Features and Functions
2.6.2
Data Security
The CP 243-1 IT is a physical connection between the Internet, Ethernet and S7-
200 backplane bus. It offers:
• No protection against intended or accidental manipulations of the data areas
and/or system states of the local or geographically remote CPUs
• No firewall functionality
Possible Internet access by the CP 243-1 IT to data stored on the S7-200 CPU al-
ways harbors the danger of misuse. For this reason, it is a good idea to change the
passwords assigned to the various users at regular intervals.
Additional information on the subject of security can be found in the document on
information technology for the Siemens AG automation technology.
The CP 243-1 IT disconnects an active STEP 7 Micro/WIN 32 connection when no
STEP 7 Micro/WIN job was sent to the CPU during the last 50 seconds. This pre-
vents the Micro/WIN server on the CP 243-1 IT from being blocked by network er-
rors which in turn prevents a new connection to STEP 7 Micro/WIN 32.
Note
Server accesses via the CP 243-1 IT to the S7-200 CPU are possible both in RUN
and STOP modes of the CPU. In STOP mode, however, program variables or I/O
values are not updated.
Caution
The user name and related password required to log in on an FTP server are al-
ways transmitted unencrypted over the network in accordance with valid general
specifications of the FTP protocol.
2.6.3
Communication Security
The CP 243-1 IT is equipped with a "Keep Alive" routine. This means that the CP
243-1 IT is able to automatically recognize the failure of a communication partner
or the applicable connection within a configurable period of time.
The Keep Alive time which is specified when the CP 243-1 IT is configured is the
time after which this internal routine is started. The routine attempts to reach the
communication partner. It takes approx. 10 seconds for this routine to be per-
formed. If the communication partner cannot be reached during this time, the CP
243-1 automatically concludes the connection to this partner. If the CP 243-1 IT is
the client, it then attempts to establish this connection again. Failure of the com-
munication partner is reported to the user with the routines described in chapter 6.
You should always activate the Keep Alive monitoring routine on all systems in-
volved in communication (if these systems have such a routine).
Note
The Keep Alive routine will not work unless the communication partner also sup-
ports this routine in accordance with RFC1122 and RFC793.
42
03/03
CP 243-1 IT
J31069-D0429-U001-A0-7618