Configuration, programming
4.4 IP configuration
CP 1543-1
40
Operating Instructions, 12/2019, C79000-G8976-C289-08
Security settings of the CP
The settings of the internal CP firewall do not have an effect on communication over the
virtual interface. This means the security functions of the communication module cannot
protect the data traffic via the virtual interface.
NOTICE
Connecting to non-secure networks
Use of the virtual interface via the CP is only possible when the security functions of the CP
are disabled.
If you connect the CP to a non-secure network, it is absolutely necessary to connect an
additional firewall to the interface between the CP and the non-secure network. For this
purpose, use a security module, e.g. SCALANCE S602 V3 or S623.
4.4.5
Programmed connections: Restriction of firewall rules
Restrictions with programmed connections and configured security functions
In principle, it is possible to set up communications connections program-controlled using the
program block TCON and at the same time by configuring the firewall.
Note
Partner IP addresses not in firewall rules
When configuring specified connections (active endpoints) in STEP 7, the IP addresses of
the partners are not entered automatically in the firewall configuration.