Use Cases
SICAM A8000 / CP-8000 • CP-8021 • CP-8022 Manual Unrestricted 599
DC8-037-2.02, Edition 10.2017
E.7 Usage of the Internal GPRS Modem (CP-8022)
Features/Settings for Application without IPsec VPN
• Communication with the control system via IEC 60870-5-104 (GPRS interface X7)
• The default router is in this case the GPRS network and that is adjusted internally with
connection setup. It can not be parameterized.
• Network settings | GPRS | enable GPRS communication = YES
Features/Settings for Application with IPsec VPN
• Communication with the control system via IEC 60870-5-104 (GPRS interface X7)
• Network settings | Security | IP security enabled = YES
Afterwards, the parameters which are required for the configuration of the IPSec connec-
tion, are available under Network settings | Security | IP security :
ICMP ping reply
IPSec VPN tunnel 1 enabled
IPSec VPN tunnel 2 enabled
Local site | Identifier (Local ID)
Remote site 1 | Identifier (Remote ID)
Remote site 1 | IP-Address
Remote site 1 | Subnet IP-Address
Remote site 1 | Subnet mask
IKE security associations 1 | Internet key exchange (IKE) Version
IKE security associations 1 | SA lifetime (timeout)
IKE security associations 1 | Auto-selection of authentication & en-
cryption
*)
IPSec authentication | Pre-shared key
IPSec security associations 1 | SA lifetime (timeout)
IPSec security associations 1 | SA lifetime (data size limit)
IPSec security associations 1 | Auto-selection of authentication & en-
cryption
*)
IPSec tunnel supervision by ping 1 | Ping enabled
IPSec tunnel supervision by ping 1 | Ping cycle time
IPSec tunnel supervision by ping 1 | Ping peer IP-address
___
*)
if NO:
Encryption algorithm
Authentication algorithm
Diffie Hellman group
Note for network configuration
CP-8022 and the remote station must be configured in different networks when IPSec VPN is used.
The parameters Remote site <x> |Subnet IP address and Remote site <x> |Subnet mask
are necessary for the SICAM A8000 internal router function.
The certificate SHA256 must be used (obsolete: SHA1).
In Google Chrome ® the cache must be deleted before the logon with SICAM WEB via https.
For routing in 2 tunnels it is necessary to define both remote stations (remote site 1 and remote site 2).