Industrial ethernet security web based management (320 pages)
Summary of Contents for Siemens SCALANCE M812
Page 1
___________________ Preface ___________________ Security recommendations ___________________ SIMATIC NET Description of the device ___________________ Installation Industrial Remote Communication Remote Networks ___________________ SCALANCE M812, M816 Connecting up ___________________ Dimension drawings Operating Instructions ___________________ Technical specifications ___________________ Approvals 08/2018 C79000-G8976-C331-06...
Page 2
Note the following: WARNING Siemens products may only be used for the applications described in the catalog and in the relevant technical documentation. If products and components from other manufacturers are used, these must be recommended or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and maintenance are required to ensure that the products operate safely and without any problems.
There, you will find among other things optical performance data of the communications partner that you require for the installation. The "SIMATIC NET Industrial Ethernet" system manual can be found on the Internet pages of Siemens Industry Online Support under the following entry ID: 27069465 (https://support.industry.siemens.com/cs/ww/en/view/27069465) ● "Passive network components" system manual This system manual contains installation instructions for several of the most common components and guidelines for setting up networked automation plants in buildings.
Page 4
● Product CD / product DVD ● SIMATIC NET Manual Collection You will find the article numbers for the Siemens products of relevance here in the following catalogs: ● SIMATIC NET Industrial Communication / Industrial Identification, catalog IK PI ●...
Page 5
Siemens’ products and solutions undergo continuous development to make them more secure. Siemens strongly recommends that product updates are applied as soon as they are available and that the latest product versions are used. Use of product versions that are no longer supported, and failure to apply the latest updates may increase customers’...
Explanations of many of the specialist terms used in this documentation can be found in the SIMATIC NET glossary. You will find the SIMATIC NET glossary on the Internet at the following address: 50305045 (https://support.industry.siemens.com/cs/ww/en/view/50305045) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
● Keep the software up to date. Check regularly for security updates of the product. You will find information on this on the Internet pages "Industrial Security (https://www.siemens.com/industrialsecurity)". ● Inform yourself regularly about security advisories and bulletins published by Siemens ProductCERT (https://www.siemens.com/cert/en/cert-security-advisories.htm). ● Only activate protocols that you really require to use the device.
Page 10
● It is recommended that you use password-protected certificates in the PKCS #12 format ● It is recommended that you use certificates with a key length of at least 2048 bits. ● Change keys and certificates immediately, if there is a suspicion of compromise. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 11
● Using a firewall, restrict the services and protocols available to the outside to a minimum. ● For the DCP function, enable the "DCP read-only" mode after commissioning. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 12
(when configured) HTTPS TCP/443 Open Open Closed SNTP UDP/123 Open Closed Closed (only outgoing) SNMP v1/v3 UDP/161 Open Open Closed Yes (when (when configured) configured) DNS Server TCP/53 Open Open Closed (when configured) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 13
(when configured) UDP/1813 TIA Portal Cloud TCP/9023 Open Open Closed Connector (variable) (when configured) SMTP TCP/25 Open Closed Closed (only outgoing) HTTP proxy TCP/variable Open Closed Closed (only outgoing) Only with SCALANCE M804PB SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Description Article number SCALANCE M812-1 ADSL2+ router Analog phone connection (Annex A) 6GK5812-1AA00-2AA2 ISDN connection (Annex B) 6GK5812-1BA00-2AA2 SCALANCE M816-1 ADSL2+ router Analog phone connection (Annex A) 6GK5816-1AA00-2AA2 ISDN connection (Annex B) 6GK5816-1BA00-2AA2 SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 16
• Injury to persons • Loss of the approvals • Violation of the EMC regulations Use only undamaged parts. 1. Make sure that the package is complete. 2. Check all the parts for transport damage. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Description of the device 2.3 LED display LED display 2.3.1 SCALANCE M812-1 SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 19
The bootloader waits in this state for a new firmware file that you can download using TFTP. Flashing Firmware on PLUG The device is performing a firmware update or downgrade. at the interval: 2000 ms on / 200 ms off SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 20
Ethernet connection to local computer or LAN not established Ethernet connection to local computer or LAN established Device receiving / sending data Digital input inactive Digital input active. Digital output inactive Digital output active. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Description of the device 2.3 LED display 2.3.2 SCALANCE M816-1 SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 22
DSLAM in the central office. Flashing DSL line training has failed or the DSL cable connection is down. DSL line training is completed and the DSL connection is established. VPN not established VPN established SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 23
Ethernet connection to local computer or LAN not established Ethernet connection to local computer or LAN established Device receiving / sending data Digital input inactive Digital input active. Digital output inactive Digital output active. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Input for the power supply L1, M2, L2, M2 ② Functional ground ③ Terminal strip with two screw connectors Digital input +DI, -DI ④ Terminal strip with two screw connectors Digital output +DO, -DO SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 25
16 AWG Wire end ferrule without plastic collar to DIN 0.2 mm 1.5 mm 46228/1 Wire end ferrule with plastic collar to DIN 0.2 mm 1.5 mm 46228/4 Stripped length 7 mm 7 mm SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
– Now release the button. The bootloader waits in this state for a new firmware file that you can download by TFTP. You will find more information in the section "Service and Maintenance" in the SCALANCE M-800 Web Based Management configuration manual. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 27
You will find more information in the section "Service and Maintenance" in the SCALANCE M-800 Web Based Management configuration manual. WARNING EXPLOSION HAZARD Do not press the SET button if there is a potentially explosive atmosphere. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
PLUG. License information on the KEY-PLUG In addition to the configuration, the KEY-PLUG also contains a license that allows the use of Siemens Remote Services. See also Accessories (Page 17) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
General notes on use according to ATEX and IECEx WARNING To comply with EC Directive 2014/34 EU (ATEX114) or the conditions of IECEx, this enclosure or cabinet must meet the requirements of at least IP54 in compliance with EN 60529. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Keep to the minimum clearances to other components or to walls of a housing so that the convection ventilation of the device is not blocked. ● Below at least 10 cm ● Above at least 10 cm SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
7. Connect the terminal with as short a cable as possible ≤ 150 mm and a large cross- sectional area of 1.5 mm² to the functional ground of the system, see section "Terminals (Page 24)“ and section “Grounding (Page 44)“. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 32
Installation 3.2 Wall mounting See also Dimension drawings (Page 53) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Dismantling 1. Disconnect all connected cables. 2. Release the DIN rail catch on the bottom of the device using a screwdriver. 3. Pull lower part of the device away from the DIN rail. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
(Page 24)“ and section “Grounding (Page 44)“. Dismantling 1. Disconnect all connected cables. 2. Using a screwdriver, pull down the catch on the rear of the device. 3. Remove the device from the standard rail. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
(Page 24)“ and section “Grounding (Page 44)“. Dismantling 1. Disconnect all connected cables. 2. Using a screwdriver, pull down the catch on the rear of the device. 3. Remove the device from the standard rail. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
(Page 44)“ and section “Terminals (Page 24)“. Dismantling 1. Disconnect all connected cables. 2. Using a screwdriver, pull down the catch on the rear of the device. 3. Remove the device from the pedestal. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 37
Installation 3.6 Mounting on a pedestal See also Accessories (Page 17) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 38
Installation 3.6 Mounting on a pedestal SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Connecting up WARNING EXPLOSION HAZARD Replacing components may impair suitability for Class 1, Division 2 or Zone 2. WARNING EXPLOSION HAZARD Do not open the device when the supply voltage is turned on. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
WARNING Take measures to prevent transient voltage surges of more than 40% of the rated voltage. This is the case if you only operate devices with SELV (safety extra-low voltage). SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 41
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations only. WARNING EXPLOSION HAZARD You may only connect or disconnect cables carrying electricity when the power supply is switched off or when the device is in an area without inflammable gas concentrations. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
The power supply is connected using a 5-pin terminal block. The power supply is non- floating. Signal Description 24 VDC Ground Ground 24 VDC Functional ground, refer to the section Grounding (Page 44)" SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 43
2 circuits as specified in the National Electrical Code ® (ANSI/NFPA 70). Refer to the section Connecting up (Page 39) and the installation instructions and instructions for use of the manufacturer of the power supply, the battery or the accumulator. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
(Page 24)“. Such a cable should be kept as short as possible. If cables are installed permanently, it is advisable to remove the insulation of the shielded cable and to establish contact on the shield/PE conductor bar. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
The voltage at the digital input/output must not exceed 30 VDC and not fall below -30 VDC, otherwise the digital input/output will be destroyed. Note Interference pulse Zo avoid evaluating an interference pulse, the pulse for the signal 1 (TRUE / HIGH) must be at least 200 ms. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 46
The 2-pin terminal block has the following assignment: 24 VDC DI- (input ground) If there is an adequate switching voltage at the digital input, the digital input is active and the "DI" LED is lit. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 47
Connecting up 4.4 Digital input/output Digital output The 2-pin terminal block has the following assignment: Relay 24 VDC / 1 A Relay 24 VDC / 1 A SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
To reduce the risk of fire only use telephone cable with 26 AWG (0.125 mm ) or larger. Connect the device to the DSL socket of the splitter. Cable assignment Contact 10/100 Mbps SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
To set up the device, connect a PC with a Web browser to one of the Ethernet ports. For the connection, use a path cable with an RJ-45 plug. You will find the properties of the Ethernet interface in the technical specifications. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
2. Insert the PLUG correctly oriented into the slot. To ensure this, the housing of the PLUG has a protruding ridge on the long side. The slot has a groove at this position. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 51
Removing the PLUG 1. Turn off the power to the device. 2. Insert a screwdriver between the front edge of the PLUG and the slot and release the PLUG. 3. Remove the PLUG. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Page 52
Connecting up 4.7 Replacing the PLUG SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Dimension drawings SCALANCE M812-1 Dimensions are specified in mm. Figure 5-1 Front view SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Technical specifications SCALANCE M812 \ M816 SCALANCE M812- 1 SCALANCE M816-1 Article number Annex A 6GK5 812-1AA00-2AA2 6GK5 816-1AA00-2AA2 Annex B 6GK5 812-1BA00-2AA2 6GK5 816-1BA00-2AA2 Ethernet interface Attachment to Industrial Quantity Ethernet Design RJ-45 jack Characteristics: 10/100BASE-T • Ethernet IEEE 802 •...
Page 58
Technical specifications 6.1 SCALANCE M812 \ M816 SCALANCE M812- 1 SCALANCE M816-1 For state "1": 13 to 30 VDC For state "0": -30 to 3 VDC Maximum input current 8 mA Cables should be routed in pairs Maximum cable length < 30 m Inputs isolated from electronics.
Page 59
Technical specifications 6.1 SCALANCE M812 \ M816 SCALANCE M812- 1 SCALANCE M816-1 Product functions Configuration / management Web Based Management (WBM) via HTTP and • HTTPS. Command Line Interface (CLI) via Telnet and • Security Router with NAT function •...
Page 60
Technical specifications 6.1 SCALANCE M812 \ M816 SCALANCE M812- 1 SCALANCE M816-1 Other functions Time-of-day synchronization • – NTP client and NTP server – Secure NTP server – SIMATIC Time Client – SNTP Client DHCP • – DHCP server (local network) –...
You can check which of the following approvals have been granted for your product by the markings on the type plate. Current approvals on the Internet You will find the current approvals for the product on the Internet pages of Siemens Industry Online Support at the following link: (https://support.industry.siemens.com/cs/ww/en/ps/15982/cert)
The test was performed with a device and a connected communications partner that also meets the requirements of the standards listed above. When operating the device with a communications partner that does not comply with these standards, adherence to the corresponding values cannot be guaranteed. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
DE-76181 Karlsruhe Germany You will find the current EC declaration of conformity for these products on the Internet pages of Siemens Industry Online Support (https://support.industry.siemens.com/cs/ww/en/ps/15326/cert). The products described in these operating instructions meet the requirements of the following EC directives: ●...
2014/30/EU "Electromagnetic Compatibility" for the following areas of application: Applied standards: ● EN 55024 Information technology equipment - Immunity characteristics - Limits and methods of measurement ● EN 55032 + AC Electromagnetic compatibility of multimedia equipment - Emission Requirements SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
2011/65/EU for the restriction of the use of certain hazardous substances in electrical and electronic equipment: Applied standard: ● EN 50581 Technical documentation for the assessment of electrical and electronic products with respect to restriction of hazardous substances SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
Area". You will find this document • on the data medium that ships with some devices. • on the Internet pages under Siemens Industry Online Support (https://support.industry.siemens.com/cs/ww/en/). Enter the document identification number "C234" as the search term. The products described in these operating instructions meet the requirements of the EU directive 2014/34/EU "Equipment and Protective Devices for Use in Potentially Explosive...
Page 67
– EN 60079-7 (Explosive atmospheres - Part 7: Equipment protection through increased safety "e") – EN 60079-0 (Explosive atmospheres - Part 0: Equipment - General requirements) You will find the current versions of the standards in the currently valid ATEX certificates. SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
You will find the current versions of the standards in the currently valid IECEx certificates. A.3.3 RCM / C-TICK The products meet the requirements of the AS/NZS CISPR11 : 2011 standard (Industrial, scientific and medical equipment - Radio- frequency disturbance characteristics - Limits and methods of measurement). SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...
A.3.7 Marking for the customs union EAC (Eurasian Conformity) Eurasian Economic Union of Russia, Belarus, Armenia, Kazakhstan and Kyrgyzstan Declaration of conformity according to the technical regulations of the customs union (TR ZU) SCALANCE M812, M816 Operating Instructions, 08/2018, C79000-G8976-C331-06...