Communications services
3.6 Secure Communication
Communication
Function Manual, 05/2021, A5E03735815-AJ
73
3.6.3
Secure Open User Communication
3.6.3.1
Secure OUC of an S7-1500 CPU as TLS client to an external PLC (TLS server)
The following section describes how you can set up Open User Communication via TCP from
an S7-1500 CPU as TLS client to a TLS server.
Setting up a secure TCP connection from an S7-1500 CPU as TLS client to a TLS server
S7-1500 CPUs as of firmware version V2.0 support secure communication with addressing via
a Domain Name System (DNS).
For secure TCP communication over the domain name you need to create a data block with
the TCON_QDN_SEC system data type yourself, assign parameters and call it directly at one of
the instructions TSEND_C, TRCV_C or TCON.
Requirements:
•
Current date and time are set in the CPU.
•
Your network includes at least one DNS server.
•
You have configured at least one DNS server for the S7-1500 CPU.
•
TLS client and TLS server have all the required certificates.
To set up a secure TCP connection to a TLS server, follow these steps:
1.
Create a global data block in the project tree.
2.
Define a tag of the data type TCON_QDN_SEC in the global data block.
The example below shows the global data block "Data_block_1" in which the tag
"DNS ConnectionSEC" of the data type TCON_QDN_SEC is defined.
Figure 3-18 Data type TCON_QDN_SEC
3.
Set the connection parameters of the TCP connection in the "Start value" column. Enter the
fully qualified domain name (FQDN) of the TLS server, for example, for "RemoteQDN".
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......