Application and functions
1.7 Security functions for communication
RTU303xC
Operating Instructions, 06/2019, C79000-G8976-C382-06
33
OpenVPN
For different connections, the RTU uses the VPN technology of OpenVPN. Between the
RTU and the connection partner, a VPN tunnel is established via an open VPN server and
the RTU is the OpenVPN client.
The RTU can use the security functions of the "OpenVPN" service for the following
connections:
●
Connections of the RTU to a DNP3 master
●
Connections of the RTU to an IEC master
●
Connections of the RTU to an ST7 partner
●
Connections of the RTU to the telecontrol server
●
Connections of the RTU with a Syslog server
●
FTP file transfer
●
Connections of a configuration PC to the RTU via the Internet (only HTTP) and the mobile
wireless network
No OpenVPN is required for the connection of a service PC to the RTU via the Web
server of TCSB.
●
SNTP
An OpenVPN server is required to establish the connections listed above (see below).
OpenVPN is implemented on the RTU as a TUN device (routing mode). The following
security functions are supported:
●
Encryption
The data to be transferred is encrypted with the CBC method. As standard, AES-256 or
BF (Blowfish in Cipher Block Chaining) can be used.
Note: BlowFish is no longer considered secure and is currently only supported for
reasons of compatibility.
●
Authentication of the connection partner
SHA-1, SHA-224 or SHA-256 can be used as hash algorithms for authenticating the user
data.
The RTU uses OpenVPN version V2.3.11.
OpenVPN server
The OpenVPN server must support the following functions:
●
OpenVPN V2.3.11 or higher
●
OpenSSL with TLS as of version 1.2
●
Configuration of the server for TLS version 1.2
●
Use of "tls-version-min 1.0" in the OpenVPN configuration
Содержание Simatic RTU3030C
Страница 248: ...Configuration WBM 4 24 Tag tables RTU303xC 248 Operating Instructions 06 2019 C79000 G8976 C382 06 ...
Страница 350: ...Dimension drawings RTU303xC 350 Operating Instructions 06 2019 C79000 G8976 C382 06 Figure B 2 Side view ...
Страница 376: ...Accessories C 7 Overvoltage protection modules RTU303xC 376 Operating Instructions 06 2019 C79000 G8976 C382 06 ...
Страница 390: ...Documentation references E 10 10 RTU303xC 390 Operating Instructions 06 2019 C79000 G8976 C382 06 ...