Configuration
4.9 Security (CP 1543SP-1)
CP 154xSP-1
72
Operating Instructions, 12/2019, C79000-G8976-C426-05
Use the procedure for disabling the node as explained below only if the described problem
occurs.
Disable the node in the SOFTNET Security Client tunnel overview:
1.
Remove the checkmark in the "Enable active learning" check box.
The lower-level node initially disappears from the tunnel list.
2.
In the tunnel list, select the required connection to the CP.
3.
With the right mouse button, select "Enable all members" in the shortcut menu.
The lower-level node appears again temporarily in the tunnel list.
4.
Select the lower-level node in the tunnel list.
5.
With the right mouse button, select "Delete entry" in the shortcut menu.
Result: The lower-level node is now fully disabled. VPN tunnel communication to the CP can
be established.
4.9.5.5
Establishment of VPN tunnel communication between the CP and SCALANCE M
Create a VPN tunnel between the CP and a SCALANCE M router as described for the
stations.
VPN tunnel communication will only be established if you have selected the check box
"Perfect Forward Secrecy" in the global security settings of the created VPN group ("VPN
groups > Authentication").
If the check box is not selected, the CP rejects establishment of the tunnel.
4.9.5.6
CP as passive subscriber of VPN connections
Setting permission for VPN connection establishment with passive subscribers
If the CP is connected to another VPN subscriber via a gateway, you need to set the
permission for VPN connection establishment to "Responder".
This is the case in the following typical configuration:
VPN subscriber (active)
⇔
gateway (dyn. IP address)
⇔
Internet
⇔
gateway (fixed IP
address)
⇔
CP (passive)
Configure the permission for VPN connection establishment for the CP as a passive
subscriber as follows:
1.
In STEP 7, go to the devices and network view.
2.
Select the CP.
3.
Open the parameter group "VPN“ in the local security settings.
4.
For each VPN connection with the CP as a passive VPN subscriber, change the default
setting "Initiator/Responder" to the setting "Responder".