Anybus Defender Series 4000 and up
This guide explains how to create a basic firewall rule on the Anybus Defender. Firewall rules are used to control which devices and services are allowed to communicate through the Defender. Firewall Rules are created on the interfaces where the traffic comes INTO the firewall. E.g. to enable communication from WAN to LAN, your rule must be on the WAN interface.
Select the interface where the traffic enters the Defender.
Example:
Destination Port Range (From): Select applicable server, example. HTTPS
NOTE: When selecting service in From See that the service in To selects the same protocol, otherwise adjust
NOTE 2: When selecting Other specify the port number in Custom (example: 8080) AND make sure the TO field matches - even if it's only ONE port that is allowed to pass)
HMI:
192.168.200.20
PLC:
192.168.100.40
Rule:
Action: Pass Interface : VLAN200 Protocol: TCP Source: 192.168.200.20 Source Port: Any Destination: 192.168.100.40 Destination Port: 502 Description: Allow HMI to PLC Modbus
The rule is placed on the interface where the HMI traffic enters the Defender.
By default traffic that matches rules will not result in a log entry. To enable explicit logging, in the rule you can enable "Log packets that are handled by this rule"
Example of Syslog :
2026-08-31T09:32:19.568488+02:00 Master-Defender-AUTHORIZED-USE-ONLY.localdomain filterlog[58296] 10,,,1000000103,igb0,match,block,in,4,0x0,,1,0,0,none,2,igmp,36,10.10.10.201,224.0.0.1,datalength=12
In Menu: Status -> System Logs and then in Tab Firewall -> Normal View you can see the logged entries of blocked connection requests. Allowed connections are not logged, unless specifically enabled in the Firewall Rule that matches the traffic
See the Timestamp, interface, source IP and port, destination IP and Port and Protocol detected. Mouseover the "-" in from of the source reveals an "Easy Rule: Add to Block List". This will create an explicit block for this originating IP in Firewall Rules. Traffic is already denied by default, but creating this Block Rule will remove the log entries.
In the same way clicking "+" in front of the Destination IP and port will create a rule to Allow traffic to this IP and Port.
The "+" Create Easy Rule shows a template of the rule that will be created:
When pressing Confirm a rule will be created and active direct.
Under Firewall -> Rules you will find the new rules lowest in the list with clearly marked comments.
The rules can be moved with Drag & Drop.
After dropping the rule in desired place, press SAVE and Apply Changes.
© HMS Networks AB 2026