Siemens SIMATIC S7-1500 System Manual page 349

Redundant system
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

Protection
11.3 Local user management
Continuing to use access levels
Even though the new local user administration replaces the usual access protection via
corresponding function rights of individual users, there is still the possibility to continue to
use this familiar access protection. This is required, for example, for HMI devices which only
support access levels and which do not benefit yet from possibilities of the new user
administration.
If you require the configuration of an access level, for example, to ensure an HMI device
access even without user or password access, you have to activate the "Use legacy access
control via access levels" option in the CPU properties.
Note
Users for OPC UA server
Independent of the access protection, you always have to configure the users for the OPC UA
server in the project tree ("Security settings > Users and roles" area).
Restrictions on continued use of the access levels
When using the "Legacy access control" option, you cannot select the access level directly in
the table for setting the access levels. This selection can only be set for the new local user
administration in one way: Via the access protection function rights of the "Anonymous" user.
The local user "Anonymous" is created in a project by the system by default. With the help of
this user, you determine the behavior of the CPUs in the project for someone who logs in
without a user name and password. For security reasons, the anonymous user is deactivated
and needs to be activated before use.
The area where you set the access levels leads you via a link to the editor for the required
settings for the "Anonymous" user.
Examples:
• If the "Anonymous" user is deactivated or if the "Anonymous" user is activated and no
function rights have been assigned to that user, then nobody can log in without a user
name and password (corresponds to the access level "No access (complete protection")).
• If the "Anonymous" user is activated and the "Full access" function right for a CPU is
assigned to that user via a corresponding role, the result of this setting is "No protection".
You can achieve the same effect with regard to access protection by setting "No access
protection" in the "Protection & Security" area of the CPU properties.
348
S7-1500R/H redundant system
System Manual, 01/2024, A5E41814787-AF

Advertisement

Table of Contents
loading

This manual is also suitable for:

Simatic s7-1500r/h

Table of Contents