Recommendations on network security
3
NOTICE
Information security
Connect to the device and change the standard password for the user set in the factory "admin"
and "" before you operate the device.
To prevent unauthorized access to the device and/or network, observe the following security
recommendations.
General
• Check the device regularly to ensure that these recommendations and/or other internal
security policies are complied with.
• Evaluate the security of your location and use a cell protection concept with suitable products
https://www.industry.siemens.com/topics/global/en/industrial-security/pages/
• When the internal and external network are disconnected, an attacker cannot access internal
data from the outside. Therefore operate the device only within a protected network area.
• No product liability will be accepted for operation in a non-secure infrastructure.
• Use VPN to encrypt and authenticate communication from and to the devices.
• For data transmission via a non-secure network, use an encrypted VPN tunnel (IPsec,
OpenVPN).
• Separate connections correctly (WBM, SSH etc.).
• Check the user documentation of other Siemens products that are used together with the
device for additional security recommendations.
• Using remote logging, ensure that the system protocols are forwarded to a central logging
server. Make sure that the server is within the protected network and check the protocols
regularly for potential security violations or vulnerabilities.
Physical access
• Restrict physical access to the device to qualified personnel.
– The memory card or the PLUG (C-PLUG, KEY-PLUG) contains sensitive data such as
certificates, keys etc. that can be read out and modified.
– Using the button, you can reset the device to the factory defaults.
• If the device is publicly accessible, disable the functions of the button using the software.
• Lock unused physical ports on the device. Unused ports can be used to gain forbidden access
to the plant.
MM900 media modules for SCALANCE XR-500M
Compact Operating Instructions, 04/2022, A5E03275846-05
9