Security recommendations
SCALANCE MUM856-1
12
Operating Instructions, 08/2021, C79000-G8976-C628-02
•
Enable only those services that are used on the device, including physical ports. Free
physical ports can potentially be used to gain access to the network behind the device.
•
For optimal security, use SNMPv3 authentication and encryption mechanisms whenever
possible, and use strong passwords.
•
Configuration files can be downloaded from the device. Ensure that configuration files are
adequately protected. The options for achieving this include digitally signing and
encrypting the files, storing them in a secure location, or transmitting configuration files
only through secure communication channels.
Configuration files can be password protected during download. You enter passwords on
the WBM page "System > Load & Save > Passwords".
•
When using SNMP (Simple Network Management Protocol):
–
Configure SNMP to generate a notification when authentication errors occur.
For more information, see WBM "System > SNMP > Notifications".
–
Ensure that the default community strings are changed to unique values.
–
Use SNMPv3 whenever possible. SNMPv1 and SNMPv2c are considered non-secure and
should only be used when absolutely necessary.
–
If possible, prevent write access above all.
Secure/ non-secure protocols
•
Use secure protocols if access to the device is not prevented by physical protection
measures.
•
Restrict the use of non-secure protocols. While some protocols are secure (e.g. HTTPS,
SSH, 802.1X, etc.), others were not designed for the purpose of securing applications (e.g.
SNMPv1/v2c, RSTP, etc.).
Therefore, take appropriate security measures against non-secure protocols to prevent
unauthorized access to the device/network. Use non-secure protocols on the device using
a secure connection (e.g. SINEMA RC).
•
If non-secure protocols and services are required, ensure that the device is operated in a
protected network area.
Содержание SIMATIC NET SCALANCE MUM856-1
Страница 58: ...Maintenance and cleaning SCALANCE MUM856 1 58 Operating Instructions 08 2021 C79000 G8976 C628 02 ...
Страница 68: ...Dimension drawings SCALANCE MUM856 1 68 Operating Instructions 08 2021 C79000 G8976 C628 02 Side view Top view ...
Страница 69: ...Dimension drawings SCALANCE MUM856 1 Operating Instructions 08 2021 C79000 G8976 C628 02 69 Rear view ...
Страница 70: ...Dimension drawings SCALANCE MUM856 1 70 Operating Instructions 08 2021 C79000 G8976 C628 02 ...
Страница 84: ...Approvals 10 5 General approvals SCALANCE MUM856 1 84 Operating Instructions 08 2021 C79000 G8976 C628 02 ...