Siemens CP 343-1 manual Influence of MPI on Connections via Industrial Ethernet

Models: CP 343-1

1 56
Download 56 pages 42.23 Kb
Page 50
Image 50

9 Further Notes on Operation

Access Permissions using Community Name

The CP uses the following community names for assigning permissions:

SFor read access: “public”

Sfor read and write access: “private” (note the use of lower−case letters!)

9.4Possible Security Gaps on Standard IT Interfaces / Preventing Illegal Access

With various SIMATIC NET components, such as OSMs/ESMs, a wide range of parameter assignment and diagnostic functions (for example, Web servers, network management) are available over open protocols and interfaces. The possibility of unauthorized misuse of these open protocols and interfaces by third parties, for example to manipulate data, cannot be entirely excluded.

When using the functions listed above and these open interfaces and protocols (for example, SNMP, HTTP), you should take suitable security measures to prevent unauthorized access to the components and the network particularly from within the WAN/Internet.

Notice

We expressly point out that automation networks must be isolated from the rest of the company network by suitable gateways (for example using tried and tested firewall systems). We do not accept any liability whatsoever, whatever the legal justification, for damage resulting from non−adherence to this notice.

If you have questions on the use of firewall systems and IT security, please contact your local Siemens office or representative. You will find the address in the SIMATIC catalog IK PI or on the Internet at

http://www.automation.siemens.com/net > Contact & Partners > Local Partners.

9.5Influence of MPI on Connections via Industrial Ethernet

If a station on MPI is added or removed, for example because a service PG has been connected or disconnected, it is possible that active communication connections on the communications bus are aborted. This has the following effects on the communication connections on Industrial Ethernet:

SAll S7 connections are temporarily aborted.

This does not apply when using CPUs with a separate K bus (for example, the CPU 318−2, CPU 317−2 PN/DP, CPU 319−3 PN/DP).

B3L−50

CP 343-1 Lean for Industrial Ethernet / Manual Part B3L

Release 03/2007

C79000-G8976-C198-04

Page 50
Image 50
Siemens CP 343-1 manual Influence of MPI on Connections via Industrial Ethernet, Access Permissions using Community Name