Protection
9.2 Configuring access protection for the CPU
Automation system
System Manual, 12/2017, A5E03461182-AE
193
9.2
Configuring access protection for the CPU
Introduction
The CPU offers four access levels to limit access to specific functions.
By setting up the access levels and the passwords for a CPU, you limit the functions and
memory areas. This restriction applies to all functions and memory areas which are
accessible without entering a password. The individual access levels as well as their
associated passwords are specified in the object properties of the CPU.
Access levels of the CPU
Table 9- 1
Access levels and access restrictions
Access levels
Access restrictions
Complete ac-
cess (no protec-
tion)
Every user can read and change the hardware configuration and the blocks.
Read access
With this access level, read-only access to the hardware configuration and the
blocks is possible without entering a password, which means you can download
hardware configuration and blocks to the programming device. In addition, HMI
access and access to diagnostics data is possible.
Without entering the password, you cannot load any blocks or hardware configura-
tion into the CPU. Additionally, the following are not possible without the pass-
word: Writing test functions and firmware update (online).
HMI access
With this access level only HMI access and access to diagnostics data is possible
without entering the password.
Without entering the password, you can neither load blocks and hardware configu-
ration into the CPU, nor load blocks and hardware configuration from the CPU into
the programming device.
Additionally, the following are not possible without the password: Test functions,
changing the operating mode (RUN/STOP), firmware update and display of
online/offline comparison status.
No access
(complete pro-
tection)
When the CPU has complete protection, no read or write access to the hardware
configuration and the blocks is possible (without access authorization in the form
of a password). HMI access is also not possible. The server function for PUT/GET
communication is disabled in this access level (cannot be changed).
Authentication with the password will again provide you full access to the CPU.
A list of which functions are available in the different access levels is available in the "Setting
options for the protection" entry in the STEP 7 online help.
Summary of Contents for Simatic S7-1500/ET 200MP
Page 1: ......