Special functions of the CPU 410
9.4 Field Interface Security
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
139
9.4
Field Interface Security
Activating additional protection at the DP or PNIO interface
If want to prevent access to the CPU over the DP or PNIO interface, you can block that
access.
To achieve the greatest possible protection from unauthorized access, you can disable all
functions that are not required for the actual automation task. For the IO interfaces (DP and
PN), this means that all incoming connection requests are rejected.
You can prevent an incoming connection attempt for each interface with the setting "Activate
additional protection at the interface (Field Interface Security)" in HW Config. This prevents
any connections being established by external bus nodes. All requests are then rejected.
The connections required for IO operation are still established from the CPU
Features of disable
●
If you have set a disable for a specific interface, connections that have already been
established passively over this interface will be terminated. This applies for all connection
types.
●
If an incoming connection is rejected because a disable is set, a security event (SysLog)
is generated.
●
A T_CONNECT for a passive connection (ISOonTCP or TCP) is canceled and an error
output at a disabled interface.
●
The receipt of UDP message frames (TURCV, both active and passive) is not possible at
a blocked interface. TURCV is canceled and an error output.
●
The disable applies irrespective of the CPU protective levels.
●
For configured H connections with individual partial connections both over X5 and over
X8, the partial connections are terminated.
9.5
Access-protected blocks
S7-Block Privacy
The STEP 7 add-on package S7-Block Privacy can be used to protect the functions and
function blocks against unauthorized access.
Observe the following information when using S7-Block Privacy:
●
S7-Block Privacy is operated by means of shortcut menus. To view a specific menu help,
press the "F1" function key.
●
You can no longer edit protected blocks in STEP 7. Moreover, testing and commissioning
functions such as "Monitor blocks" or breakpoints are no longer available. Only the
interfaces of the protected block remain visible.