Configuration, programming
4.8 Security
CP 1543-1
Operating Instructions, 12/2019, C79000-G8976-C289-08
63
4.8.2.1
Creating VPN tunnel communication between S7-1500 stations
Requirements
To create a VPN tunnel between two S7-1500 stations, the following requirements must be
met:
●
Two S7-1500 stations have been configured.
●
Participating CP 1543-1 a
re configured with a firmware version ≥
V1.1.
●
The Ethernet interfaces of the two stations are located in the same subnet.
Note
Communication also possible via an IP router
Communication between the two S7-1500 stations is also possible via an IP router. To use
this communications path, however, you need to make further settings.
Procedure
To create a VPN tunnel, you need to work through the following steps:
1.
Create a security user.
If the security user has already been created: Log on as a user.
2.
Select the "Activate security features" check box.
3.
Create the VPN group and assign security modules.
4.
Configure properties of the VPN group.
Configure local VPN properties of the two CPs.
You will find a detailed description of the individual steps in the following paragraphs of this
section.
Creating a security user
To create a VPN tunnel, you require appropriate configuration rights. To activate the security
functions, you need to create at least one security user.
1.
In the local security settings of the CP, click the "User logon" button.
Result: A new window opens.
2.
Enter the user name, password and confirmation of the password.
3.
Click the "User login" button.
You have created a new security user. The security functions are now available to you.
With all further logons, log on as user.