Remote Access To Cpu; Using A Web Server; Recording Security Events - Siemens SIMATIC S7-1500 System Manual

Drive controller
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

Industrial cybersecurity
4.9 Secure operation of CPUs
4.9.10

Remote access to CPU

4.9.10.1

Using a Web server

When using Web servers, traditional firewalls are no longer sufficient to protect modern
networks.
You can find information on potential risks when using web servers in the Web Server
Function Manual (https://support.industry.siemens.com/cs/ww/en/view/59193560).
4.9.11

Recording Security events

Syslog storage
Syslog stands for "System Logging Protocol," a standard for storing, transmitting and
collecting log messages triggered by security events. Predefined events in a network device
are collected as security events in the device (syslog client) and stored as syslog messages in
the local cache.
A syslog server collects and categorizes syslog messages, which can then be analyzed and
filtered and displayed in various ways. Additionally, notifications for critical events can be
configured.
These security events for the CPU are collected in the CPU diagnostics buffer:
• Going online with the correct or incorrect password
• Manipulated CPU communication data detected
• Manipulated CPU data detected on memory card
• Manipulated firmware update file detected
• Changed protection level (access protection) downloaded to the CPU
• Password legitimization restricted or enabled (via an instruction).
• Online access to CPU denied due to the possible number of simultaneous access attempts
being exceeded
• Timeout when an existing online connection is inactive
• Logging on to the Web server with the correct or incorrect password
• Creating a backup of the CPU
• Restoring the CPU configuration
Firmware update for CPU and SINAMICS Integrated and system update
1)
The SINAMICS configuration is also backed up. You can find more information in the
2)
section Backing up and restoring the CPU configuration (Page 284).
The above-listed security events are also stored as syslog messages in the local cache of a CPU
as of firmware version V3.1. You can find an overview of all syslog messages in the following
Entry (https://support.industry.siemens.com/cs/ww/en/view/109823696).
The content of a syslog message is based on IEC 62443-3-3.
42
1)
2)
2)
SIMATIC Drive Controller
System Manual, 11/2023, A5E46600094-AD

Advertisement

Table of Contents
loading

Table of Contents