Configuration
4.9 Security (CP 1543SP-1)
CP 154xSP-1
70
Operating Instructions, 12/2019, C79000-G8976-C426-05
4.9.5.3
Creating a VPN tunnel for S7 communication between stations
Requirements
To allow a VPN tunnel to be created for S7 communication between two S7 stations or
between an S7 station and an engineering station with a security CP (for example CP 1628),
the following requirements must be met:
●
The two stations have been configured.
●
The CPs in both stations must support the security functions.
●
The Ethernet interfaces of the two stations must be networked.
Note
Communication also possible via an IP router
Communication between the two stations is also possible via an IP router. To use this
communications path, however, you need to make further settings.
Procedure
To create a VPN tunnel, you need to work through the following steps:
1.
Creating a security user
If the security user has already been created: Log on as this user.
2.
Enable the "Activate security features" option
3.
Creating the VPN group and assigning security modules
4.
Configure the properties of the VPN group
5.
Configure local VPN properties of the two CPs
You will find a detailed description of the individual steps in the following paragraphs of this
section.
Enable security functions
After logon, enable the "Activate security features" option on both CPs under "Security".
You now have the security functions available for both CPs.
Creating the VPN group and assigning security modules
1.
In the global security settings, navigate to "VPN groups" > "Add new VPN group".
2.
Double-click on the entry "Add new VPN group", to create a VPN group.
Result: A new VPN group is displayed below the selected entry.