SmartSDR v4.1.5 | SmartSDR v4.1.5 Release Notes
SmartSDR v3.10.15 | SmartSDR v3.10.15 Release Notes
The latest 4O3A Genius Product Software:
The latest 4O3A Genius Product Software and Firmware
If you are needing assistance with FlexRadio products, please refer to the product documentation or check the Help Center for known solutions. Need technical support from FlexRadio? It's as simple as creating a HelpDesk ticket.
Smartlink Server IP ranges - locking down firewall access
For good security reasons I want to limit the range of IP addresses that can use the Smartlink port forwarding capability of my firewall to only the Flex smartlink servers. Can somebody advise the server ip address ranges in use please so i can tighten my firewall access? Many thanks
Comments
-
In your Router/Firewall you should be able to check on the current connections in use and find the IP addresses you require on the ports you have configured (4992 and 4993 on the LAN - Trusted Side)
But, you then won't be able to connect to the radio from a remote site if do not know the IP address that you are operating remotely from since the connection from the User to the Radio is a Peer to Peer connection in order to provide the best performance.
If you are concerned about security, the connection is a secure TLS-encrypted connection and without the proper encryption keys you can't connect to the radio anyway.
73
0 -
Many thanks Mike. I was under the impression (clearly mistaken) that the Smartlink system acted as a relay in the comms channel - so if I understand you correctly the role of the Smartlink server is only to act as a broker for the initial connecton of the remote user directly to the radio over TLS at which point the Smartlink system has no further role to play.
My desire to lock down the 'allowed' ip addresses to connect to the designated ports on the router was simply to minimise the attack surface.
730 -
That is correct. It is just the lookup resource.
You could still do that, but you need to know all the IP addresses you are going to be operating from.
0 -
Many thanks for the replies @Mike-VA3MW0
Leave a Comment
Categories
- All Categories
- 388 Community Topics
- 2.2K New Ideas
- 658 The Flea Market
- 8.4K Software
- 156 SmartSDR+
- 6.5K SmartSDR for Windows
- 186 SmartSDR for Maestro and M models
- 439 SmartSDR for Mac
- 275 SmartSDR for iOS
- 265 SmartSDR CAT
- 204 DAX
- 386 SmartSDR API
- 9.4K Radios and Accessories
- 53 Aurora
- 297 FLEX-8000 Signature Series
- 7.2K FLEX-6000 Signature Series
- 970 Maestro
- 58 FlexControl
- 866 FLEX Series (Legacy) Radios
- 944 Genius Products
- 471 Power Genius XL Amplifier
- 347 Tuner Genius XL
- 126 Antenna Genius
- 306 Shack Infrastructure
- 215 Networking
- 468 Remote Operation (SmartLink)
- 142 Contesting
- 811 Peripherals & Station Integration
- 144 Amateur Radio Interests
- 1.1K Third-Party Software
