Ip Configuration" Parameter Group - Siemens S7-300 Configuration Manual

Hide thumbs Also See for S7-300:
Table of Contents

Advertisement

Enable security - effects
If IP access protection is enabled for IP communication, when the security function is
enabled, the firewall is activated automatically regardless of the entries. The IP-ACL entries
created in STEP 7 are adopted with the corresponding rights as firewall rules. These firewall
rules derived from the ACL entries when security is enabled apply only on the interface to
the external network.
Note
IP-ACL without entries when security is enabled
If you adopt an IP-ACL without entries, the firewall is enabled and it is no longer possible to
access the CP from external. To make CP available, configure suitable firewall rules in the
advanced mode of SCT.
Note
Behavior in the internal subnet
When you enable security, there are initially no access restrictions between communications
partners connected in the internal network.
The following therefore applies to internal subnets: Previously existing entries in the IP-ACL
that restricted communication to certain partners are not initially effective when security is
enabled.
When security is enabled, it is then possible to make detailed firewall settings for individual
nodes. With specified connections to external partners, firewall rules are automatically
created in SCT that allow connection establishment. With unspecified connections, you must
first configure the relevant firewall rules.
Stateful packet inspection
The firewall and NAT/NAPT router supports the "Stateful Packet Inspection" mechanism. As
a result, reply frames can pass through the NAT/NAPT router and firewall without it being
necessary for their addresses to be included in the firewall rule and the NAT/NAPT address
conversion. IP addresses that would appear temporarily in the ACL if security were disabled
can be detected by the mechanism of Stateful Packet Inspection. Such IP addresses are
then not visible in the corresponding pages of diagnostics.
3.3.7

"IP configuration" parameter group

Meaning
You can decide the route and the method with which the IP address of the local interface is
obtained and assigned.
With the options available here, it is possible to assign IP addresses "dynamically" outside
the configuration.
Configuring and commissioning S7 CPs for Industrial Ethernet
Configuration Manual, 09/2013, C79000-G8976-C182-13
Configuring the Ethernet CP with STEP 7
3.3 Setting further CP properties
55

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S7-400

Table of Contents