Chapter 4. Security Capabilities
16
PACSystems PROFINET IO Devices Secure Deployment Guide
GFK-2904D
The subjects defined and supported by each server protocol are indicated in the following table:
Transport Medium
Functionality
Application Protocol
Subjects Available
Serial
Firmware Update
SNP Slave
Anonymous
Ethernet
Web Server
HTTP
Anonymous
Web Server Firmware Update
HTTP
Firmware Updater
Web Server Password Reset
HTTPS
Anonymous
Specifying Access Rights
For each subject, PROFINET I/O Devices from GE Automation & Controls provide predefined access rights.
Predefined Access Rights
Using the SNP Slave Application Protocol to update firmware on a PROFINET I/O Device, the Anonymous
Subject is granted the same Service Request PRIV Level as the highest
PRIV Level user
that currently has no
password. This equates to PRIV Level 4 user on PROFINET I/O Devices which allows Write Access to support
the Firmware Update Functionality.
Physical Access
The Web Server Password Reset feature requires physical access to the PROFINET I/O Device to assign the
Firmware Updater password.
Enforcement
Each of the PROFINET I/O Devices enforces the access rights for the data and services that it provides.
Summary of Contents for PACSystems* RX3i
Page 6: ...Contents GFK 2904D July 2018 iii Table of Figures Figure 1 Reference Architecture 23...
Page 7: ......
Page 11: ......
Page 21: ......
Page 33: ......