Description
2.2 Setting up PROFINET
PROFINET with STEP 7
Function Manual, 05/2021, A5E03444486-AL
41
Protective measures
The most important precautions to prevent manipulation and loss of data security in the
industrial environment are:
•
Physical access protection to the devices
•
Filtering and control of data traffic by means of firewall
•
A virtual private network (VPN) is used to exchange private data on a public network
(Internet, for example).
The most common VPN technology is IPsec. IPsec (Internet Protocol Security) is a
collection of security protocols that are used as the basis for the IP protocol at the
mediation level and allow a secured communication via potentially unsecure IP networks.
•
Segmenting in protected automation cells
This concept has the aim of protecting the lower-level network devices by means of
security modules. A group of protected devices forms a protected automation cell.
•
Authentication (identification) of the devices
The security modules identify each other over a safe (encrypted) channel using
authentication procedures. It is therefore impossible for unauthorized parties to access a
protected segment.
•
Encrypting the data traffic
The confidentiality of data is ensured by encrypting the data traffic. Each security module
is given a VPN certificate which includes the encryption key.
2.2.4.2
Network components and software
Protection against unauthorized access
The following solutions may be used to connect industrial networks to the intranet and
Internet to protect against internal and external threats:
•
Communication processors, such as the SIMATIC CP 1543-1
•
SCALANCE X-300 and SCALANCE S - the data security components of the SIMATIC NET
product family
•
SOFTNET security client for use on PCs
Features
Both of these products have a wide variety of features, such as:
•
Easy integration of existing networks without configuration, with integrated firewall.
•
Segmenting in protected automation cells
•
Authentication (identification) of the devices
•
Encrypting the data traffic
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......