
Security recommendations
SCALANCE W774-1 /W734-1
Operating Instructions, 07/2020, C79000-G8976-C325-14
9
Secure/non-secure protocols and services
•
Avoid and disable non-secure protocols, for example Telnet and TFTP. For historical
reasons, these protocols are still available, however not intended for secure
applications. Use non-secure protocols on the device with caution.
•
Check whether use of the following protocols and services is necessary:
–
Non-authenticated and unencrypted ports
–
LLDP
–
Syslog
–
DHCP options 66/67
–
TFTP
•
The following protocols provide secure alternatives:
–
SNMPv1/v2c
→
SNMPv3
Check whether use of SNMPv1/v2c is necessary. SNMPv1/v2c is classified as
non-secure. Use the option of preventing write access. The product provides you
with suitable setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
Use SNMPv3 in conjunction with passwords.
–
HTTP
→
HTTPS
–
Telnet
→
SSH
–
TFTP
→
SFTP
•
Use secure protocols when access to the device is not prevented by physical
protection measures.
•
To prevent unauthorized access to the device or network, take suitable protective
measures against non-secure protocols.
•
If you require non-secure protocols and services, operate the device only within a
protected network area.
•
Restrict the services and protocols available to the outside to a minimum.
•
For the DCP function, enable the "Read Only" mode after commissioning.
Содержание SIMATIC NET SCALANCE W734-1
Страница 12: ...Security recommendations SCALANCE W774 1 W734 1 12 Operating Instructions 07 2020 C79000 G8976 C325 14 ...
Страница 64: ...Approvals SCALANCE W774 1 W734 1 64 Operating Instructions 07 2020 C79000 G8976 C325 14 ...
Страница 66: ...Index SCALANCE W774 1 W734 1 66 Operating Instructions 07 2020 C79000 G8976 C325 14 Type designations 14 ...