Ip Access Protection" Parameter Group - Siemens S7-300 Configuration Manual

Hide thumbs Also See for S7-300:
Table of Contents

Advertisement

Configuring the Ethernet CP with STEP 7
3.3 Setting further CP properties
3.3.6

"IP access protection" parameter group

Function
Using IP access protection gives you the opportunity of restricting communication over the
CP of the local S7 station to partners with specific IP addresses. Partners you have not
authorized therefore have no access to data of the S7 station using the IP protocol (S7
connections) via the CP configured in this way.
IP access protection relates to all messages handled by the IP protocol (TCP, ISO-on-TCP,
UDP, ICMP).
In this parameter group, you can activate or deactivate IP access protection and can enter
specific IP addresses in an IP access control list (IP-ACL).
With Advanced CPs, it is possible to send entries for the IP access control list to the CP
using HTTP (see section Sending entries for the IP access protection to the Advanced CP
using HTTP/HTTPS (Page 66)).
Blocked access attempts are registered on the CP and can be viewed with special
diagnostics in the "IP access protection" diagnostic object. If the CP has IT functionality, a
LOG file is also created in the file system of the CP that you can view with a WEB browser.
Note
Security enabled
As soon as you enable security, IP access protection is effective only on the interface to the
external network.
To achieve effective IP access protection within the local subnet when security is enabled,
you need to make special firewall settings.
following descriptions apply to the situation when security is disabled. You will find further
information relating to the situation when security is enabled at the end of the chapter.
IP access protection for configured communication partners
To restrict access so that only the communication partners you specified in the configuration
have access, you simply need to enable access protection. In this case, you do not need to
enter any IP addresses in the list.
These communication partners include:
● Stations to which communication connections are configured;
These include (except with S7 connections) connections on which the connection partner
is located in a different subnet.
The following types of access are not taken into account and therefore rejected:
52
Configuring and commissioning S7 CPs for Industrial Ethernet
Configuration Manual, 09/2013, C79000-G8976-C182-13

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S7-400

Table of Contents