Siemens S7-300 Configuration Manual page 53

Hide thumbs Also See for S7-300:
Table of Contents

Advertisement

● PROFINET IO devices when the Ethernet CP is used as a PROFINET IO controller
● NTP servers, SMTP servers, DNS servers and DHCP servers.
IP access protection relates to all connection types that use the IP protocol (TCP, ISO-on-
TCP, UDP, S7)
Note on dynamically assigned IP addresses:
Since each service manages its dynamic entry in the ACL itself, it is perfectly possible for the
same IP address to appear several times in module diagnostics.
Note
PING command - no dynamic adoption of the IP address
IP addresses accessed using a PING command are not entered dynamically in the IP
access control list.
IP access protection for partners with specific IP addresses
To allow access only by certain IP addresses, enter these IP addresses in the IP access
control list. These can, for example, be the IP addresses of connection partners that
remained unspecified in the connection configuration, of individual programming devices or
of connection partners on PROFINET CBA.
The IP addresses you have specified in the connection configuration always belong to the
permitted IP addresses. This means that you do not need to enter these IP addresses
explicitly in the IP-ACL.
Configuring and commissioning S7 CPs for Industrial Ethernet
Configuration Manual, 09/2013, C79000-G8976-C182-13
– Configured connections with an unspecified partner
All partners on unspecified connections (with unconfigured IP addresses) are rejected.
– Connections in PROFINET CBA will be treated as unspecified connections. You will
need to enter the IP addresses of such connections explicitly in the IP access control
list.
– Access by connection partners specified in the user program with the program block
IP_CONFIG (FB55) do not automatically have permission and are rejected.
The CP enters the IP addresses of PROFINET IO devices dynamically in the IP access
control list when the CPU is in RUN mode.
If the CPU changes to STOP mode, the IP addresses of the PROFINET IO devices are
deleted from the access list.
The IP addresses of NTP servers, SMTP servers, DNS servers and DHCP servers are
also entered and removed dynamically when there are requests to these servers. This
may mean that IP addresses only appear temporarily in the display of the STEP 7 special
diagnostics.
Configuring the Ethernet CP with STEP 7
3.3 Setting further CP properties
53

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S7-400

Table of Contents