Security Recommendations - Siemens SIMATIC RF1100 Operating Instructions Manual

Hide thumbs Also See for SIMATIC RF1100:
Table of Contents

Advertisement

Security recommendations

To prevent unauthorized access, observe the following security recommendations when
working with the reader and WBM (Web Based Management).
General
• Check regularly that the device complies with these recommendations and/or other internal
security policies.
• Evaluate your plant as a whole in terms of security. Use a cell protection concept with suitable
products.
• Keep the software up to date. Always use the latest firmware/software version of the device.
Check regularly for security updates of the products and use them. After the release of a new
version, previous versions are no longer supported and are not maintained.
Information regarding product news and new software versions is available at the following
address:
Link (https://support.industry.siemens.com/cs/ww/en/ps/24224)
• Do not connect the device directly to the Internet. Operate the device within a protected
network area. Use a firewall to connect the internal, protected network to external networks
and configure it with restrictive rules.
• For data transmission via a non-secure network, use additional security components that
provide an encrypted VPN tunnel (IPsec, OpenVPN).
• Terminate connections correctly (e.g. logout in WBM).
• Use the device only for system access control (and not for physical access control).
Physical access
• Restrict physical access to the device to qualified and authorized personnel.
Security functions
• Only enable protocols and functions that you actually need to use the device. Note that, in
the factory setting, all protocols/functions can be used and all transponders and card types
listed below are recognized. However, while the device has established a connection via a
protocol, all other protocols are disabled.
• The XML/Modbus protocols are sent unencrypted. Take suitable measures to ensure that the
XML/Modbus communication is tap-proof.
• For optimal security, use SNMPv3 authentication and encryption mechanisms. SNMPv1 is
classified as non-secure and should only be used when absolutely necessary.
• Use the latest Web browser version compatible with the product to ensure you are using the
most secure encryption methods available.
SIMATIC RF1100
Operating Instructions, 08/2023, C79000-G8976-C698-02
2
9

Advertisement

Table of Contents
loading

Table of Contents