Configuring Security Services
Original instructions
Introduction
The Control Expert DTM provides security services to the BMENOC0301/11 Ethernet communication module. Enable and disable these services on the Security tab in the Control Expert DTM.
Access the Security Tab
View the Security configuration options:
Step
Action
1
Open your Control Expert project.
2
Open the DTM Browser (Tools → DTM Browser).
3
In the DTM Browser, double-click the name that you assigned to the BMENOC0301/11 module. to open the configuration window.
NOTE: You can also right-click the module, and select Open.
4
Select Security in the navigation tree to view the configuration options.
NOTE: For general safety information, refer to the cyber security manual.
Service Selection
This table describes the available services:
Service
Description
Enable or disable (default) these items:
  • firmware upgrade
  • device configuration management using the FDR service
NOTE: Local data storage remains operational, but remote access to data storage is disabled.
Enable or disable (default) the ability to read X80 I/O module configuration files using the FDR service.
NOTE: In M580 Hot Standby systems, you can disable TFTP services in the Ethernet screen for the BMENOC0301/11 module. (Its DIO modules either do not push their configuration in the FDR server or they use only FTP.) In such cases, the Hot Standby FDR synchronization does not work (because it is based on TFTP).
Enable or disable (default) the web access service.
Access Control
Enabled (default): Deny Ethernet access to the Modbus and EtherNet/IP server by unauthorized network devices.
Disabled: There is no restriction on which network devices can access the Modbus and EtherNet/IP server.
Enable or disable (default) secure communications for traffic between the IP address that corresponds to a BMENOC0301/11 module and another IP address using IPsec.
Pre-Shared Key
This field is associated with IPsec, and is empty by default. If you enable IPsec, enter 16 characters. Please select a value that is difficult to guess (combination of upper and lower case letters, numbers, and special characters).
Enable DH 2048
Check this box to enable and generate 2048-bit Diffie-Hellman parameters.
NOTE:
  • When you select Enable Confidentiality, you cannot disable the individual Ethernet services. (In this case, encryption helps protect these services.)
  • This check box is disabled when IPsec is enabled.
Enable Confidentiality
Check this box to enable and encrypt all Ethernet services.
NOTE: This check box is disabled when IPsec is enabled.
Enable or disable (default) the automatic assignment of IP addressing settings. For DHCP, also enables/disables automatic assignment of subnet mask, gateway IP address, and DNS server names.
Enable or disable (default) the protocol used to monitor network-attached devices.
Enable or disable (default) access to the EtherNet/IP server and its electronic data sheets (EDS), which classify each network device and its functionality.
NOTE:
  • The default settings represent a moderate level of security. The increased security reduces the communication capabilities and the access to communication ports.
  • Services that are selected online (through Control Expert or ETH_PORT_CTRL) apply only to the rack on which the EF runs.
  • Refer to the ETH_PORT_CTRL topic for information regarding using this function block to enable/disable the FTP, TFTP, HTTP, and DHCP/BOOTP protocols.
Enabling Security
Set the Security tab parameters before you download the application to the CPU. When they are disabled, security services can be enabled only when you download a new application.
Use these steps to set the security level quickly:
Step
Action
1
In a respective service, select Enabled in the associated pull-down menu.
NOTE: When you enable or disable a service, the pencil symbol appears to indicate that you are editing the security settings.
2
Click Enforce Security to reset all services to the default states (above) and implement the highest level of security.
3
Click Unlock Security to use the lowest level security settings (opposite of default settings).
4
Click Apply to enable the service.
NOTE: The pencil symbol disappears.
5
Save your project (File → Save).
Using Access Control for Authorized Addresses
Use the Access Control page to restrict device access to the BMENOC0301/11 module or the CPU communication server service via the BMENOC0301/11 module in its role as either a Modbus TCP, EtherNet/IP, FTP, TFTP, HTTP, or SNMP server. When you enable access control in the Security dialog, add the IP addresses of devices, for which you want to communicate with the BMENOC0301/11 module, to the list of Authorized Addresses:
You can enter a maximum of 128 authorized IP addresses.
Adding Devices to the Authorized Addresses List
To add devices to the Authorized Addresses list:
Step
Action
1
Set Access Control to Enabled.
2
In the IP Address column of the Authorized Addresses list, double-click the default IP address (0.0.0.0) to enter an IP address.
3
Enter the address of the device to access the BMENOC0301/11 module or the CPU communication server service via the BMENOC0301/11 module with either of these methods:
  • Add a single IP address: Enter the IP address of the device and select No in the Subnet column.
  • Add a subnet: Enter a subnet address in the IP Address column. Select Yes in the Subnet column. Enter a subnet mask in the Subnet Mask column.
NOTE: A red exclamation point (!) indicates a detected error in the entry. You can save the configuration only after the detected error is addressed.
4
Repeat these steps for each additional device or subnet to which you want to grant access to the BMENOC0301/11 module or the CPU communication server service via the BMENOC0301/11 module.
NOTE: You can enter up to 128 authorized IP addresses or subnets.
5
Click Apply.
Removing Devices from the Authorized Addresses List
To remove devices from the Authorized Addresses list:
Step
Action
1
In the Authorized Addresses list, select the IP address of the device to delete.
2
Set the IP address to 0.0.0.0.
3
Select No in the Subnet column.
4
Click Apply.
Finishing the Configuration
Click a button to finish: