On the system side, SIMATIC PCS 7 supports implementation of guidelines and recommendations of the security concept by:
CP 1628 communication module CP 1628 communication moduleThe CP 1628 is a PCI Express card (PCIe x1) with its own microprocessor and integrated 2-port switch (2 x RJ45 connection, 10/100/1000 Mbps) for the connection of SIMATIC PCS 7 workstations to Industrial Ethernet. In contrast to the comparable CP 1623, it has additional security features:
With the built-in security mechanisms, the CP 1628 can protect PCS 7 stations as well as their data communication within an automation network and remote access over the Internet. It enables secure access to individual stations or entire automation cells that are protected by security modules. Different security measures, such as firewall and VPN over IPsec tunnel, can also be combined. For more information and technical specifications for the CP 1628 communication module, refer to the Catalog IK PI, section Industrial Ethernet, under System Utilities, System connection for PG/PC/IPC. SCALANCE S Industrial Security Appliances SCALANCE S Industrial Security AppliancesThe SCALANCE S Industrial Security Appliances provide scalable security features, such as firewall, port filter, NAT, NAPT address translation and DHCP server (S602, S612, S623 and S627‑2M) as well as authentication and data encryption with virtual private network (VPN) over IPsec tunnel (S612, S623 and S627-2M). They can be used, for example, to safeguard the cross-cell data exchange between components of automation and process control systems. Since they can be operated in bridge mode as well as router mode, they can therefore also be used directly at IP subnet boundaries. The SCALANCE S Industrial Security Appliances have a rugged industrial design. For connection to Industrial Ethernet, they have 2 (S602 and S612) or 3 (S623 and S627-2M) 10/100/1000 Mbps ports (RJ45). The S627-2M also has two slots for optional 2-port media modules (electrical or optical; for ordering data, see SCALANCE X-300). Product versions:
Note: Using the supplied Security Configurations Tool (SCT), it is easy to create and configure the Industrial Security Appliances that can communicate securely with one another. You do not require any special IT knowledge. The complete configuration can be saved on the optional swap medium C‑PLUG (order separately) and transmitted to another Industrial Security Appliance. This permits easy and fast replacement of modules in the event of a fault. For more information and technical specifications of the SCALANCE S Industrial Security Appliances, see Catalog IK PI, section "Industrial Ethernet", "Industrial Ethernet Security". Automation firewallThe automation firewall (see Catalog ST PCS 7 AO, "Architecture and Configuration" section) features Stateful Inspection packet filter, application layer firewall, VPN gateway functionality, URL filtering, Web proxy and intrusion prevention. Depending on the plant size, it can be used as a front and back firewall or in a three-homed configuration. It thus protects the access point to the production environment, e.g. from the office or intranet networks. The automation firewall is supplied preinstalled. The value of the Automation Firewall is increased even further by integrated services, e.g.:
Additive services complete the offerings, for example, customized firewall solutions or integration of firewalls in customer systems. |
| Каталог 2018 | Каталог 2017 | Каталог 2016 | Каталог 2015 | Каталог 2014 | Каталог 2013 | Каталог 2012 | Сертификат | Контакты | Карта сайта | Поиск |


