Siemens CP 1243-8 IRC Operating Instructions Manual page 92

Simatic net s7-1200 telecontrol
Table of Contents

Advertisement

Configuration and operation
4.8 Security functions
Creating a security user
To create a VPN tunnel, you require appropriate configuration rights. To activate the security
functions, you need to create at least one security user.
1. In the local security settings of the CP, click the "User login" button.
Result: A new window opens.
2. Enter the user name, password and confirmation of the password.
3. Click the "Logon" button.
You have created a new security user.
With all further logons, log on as user.
Select the "Activate security features" check box
After logging on, you need to select the "Activate security features" check box in the local
security settings of both CPs.
You now have the security functions available for both CPs.
Creating the VPN group and assigning security modules
1. In the global security settings, select the entry "VPN groups" > "Add new VPN group".
2. Double-click on the entry "Add new VPN group", to create a VPN group.
Result: A new VPN group is displayed below the selected entry.
3. In the global security settings, double-click on the entry "VPN groups" > "Assign module
to a VPN group".
4. Assign the security modules between which VPN tunnels will be established to the VPN
group.
Note
Current date and current time on the CP for VPN connections
Normally, to establish a VPN connection and the associated recognition of the certificates to
be exchanged, the current date and the current time are required on both stations.
The establishment of a VPN connection to an engineering station or an ST7cc/sc PC runs as
follows along with the time of day synchronization of the CP:
On the engineering station or the ST7cc/sc PC, you want the CP to establish a VPN
connection. The VPN connection is established even if the CP does not yet have the current
time. Otherwise the certificates used are evaluated as valid and the secure communication
will work.
Following connection establishment, the CP synchronizes its time of day with the PC
because the ST7cc/sc PC is the time master if telecontrol communication is enabled.
92
Operating Instructions, 06/2015, C79000-G8976-C385-01
CP 1243-8 IRC

Advertisement

Table of Contents
loading

Table of Contents