Configuration and operation
4.8 Security functions
CP 1243-8 IRC
Operating Instructions, 06/2015, C79000-G8976-C385-01
95
Select the "Allow*" action for S7 connections in advanced firewall mode ("Security > Firewall
> IP rules") for both communications directions of the VPN tunnel.
4.8.2.3
Online diagnostics and downloading to station with the firewall activated
Setting the firewall - steps involved
With the security function enabled, follow the steps outlined below:
1.
In the global security settings (see project tree), select the entry "Firewall > Services >
Define services for IP rules".
2.
Select the "ICMP" tab.
3.
Insert a new entry of the type "Echo Reply" and another of the type "Echo Request".
4.
Now select the CP in the S7-1200 station.
5.
Enable the advanced firewall mode in the local security settings of the CP in the "Security
> Firewall" parameter group.
6.
Open the "IP rules" parameter group.
7.
In the table, insert a new IP rule for the previously created global services as follows:
–
Action: Allow; "From external -> To station " with the globally created "Echo request"
service
–
Action: Allow; "From station -> to external" with the globally created "Echo reply"
service
8.
For the IP rule for the Echo Request, enter the IP address of the PG/PC in "Source IP
address". This ensures that only PING packets from your PG/PC can pass through the
firewall.
4.8.2.4
Notation for the source IP address (advanced firewall mode)
If you specify an address range for the source IP address in the advanced firewall settings of
the CP, make sure that the notation is correct:
●
Separate the two IP addresses only using a hyphen.
Correct: 192.168.10.0-192.168.10.255
●
Do not enter any other characters between the two IP addresses.
Incorrect: 192.168.10.0 - 192.168.10.255
If you enter the range incorrectly, the firewall rule will not be used.
Содержание CP 1243-8 IRC
Страница 10: ...Table of contents CP 1243 8 IRC 10 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 104: ...Diagnostics and upkeep 6 3 Module replacement CP 1243 8 IRC 104 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 112: ...Approvals CP 1243 8 IRC 112 Operating Instructions 06 2015 C79000 G8976 C385 01 ...
Страница 114: ...Dimension drawings CP 1243 8 IRC 114 Operating Instructions 06 2015 C79000 G8976 C385 01 Figure B 2 From above ...
Страница 134: ...Accessories C 4 Connecting cables CP 1243 8 IRC 134 Operating Instructions 06 2015 C79000 G8976 C385 01 ...