Properties and services   
1.4 Further services and characteristics of the CP 
  CP 443-1 Advanced (GX30) 
18  Manual, 03/2019, C79000-G8976-C256-05 
 
Further services and characteristics of the CP 
● 
 
Depending on the configuration, the security functions of the CP provide protected 
communication beyond network boundaries and within a network. 
– 
Protection concept beyond network boundaries - separation of the internal from the 
external network
 
On its gigabit interface, the CP provides the option of secure access from an external 
network connected here to the internal network (PROFINET interface). 
With a combination of different security measures such as firewall, NAT/NAPT routers 
and VPN (Virtual Private Network) over IPsec tunnels, the CP protects individual 
devices or even entire automation cells from unauthorized access. 
The CP allows this protection flexibly, without repercussions, protocol-independent (as 
of Layer 2 according to IEEE 802.3). 
The secure protocols HTTPS, FTPS, NTP (secure) and SNMPv3 can also be 
activated. 
– 
Communication in the internal network (PROFINET interface)
 
If security is enabled, you now have the option of using the secure protocols HTTPS, 
FTPS, NTP (secure) and SNMPv3 within the internal network. 
Note: The switch function of the PROFINET interface integrated in the CP forwards 
frames in the internal subnet regardless of the security setting of the CP. 
– 
 
Support of SSL/TLS encryption for the secure transfer of e-mails 
 
Note 
UDP multicast 
UDP multicast via a VPN channel is not supported.
 
You need to enable the security functions in the configuration.