Configuring with Web Based Management 
  4.7 "Security" menu 
SCALANCE SC-600 Web Based Management (WBM) 
Configuration Manual, 10/2021, C79000-G8976-C475-03 
329 
•  Operation 
Specify who establishes the VPN connection. You will find more detailed information 
in "Technical basics > VPN connection establishment (Page 64)". 
–  Disabled 
The VPN connection is disabled. 
–  start 
The device attempts to establish a VPN connection to the partner. 
–  wait 
The device waits for the partner to initiate the connection establishment. 
–  on demand 
The VPN connection is established when necessary. 
–  start on DI 
If the event "Digital In" occurs, the device attempts to establish a VPN connection 
to the partner. 
This is on condition that the event "Digital In" is forwarded to the VPN connection. 
For this purpose, enable "VPN tunnel" for the "Digital In" event under "System" > 
"Events" > "Configuration". 
–  wait on DI 
If the event "Digital In" occurs, the device waits for the partner to initiate 
connection establishment. 
This is on condition that the event "Digital In" is forwarded to the VPN connection. 
This is on condition that the event "Digital In" is forwarded to the VPN connection. 
For this purpose, enable "VPN tunnel" for the "Digital In" event under "System" > 
"Events" > "Configuration". 
•  Keying Protocol 
Specify whether IKEv2 or IKEv1 will be used. 
•  Interface 
Select the interface via which a VPN connection is being established. 
•  Remote End 
Select the required remote station. Only partners that have been configured on the 
"Remote End" WBM page can be configured. 
•  Local Subnet 
Enter the local subnet. Use the CIDR notation. The local network can also be a single 
PC or another subset of the local network. Multiple subnets can be used only with 
IKEv2. In this case, enter the subnets separated by a comma.