Safety notices
1.1 Security recommendations
SCALANCE XP-200
14
Operating Instructions, 05/2016, C79000-G8976-C428-01
Secure/non-secure protocols
●
Avoid or disable non-secure protocols, for example Telnet and TFTP. For historical
reasons, these protocols are still available, however not intended for secure applications.
Use non-secure protocols on the device with caution.
●
Avoid or disable non-secure protocols. Check whether use of the following protocols is
necessary:
–
PROFINET
–
Broadcast pings
–
Non authenticated and unencrypted interfaces
–
ICMP (redirect)
–
MRP, HRP
–
GMRP and IGMP
–
LLDP
–
Syslog
–
RADIUS
–
DHCP Options 66/67
–
TFTP
–
GMRP and GVRP
–
Multicast routing
●
The following protocols provide secure alternatives:
–
SNMPv1/v2
→
SNMPv3
Check whether use of SNMPv1 is necessary. SNMPv1 is classified as non-secure.
Use the option of preventing write access. The product provides you with suitable
setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
Use SNMPv3 in conjunction with passwords.
–
HTTP
→
HTTPS
–
TFTP
→
FTPS
–
Telnet
→
SSH
–
SNTP
→
NTP
●
Use secure protocols when access to the device is not prevented by physical protection
measures.
●
To prevent unauthorized access to the device or network, take suitable protective
measures against non-secure protocols.
●
If you require non-secure protocols and services, operate the device only within a
protected network area.
Summary of Contents for SCALANCE XP-200
Page 8: ...Introduction SCALANCE XP 200 8 Operating Instructions 05 2016 C79000 G8976 C428 01 ...
Page 84: ...Dimension drawings SCALANCE XP 200 84 Operating Instructions 05 2016 C79000 G8976 C428 01 ...
Page 92: ...Approvals SCALANCE XP 200 92 Operating Instructions 05 2016 C79000 G8976 C428 01 ...