background image

Chapter 3. Communication Requirements 

10 

PACSystems PROFINET IO Devices Secure Deployment Guide 

GFK-2904D 

3.3

 

PROFINET 

This section describes the communication paths needed to support common operations on a PROFINET 
network. 
 

 

Installing an I/O Device 

Commissioning, adding, or replacing an I/O device requires that the device be assigned a unique name to use 
on the PROFINET network. Doing this requires supporting the following communication path. 
 

Protocol

 

Proficy Machine Edition

 

I/O Device

 

PROFINET DCP 

Client 

Server 

 
Supporting this path will allow Proficy Machine Edition to directly discover all of the PROFINET I/O devices that 
are connected to the same subnet as the computer. (Note that this protocol is not routable.) Proficy Machine 
Edition implements the Client functionality directly from the computer network adapter, so I/O devices must 

be local to the computer’s network adapter. It can then be used to (re

-)assign a unique name to the I/O device 

being installed. 
 

Note: 

This protocol can also be used to make other modifications to the I/O device, such as 
assigning a new IP address or resetting it to factory defaults. However, those functions 
are not generally required when Installing an I/O device. 

 

 

Network Discovery and Device Identification 

Proficy Machine Edition can also request information about the devices on a PROFINET network from a 
PACSystems Controller, and then retrieve additional identification information about each device. This request 
is sent to the PACSystems Controller using the Service Request protocol (described elsewhere) embedded 
within the SRTP or SNP protocols. The PACSystems Controller satisfies those requests using the following 
communication paths. 
 

Protocol

 

Local I/O Controller

 

Remote I/O Controllers and I/O Devices

 

DCE/RPC 

Client 

Server 

PROFINET DCP 

Client 

Server 

 
 

Note: 

No mechanism is provided through this communication path for assigning a name to a 
new I/O device. 

 

Summary of Contents for PACSystems* RX3i

Page 1: ...mation Controls For Public Disclosure Programmable Control Products PACSystems PROFINET IO Devices Secure Deployment Guide GFK 2904D PACSystems PROFINET IO Devices Secure Deployment Guide GFK 2904D Ju...

Page 2: ...rmational purposes only and GE makes no warranty as to the accuracy of the information included herein Changes modifications and or improvements to equipment and specifications are made periodically a...

Page 3: ...utomation com support Americas Phone 1 800 433 2682 International Americas Direct Dial 1 780 420 2010 if toll free 800 option is unavailable Customer Care Email digitalsupport ge com Primary language...

Page 4: ...mendations 6 2 5 Checklist 6 Chapter 3 Communication Requirements 7 3 1 Supported Protocols 8 ETHERNET Protocols 8 Serial Protocols 8 3 2 Service Requests 9 SNP 9 3 3 PROFINET 10 Installing an I O Dev...

Page 5: ...s 20 Firmware Signatures 20 Logging and Auditing 20 Chapter 5 Configuration Hardening 21 5 1 Scanner 21 5 2 Genius Gateway 22 Chapter 6 Network Architecture and Secure Deployment 23 6 1 Reference Arch...

Page 6: ...Contents GFK 2904D July 2018 iii Table of Figures Figure 1 Reference Architecture 23...

Page 7: ......

Page 8: ...ionals and developers responsible for deploying and configuring PROFINET I O products Secure deployment information is provided in this manual for the following products supplied by GE Automation Cont...

Page 9: ...ns in this Manual Rev Date Description D Jul 2018 Updated for IC695PNS101 IC695CEP001 C Feb 2017 Updated for replacement IC695PNS001 Bxxx implementation B Jun 2016 Updated Internet Layer Protocols tab...

Page 10: ...EP PROFINET I O Controller Manual GFK 2571 RX3i Manuals PACSystems RX3i System Manual GFK 2314 PACSystems RX3i PROFINET Scanner Manual GFK 2737 PACSystems RX3i CEP PROFINET Scanner User Manual GFK 28...

Page 11: ......

Page 12: ...Article GE Intelligent Platforms Security Advisories 2 2 Firewall Firewalls and other network security products including Data Diodes and Intrusion Prevention Devices can be an important component of...

Page 13: ...whitelisting software on control systems computers and keep the whitelist up to date 2 5 Checklist This section provides a sample checklist to help guide the process of securely deploying PROFINET I...

Page 14: ...uired for the intended application Successfully doing this requires knowing which protocol is needed for each system level interaction This section describes how the supported serial and Ethernet appl...

Page 15: ...client PROFINET DCP server PROFINET I O HTTP Server HTTPS Server MRP SNMP v1 server SNMP v2c server Serial Protocols In addition to Ethernet PROFINET I O Devices may also support communication over s...

Page 16: ...rds and OEM key and sweep information View and optionally clear a log of any faults that have occurred in the Controller The Service Request protocol is transported over a specific media by encapsulat...

Page 17: ...to the computer s network adapter It can then be used to re assign a unique name to the I O device being installed Note This protocol can also be used to make other modifications to the I O device suc...

Page 18: ...e of the application Protocol I O Controller I O Devices DCE RPC Client Server DCE RPC Server Client PROFINET DCP Client Server PROFINET I O Bi directional Bi directional In addition if the PROFINET n...

Page 19: ...a diagram showing firewall placement Lower Level Protocols Ethernet communication is typically described using four layers each with its own set of protocols At the top of that hierarchy is the Applic...

Page 20: ...quests to other servers using any of several different protocols The exact set of protocols that are enabled used will depend on which modules are installed how they are configured and the details of...

Page 21: ......

Page 22: ...ization and Enforcement Approving or rejecting access requests This section describes the Access Control capabilities supported by GE Automation Controls PROFINET I O Devices which includes its Author...

Page 23: ...ces from GE Automation Controls provide predefined access rights Predefined Access Rights Using the SNP Slave Application Protocol to update firmware on a PROFINET I O Device the Anonymous Subject is...

Page 24: ...on GE Automation Controls PROFINET I O Device PROFINET communications Plaintext Login Authentication for a protocol may involve sending a plaintext password to the Server In some cases these plaintex...

Page 25: ...th another network node on the same physical network a Next Generation Firewall could be deployed between the two network nodes This Next Generation Firewall should be configured to explicitly whiteli...

Page 26: ...subject must be separately managed for each instance of a given kind of server Changing Passwords Functionality Authenticated Subjects How Passwords are assigned Firmware Update PRIV Level 4 user Stat...

Page 27: ...n the table below Therefore compensating controls may be required to meet an installation s security requirements for protecting data in flight Protocol Provided Security Capabilities Transport Medium...

Page 28: ...0 in the hardware configuration and download to the PROFINET I O controller Ethernet Port Enable Set Port Speed of Port submodule to Disabled in the hardware configuration and download to the PROFINET...

Page 29: ...roller SD Card Identity Set the name of the Device using a DCP Client with the SD Card inserted Remove SD Card and enable the physical Write protect feature on the SD Card Re insert the SD Card in the...

Page 30: ...ion provides security recommendations for deploying PROFINET I O Devices from GE Automation Controls in the context of a larger network 6 1 Reference Architecture The Figure 1 shows a reference deploy...

Page 31: ...ts to just the minimum set required Further every access attempt successful or not and all blocked traffic should be recorded in a security log that is regularly audited 6 3 Access and Process Control...

Page 32: ...DCP protocol However to help ensure that the Maintenance computer cannot be used to launch attacks on the I O devices using other protocols the firewall it connects through should block all protocols...

Page 33: ......

Page 34: ...nd jitter As a result network architectures that require real time communications to pass through such devices may limit the applications that can be successfully deployed 7 3 Additional Guidance Prot...

Page 35: ...s are available on our web site www geautomation com Additional Resources For more information please visit our web site www geautomation com Copyright 2014 2018 General Electric Company All Rights Re...

Reviews: