Configuration
4.11 Security
CP 1243-7 LTE
70
Operating Instructions, 04/2017, C79000-G8976-C381-03
●
Secure access to a server ("end-to-end" connection)
●
Communication between two servers without being accessible to third parties (end-to-end
or host-to-host connection)
●
Protection of computers and their communication within and automation network
●
Secure remote access from a PC/PG to automation devices or networks protected by
security modules via public networks.
4.11.6.2
Addressing the CP when using VPN
IP addresses and VPN ports
In normal mobile wireless networks it is not possible to reach a dynamic IP address assigned
to the CP by the mobile wireless network provider from the Internet. For this reason, for
incoming connections make sure that the CP is assigned a fixed public IP address by the
mobile wireless network provider.
You must also make sure that apart from this IP address, the ports required for VPN are
reachable from the Internet.
4.11.6.3
Creating a VPN tunnel for S7 communication between stations
Requirements
To allow a VPN tunnel to be created for S7 communication between two S7 stations or
between an S7 station and an engineering station with a security CP (for example CP 1628),
the following requirements must be met:
●
The two stations have been configured.
●
The CPs in both stations must support the security functions.
●
The Ethernet interfaces of the two stations are located in the same subnet.
●
All receiving stations require a fixed IP address to be reachable via the public networks.
For this, a special mobile wireless contract is normally necessary for the mobile wireless
CP.
Note
Communication also possible via an IP router
Communication between the two stations is also possible via an IP router. To use this
communications path, however, you need to make further settings.