Siemens SIMATIC NET SCALANCE S615 Configuration Manual page 52

Industrial ethernet security web based management
Hide thumbs Also See for SIMATIC NET SCALANCE S615:
Table of Contents

Advertisement

Technical basics
3.5 Security functions
Default Ciphers
During connection establishment a preset list can be transferred to the VPN connection
partners. The list contains combinations of the three algorithms (Encryption, Authentication,
Key Derivation). To establish a VPN connection, the VPN connection partner must support at
least one of these combinations. The combinations depend on the phase und the key exchange
method IKE).
Combination
Encryption
Authentica‐
tion
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
x: Combination is part of the default cipher
-: Combination is not part of the default cipher
none: For phase 2, no separate keys are exchanged. This means that Perfect Forward Secrecy (PFS) is disabled.
Requirements of the VPN partner
The VPN partner must support IPsec with the following configuration to be able to establish an
IPsec connection successfully:
● Authentication with partner certificate, CA certificates or pre-shared key
● IKEv1 or IKEv2
● Support of at least one of the following DH groups: Diffie-Hellman group 1, 2, 5 and 14 - 18
● 3DES or AES encryption
● MD5, SHA1, SHA256, SHA384 or SHA512
● Tunnel mode
If the VPN partner is downstream from a NAT router, the partner must support NAT-T. Or, the
NAT router must know the IPsec protocol (IPsec/VPN passthrough).
NAT traversal (NAT-T)
There may be a NAT router between the device and the VPN gateway of the remote network.
Not all NAT routers allow IPsec frames to pass through. This means that it may be necessary
to encapsulate the IPsec frames in UDP packets to be able to pass through the NAT router.
52
Key derivation
IKEv1
DH Group 14
DH Group 16
DH Group 14
DH Group 16
none
none
none
none
Phase 1
IKEv2
x
x
x
x
-
x
-
x
-
-
-
-
-
-
-
-
SCALANCE S615 Web Based Management
Configuration Manual, 11/2019, C79000-G8976-C388-08
Phase 2
IKEv1
IKEv2
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents