2 Abridged checklist
Check the following steps for each SCALANCE device:
• Use the latest firmware
• Disable "http" and use "https" instead
• Change default passwords for the users "admin" and "user"
• Disable "Telnet" and use "ssh" for the CLI instead
If not using CLI, disable "Telnet" and "ssh"
• Restrict DCP access to read-only
• Restrict SNMPv1/2 to read-only access at minimum, use of SNMP V3 is
preferred
• Use at least TLS version V1.2 / SFTP instead of TFTP / Syslog with TLS
• Switch off option 66, 67 for DHCP client
• Disable PROFINET interface if not using PROFINET
• Enable time synchronization
• With SCALANCE X, disable preset ring ports
• Disable "spanning tree" if it is not needed
• Disable the option "SINEMA Configuration Interface"
• If PROFINET data traffic is running over the device and no custom VLAN
configuration is being used, then enable "VLAN 0 aware mode"
(X-300) or "802.1D Transparent Bridge"
• Enable WLAN encryption and use WPA2
• Set the default gateway in all devices
If a gateway is not being used, still set the gateway address to an unused IP
address in the local network
• Create a configuration backup via WBM or C-Plug