Secure/non-secure protocols
• Avoid or disable non-secure protocols, for example Telnet and TFTP. For historical reasons,
these protocols are available, however not intended for secure applications. Use non-secure
protocols on the device with caution.
• Check whether use of the following protocols and services is necessary:
– Non authenticated and unencrypted ports
– MRP, HRP
– LLDP
– DHCP Options 66/67
The following protocols provide secure alternatives:
– HTTP → HTTPS
– TFTP → FTPS
– Telnet → SSH
– SNTP → NTP
Check whether use the use of NTP is necessary. NTP is classified as non-secure. Activate
Secure NTP when the NTP server supports this protocol and use the authentication and
encryption mechanisms of Secure NTP.
– SNMPv1/v2c → SNMPv3
Check whether use of SNMPv1/v2c. is necessary. SNMPv1/v2c are classified as non-
secure. Use the option of preventing write access. The device provides you with suitable
setting options.
If SNMP is enabled, change the community names. If no unrestricted access is necessary,
restrict access with SNMP.
Use the authentication and encryption mechanisms of SNMPv3.
• Use secure protocols when access to the device is not prevented by physical protection
measures.
• If you require non-secure protocols and services, operate the device only within a protected
network area.
• Restrict the services and protocols available to the outside to a minimum.
• For the DCP function, enable the "DCP read-only" mode after commissioning.
Available protocols
The following list provides you with an overview of the open protocol ports.
The table includes the following columns:
• Protocol
• Port number
• Port status
– Open
– Closed
Recommendations on network security
SCALANCE X-200
16
Operating Instructions, 11/2021, C79000-G8976-C284-15
Содержание SIMATIC NET SCALANCE X-200
Страница 8: ...Introduction SCALANCE X 200 8 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 12: ...Safety notices SCALANCE X 200 12 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 18: ...Recommendations on network security SCALANCE X 200 18 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 56: ...Installation and removal 4 9 Disassembly SCALANCE X 200 56 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 80: ...Maintenance and cleaning SCALANCE X 200 80 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 92: ...Technical specifications SCALANCE X 200 92 Operating Instructions 11 2021 C79000 G8976 C284 15 ...
Страница 110: ...Index SCALANCE X 200 110 Operating Instructions 11 2021 C79000 G8976 C284 15 ...