Application and properties
1.3 Other services and properties
CP 1243-8 IRC
Operating Instructions, 06/2015, C79000-G8976-C385-01
17
Industrial Ethernet Security - Security functions of the CP
With Industrial Ethernet Security, individual devices, automation cells or network segments
of an Ethernet network can be protected. The data transfer via the CP can be protected from
the following attacks by a combination of different security measures:
●
Data espionage
●
Data manipulation
●
Unwanted access
Secure underlying networks can be operated via additional Ethernet/PROFINET interfaces of
the CPU.
The following security functions can be used independently of telecontrol communication. As
a result of using the CP, as a security module, the following security functions are accessible
to the S7-1200 station on the interface to the external network:
●
Firewall
–
IP firewall with stateful packet inspection (layer 3 and 4)
–
Firewall also for "non-IP" Ethernet frames according to IEEE 802.3 (layer 2)
–
Limitation of the transmission speed ("Bandwidth limitation")
–
Global firewall rule sets
●
Protection for devices and network segments
The protection provided by the firewall can cover individual devices, several devices or
even entire network segments.
●
Communication made secure by IPsec tunnels (VPN)
VPN tunnel communication allows the establishment of secure IPsec tunnels for
communication with one or more security modules.
The CP can be put together with other modules to form VPN groups during configuration.
IPsec tunnels (VPN) are created between all security modules of a VPN group. All
internal nodes of these security modules can communicate securely with each other
through these tunnels.
●
Logging
To allow monitoring, events can be stored in log files that can be read out using the
configuration tool or can be sent automatically to a Syslog server.
●
NTP (secure)
For secure transfer during time-of-day synchronization (with telecontrol communication
disabled)
●
STARTTLS / SMTPS
For the secure transfer of e-mails
●
HTTPS
For secure access to the Web server of the CPU
●
SNMPv3
For secure transmission of network analysis information safe from eavesdropping
Содержание CP 1243-8 IRC
Страница 10: ...Table of contents CP 1243 8 IRC 10 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 104: ...Diagnostics and upkeep 6 3 Module replacement CP 1243 8 IRC 104 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 112: ...Approvals CP 1243 8 IRC 112 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 114: ...Dimension drawings CP 1243 8 IRC 114 Operating Instructions 06 2015 C79000 G8976 C385 01 Figure B 2 From above ...
Страница 134: ...Accessories C 4 Connecting cables CP 1243 8 IRC 134 Operating Instructions 06 2015 C79000 G8976 C385 01 ...