Com600 Configuration Service - ABB COM600 series 5.0 Cyber Security Deployment Manualline

Substation management unit
Hide thumbs Also See for COM600 series 5.0:
Table of Contents

Advertisement

1MRS758267
3.2.4.
COM600 series 5.0
Cyber Security Deployment Guideline
Rule name
SNTP
Offside remoting
GATServer
RemoteDesktop(UDP)
RemoteDesktop(TCP)
IEC 61850 OPC Server
SAB600
Vtrin
Gateway Service
CodeMeter Runtime Server

COM600 Configuration Service

The Configuration Service running in COM600 allows a configuration to be loaded into
COM600. A typical COM600 engineering workflow involves a COM600 application
engineer performing application configuration using SAB600 application in a workstation.
After the configuration is ready, it is uploaded to COM600 using Gateway Management
tool in SAB600. See Appendix 1 for details on how to launch Gateway Management
Tool.
When Gateway Management tool is launched in SAB600, it will attempt to establish a
network connection to COM600 to upload additional configuration settings. Configuration
Service running in COM600 will accept the connection.
A COM600 user with administrative privileges can
enable/disable Configuration Service using COM600
WebHMI. ABB recomments that Configuration Service is
enabled only at times when a new application configuration
Rule description
Allows TCP connection on port 123. This rule allows incoming
SNTP messages which are further handle by SNTP client in
COM600.
Allows TCP connection on port 4934. This rule allows incoming
messages for Offside related application in COM600.
Allows TCP connection on port 8089. This rule allows incoming
messages for GOOSE Analyzer application in COM600.
Allows UDP connection on port 3389. This rule allows incoming
connection requests for Windows Remote Desktop application.
Allows TCP connection on port 3389. This rule allows incoming
connection requests for Windows Remote Desktop application.
Allows any connection on any port for program IEC 61850 client
in COM600.
Allows any connection on any port for COM600 Configuration
Service. This rules allows connection requests from SAB600
Gateway Management tool to COM600.
Allows any connection on any port for VTRIN Server. This rule
allows incoming connection requests for Data Historian
application in COM600.
Allows any TCP/UDP connection for CoDeSys Gateway Ser-
vice. This rule allows connection requests from Logic Editor in
SAB600 to Logic Processor in COM600.
Allows any TCP/UDP connection for CodeMeter. This applica-
tion is used in license management for Logic Processor
(CoDeSys) application.
21

Advertisement

Table of Contents
loading

Table of Contents