Safety notes
2.1 Security recommendations
SCALANCE XR-500
12
Operating Instructions, 05/2017, A5E03275845-11
Software (security functions)
●
Keep the firmware up to date. Check regularly for security updates for the device. You will
find information on this on the Internet pages Industrial Security
http://www.siemens.com/industrialsecurity
●
Inform yourself regularly about security recommendations by Siemens ProductCERT
http://www.siemens.com/cert/en/cert-security-advisories.htm
●
Only activate protocols that you require to use the device.
●
Restrict access to the management of the device with rules in an access control list
(ACL).
●
The option of VLAN structuring provides protection against DoS attacks and unauthorized
access. Check whether this is practical or useful in your environment.
●
Use a central logging server to log changes and accesses. Operate your logging server
within the protected network area and check the logging information regularly.
Passwords
●
Define rules for the assignment of passwords.
●
Regularly change your passwords to increase security.
●
Use passwords with a high password strength.
●
Make sure that all passwords are protected and inaccessible to unauthorized persons.
●
Do not use the same password for different users and systems.
Certificates and keys
●
On the device there is a preset SSL certificate with key. Replace this certificate with a
self-made certificate with key. We recommend that you use a certificate signed either by
a reliable external or by an internal certification authority.
●
Use a certification authority including key revocation and management to sign certificates.
●
Make sure that user-defined private keys are protected and inaccessible to unauthorized
persons.
●
It is recommended that you use password-protected certificates in the PKCS #12 format
●
Verify certificates and fingerprints on the server and client to prevent "man in the middle"
attacks.
●
It is recommended that you use certificates with a key length of at least 2048 bits.
●
Change certificates and keys immediately, if there is a suspicion of compromise.
Содержание SCALANCE XR-500
Страница 16: ...Safety notes 2 1 Security recommendations SCALANCE XR 500 16 Operating Instructions 05 2017 A5E03275845 11 ...
Страница 36: ...Description of the device 3 5 Combo ports SCALANCE XR 500 36 Operating Instructions 05 2017 A5E03275845 11 ...
Страница 72: ...Connecting 5 8 Functional ground SCALANCE XR 500 72 Operating Instructions 05 2017 A5E03275845 11 ...
Страница 74: ...Uninstalling SCALANCE XR 500 74 Operating Instructions 05 2017 A5E03275845 11 ...
Страница 94: ...Technical data 8 5 Switching properties SCALANCE XR 500 94 Operating Instructions 05 2017 A5E03275845 11 ...
Страница 110: ...Certification 10 2 Mechanical stability in operation SCALANCE XR 500 110 Operating Instructions 05 2017 A5E03275845 11 ...