Siemens SIMATIC S7-1200 CP 1243-8 IRC Operating Instructions Manual page 21

For telecontrol
Hide thumbs Also See for SIMATIC S7-1200 CP 1243-8 IRC:
Table of Contents

Advertisement

Further configurable security functions of the CP
The following security functions can be used independently of telecontrol communication.
Due to the activation of the security functions of the CP in the configuration, the following
functions are accessible to the S7-1200 station on the interface to the external network:
● Firewall
– IP firewall with stateful packet inspection (layer 3 and 4)
– Firewall also for "non-IP" Ethernet frames according to IEEE 802.3 (layer 2)
– Limitation of the transmission speed to restrict flooding and DoS attacks ("Define IP
– Global firewall rule sets
The protection provided by the firewall can cover individual devices, several devices or
even entire network segments.
● VPN
The following alternatives can be used:
– Secured communication via IPsec tunnels
– Remote maintenance via SINEMA Remote Connect
● Logging
To allow monitoring, events can be stored in log files that can be read out using the
configuration tool or can be sent automatically to a Syslog server.
● NTP (secure)
For secure transfer during time-of-day synchronization (with telecontrol communication
disabled)
● STARTTLS / SMTPS
For secure sending of e-mails
● HTTPS
For secure access to the Web server of the CPU
● SNMPv3
Foe secure transfer of network diagnostic information
For the range of performance of the security functions refer to the section Performance data
and configuration limits (Page 22).
For a description of the configuration, refer to the section Security (Page 104).
CP 1243-8 IRC
Operating Instructions, 02/2018, C79000-G8976-C385-03
packet filter rules")
VPN communication allows the establishment of secure IPsec tunnels for
communication with one or more security modules. The CP can be grouped together
with other modules to form VPN groups during configuration. IPsec tunnels are
created between all security modules of a VPN group.
It is not necessary and not possible to create a VPN group for communication via a
SINEMA RC server. The SINEMA RC Server manages the communication between
the devices and the security mechanisms (OpenVPN).
Application and functions
1.6 Security functions
21

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents