• Topic ID: id_11039090
  • Version: 2.0
  • Date: Jan 30, 2019 9:42:17 PM

Product Network Filter Theory

1 Theory

What Is PNF?

PNF = Product Network Filters

Host based SW firewall

Found on all Linux DI product systems as of 2005

Why Does PNF Exist?

Respond to customer concerns regarding product security

Secure the product network interface (including remote service)

Significantly reduce the risk of virus/worm attack on product

Impact to the Customer and GE Service

The majority of situations will require no-extra effort

Custom network environments will require configuration

Some applications will need to update the PNF configuration

Firewall

System to monitor, route, and block network traffic

Can exist on either a product or separate HW device

Does not handle authentication of users

Network Listeners

Process on a system that wait for network traffic

Easily detected by customers or hackers

Common target point for exploits (ex: Blaster worm)

Vulnerabilities

Holes in system security with the potential of exploitation

New ones come out every day

Solved by patching or removing the vulnerable process

2 Tabs

Service

Only viewable by GE service

Configure source of InSite connectivity

Default values only allow communication from the GE back office

Could require configuration for custom environments

Refer to the remote service connectivity team

Additional allowed nodes not viewable by the customer

Named Service

Turn on common network services (ex: telnet, ftp, …etc.)

Can allow communication only from specific IP addresses

Possible to add multiple IP rules for a single service

DICOM

Default opens port 4006

Can add multiple DICOM ports

Accepts communication from any IP

Allowed Nodes

Allows all communication over any port from a specified IP

Can have range of IP address like subnets

Expert

Custom rules with full control

Most likely only used by IT savvy users

Help

Existing content came from engineering

3 Control Boxes

3.1 Firewall Box

  • Turns firewall on and off

  • When the firewall is off, all network traffic in both directions are allowed

  • Must hit “apply” for new state to take effect

  • Used for trouble shooting

3.2 Configuration Control Box

Apply

Saves all current changes to configuration

Save Config

Makes a backup of current configuration

Restore Config

Restores last backup of configuration

Restore Default Config

Goes back to the factory default settings

4 General

Installation

Default configuration of firewall should be turned on

Should not require any information from the customer

Exception comes with custom infrastructure with remote service

The remote connectivity team should manage these cases

Backup and Restore

Configuration can be saved through a load from cold

Engineering must have the appropriate files set

Troubleshooting

Both GUI and command line tools available to turn off the firewall

Support from the GE remote connectivity team