Siemens SIMATIC NET System Manual page 264

Industrial ethernet / profinet industrial ethernet
Hide thumbs Also See for SIMATIC NET:
Table of Contents

Advertisement

SCALANCE network components
4.8 SCALANCE S Industrial Security Appliance
SCALANCE S as DHCP server
A DHCP server assigns an IP address to each client throughout the network. DHCP
(Dynamic Host Configuration Protocol) in conjunction with a suitable server, allows the
dynamic assignment of an IP address and other configuration parameters to computers
within the network. SCALANCE S Security Appliances can be operated in the internal
network as DHCP servers. This allows IP addresses to be assigned automatically to the
devices connected to the internal network. The IP addresses are assigned either dynamically
from a defined range of addresses or a specific device is assigned a specific IP address
according to the definition.
Testing, diagnostics, logging and Syslog
For test and monitoring purposes, the Industrial Security Appliances dispose of diagnostics
and logging functions.
● Diagnostics functions
In online mode various system and status functions can be used for diagnostics.
● Logging functions
The system and security events are logged. The events are logged in the buffer areas of
the Industrial Security Appliance (local logging) or of a server (network Syslog). You
select the events to be logged in the log settings for the relevant Industrial Security
Appliance.
IPsec tunnel (only for SCALANCE S615, SC642-2C, SC646-2C)
The Internet Protocol Security (IPsec) is a Layer 3 tunneling protocol. The IPsec tunnel
provides the nodes with a secure data connection through the non-secure external network
to other devices that are protected by the SCALANCE S devices.
The encryption of the data transmission with VPN (IPsec) provides the following:
● Protection against espionage: The data exchanged are safe from eavesdropping
(ensuring confidentiality).
● Protection against manipulation: The data exchanged are safe from
corruption/counterfeiting (ensuring integrity).
● Authenticity: Only authorized nodes can establish a tunnel (ensuring the legitimacy of the
communication)
For the configuration of Virtual Private Networks (VPN), SCALANCE S devices as well as
the SOFTNET Security Client modules, which are integrated in an internal network, are
combined into groups in the configuration. IPsec tunnels are established automatically
between the SCALANCE S devices and SOFTNET Security Client modules that belong to
the same group.
264
System Manual, 09/2019, C79000-G8976-C242-10
Industrial Ethernet

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents