffic from the site's internal network to the Diagnostic Imaging System.

  1. Application software must be up.

  2. Click the Service icon to access the Common Service Desktop (CSD).

  3. Select the following: Configuration > Configure PNF

  4. The Main PNF Screen is displayed Figure 1.

note:

The GE Service tab may not be available on all systems.

Figure 1. Main PNF Screen (PNF Version 2.8-3 Example)

Notice Image
  • notice
  • ALL settings made in the PNF Tool are saved on the System State (Reconfig Info). If a NEW load from cold should need to be performed, the PNF settings will be restored during the System State Restore.

2 Firewall

Notice Image
  • notice
  • The Firewall should be ON at all times; this is the default setting. If issues are found because of the Firewall, contact the OLC connectivity team to resolve issues. It is not acceptable to leave the firewall OFF.

In order to turn the firewall ON or OFF:

  1. Click the radio buttons (Figure 2).

    Figure 2. Firewall Radio Buttons

  2. Click the Apply button.

The Firewall Settings buttons are common across all tabs in the PNF tool. See Figure 3. These buttons can be clicked at any time and in any tab. The function of that button will be applied by the tool at the current state of all tabs.

Figure 3. Firewall Settings Buttons

Apply

In order for the system to recognize any changes made, click the Apply button, any changes that have been made on ANY tab will be applied to the PNF configuration. A reboot is not necessary, the changes go into effect right after the button click

Backup

The Backup button should be clicked before making any changes on any of the tabs in PNF. This button allows that the current configuration is stored.

Restore

The Restore button will return the PNF configuration backup version.

Factory Defaults

The Factory Defaults button will reset the PNF configuration defaults.

3 Customer View

3.1 Named Services Tab

The Named Services Tab, is the screen where the site's network administrator selects a standard networking service to dictate network traffic to or from this system to the site's network. See Figure 1.

3.1.1 Adding a network Service

  1. To add a network service, click the drop-down menu labeled Services for a list of standard Networking Services.

    Standard Networking Services offered are:

    • ftp

    • http

    • https

    • ldap

    • ntp

    • ping (icmp)

    • portmap

    • rexec

    • rlogin

    • rsh

    • ssh

    • ssl / tls

    • telnet

    • tftp

  2. Select a network service from the drop-down menu, and click Add. This service is now added to the list.

  3. Click Apply.

3.1.2 3.2.1 Deleting a network Service

  1. To delete a network service, check the box next to the Service on the list.

  2. Click the Delete button.

  3. Click Apply.

3.2 Allowed Nodes Tab

To view Allowed Nodes, open a Unix Shell and type:

{ctuser@hostname} cat /usr/g/config/modality.filters

The Allowed Nodes tab is where the IP address is entered for the network service(s) added via the Named Services tab. See Figure 4.

Figure 4. Allowed Nodes (PNF Version 2.8-3 Example)

3.2.1 Adding an Allowed Node

  1. Enter the IP address for the network service in the field below Node IP.

  2. Click Add.

  3. Once all Nodes have been added, click Apply .

3.2.2 Removing an Allowed Node

  1. Check the box next to the Node IP in the list.

  2. Click the Delete button to remove the Node IP from the list.

  3. Once all changes have been made, click Apply.

3.3 DICOM Setup

The DICOM screen may be used to verify that the correct DICOM port was populated during installation. This field should be auto-populated during the initial setup of the DICOM ports. Additional DICOM ports can also be added at this screen. See Figure 5.

Figure 5. DICOM Tab (PNF Version 2.8-3 Example)

3.3.1 Adding a DICOM Port

  1. Enter the DICOM Port in the field next to the New label.

  2. Click Add.

  3. Once all DICOM Ports have been added, click Apply .

3.3.2 Removing a DICOM Port

  1. Check the box next to the DICOM Port in the list.

  2. Click the Delete button to remove the DICOM Port from the list.

  3. Once all changes have been made, click Apply.

3.4 Expert Tab

The Expert Tab gives the network administrator the ability to create rules for the network services allowed in the Named Services screen.

This tab is also used to view all of the application rules that have been created. See Figure 6.

Figure 6. Expert Tab (PNF Version 2.8-3 Example)

3.4.1 Creating a Rule

  1. To create a rule for the firewall, enter the application name in the Application Name field.

  2. Enter the Port info in the Port field.

  3. Click on the Protocol drop-down menu for the rule to be applied (all, tcp, udp).

  4. Enter the IP address to which this rule will be applied.

  5. Once all fields have been populated, click Add.

  6. Click Apply.

3.4.2 Removing a Rule

  1. Check the box next to the Application name in the list.

  2. Click the Delete button to remove the rule from the list.

  3. Once all changes have been made, click Apply.

3.5 Debug Tab

The Debug Tab displays a list of all firewall rules applied to this system. See Figure 7.

Figure 7. Debug Tab (PNF Version 2.8-3 Example)

4 Troubleshooting

Troubleshooting the firewall can be done by turning the Firewall On and Off. Click Apply. See Firewall.

Notice Image
  • notice
  • The Firewall should be ON at all times, this is the default setting. If issues are found because of the Firewall, contact the OLC connectivity team to resolve issues. It is not acceptable to leave the firewall OFF.

5 Finalization

One all the necessary changes/settings have been made, perform the following steps:

  1. Turn off the telnet port via instructions found in Named Services tab: Named Services Tab.

    note:

    Turn off the telnet port to make the system most secure.

  2. At the Firewall Setting buttons, click Apply. See Figure 3.

  3. In order to store this configuration in the system data, click the BackupFirewall Setting button.