Recommendations On Network Security - Siemens SIMATIC NET MM900 Compact Operating Instructions

Industrial ethernet switches
Hide thumbs Also See for SIMATIC NET MM900:
Table of Contents

Advertisement

Recommendations on network security

NOTICE
Information security
Connect to the device and change the standard password for the user set in the factory "admin"
and "" before you operate the device.
To prevent unauthorized access to the device and/or network, observe the following security
recommendations.
General
• Check the device regularly to ensure that these recommendations and/or other internal
security policies are complied with.
• Evaluate the security of your location and use a cell protection concept with suitable products
(https://www.industry.siemens.com/topics/global/en/industrial-security/pages/
default.aspx).
• When the internal and external network are disconnected, an attacker cannot access internal
data from the outside. Therefore operate the device only within a protected network area.
• No product liability will be accepted for operation in a non-secure infrastructure.
• Use VPN to encrypt and authenticate communication from and to the devices.
• For data transmission via a non-secure network, use an encrypted VPN tunnel (IPsec,
OpenVPN).
• Separate connections correctly (WBM, SSH etc.).
• Check the user documentation of other Siemens products that are used together with the
device for additional security recommendations.
• Using remote logging, ensure that the system protocols are forwarded to a central logging
server. Make sure that the server is within the protected network and check the protocols
regularly for potential security violations or vulnerabilities.
Physical access
• Restrict physical access to the device to qualified personnel.
– The memory card or the PLUG (C-PLUG, KEY-PLUG) contains sensitive data such as
– Using the button, you can reset the device to the factory defaults.
• If the device is publicly accessible, disable the functions of the button using the software.
• Lock unused physical ports on the device. Unused ports can be used to gain forbidden access
to the plant.
MM900 media modules for SCALANCE XR-500M
Compact Operating Instructions, 04/2022, A5E03275846-05
certificates, keys etc. that can be read out and modified.
3
9

Advertisement

Table of Contents
loading

Table of Contents