Are the firewall settings correct?

AI Model Manager Troubleshooting Guide

Portfolio
Industrial AI
Product
AI Model Manager
Software version
1.2.0
Language
en-US

AI Model Manager executes actions through the Industrial Edge Management. In order for this process to go through correctly, the network and firewall configurations has to be set correctly on the Industrial Edge Management. The required setting can be found in the Industrial Edge Security overview 2.3.2 "IP protocols and ports".

All the required settings can be found in the Industrial Edge Security overview document. AI Model Manager API must be accessible from all Industrial Edge Devices that are the target of the deployments. The IED (physical or virtual) on which AI Model Manager is installed (Manager device) may have several network interfaces. One of them must be reachable from the target devices using the assigned IPv4 address. If the manager device and the target devices are connected to different networks, there must be a network route that makes this possible.

If you are installing AI Model Manager on a virtual device, we recommend that you configure a Bridged Network Adapter for the virtual machine. Then the virtual network adapter can have an IP address assigned from the host network.

In addition to the required network settings for Industrial Edge, the following ingress and egress rules must be implemented in the firewalls for the listed features to work.

Port

Protocol

Direction

Usage/Feature

443, TCP

HTTPS

Ingress

Application UI, API Integration workspace

443, TCP

HTTPS

Egress

Downloading Packages from Cloud storage services, Access to Siemens AI Services API