4.8.10.6
CP as passive subscriber of VPN connections
Setting permission for VPN connection establishment with passive subscribers
If the CP is connected to another VPN subscriber via a gateway, you need to set the
permission for VPN connection establishment to "Responder".
This is the case in the following typical configuration:
VPN subscriber (active) ⇔ gateway (dyn. IP address) ⇔ Internet ⇔ gateway (fixed IP
address) ⇔ CP (passive)
Configure the permission for VPN connection establishment for the CP as a passive
subscriber as follows:
1. In STEP 7, go to the devices and network view.
2. Select the CP.
3. Open the parameter group "VPN" in the local security settings.
4. For each VPN connection with the CP as a passive VPN subscriber, change the default
setting "Initiator/Responder" to the setting "Responder".
4.8.10.7
SYSLOG
Use of SYSLOG only with 1 VPN connection
If you want to use SYSLOG with level 7 (debug) via Vpn connections, this is only possible
with a single established VPN connection.
4.8.11
Configuration of the TeleService access
Configuration for using TeleService
To meet the requirements for using the TeleService functions for the CP, you need to make
the necessary settings at the following points in STEP 7.
"Communication types" parameter group of the CP
Select the following options:
● Enable telecontrol communication
● Activate online functions
CP 1243-1
Operating Instructions, 12/2016, C79000-G8976-C365-02
Configuration
4.8 Security
63