- Topic ID: id_11039090
- Version: 2.0
- Date: Jan 30, 2019 9:42:17 PM
Product Network Filter Theory
1 Theory
- What Is PNF?
-
PNF = Product Network Filters
Host based SW firewall
Found on all Linux DI product systems as of 2005
- Why Does PNF Exist?
-
Respond to customer concerns regarding product security
Secure the product network interface (including remote service)
Significantly reduce the risk of virus/worm attack on product
- Impact to the Customer and GE Service
-
The majority of situations will require no-extra effort
Custom network environments will require configuration
Some applications will need to update the PNF configuration
- Firewall
-
System to monitor, route, and block network traffic
Can exist on either a product or separate HW device
Does not handle authentication of users
- Network Listeners
-
Process on a system that wait for network traffic
Easily detected by customers or hackers
Common target point for exploits (ex: Blaster worm)
- Vulnerabilities
-
Holes in system security with the potential of exploitation
New ones come out every day
Solved by patching or removing the vulnerable process
2 Tabs
- Service
-
Only viewable by GE service
Configure source of InSite connectivity
Default values only allow communication from the GE back office
Could require configuration for custom environments
Refer to the remote service connectivity team
Additional allowed nodes not viewable by the customer
- Named Service
-
Turn on common network services (ex: telnet, ftp, …etc.)
Can allow communication only from specific IP addresses
Possible to add multiple IP rules for a single service
- DICOM
-
Default opens port 4006
Can add multiple DICOM ports
Accepts communication from any IP
- Allowed Nodes
-
Allows all communication over any port from a specified IP
Can have range of IP address like subnets
- Expert
-
Custom rules with full control
Most likely only used by IT savvy users
- Help
-
Existing content came from engineering
3 Control Boxes
3.1 Firewall Box
-
Turns firewall on and off
-
When the firewall is off, all network traffic in both directions are allowed
-
Must hit “apply” for new state to take effect
-
Used for trouble shooting
3.2 Configuration Control Box
- Apply
-
Saves all current changes to configuration
- Save Config
-
Makes a backup of current configuration
- Restore Config
-
Restores last backup of configuration
- Restore Default Config
-
Goes back to the factory default settings
4 General
- Installation
-
Default configuration of firewall should be turned on
Should not require any information from the customer
Exception comes with custom infrastructure with remote service
The remote connectivity team should manage these cases
- Backup and Restore
-
Configuration can be saved through a load from cold
Engineering must have the appropriate files set
- Troubleshooting
-
Both GUI and command line tools available to turn off the firewall
Support from the GE remote connectivity team