Vpn; Vpn (Virtual Private Network) - Siemens CP 1243-8 IRC Operating Instructions Manual

Simatic net s7-1200 telecontrol
Table of Contents

Advertisement

Configuration and operation
4.8 Security functions
4.8.1

VPN

4.8.1.1

VPN (Virtual Private Network)

VPN tunnel
Virtual Private Network (VPN) is a technology for secure transportation of confidential data in
public IP networks, for example the Internet. With VPN, a secure connection (tunnel) is set
up and operated between two secure IT systems or networks via a non-secure network.
One of the main features of the VPN tunnel is that it forwards all frames even from protocols
of higher layers (HTTP, FTP telecontrol protocols of the application layer etc.).
The data traffic between two network components is handled unrestricted through a physical
network. This allows networks to be connected together via an intermediate network.
VPN ensures information security in networked automation systems
Properties
● VPN forms a logical network that is embedded in a physical network. VPN uses the usual
addressing mechanisms of the physical network, however it transports only the frames of
the VPN subscribers and therefore operates independent of the rest of the physical
network.
● VPN allows communication of the subscribers in the VPN network with the physical
network.
● VPN is based on tunnel technology and can be configured for individual subscribers.
● Communication between the VPN partners is protected from eavesdropping or
manipulation by using passwords, public keys or a digital certificate (authentication).
Areas of application
● Local area networks can be connected together securely via the Internet ("site-to-site"
connection).
● Secure access to a company network ("end-to-site" connection)
● Secure access to a server ("end-to-end" connection)
● Communication between two servers without being accessible to third parties (end-to-end
or host-to-host connection)
● Protection of computers and their communication within and automation network
● Secure remote access from a PC/PG to automation devices or networks protected by
security modules via public networks.
90
Operating Instructions, 06/2015, C79000-G8976-C385-01
CP 1243-8 IRC

Advertisement

Table of Contents
loading

Table of Contents