Safety Instructions
2.2 Security information
SIMATIC IPC1047E
Operating Instructions, 03/2021, A5E50259546-AA
25
NOTICE
Danger for machine and plant through unauthorized access
IPMI (Intelligent Platform Management Interface) permits remote monitoring and remote
maintenance of the device. There is a risk of unauthorized remote access with damage to
the machine and plant.
•
Keep the IPMI firmware up to date.
•
Remote access possibilities are disabled by default. Only enable them if absolutely
necessary.
Observe the following general information on operating systems and software on the
device:
•
Disable or uninstall any unnecessary services.
•
Immediately install the latest security updates and patches provided (by Microsoft).
•
Encrypt security-relevant and confidential data.
IPMI remote monitoring has a device-specific password in the delivery state. This password
can be found in a sticker behind the lockable front door. If accessible to third parties,
unauthorized access to the device is possible.
•
Change the device-specific password immediately after commissioning the device.
•
Assign a strong user name and password.
You can find additional information in the sections "Monitoring functions (Page 50)" and
"IPMI Setup (Page 102)".
The IPMI interface is a dedicated Ethernet interface which can only be used for this purpose.
•
To prevent unauthorized access, only operate the IPMI interface in a dedicated network.
•
Alternatively, do not connect IPMI-enabled devices to the Internet or any network at all.
Note
BIOS protection
An unauthorized user can access the device by booting, via the BIOS or USB and cause
damage to the machine and plant.
Proceed as follows in the BIOS setup:
•
Set the supervisor password.
Make a note of this password and keep it in a suitable location that is protected against
unauthorized access.
•
Disable keyboard operation during the BIOS self test (POST).
•
Disable the possibility to boot from USB unless absolutely necessary.
•
Disable the response of the Windows operating system to plugging in a USB device.
•
Keep the BIOS firmware up to date.
You can obtain more detailed information about the BIOS setup from the manufacturer in the
manual on the motherboard (Page 108).