Introduction
Control Expert provides security services for the CPU. Enable and disable these services on the tab in Control Expert.
Accessing the Security Tab
View the
configuration options:Step |
Action |
---|---|
1 |
Open your Control Expert project. |
2 |
Double-click the Ethernet ports on the CPU in the local rack (or right-click the Ethernet ports and select . |
3 |
Select the Ethernet services. tab in the window to enable/disable |
Available Ethernet Services
You can enable/disable these Ethernet services:
Field |
Comment |
|
---|---|---|
Enforce Security and Unlock Security |
||
FTP |
Enable or disable (default) firmware upgrade, SD memory card data remote access, data storage remote access, and device configuration management using the FDR service. NOTE: Local data storage remains operational,
but remote access to data storage is disabled.
|
|
TFTP |
Enable or disable (default) the ability to read RIO drop configuration and device configuration management using the FDR service. NOTE: Enable this service to use eX80 Ethernet adapter
modules.
|
|
HTTPS |
Enable or disable (default) the web access service. |
|
DHCP / BOOTP |
Enable or disable (default) the automatic assignment of IP addressing settings. For DHCP, also enable/disable automatic assignment of subnet mask, gateway IP address, and DNS server names. |
|
SNMP |
Enable or disable (default) the protocol used to monitor the device. |
|
EIP |
Enable or disable (default) access to the EtherNet/IP server. |
|
|
Enable (default) or disable Ethernet access to the multiple servers in the CPU from unauthorized network devices. |
|
(1) |
|
/ |
|
0.0.0.0 ... 223.255.255.255 |
|
|
224.0.0.0 ... 255.255.255.252 |
|
|
Select this to grant access to the FTP server in the CPU. |
|
|
Select this to grant access to the TFTP server in the CPU. |
|
|
Select this to grant access to the HTTP secured server in the CPU. |
|
|
Select this to grant access to port 502 (typically used for Modbus messaging) of the CPU. |
|
|
Select this to grant access to the EtherNet/IP server in the CPU. |
|
|
Select this to grant access to the SNMP agent resident in the CPU. |
|
1 Set Access Control to Enabled to modify this field. |
Enable/Disable Ethernet Services
You can enable/disable Ethernet services on the tab as follows:
Enable/disable FTP, TFTP, HTTP, EIP, SNMP, and DHCP/BOOTP for all IP addresses. (You can use this feature offline only. The configuration screen is grayed in online mode.)
– or –
Enable/disable FTP, TFTP, HTTP, Port 502, EIP, and SNMP for each authorized IP address. (You can use this feature online.)
Set the CPU. The default settings (maximum security level) reduce the communication capacities and port access.
tab parameters before you download the application to theand Fields
When you click
(the tab default setting):, , , , , and are disabled and is enabled.
When you click
:, , , , , and are enabled, and is disabled.
Using Access Control for Authorized Addresses
Use the CPU in its role as a server. After you enable access control in the dialog, you can add the IP addresses of the devices that you want to communicate with the CPU to the list of :
area to restrict device access to theBy default, the IP address of the CPU’s embedded Ethernet I/O scanner service with EtherNet/IP or Modbus TCP.
set to allows any device in the subnet to communicate with the CPU throughAdd the IP address of any client device that may send a request to the CPU’s Ethernet I/O scanner service, which, in this case, acts as a Modbus TCP or EtherNet/IP server.
Add the IP address of your maintenance PC to communicate with the PAC through the CPU’s Ethernet I/O scanner service via Control Expert to configure and diagnose your application.
You can enter a maximum of 127 authorized IP addresses or subnets.
Adding Devices to the
ListTo add devices to the
list:Step |
Action |
---|---|
1 |
Set to . |
2 |
In the column of the list, enter an IP address. |
3 |
Enter the address of the device to access the CPU’s Ethernet I/O scanner service with either of these methods:
NOTE:
|
4 |
Select one or more of the following methods of access you are granting the device or subnet: , , , , , . |
5 |
Repeat steps 2 - 4 for each additional device or subnet to which you want to grant access to the CPU’s Ethernet I/O scanner service. NOTE: You can enter up
to 127 authorized IP addresses or subnets.
|
6 |
Click . |
Removing Devices from the
ListTo remove devices from the
list:Step |
Action |
---|---|
1 |
In the list, select the IP address of the device to delete. |
2 |
Press the button. |
3 |
Click . |