Secure Path Through the Firewall

 

Many times we have seen plans to include a web server in in-plant equipment scuttled by serious security issues. What is often overlooked is that for a person outside the plant to use a browser to interrogate a web server inside the plant, they must cross the firewall. More often than not, an external third party will not be granted permission (if it is even possible) to access data from within the plant over the Ethernet (intranet) network structure.

 

The generally preferred alternative is to configure RemoteLog as a client that initiates the conversation, in the same manner as a user addressing a web site from a standard web browser. In this manner, the client RemoteLog within the plant sends a message out through the firewall. The firewall software, monitoring the IP address in the outgoing message then allows that address to respond back to the same client. (This standard security technique is similar in principal to a dial back system that only allows data to be transferred after the source of the request has been confirmed.)