SmartSDR v3.7.4 and the SmartSDR v3.7.4 Release Notes | SmartSDR v2.12.1 and the SmartSDR v2.12.1 Release Notes
SmartSDR v1.12.1 and the SmartSDR v1.12.1 Release Notes
Power Genius XL Utility v3.8.8 and the Power Genius XL Release Notes v3.8.8
Tuner Genius XL Utility v1.2.11 and the Tuner Genius XL Release Notes v1.2.11
Antenna Genius Utility v4.1.8
Need technical support from FlexRadio? It's as simple as Creating a HelpDesk ticket.
Smartlink Server IP ranges - locking down firewall access
For good security reasons I want to limit the range of IP addresses that can use the Smartlink port forwarding capability of my firewall to only the Flex smartlink servers. Can somebody advise the server ip address ranges in use please so i can tighten my firewall access? Many thanks
Comments
-
Mike-VA3MW Administrator, FlexRadio Employee, Community Manager, Super Elmer, Moderator adminOptions
In your Router/Firewall you should be able to check on the current connections in use and find the IP addresses you require on the ports you have configured (4992 and 4993 on the LAN - Trusted Side)
But, you then won't be able to connect to the radio from a remote site if do not know the IP address that you are operating remotely from since the connection from the User to the Radio is a Peer to Peer connection in order to provide the best performance.
If you are concerned about security, the connection is a secure TLS-encrypted connection and without the proper encryption keys you can't connect to the radio anyway.
73
0 -
Many thanks Mike. I was under the impression (clearly mistaken) that the Smartlink system acted as a relay in the comms channel - so if I understand you correctly the role of the Smartlink server is only to act as a broker for the initial connecton of the remote user directly to the radio over TLS at which point the Smartlink system has no further role to play.
My desire to lock down the 'allowed' ip addresses to connect to the designated ports on the router was simply to minimise the attack surface.
730 -
Mike-VA3MW Administrator, FlexRadio Employee, Community Manager, Super Elmer, Moderator adminOptions
That is correct. It is just the lookup resource.
You could still do that, but you need to know all the IP addresses you are going to be operating from.
0
Leave a Comment
Categories
- All Categories
- 251 Community Topics
- 2.1K New Ideas
- 490 The Flea Market
- 7.4K Software
- 5.9K SmartSDR for Windows
- 135 SmartSDR for Maestro and M models
- 332 SmartSDR for Mac
- 241 SmartSDR for iOS
- 224 SmartSDR CAT
- 161 DAX
- 344 SmartSDR API
- 8.6K Radios and Accessories
- 6.9K FLEX-6000 Signature Series
- 781 Maestro
- 42 FlexControl
- 836 FLEX Series (Legacy) Radios
- 733 Genius Products
- 393 Power Genius XL Amplifier
- 254 Tuner Genius XL
- 86 Antenna Genius
- 224 Shack Infrastructure
- 151 Networking
- 375 Remote Operation (SmartLink)
- 119 Contesting
- 586 Peripherals & Station Integration
- 116 Amateur Radio Interests
- 810 Third-Party Software