ENG_652673.XML
Security communications processors for SIMATIC S7 and PG/PC
Reliable cell protection on the controller level
Since in many automation environments it is also necessary to segment the network for individual SIMATIC S7 controllers and their lower-level networks, the cell protection concept can also be implemented for any use cases by means of dedicated security communications processors. The components can be positioned in the rack of the corresponding target system for this purpose and provide integrated security functions, in addition to the conventional communication functions of a communications processor, such as S7 routing or web diagnostics. The automation cell thus formed, consisting of the controller and lower-level network, can be protected against unauthorized access with the aid of firewall rules. Connections to and from the automation cell can also be authenticated and encrypted through the added use of VPN tunnels, which, in turn, allows the data communication to be protected against eavesdropping or data manipulation.
G_IK10_XX_10373
Network segmentation with SCALANCE S Industrial Security Appliances and security communications processors
The following security communications processors are available on the controller level for implementing an integrated cell protection concept:
Cell protection for SIMATIC S7-1200:
The SIMATIC CP 1243-1, CP 1243-7 LTE and CP 1243-8 IRC communications processors are available to protect single SIMATIC S7-1200 controllers. In addition to their communications functions, they offer an integrated firewall and the possibility of terminating VPN endpoints, thereby making additional, separate security components superfluous. Furthermore, the communications processors can also be used for integrating the S7 stations into the telecontrol centers.
Cell protection for SIMATIC S7-1500:
The SIMATIC CP 1543-1 and CP 1543SP-1 communications processors are available to protect single SIMATIC S7-1500 controllers. In addition to their communications functions, they offer an integrated firewall and the possibility of terminating VPN endpoints, thereby making additional, separate security components superfluous.