EasyManuals Logo
Home>Siemens>Network Router>SIMATIC NET ET 200SP

Siemens SIMATIC NET ET 200SP User Manual

Siemens SIMATIC NET ET 200SP
122 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #91 background imageLoading...
Page #91 background image
Configuration and operation
4.6 Security configuration(CP 1543SP-1)
CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1
Operating Instructions, 01/2017, C79000-G8976-C426-03
91
VPN subscriber (active) ⇔ gateway (dyn. IP address) ⇔ Internet ⇔ gateway (fixed IP
address) ⇔ CP (passive)
Configure the permission for VPN connection establishment for the CP as a passive
subscriber as follows:
1. In STEP 7, go to the devices and network view.
2. Select the CP.
3. Open the parameter group "VPN“ in the local security settings.
4. For each VPN connection with the CP as a passive VPN subscriber, change the default
setting "Initiator/Responder" to the setting "Responder".
4.6.2
Firewall
4.6.2.1
Pre-check of messages by the MAC firewall.
Each incoming or outgoing frame initially runs through the MAC firewall (layer 2). If the frame
is discarded at this level, it will not be checked by the IP firewall (layer 3). This means that
with suitable MAC firewall rules, IP communication can be restricted or blocked.
4.6.2.2
Online diagnostics and downloading to station with the firewall activated
Setting the firewall - steps involved
With the security function enabled, follow the steps outlined below:
1. In the global security settings (see project tree), select the entry "Firewall > Services >
Define services for IP rules".
2. Select the "ICMP" tab.
3. Insert a new entry of the type "Echo Reply" and another of the type "Echo Request".
4. Now select the CP in the ET 200SP station.
5. Enable the advanced firewall mode in the local security settings of the CP in the "Security
> Firewall" parameter group.
6. Open the "IP rules" parameter group.
7. In the table, insert a new IP rule for the previously created global services as follows:
Action: Allow; "From external -> To station " with the globally created "Echo request"
service
Action: Allow; "From station -> to external" with the globally created "Echo reply"
service
8. For the IP rule for the Echo Request, enter the IP address of the PG/PC in "Source IP
address". This ensures that only PING packets from your PG/PC can pass through the
firewall.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Siemens SIMATIC NET ET 200SP and is the answer not in the manual?

Siemens SIMATIC NET ET 200SP Specifications

General IconGeneral
BrandSiemens
ModelSIMATIC NET ET 200SP
CategoryNetwork Router
LanguageEnglish

Related product manuals