When Learning Mode is active, all traffic is allowed to pass through the Defender Compact. The device monitors the communication (for example from FlexEdge to Modbus devices) and records the traffic so firewall rules will be generated "automatically". The type of devices passing their data is important during testing because each device generates unique network traffic depending on the service it uses, including its IP address, protocol, and port.
The Anybus Defender Compact’s physical packaging includes a two-pin connector that can be used when preparing the device for learning mode. The User manual on configuring connectors can be found here Anybus_Defender_Compact-Manual_env2 - The User manual explains which terminals to connect at page 19 to 21.
This article explains configuring the Anybus Defender Compact in learning mode through its firmware (Anybus Defender Compact).
NOTE: Make sure your Defender Compact is in Factory Default mode.
To install the Defender compact for learning in a live network, take the following steps:
Traffic shall now be allowed without restrictions through the device. To view the recorded traffic and activate filtering you need to connect with Anybus Compact Manager.
Install Anybus Compact Manager and create a new project.
And activate the device by going online
Connect to the device - via USB
When device is connected, navigate to “Packet filter” and Download Network data. When packet filter is inactive, the device captures incoming traffic, and it is then displayed what devices are connected to the compact. The Anybus Defender should learn what traffic is passing it, including modbus traffic passing from Flex Edge to Modbus as in our example setup. Select to "Download Networkdata".
The process will load until finished. Meanwhile Anybus Defender is capturing traffic passing through and from source to Compact - NAT/FW.
Once finished loading, certain devices or single IP Addresses can be found and activated if selected. First, the ip address of the FlexEdge is configured in packet filter. The ip address of the FlexEdge becomes present in Firewall Rules.
This will automatically create rules under “Packet filter” -> “Rules” that applies after traffic learnt in the Compact - NAT/FW. Compact - NAT/FW now allows traffic passing from LAN to WAN. The images below explains with arrows and signs what IP addresses are allowed to pass.
Your configuration is now complete, after uploading and activating the configuration the firewall will now deny all traffic except what is explicitly allowed by the rules.