Technical basics
3.8 Security functions
SCALANCE SC-600 Web Based Management (WBM)
56 Configuration Manual, 10/2021, C79000-G8976-C475-03
You configure the firewall in "Security > Firewall".
Note
IP packets via layer 2 (within the same VLAN)
If the IP packets from the device are sent via a switch port (layer 2), these IP packets are
not checked based on firewall rules. The firewall has no effect on packets forwarded
at
Communication directions
Access from IP subnet vlan x to IP subnet vlan x.
Example:
vlan1 (INT) → vlan2 (EXT)
Access from the local IP subnet to the external IP subnet.
Access from the IP subnet to the device.
Access from the IP subnet to the SINEMA RC connection.
IPsec <Connection
Name>
Access from the IP subnet to the VPN tunnel partners that can be
reached via all VPN connections (all) or via a certain VPN connection
<Connection Name>.
Access from the device to the IP subnet.
Access from the device to the SINEMA RC connection.
IPsec <Connection
Access from the device to the VPN tunnel partners that can be
reached via all VPN connections(all) or via a certain VPN connection
(<Connection Name>).
Access from SINEMA RC connections to the IP subnet.
Access from SINEMA RC connections to the device.
IPsec <Connection
Access from the SINEMA RC server to the tunnel partners that can be
reached via all VPN connections (all) or via a certain VPN connection
<Connection Name>.
IPsec <Connection
Name>
Access via VPN tunnel partners to the IP subnet.
Access via VPN tunnel partners to the device.
Access via VPN tunnel partners to the SINEMA RC connection.
Firewall factory setting
Service
from internal (vlan1) to the
from external (vlan2) to the
yes, is rerouted to HTTPS