2 Abridged checklist
Checklist
Article ID: 109745536, V2.0, 05/2022
7
©
S
iem
e
n
s A
G
2
0
2
2
A
ll r
igh
ts
re
se
rv
e
d
2
Abridged checklist
Check the following steps for each SCALANCE device:
•
Use the latest firmware
•
Disable "http" and use "https" instead
•
Change default passwords for the users "admin" and "user"
•
Disable "Telnet" and use "ssh" for the CLI instead
If not using CLI, disable "Telnet" and "ssh"
•
Restrict DCP access to read-only
•
Restrict SNMPv1/2 to read-only access at minimum, use of SNMP V3 is
preferred
•
Use at least TLS version V1.2 / SFTP instead of TFTP / Syslog with TLS
•
Switch off option 66, 67 for DHCP client
•
Disable PROFINET interface if not using PROFINET
•
Enable time synchronization
•
With SCALANCE X, disable preset ring ports
•
Disable "spanning tree" if it is not needed
•
Disable the option "SINEMA Configuration Interface"
•
If PROFINET data traffic is running over the device and no custom VLAN
configuration is being used, then enable "VLAN 0 aware mode"
(X-300) or "802.1D Transparent Bridge"
•
Enable WLAN encryption and use WPA2
•
Set the default gateway in all devices
If a gateway is not being used, still set the gateway address to an unused IP
address in the local network
•
Create a configuration backup via WBM or C-Plug
Note
Not all of the features described above are available on all SCALANCE devices.
The features available depend on the SCALANCE model and the firmware
version you are using.