Configuration and operation 
  4.13 Security functions 
CP 1243-7 LTE 
Operating Instructions, 01/2015, C79000-G8976-C381-01 
59 
With Industrial Ethernet Security, individual devices or network segments of an Ethernet 
network can be protected: 
●  Access to individual devices and network segments protected by security modules is 
allowed. 
●  Secure connections via non-secure network structures becomes possible. 
Due to the combination of different security measures such as firewall, NAT/NAPT routers 
and VPN via IPsec tunnels, security modules protect against the following: 
●  Data espionage 
●  Data manipulation 
●  Unwanted access 
 
Addressing the CP when using VPN 
IP addresses and VPN ports 
In normal mobile wireless networks it is not possible to reach a dynamic IP address assigned 
to the CP by the mobile wireless network provider from the Internet. For this reason, for 
incoming connections make sure that the CP is assigned a fixed public IP address by the 
mobile wireless network provider. 
You must also make sure that apart from this IP address, the ports required for VPN are 
reachable from the Internet. 
 
Creating a VPN tunnel for S7 communication between stations 
Requirements 
To allow a VPN tunnel to be created for S7 communication between two S7 stations or 
between an S7 station and an engineering station with a security CP (for example CP 1628), 
the following requirements must be met: 
●  The two stations have been configured. 
●  The CPs in both stations must support the security functions. 
●  The Ethernet interfaces of the two stations are located in the same subnet. 
●  All receiving stations require a fixed IP address to be reachable via the public networks. 
For this, a special mobile wireless contract is normally necessary for the mobile wireless 
CP. 
 
Note 
Communication also possible via an IP router 
Communication between the two stations is also possible via an IP router. To use this 
communications path, however, you need to make further settings.