Properties and services
1.4 Further services and characteristics of the CP
CP 443-1 Advanced (GX30)
18
Manual, 03/2019, C79000-G8976-C256-05
1.4
Further services and characteristics of the CP
●
Security functions
Depending on the configuration, the security functions of the CP provide protected
communication beyond network boundaries and within a network.
–
Protection concept beyond network boundaries - separation of the internal from the
external network
On its gigabit interface, the CP provides the option of secure access from an external
network connected here to the internal network (PROFINET interface).
With a combination of different security measures such as firewall, NAT/NAPT routers
and VPN (Virtual Private Network) over IPsec tunnels, the CP protects individual
devices or even entire automation cells from unauthorized access.
The CP allows this protection flexibly, without repercussions, protocol-independent (as
of Layer 2 according to IEEE 802.3).
The secure protocols HTTPS, FTPS, NTP (secure) and SNMPv3 can also be
activated.
–
Communication in the internal network (PROFINET interface)
If security is enabled, you now have the option of using the secure protocols HTTPS,
FTPS, NTP (secure) and SNMPv3 within the internal network.
Note: The switch function of the PROFINET interface integrated in the CP forwards
frames in the internal subnet regardless of the security setting of the CP.
–
SMTPS with STARTTLS
Support of SSL/TLS encryption for the secure transfer of e-mails
Note
UDP multicast
UDP multicast via a VPN channel is not supported.
You need to enable the security functions in the configuration.