VPN tunnel between SCALANCE M-800 and security CPs 
  4.1 Procedure in principle 
SCALANCE M-800 Getting Started 
Getting Started, 06/2015, C79000-G8976-C337-04 
145 
Internal network 
2 
DSL router  192.168.184.254 
Fixed IP address (WAN IP 
address), e.g. 91.19.6.84 
PC1 with CP 
1628 
For CP 1628: The IP address 
of the NDIS interface, e.g. 
192.168.184.10. 
(is configured on PC1) 
For CP 343-1 Advanced or 
CP 434-1 Advanced: The IP 
address of the PROFINET 
For CP 1628: The IP address of 
the Industrial Ethernet interface, 
e.g. 192.168.184.2. 
For CP 343-1 Advanced or 
CP 434-1 Advanced:  
The IP address of the Gbit 
interface. 
PC2  192.168.184.20 
 
●  The CP 1628 is connected to the Internet via the DSL router. 
●  In the properties of the CP, the internal IP address of the DSL router is configured as a 
default gateway. 
●  the SCALANCE M-800 is connected to the WAN , refer to "Connecting SCALANCE M-
800 to the WAN (Page 11)". 
●  The SCALANCE M-800 can be reached via the Admin PC and you are logged in to the 
WBM as "admin". 
Steps in configuration 
Example 1: Secure VPN tunnel with PSK
 
Configuring a VPN tunnel with the SCT V3.x 
1.  Creating project and modules with SCT (Page 147) 
2.  Configuring a tunnel connection (Page 148) 
3.  Downloading the configuration to the CP and saving the M-800 configuration (Page 150) 
Configuring a VPN tunnel with the SCT V4.x 
1.  Creating project and modules with SCT (Page 152) 
2.  Configuring a tunnel connection (Page 154) 
3.  Downloading the configuration to the CP and saving the M-800 configuration (Page 156) 
Configuring SCALANCE M-800 
1.  Activating VPN (Page 157) 
2.  Configuring the VPN remote end (Page 157) 
3.  Configuring a VPN connection (Page 158) 
4.  Configuring VPN authentication (Page 159)