earth_america
user_standard Log on
earth_america
Log on to rate and give feedback 1 2 3 4 5 Log on to rate
0
How to

How to


Products: FDP Server
Functionalities: Security
5/11/2026

Adding a Device to the Allowlist

You add a device to the allowlist so that it can communicate with the field server.

Show More
action_close

You add the IP addresses of the devices that are allowed to communicate with the automation server or the FDP server to the firewall whitelist. This helps prevent connection attempts from unauthorized devices.

The IP addresses of the devices are specified in the whitelist by their IP addresses or by specifying an address mask that includes the device addresses. This makes it possible to add a mask of IP addresses to the whitelist using CIDR notation. The whitelist can be edited at any time.

Start by adding the computer you are using to the whitelist before you add other devices. If you do not add the computer you are using to the whitelist, you lock yourself out from the automation server or the FDP server.

Notice

LOSS OF COMMUNICATION

Make sure that you add the computer you are using to the whitelist.

Failure to follow these instructions can result in loss of server communication.

Automation server whitelist

The default whitelist is 0.0.0.0/0 for IPv4 and ::/0 for IPv6. It allows all devices to communicate with the automation server. When you add IP addresses to the whitelist, only the devices with IP addresses on the whitelist can communicate with the automation server.

If you remove the 0.0.0.0/0 pattern or the ::/0 pattern from the whitelist on an AS-B, AS-P, or AS-P-3 server, no device can communicate with the automation server.

If you lock yourself out, you can connect to the automation server using the USB and then reset the whitelist.

FDP server whitelist

The default whitelist is empty for both IPv4 and IPv6. The empty whitelist allows all devices to communicate with the FDP server. When you add IP addresses to the whitelist, only devices with IP addresses on the whitelist can communicate with the FDP server.

You can connect to the FDP server from Device Administrator using a network cable with a link-local connection, even if the IP address of your device is not on the whitelist. This means that if your device is locked out, you can connect to the FDP server using a network cable and then reset the whitelist. For more information, see Connecting to an FDP Server from Device Administrator Using a Network Cable .

If you for some reason cannot connect to the FDP server using a network cable, you can perform a factory reset of EcoStruxure Fire Operation. The factory reset will also reset the whitelist.

Maximum size

The maximum allowed size of a whitelist is 2048 bytes, approximately 100 devices.

If you have a number of automation servers or FDP servers that use the same whitelist configuration, you can configure all the servers at the same time.

In WorkStation, use Mass Editing:

For more information, see Mass Edit .

For more information, see Mass Editing Objects .

In WebStation, use Multi-editing in Search:

For more information, see Search in WebStation .

For more information, see Multi-editing in Search .

Notice

LOSS OF COMMUNICATION

Make sure that you add the computer you are using to the whitelist.

Failure to follow these instructions can result in loss of server communication.

To add a field server to the whitelist
  1. In Device Administrator, click Servers and then click the server.

  2. Click Firewall .

  3. In the Allowlist box, type the IP numbers. A whitespace is required between every IP address in the list.

    Tip:

    To add a complete subnet of IP addresses, add the subnet according to the CIDR network prefix notation syntax.

  4. Click OK .

  • Firewall
  • Firewall Tab
  • Removing a Device from the Allowlist