System description
2
The security architecture provides for two main user groups: administrators and users associated with
a plant network. As a basic principle, administrators have access to all networks und administrative
functions of the ServiceServer; plant network users can only access the allocated plant network.
Abbildung 1.2. VPN-concept of the Remoteserviceproducts
Eurogard offers a free and efficient OpenVPN client which administers your certificates, logs access
times to various plants and securely sets up connections to the routers at the plant via a mouse click.
The Eurogard ServiceServer and router provide a complete solution for the remote access to IP-based
automation structures in machines and plants.
As the ServiceRouter, the ServiceServer has two network sides at its disposal.
• WAN-side
Used to connect the device to the Internet. Here, access to plant networks or to the LAN side is
only possible indirectly via VPN.
• LAN-side
This is the primary “working network”. Here, all units and PC’s have direct access to all plant
networks and their devices.
All data packets from LAN devices sent to the Internet via the Server are masked via Source-NAT by
the Server. As a consequence, only the external Server IP is outwardly visible, in case the device goes
online indirectly on the WAN-side via the in-house network. This helps to keep down the installation
and administration efforts and expenses.
A so-called service network is installed on the ServiceServer for each plant for which a remote
service is to be set up. This is shown on the right hand side of Abbildung 1.2, „VPN-concept of the
Remoteserviceproducts“. In order to allow for admin network access to each single network at the
same time, a unique network IP-address has to be assigned to each of these networks.
The next step is to create an account for an Eurogard ServiceRouter on the Server. A configuration
file is downloaded from the Server into the Router. This Router is parameterised and integrated into
the plant network. It acts as intermediary between the various devices of the plant and the service
network of the ServiceServer. All IP terminals of the plant can now be accessed via the LAN network
at the Server.
Содержание ServiceServer
Страница 1: ...Eurogard Service Server Manual Falk Sch nfeld schoenfeld eurogard de...
Страница 2: ...Eurogard Service Server Manual by Falk Sch nfeld Copyright 2011 2014 Eurogard GmbH...
Страница 5: ...Eurogard Service Server v A Wichtige Begriffe 46...
Страница 6: ...vi List of Figures 1 1 Eurogard ServiceServer 1 1 2 VPN concept of the Remoteserviceproducts 2...
Страница 30: ...Configuration options of the ServiceServer 23 Click the tab Contents and then Certifikates...