1.2.2
Secure access with S615
Secure remote access and network segmentation with SCALANCE S615
A secure connection for data exchange between an automation plant and remote stations will
be established via the Internet and mobile wireless network. At the same time, a secure
connection will be established when necessary for service purposes. This connection is,
however, restricted to a specific plant section or a specific machine.
In the automation plant, a SCALANCE S615 is connected to the Internet via the ADSL+ router
M812-1. The remote stations will be connected to the Internet via the LTE-CP 1243-7 or the
HSPA+ router SCALANCE M874-3. The devices establish a VPN connection to the
SCALANCE S615 via which data can be exchanged securely.
When necessary, the service technician connects to the Internet. With the SOFTNET Security
Client, he or she establishes a secure VPN connection to the S615. Various IP subnets are
connected to the S615 between which the integrated firewall checks communication. This
allows the communication of the service technician to be restricted to a specific IP subnet.
Industrial Ethernet
Automation application
Automation system
SCALANCE
S615
PROFINET
PROFINET
PROFINET
VPN tunnel
Remote stations
SCALANCE
M874-3
SIMATIC
S7-1200 with
CP 1243-7 (LTE)
VPN
tunnel
SCALANCE
M812-1
GPRS/UMTS/LTE
GPRS/
UMTS/
LTE
Internet
Internet
router
SIMATIC
Field PG with
SOFTNET
Security
Client
SIMATIC S7-1500
with CP 1543-1
Automation cell 1
Automation cell 2
Automation cell 3
Plant network
1.3
Requirements for operation
Power supply
A power supply with a voltage between 12 VDC and 24 VDC that can provide sufficient current.
Description
1.3 Requirements for operation
SCALANCE S615 Web Based Management
16
Configuration Manual, 11/2019, C79000-G8976-C388-08