Siemens SIMATIC NET S7-300 Manual page 74

Cps for industrial ethernet
Hide thumbs Also See for SIMATIC NET S7-300:
Table of Contents

Advertisement

3 Operating the Ethernet CP with
IP Access Protection Tab
Using IP access protection gives you the opportunity of restricting communication
over the CP of the local S7 station to partners with specific IP addresses. Partners
V 5.2.1
you have not authorized cannot access data of the S7 station over the CP using
the IP protocol (S7 connections).
In this tab, you can activate or deactivate IP access protection and can enter IP
addresses in an IP access control list (IP-ACL).
Attempted access that was blocked is registered on the CP. You can view these
entries with NCM Diagnostics in the "IP access protection" object. If the CP has
IT functionality, an archive file (LOG file) is also created in the file system of the CP
and you can view this with a WEB browser. You will find the LOG file as an HTML
file in the file system of the CP in the following folder:
- ram/security/IPLogFile.htm
As default, IP access protection is deactivated.
S IP access protection for configured connections with specified partners
If you want to restrict access to the precise set of partners you specify during
connection configuration, you simply need to activate access protection. In this
case, you do not need to enter IP addresses in the list.
Remember, however, that on unspecified connections, all other IP addresses
(unconfigured in the project engineering) are unauthorized and are rejected.
This automatic restriction to configured IP addresses does not apply to the
programmed connections mode.
IP access protection relates to all connection types handled using the IP
protocol (TCP, ISO-on-TCP, UDP)
S IP access protection for partners with specific IP addresses
To allow IP access for specific IP addresses, enter these IP addresses in the IP
access control list.
The IP addresses you specify when you configure the connection always
belong to the permitted IP addresses and do not, therefore, need to be entered
explicitly in the IP-ACL. This also applies to IP addresses obtained dynamically
over an E-mail connection from a DNS server.
A -74
S7-CPs for Industrial Ethernet Configuring and Commissioning
Release 01/2007
C79000-G8976-C182-07

Advertisement

Table of Contents
loading

Table of Contents