Configuring Security Services
Original instructions
Introduction
The Control Expert DTM provides security services to the BMENOC0321 control network module. Enable and disable these services on the Security tab in the Control Expert DTM.
Access the Security Tab
View the Security configuration options:
Step
Action
1
Open your Control Expert project.
2
Open the DTM Browser (Tools → DTM Browser).
3
In the DTM Browser, double-click the name that you assigned to the BMENOC0321 module. to open the configuration window.
NOTE: You can also right-click the module, and select Open.
4
Select Security in the navigation tree to view the configuration options.
NOTE: For general safety information, refer to the cyber security manual.
Service Selection
Enable and disable these services in the Security tab:
Service
Description
Enable or disable (default) these items:
  • firmware upgrade
  • device configuration management using the FDR service
NOTE: Local data storage remains operational, but remote access to data storage is disabled.
Enable or disable (default) the ability to read X80 I/O module configuration files using the FDR service.
NOTE: In M580 Hot Standby systems, you can disable TFTP services in the Ethernet screen for the BMENOC0321 module. (You might do this if connected DIO modules either do not push their configuration to the FDR server in the module, or if they use only FTP to transfer their configuration to this server.) However, if TFTP is disabled, Hot Standby synchronization cannot be performed because it is based on TFTP.
Enable or disable (default) the web access service.
Access Control
  • Enabled (default): Deny Ethernet access to the Modbus and EtherNet/IP server by unauthorized network devices.
  • Disabled: There is no restriction on which network devices can access the Modbus and EtherNet/IP server.
Enable or disable (default) secure communications for traffic between the IP address that corresponds to a BMENOC0321 module and another IP address using IPsec.
Pre-Shared Key
This field is associated with IPsec, and is empty by default. If you enable IPsec, enter 16 characters. Select a value that is difficult to guess (combination of upper and lower case letters, numbers, and special characters).
Enable or disable (default) the automatic assignment of IP addressing settings. Your DHCP selection also enables/disables automatic assignment of subnet mask, gateway IP address, and DNS server names.
Enable or disable (default) the protocol used to monitor network-attached devices.
Enable or disable (default) access to the EtherNet/IP server and its electronic data sheets (EDS), which classify each network device and its functionality.
NOTE:
  • The default settings represent the maximum security level. The increased security reduces the communication capabilities and the access to communication ports.
  • Services that are selected online (through Control Expert or ETH_PORT_CTRL) apply only to the rack on which the EF runs.
  • Refer to the discussion of the ETH_PORT_CTRL function block to enable/disable the FTP, TFTP, HTTP, and DHCP/BOOTP protocols.
Enabling Security
Set the Security tab parameters before you download the application to the CPU. When they are disabled, security services can be enabled only when you download a new application.
Use these steps to set the security level quickly:
Step
Action
1
In a respective service, select Enabled in the associated pull-down menu.
NOTE: When you enable or disable a service, the pencil symbol appears to indicate that you are editing the security settings.
2
Click Enforce Security to reset services to their default states (above) and implement the highest level of security.
3
Click Unlock Security to use the lowest level security settings (opposite of default settings).
4
Click Apply to enable the service.
NOTE: The pencil symbol disappears.
5
Save your project (File → Save).
Using Access Control for Authorized Addresses
Use the Access Control page to restrict device access to the BMENOC0321 module or the CPU communication server service via the BMENOC0321 module in its role as either a Modbus TCP, EtherNet/IP, FTP, TFTP, HTTP, or SNMP server. When you enable access control in the Security dialog, add to the list of Authorized Addresses the IP address of each device that is permitted to communicate with the BMENOC0321 module, to the list of Authorized Addresses:
You can enter a maximum of 128 authorized IP addresses.
Adding Devices to the Authorized Addresses List
To add devices to the Authorized Addresses list:
Step
Action
1
Set Access Control to Enabled.
2
In the IP Address column of the Authorized Addresses list, double-click the default IP address (0.0.0.0) to enter an IP address.
3
Enter the address of the device to access the BMENOC0321 module or the CPU communication server service via the BMENOC0321 module with either of these methods:
  • Add a single IP address: Enter the IP address of the device and select No in the Subnet column.
  • Add a subnet: Enter a subnet address in the IP Address column. Select Yes in the Subnet column. Enter a subnet mask in the Subnet Mask column.
NOTE: A red exclamation point (!) indicates a detected error in the entry. You can save the configuration only after the detected error is fixed.
4
Repeat these steps for each additional device or subnet to which you want to grant access to the BMENOC0321 module or the CPU communication server service via the BMENOC0321 module.
NOTE: You can enter up to 128 authorized IP addresses or subnets.
5
Click Apply.
Removing Devices from the Authorized Addresses List
To remove devices from the Authorized Addresses list:
Step
Action
1
In the Authorized Addresses list, select the IP address of the device to delete.
2
Press the Delete button.
3
Click Apply.
Finishing the Configuration
Click a button to finish: