VPN tunnel between SCALANCE M-800 and security CPs
4.1 Procedure in principle
SCALANCE M-800 Getting Started
Getting Started, 06/2015, C79000-G8976-C337-04
145
Internal network
2
DSL router 192.168.184.254
Fixed IP address (WAN IP
address), e.g. 91.19.6.84
PC1 with CP
1628
For CP 1628: The IP address
of the NDIS interface, e.g.
192.168.184.10.
(is configured on PC1)
For CP 343-1 Advanced or
CP 434-1 Advanced: The IP
address of the PROFINET
For CP 1628: The IP address of
the Industrial Ethernet interface,
e.g. 192.168.184.2.
For CP 343-1 Advanced or
CP 434-1 Advanced:
The IP address of the Gbit
interface.
PC2 192.168.184.20
● The CP 1628 is connected to the Internet via the DSL router.
● In the properties of the CP, the internal IP address of the DSL router is configured as a
default gateway.
● the SCALANCE M-800 is connected to the WAN , refer to "Connecting SCALANCE M-
800 to the WAN (Page 11)".
● The SCALANCE M-800 can be reached via the Admin PC and you are logged in to the
WBM as "admin".
Steps in configuration
Example 1: Secure VPN tunnel with PSK
Configuring a VPN tunnel with the SCT V3.x
1. Creating project and modules with SCT (Page 147)
2. Configuring a tunnel connection (Page 148)
3. Downloading the configuration to the CP and saving the M-800 configuration (Page 150)
Configuring a VPN tunnel with the SCT V4.x
1. Creating project and modules with SCT (Page 152)
2. Configuring a tunnel connection (Page 154)
3. Downloading the configuration to the CP and saving the M-800 configuration (Page 156)
Configuring SCALANCE M-800
1. Activating VPN (Page 157)
2. Configuring the VPN remote end (Page 157)
3. Configuring a VPN connection (Page 158)
4. Configuring VPN authentication (Page 159)