SmartSDR v4.0.1 and the SmartSDR v4.0.1 Release Notes
SmartSDR v3.10.15 and the SmartSDR v3.10.15 Release Notes
The latest 4O3A Genius Product Software and Firmware
Need technical support from FlexRadio? It's as simple as Creating a HelpDesk ticket.
Smartlink Server IP ranges - locking down firewall access
For good security reasons I want to limit the range of IP addresses that can use the Smartlink port forwarding capability of my firewall to only the Flex smartlink servers. Can somebody advise the server ip address ranges in use please so i can tighten my firewall access? Many thanks
Comments
-
In your Router/Firewall you should be able to check on the current connections in use and find the IP addresses you require on the ports you have configured (4992 and 4993 on the LAN - Trusted Side)
But, you then won't be able to connect to the radio from a remote site if do not know the IP address that you are operating remotely from since the connection from the User to the Radio is a Peer to Peer connection in order to provide the best performance.
If you are concerned about security, the connection is a secure TLS-encrypted connection and without the proper encryption keys you can't connect to the radio anyway.
73
0 -
Many thanks Mike. I was under the impression (clearly mistaken) that the Smartlink system acted as a relay in the comms channel - so if I understand you correctly the role of the Smartlink server is only to act as a broker for the initial connecton of the remote user directly to the radio over TLS at which point the Smartlink system has no further role to play.
My desire to lock down the 'allowed' ip addresses to connect to the designated ports on the router was simply to minimise the attack surface.
730 -
That is correct. It is just the lookup resource.
You could still do that, but you need to know all the IP addresses you are going to be operating from.
0 -
Many thanks for the replies @Mike-VA3MW0
Leave a Comment
Categories
- All Categories
- 361 Community Topics
- 2.1K New Ideas
- 620 The Flea Market
- 8K Software
- 34 SmartSDR+
- 6.3K SmartSDR for Windows
- 177 SmartSDR for Maestro and M models
- 416 SmartSDR for Mac
- 267 SmartSDR for iOS
- 252 SmartSDR CAT
- 188 DAX
- 378 SmartSDR API
- 9.2K Radios and Accessories
- 27 Aurora
- 224 FLEX-8000 Signature Series
- 7.1K FLEX-6000 Signature Series
- 929 Maestro
- 53 FlexControl
- 863 FLEX Series (Legacy) Radios
- 903 Genius Products
- 459 Power Genius XL Amplifier
- 326 Tuner Genius XL
- 118 Antenna Genius
- 288 Shack Infrastructure
- 202 Networking
- 445 Remote Operation (SmartLink)
- 141 Contesting
- 763 Peripherals & Station Integration
- 139 Amateur Radio Interests
- 983 Third-Party Software
