Siemens SENTRON 7KN POWERCENTER 3000 Manual page 41

Iot data platforms
Hide thumbs Also See for SENTRON 7KN POWERCENTER 3000:
Table of Contents

Advertisement

● Secure MindSphere communication: With the secure login process defined for
MindSphere and the exchange of electronic keys defined for this, communication with
MindSphere is encrypted. Communication with MindSphere can only be initiated from the
7KN Powercenter 3000 and not the reverse
● Selectable TCP ports: Spying and analysis of the communication is typically performed by
identification of the ports. If attacks of this kind are possible, another port can be chosen.
The port must be selected on both communication partners.
● Services that are not required: Every service is a point of attack, so services that are
currently not used should be deactivated.
– Identification service can be deactivated. 7KN Powercenter 3000 can then not be
– Modbus TCP gateway can be deactivated or not started automatically. 7KN
– Web user interface can be deactivated. 7KN Powercenter 3000 can then not be
● Write protection for the Web user interface on the external interface X1P1: For the Web
user interface on the external Ethernet interface X1P1, write protection can be
deactivated / activated with Settings → General, in the area "External Communication
(X1P1)" of the Web server. Write protection is activated on delivery.
● Security tests: 7KN Powercenter 3000 is regularly subjected to security tests.
Vulnerabilities are continuously remedied.
The following services must be considered in the external network environment:
Service
Layer 3 / 4
Data transfer to
MindSphere
Web user inter-
face
Modbus TCP
gateway
Time synchroni-
UDP
zation
Identification
UDP
service
Name resolution
UDP
in the local sub-
net
adjustable
*)
7KN POWERCENTER 3000
Manual, 10/2019, L1V30579222003-01
located and identified via the interface with powerconfig.
Powercenter 3000 can then no longer be used as a Modbus TCP gateway by other
applications such as powermanager or powerconfig.
accessed via the interface with web browsers and no longer manipulated via
"Settings".
Layer 7
TCP
https
TCP
http
TCP
Modbus TCP
NTP
LLMNR
7KN POWERCENTER 3000
Port
Interface
-
X1P1
Def. 80
X1P1 & X2P1
*)
Def. 502
X1P1 & X2P1
*)
-
X1P1 & X2P1
17008
X1P1 & X2P1
5355
X1P1 & X2P1
Installing, connecting, commissioning
4.7 Security features
Remote Partner
Host
MindSphere
Port
433
123
39

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents