Siemens SIMATIC S7-1500 System Manual page 350

Redundant system
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

Procedure
To activate the "Legacy access control" and set the required access level, follow these steps:
1. In the CPU properties, go to "Protection & Security > Access control".
2. Select the option "Activate access control" and, in addition, select the check box "Use legacy
access control via access levels" check box.
The access level selection cannot be used in this setting. You have to set the access level
via the "Anonymous" user of the CPU.
The "Anonymous" user is disabled in the default setting. This means that the resulting
access level for users without a password is "No access (complete protection)" (default
setting).
3. Go to "Security Settings > Users and roles" in the project navigation.
4. Activate the "Anonymous" user, if you want to set a different access level than "No access
(complete protection)". You can assign a role with function rights that grants access to the
CPU without password input, only to the activated "Anonymous" user.
5. You cannot assign function rights for a CPU directly to a user. You must first assign a role:
Therefore switch to the "Roles" tab and add a new role. Assign a meaningful name, e.g.
"PLC1-Read-Access-Role". If you assign this role to a user, this user should have read access
to PLC1 during operation.
6. Assign the required function right for the access to the CPU with the name "PLC1" to the role
"PLC1-Read-Access-Role" - in this case "Read access".
7. Switch to the "User" tab and assign the "PLC1-Read-Access-Role" role to the activated
"Anonymous" user.
Result: The "Anonymous" user has read access for PLC1. This means that the access level
tables of the CPU "PLC1" in the project are preset to "Read access" (cannot be changed)
and users who are not logged in only have read access.
For full access, or full access including fail-safe, you have to configure a password for the
full access in the table for the access protection. Users who need full access to the CPU
during runtime via an action, e.g. because a project is to be loaded onto the CPU, must
legitimize themselves for this action with this password.
Tip
To make the user rights transparent, use meaningful names for the respective roles. You
create users and roles for the entire project; you must select the function rights of a role
individually for each CPU in the project. With a descriptive name you can, for example,
immediately see which CPUs have read access and which CPUs are fully protected.
S7-1500R/H redundant system
System Manual, 01/2024, A5E41814787-AF
Protection
11.3 Local user management
349

Advertisement

Table of Contents
loading

This manual is also suitable for:

Simatic s7-1500r/h

Table of Contents