Configuration Example Y 02/2015 Setting Up A Secure VPN .

2y ago
19 Views
3 Downloads
1.68 MB
35 Pages
Last View : 10d ago
Last Download : 3m ago
Upload by : Annika Witter
Transcription

Configuration Example02/2015Setting up a secure VPNConnection betweenCP x43-1 Adv. and a mobileVPN Client Using a staticIP AddressNCP VPN Client, CP 343-1 Advanced, CP 443-1 iew/en/108909919

Warranty and LiabilityWarranty and LiabilityNoteThe Application Examples are not binding and do not claim to be completeregarding the circuits shown, equipping and any eventuality. The ApplicationExamples do not represent customer-specific solutions. They are only intendedto provide support for typical applications. You are responsible for ensuring thatthe described products are used correctly. These Application Examples do notrelieve you of the responsibility to use safe practices in application, installation,operation and maintenance. When using these Application Examples, yourecognize that we cannot be made liable for any damage/claims beyond theliability clause described. We reserve the right to make changes to theseApplication Examples at any time without prior notice. If there are any deviationsbetween the recommendations provided in these Application Examples andother Siemens publications – e.g. Catalogs – the contents of the otherdocuments have priority.We do not accept any liability for the information contained in this document.Siemens AG 2015 All rights reservedAny claims against us – based on whatever legal reason – resulting from the use ofthe examples, information, programs, engineering and performance data etc.,described in this Application Example shall be excluded. Such an exclusion shallnot apply in the case of mandatory liability, e.g. under the German Product LiabilityAct ("Produkthaftungsgesetz"), in case of intent, gross negligence, or injury of life,body or health, guarantee for the quality of a product, fraudulent concealment of adeficiency or breach of a condition which goes to the root of the contract("wesentliche Vertragspflichten"). The damages for a breach of a substantialcontractual obligation are, however, limited to the foreseeable damage, typical forthe type of contract, except in the event of intent or gross negligence or injury tolife, body or health. The above provisions do not imply a change of the burden ofproof to your detriment.Any form of duplication or distribution of these Application Examples or excerptshereof is prohibited without the expressed consent of Siemens AG.SecurityinformationSiemens provides products and solutions with industrial security functions thatsupport the secure operation of plants, solutions, machines, equipment and/ornetworks. They are important components in a holistic industrial securityconcept. With this in mind, Siemens' products and solutions undergo continuousdevelopment. Siemens recommends strongly that you regularly check forproduct updates.For the secure operation of Siemens products and solutions, it is necessary totake suitable preventive action (e.g. cell protection concept) and integrate eachcomponent into a holistic, state-of-the-art industrial security concept. Third-partyproducts that may be in use should also be considered. For more informationabout industrial security, visit http://www.siemens.com/industrialsecurity.To stay informed about product updates as they occur, sign up for a productspecific newsletter. For more information, y: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20152

Table of ContentsTable of ContentsWarranty and Liability . 21Task and Solution. 41.11.21.32Configuration and Project Engineering . .42.3Siemens AG 2015 All rights reservedTask . 4Possible solution. 4Characteristics of the solution . 6Setting up the environment . 7Required components and IP address overview. 7NCP VPN Client . 9DSL access for the CP 343-1 Advanced . 10SIMATIC S7-300 station . 10Setting up the infrastructure . 17Configuring the VPN tunnel. 18Integrating the VPN endpoint CP 343-1 Advanced . 18Integrating the VPN endpoint NCP VPN Client . 20Defining the VPN properties. 21Transferring the configuration data. 25Establishing the VPN connection in the NCP VPN Client. 273Testing the Tunnel Function . 344History . 35Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20153

1 Task and Solution1Task and Solution1.1TaskThe task is to allow a service employee secure access to an automation system viathe Internet or a company's internal network.The following customer requirements have to be considered:Protection against spying and data manipulation.Prevention of unauthorized access.Provision of secure remote access for remote maintenance and remote control.Flexible access for the service employee (regardless of the user's location).Network protection without additional security appliances on the automationside.1.2Possible solutionComplete overviewSiemens AG 2015 All rights reservedThe figure below shows one way of implementing these customer requirements:Smartphone withIPSec Client AppAutomation CellInternetRouterSIMATIC S7-300 or S7-400with CP x43-1 AdvancedStaticWAN IP AddressVPN ClientVPN TunnelIndustrial EthernetVPN ServerRemote access of a service employee to the automation cell (nodes such asSIMATIC stations, panels, drives, PCs) is protected by a VPN tunnel.Client access from a mobile device to the automation cell is established using theNCP VPN Client, a VPN client software product for the Android operating system.The CP 343-1/CP 443-1 Advanced (here: VPN server) placed in front of theautomation cell is used as the endpoint of the VPN tunnel.Access to the CP 343-1/CP 443-1 Advanced from the WAN is predefined by theuse of a static WAN IP address.WAN access on the client side is flexible; the IP address is not relevant.When establishing the VPN tunnel, the roles are defined as follows:Table 1-1ComponentVPN roleNCP Secure VPN Clientfor AndroidInitiator (VPN client); starts the VPN connectionCP x43-1 AdvancedResponder (VPN server); waits for the VPN connectionSecurity: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20154

1 Task and SolutionNCP Secure VPN Client for Android"NCP Secure VPN Client for Android" is a universal VPN client for Android-basedsmartphones and tablets (Android 4.0 "Ice Cream Sandwich" or higher). It allowsconvenient, highly secure remote access to the company network and iscompatible with IPsec gateways from different manufacturers.Secure access for tablets and smartphones to entire automation cells.Protection of data transmission against spying and spoofing by means ofcertified standards.Easy to use due to–an intuitive graphical user interface.–configuration import from third-party manufacturers.Connection control and management, connection statistics, log files; trace toolfor error diagnostics; traffic light icon to indicate the connection status.Supports the DNS client function.CP x43-1 AdvancedSiemens AG 2015 All rights reservedThe CP x43-1 Advanced (version 3 or higher) is a communications processor withsecurity functions. For the SIMATIC S7-300/S7-400, it is the bridge between thefield level and the MES level and integrates seamlessly with the security structuresof the office and IT world.The module provides protection of the data transmission between devices ornetwork segments against data manipulation/spying and unauthorized access.In addition to the basic communications services, it offers the following functions:Two separate interfaces (integrated network separation): Gigabit interface withone RJ45 port and PROFINET interface with 2 RJ45 ports.High-quality stateful inspection firewall with filtering of IP- and MAC-based datatraffic.HTTPS, FTPS, NTP (secure).IPSec VPN (data encryption and authentication).Protection of the S7 station in which the CP is operated.Protection of the internal networks connected to the PROFINET interface.Support of multiple VPN tunnels at a time.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20155

1 Task and Solution1.3Characteristics of the solutionVPN tunnel for flexible access to the automation cell - possible, for example,for a service employee.Mobile network operator's default APN can be used (no additional costs for aspecial SIM card).Controlled, encrypted data traffic between CP x43-1 Advanced and NCP VPNClient.Integrated network diagnostics via SNMP or Syslog.Siemens AG 2015 All rights reservedThe firewall, VPN server and communication settings are made directly in theCP x43-1 Advanced; the security functions are integrated in thecommunications processor.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20156

2 Configuration and Project Engineering2Configuration and Project Engineering2.1Setting up the environment2.1.1Required components and IP address overviewSoftware packagesThis solution requires the following software packages:"Security Configuration Tool V4". This software is included in the scope ofdelivery of the security modules or available as a download under the followingEntry ID: 84467278."STEP 7 V5.5", Service Pack 2 or higher, Hotfix 1. The required HSP(HSP 1058) is included in the scope of delivery of the CP 343-1 Advanced oravailable as a download under the following Entry ID: 23183356.Smartphone: NCP Secure VPN Client (Premium Version) for Android (Android4.0 "Ice Cream Sandwich" or higher) (app has to be purchased in the GooglePlay Store)Install these software packages on the appropriate devices.Siemens AG 2015 All rights reservedRequired devices/components:To set up the environment, use the following components:A CP 343-1 Advanced (article number: 6GK7343-1GX31-0XE0)A CPU 317-2 PN/DP (article number: 6ES7317-2EK14-0AB0) with an MMC.A smartphone/tablet with the Android operating system (Android 4.0 "IceCream Sandwich" or higher) and "NCP Secure VPN Client for Android". Thisexample uses a Samsung Galaxy S4 mini.A SIM card from your mobile network operator (the appropriate services, forexample the Internet, are enabled).DSL access with a static WAN IP address and a DSL router (e.g., SCALANCEM81x-1).One or two 24V power supplies with cable connector and terminal block plug(the SIMATIC modules can also be operated with a shared power supply).A DIN rail with fitting accessories for the S7-300.The necessary network cables, TP cables (twisted pair) according to the IE FCRJ45 standard for Industrial Ethernet.An appropriate cable to connect the smartphone to the PC. Generally, this is aUSB cable.NoteA different S7-300 PROFINET CPU can also be used. For the deviceenvironment in which the CP can be operated with the range of functionsdescribed here, please refer to the appropriate chapter of the CP 343-1Advanced en/documentation/advanced/?DocVersionId 42597696395&TopicId 37239174923&guiLanguage enSecurity: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20157

2 Configuration and Project EngineeringNoteYou can also use a different Internet access method (e.g., UTMS).The configuration described below refers explicitly to the components listed in"Required devices/components".IP addressesFor this example, the IP addresses are assigned as follows:Smartphone withNCP VPN ClientDynamicWAN IPSIMATIC S7-300 withCP 343-1 AdvancedDSL RouterStaticWAN IP172.16.0.1172.16.47.1172.22.80.2Siemens AG 2015 All rights reservedTable 2-1ComponentPortIP addressRouterSubnet maskSmartphoneWAN portDynamic IP address fromprovider-Assigned byproviderDSL routerWAN portStatic IP address fromprovider-Assigned byproviderDSL routerLAN port172.16.0.1-255.255.0.0CP 343-1 Adv.Gigabit port172.16.47.1172.16.0.1255.255.0.0CP 343-1 Adv.PROFINET port172.22.80.2-255.255.255.0CPUPROFINET port172.22.80.3172.22.80.2255.255.255.0Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20158

2 Configuration and Project Engineering2.1.2NCP VPN ClientPhysical connection between PC and smartphoneThe quickest way to synchronize data is to use Windows Explorer and a USBconnection between the PC and the smartphone.The following requirements have to be met:The smartphone device driver is installed on the PC. This is usually doneautomatically.The smartphone must be in "USB Mass Storage mode".If everything is configured correctly, Windows provides the phone memory as adrive.Creating the "NCP" folderThe configuration file is stored in the "NCP Import" folder.If the "NCP" folder does not yet exist, create it as follows:Siemens AG 2015 All rights reserved1. In Windows Explorer, select "Computer" "Removable Disk". The right windowpane displays the smartphone's directory tree.2. Create a new folder: "NCP". The "Import" and "Export" subfolders are addedautomatically.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/20159

2 Configuration and Project Engineering2.1.3DSL access for the CP 343-1 AdvancedStatic IP addressWAN access of the NCP VPN Client to the CP 343-1 Advanced is implementedusing a fixed public IP address. This IP address must be requested from theprovider and then stored in the DSL router.Port forwarding on the DSL routerDue to the use of a DSL router as an Internet gateway, you have to enable thefollowing ports on the DSL router and forward the data packets to the CP 343-1Advanced (VPN server; Gigabit port):UDP port 500 (ISAKMP)UDP port 4500 (NAT-T)VPN functionIf the DSL router itself is VPN-capable, make sure that this function is disabled.Siemens AG 2015 All rights reserved2.1.4SIMATIC S7-300 stationConnection between PC and controllerConnect the PC on which STEP 7 V5.5 is installed to a PROFINET port of the CPUand change the network settings on the PC as follows:IP address: 172.22.80.100Subnet mask: 255.255.255.0Factory defaultTo make sure that no old configurations are stored in the CP 343-1 Advanced,reset the module to factory default.For the appropriate chapter in the CP 343-1 Advanced manual, please use thefollowing /documentation/advanced/?DocVersionId 42597696395&TopicId 40344018827&guiLanguage enChanging the IP address of the CPUTo download the project data to the CPU, it is useful to first change the IP addressof the CPU as shown in Table 2-1.The STEP 7 function "Edit Ethernet Node " is suitable for assigning the IPaddress. For more information, please refer to the manual, Entry ID: 45531110.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201510

2 Configuration and Project EngineeringSTEP 7 projectUse the STEP 7 configuration software to create a new project and create ahardware configuration with the modules you are using.For the required IP addresses for the CP 343-1 Advanced (Gigabit port andPROFINET port) and the CPU (PROFINET port), please refer to Table 2-1.Siemens AG 2015 All rights reservedInterface configuration of the CPU:Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201511

2 Configuration and Project EngineeringSiemens AG 2015 All rights reservedInterface configuration of the CP (Gigabit port):Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201512

2 Configuration and Project EngineeringSiemens AG 2015 All rights reservedInterface configuration of the CP (PROFINET port):Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201513

2 Configuration and Project EngineeringTime-of-day synchronizationIn the OFF state, the CP 343-1 Advanced loses the current time stamp and, bydefault, is set to 01.01.1984.To establish secure communication, it is essential that the current date and timeare always set on the CP.The CP provides the following modes for time-of-day synchronization:SIMATIC Mode (used in this example)NTP Mode (Network Time Protocol)Time-of-day synchronization for the S7-300 station is configured in the hardwareconfiguration.Proceed as follows:Siemens AG 2015 All rights reserved1. Open your STEP 7 project and the hardware configuration of the S7-300station.2. In the STEP 7 object properties of the CP 343-1 Advanced, "Time-of-DaySynchronization" tab, check the "Accept time of day on CP" check box andselect "Automatic".3. Click "OK" to close the dialog.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201514

2 Configuration and Project EngineeringSiemens AG 2015 All rights reserved4. In the STEP 7 object properties of the CPU, "Diagnostics/Clock" tab, set the"As master" synchronization type and the "1 minute" time interval forsynchronization in the automation system.5. Click "OK" to close the dialog.6. Select "Station" "Save and Compile" to save and compile the configuration.7. Close the hardware configuration.NoteMore information on these modes and the configuration can be found in Chapter3.3.5 of the Configuration Manual for SIMATIC S7 CPs (Entry ID: 60053848).Loading the controllerIn the SIMATIC MANAGER, select the S7-300 station and select "PLC" "Download " to download the project to your CPU and then start the CPU.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201515

2 Configuration and Project EngineeringAdjusting the time in the CPUDue to the "SIMATIC Mode" time-of-day synchronization, the CPU cyclicallypasses on its time to the CP 343-1 Advanced.The CPU clock must no longer be in the default state. It must have been set once.Time-of-day synchronization as the time-of-day master does not start before thetime of day has been set via SFC 0 "SET CLK" or using the PG function.NoteIn the following cases, the CPU clock has not yet been set:In the as-supplied state.After resetting to the as-supplied state using the mode selector switch.After a firmware update.1. Open your STEP 7 project and the hardware configuration of the S7-300station.Siemens AG 2015 All rights reserved2. Select the CPU and select "PLC" "Set Time of Day" to open the dialog whereyou can set the time of day.3. Check the "Take from PG/PC" check boxand confirm your selection.4. Select "Close" to close the dialog.ResultThe CPU's time of day has been set to the current PG time.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201516

2 Configuration and Project Engineering2.1.5Setting up the infrastructureConnect all the components involved in this solution.Smartphone withNCP VPN ClientDSL RouterWAN PortSIMATIC S7-300 withCP 343-1 AdvancedLAN PortGigabit PortPROFINET PortPartnerPartner portTable 2-2Siemens AG 2015 All rights reservedComponentNoteLocal portCP 343-1 AdvancedGigabit portDSL routerCP 343-1 AdvancedPROFINET portE.g., an automation network (does notexist in this solution)LAN portIn all devices in the internal network of the CP 343-1 Advanced (e.g., controllers,panels, etc.), please make sure to enter the IP address of the PROFINET port asthe default gateway.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201517

2 Configuration and Project Engineering2.2Configuring the VPN tunnelSCT projectThe VPN tunnel configuration is performed using the Security Configuration ToolV4 integrated in STEP 7 and started when enabling the security function in theCP 343-1 Advanced.Components usedThis solution uses the following security components: NCP Secure VPN Client forAndroid and CP 343-1 Advanced (version 3 or higher).2.2.1Integrating the VPN endpoint CP 343-1 AdvancedOverviewTo integrate the CP into the Security Configuration Tool, perform the followingsteps:Enable the security function of the CP.Create a user and password for the SCT project integrated in STEP 7.Siemens AG 2015 All rights reservedProceed as follows:1. Open your STEP 7 project and the hardware configuration of the S7-300station.2. In the STEP 7 object properties of the CP 343-1 Advanced, "Security" tab,check the "Enable security" check box.3. In the following dialog, create a new user with a user name and the associatedpassword. The user is automatically assigned the "Administrator" role.4. Confirm your entries with "OK".5. Close the STEP 7 object properties with "OK".Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201518

2 Configuration and Project Engineering6. Confirm the following security message with "OK".7. Select "Station" "Save and Compile" to save and compile the hardwareconfiguration.8. Close the hardware configuration.ResultYou have created a new security project.Opening the SCT projectIn the hardware configuration, select the "Edit" "Security Configuration Tool"menu command to open the Security Configuration Tool and log in.Siemens AG 2015 All rights reservedResultThe security module is displayed in the list of configured modules.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201519

2 Configuration and Project Engineering2.2.2Integrating the VPN endpoint NCP VPN ClientTo integrate the NCP VPN Client component into the Security Configuration Tool,proceed as follows:1. Use "Insert" "Module" or select the appropriate menu icon to open themodule selection dialog.Define the following module:Product type: SOFTNET configurationModule: NCP VPN client for AndroidFirmware release: V2.1Siemens AG 2015 All rights reserved2. Assign a name to the module.Click "OK" to close the dialog.ResultNow the NCP VPN Client appears as an additional module.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201520

2 Configuration and Project Engineering2.2.3Defining the VPN propertiesCreating a VPN groupAll members of a VPN group are authorized to communicate with each otherthrough a VPN tunnel.To create a VPN group, proceed as follows:Siemens AG 2015 All rights reserved1. In the project tree, select the "VPN groups" item. Use "Insert" "Group" orselect the appropriate menu icon to create a new VPN group.2. One after the other, select the CP 343-1 Advanced and the NCP VPN Client("NCP") from the "All modules" list and use drag and drop to insert them intothe VPN group.ResultThe CP 343-1 Advanced and the NCP VPN Client have been assigned to VPNgroup Group1.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201521

2 Configuration and Project EngineeringDefining the VPN parameters in the CP 343-1 AdvancedThe WAN IP address of the DSL router is a piece of information that is required toestablish the VPN tunnel.Parameterize this piece of information as follows:1. In the "All modules" project tree, select the CP 343-1 Advanced anddouble-click to open its properties dialog.2. In the "VPN" tab, select the "Responder" VPN role for the CP 343-1 Advanced.In the WAN IP address / FQDN field, enter the WAN IP address of your DSLaccess point.Siemens AG 2015 All rights reservedIn addition, enable access to the internal network.3. Close the dialog with "OK".4. Confirm the message with "OK".5. Save the project.ResultThe VPN configuration is complete.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201522

2 Configuration and Project EngineeringDefining the VPN parameters in the NCP VPN ClientTo establish the VPN connection, the NCP VPN Client requires the storage path ofthe configuration file in its directory tree.Parameterize it as follows:1. In the "All modules" project tree, select the NCP VPN Client and double-click toopen its properties dialog.2. In the "VPN" tab, enter the following storage path:"/storage/emulated/0/NCP/Import"Note:The storage path must match the entry stored in the NCP VPN Client.Siemens AG 2015 All rights reservedClick "OK" to close the dialog.ResultThe VPN configuration is complete.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201523

2 Configuration and Project EngineeringChanging the authentication methodThe preshared key method is used to authenticate the VPN users.The change from "Certificate" to "Preshared key" can only be made in theAdvanced view of the Security Configuration Tool.1. Use the "View" menu item to enable Advanced mode.2. Confirm the warning with "OK".Siemens AG 2015 All rights reserved3. In the project tree, select the newly created VPN group Group1 anddouble-click to open its properties dialog.4. Select the "Preshared key" authentication method. Assign a key name of yourchoice or keep the default name.5. Close the dialog with "OK".Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201524

2 Configuration and Project Engineering6. Confirm the message with "OK".7. Save the project.ResultThe authentication method has been changed to "Preshared key".2.2.4Transferring the configuration dataThe transfer of the configuration data to the appropriate security components isimplemented in different ways:CP 343-1 Advanced:Download via the STEP 7 project.Siemens AG 2015 All rights reservedNCP VPN Client:The Security Configuration Tool generates a configuration file for import into theclient software and exports the required data to a specified location.NCP VPN Client1. Select the NCP VPN Client and select the "Transfer" "To module(s) " menucommand.2. Save the Project name .NCP.ini" configuration file to your project directory.3. Confirm the following message (timeout adjustment) with "OK".4. Close the Security Configuration Tool.ResultThe configuration file, " Project name .NCP.ini", is saved to the project directory.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201525

2 Configuration and Project EngineeringCP 343-1 Advanced1. Connect the PC on which the Security Configuration Tool is installed to aPROFINET port of the CPU and change the network settings on the PC asfollows:IP address: 172.22.80.100Subnet mask: 255.255.255.02. Select "Station" "Save and Compile" to save and compile the hardwareconfiguration.3. Select "Options" "Configure Network" to start NetPro and here, too, compilethe entire configuration using "Network" "Save and Compile ".4. Close the output to check the consistency.Siemens AG 2015 All rights reserved5. Close NetPro and the hardware configuration.6. In the SIMATIC MANAGER, select the S7-300 station and select "PLC" "Download " to download the configuration data to your CPU. Then start theCPU.7. If downloading has completed without errors, the security module startsautomatically and the new configuration has been activated.ResultThe security module is configured and in productive mode.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201526

2 Configuration and Project Engineering2.3Establishing the VPN connection in the NCP VPN ClientTransferring the configuration dataThe " Project name .NCP" configuration file generated by the SecurityConfiguration Tool contains all the settings the NCP VPN Client needs to establishthe VPN connection.Copy this file to the phone memory as described below:1. Connect the smartphone to the PC.2. In Windows Explorer, select "Computer" "Removable Disk". The right windowpane displays the smartphone's directory tree. Open the "NCP" "Import"folder.3. If necessary, use the standard Windows functions to delete any existingconfiguration files and certificates.Siemens AG 2015 All rights reserved4. Open another Windows Explorer window and navigate to your projectdirectory.5. Select the " Project name .NCP.ini" configuration file associated with the NCPVPN Client and use the standard Windows functions to copy it to the "NCP" "Import" folder in the smartphone memory.ResultThe configuration file has been transferred to the smartphone.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201527

2 Configuration and Project EngineeringOpening the NCP VPN ClientAside from a graphical user interface, the NCP VPN Client features various menucommands for manual configuration, display of log files and import/export ofconfiguration data from third-party manufacturers.Siemens AG 2015 All rights reserved1. Open the "NCP Secure VPN Client for Android" app on your smartphone.2. Press the "Menu" button on the smartphone and open "Import / Export".Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201528

2 Configuration and Project EngineeringSiemens AG 2015 All rights reservedResultBy storing the configuration file in the path specified in "Import Path" ("NCP" "Import"), it is automatically detected by the NCP VPN Client and displayed.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201529

2 Configuration and Project EngineeringConfirming the configuration fileAll the settings the NCP VPN Client needs to establish the VPN connection to theCP 343-1 Advanced are stored in the " Project name .NCP.ini" configuration file.This file has already been stored in the "NCP" "Import" folder on the smartphoneand is detected by the NCP VPN Client.Confirm this file as follows:1. Once again, press the "Menu" button on the smartphone and open "Import /Export".2. Select " Project name .NCP.ini".Siemens AG 2015 All rights reserved3. The new configuration file is saved as a profile. Click "Next" to import it.Security: NCP CPx43 StaticEntry ID: 108909919, V1.0,02/201530

2 Configuration and Project EngineeringSiemens AG 2015 All rights reserved4. The contents of the configuration file are displayed on the smartphone screen.Se

NCP Secure VPN Client for Android "NCP Secure VPN Client for Android" is a universal VPN client for Android-based smartphones and tablets (Android 4.0 "Ice Cream Sandwich" or higher). It allows convenient, highly secure remote access to the company network and is com

Related Documents:

Cisco 3560 & 3750 NetFlow Configuration Guide Cisco Nexus 7000 NetFlow Configuration Cisco Nexus 1000v NetFlow Configuration Cisco ASR 9000 NetFlow Configuration Appendix. 3 Cisco NetFlow Configuration Cisco IOS NetFlow Configuration Guide Netflow Configuration In configuration mode issue the following to enable NetFlow Export:

2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 2015 . Removal handle Sound output / wax protection system. 11 Virto V-10 Custom made shell Battery door Volume control (optional) Push button Removal handle . Before using

Configuration Management (CM): The systematic evaluation, co-ordination, review, approval or disapproval, documentation and implementation of all proposed changes in the configuration of a product, after formal establishment of its configuration baseline. Configuration Items (CI): Configuration items are the basic units of configuration management.

To determine the electron configuration of any of the first 38 elements of the periodic table To determine the identity of an element from its electron configuration To complete an orbital diagram using arrows to represent electrons . . rows on the periodic table .File Size: 863KBPage Count: 31Explore furtherElectron Configuration Chart for All Elements in the .sciencestruck.comElectron configuration of every element in the periodic tablewww.biochemhelp.comElectron Configuration Chart - ThoughtCowww.thoughtco.comList of Electron Configurations of Elementssciencenotes.orgElectron Configuration - Detailed Explanation with Examplesbyjus.comRecommended to you based on what's popular Feedback

Cisco 3560 & 3750 NetFlow Configuration Guide Cisco Nexus 7000 NetFlow Configuration Cisco Nexus 1000v NetFlow Configuration Cisco ASR 9000 NetFlow Configuration Appendix. 8 Cisco NetFlow Configuration Cisco 3560X & 3750X NetFlow Configuration Your software release may not support all the features documented in this module.File Size: 2MB

3. Layer 2 - LAN Switching Configuration Guide 4. Layer 3 - IP Services Configuration Guide 5. Layer 3 - IP Routing Configuration Guide 6. IP Multicast Configuration Guide 7. ACL and QoS Configuration Guide 8. Security Configuration Guide . IP network IRF virtual device IP network IRF link Equal to Master Slave Basic Concepts Role

Contents iv Cisco IOS XR Command Modes Reference HSRP Interface Configuration Mode CMR-6 Interface Address Family Configuration Mode CMR-7 Interface Configuration Mode CMR-7 Interface Configuration Mode (Protocol Areas) CMR-8 Interface IGMP Configuration Mode CMR-8 Interface Management Configuration Mode CMR-8 Interface Mulitcasting Mode CMR-9 Interface PIM Configuration Mode CMR-9

NP ModBus TCP N System Configuration Example 8 Add a ModBus Master Port and Node Expand the "MB NP Modbus TCP" branch on the I/O Configuration Form by clicking on the . Expand the Modbus TCP by clicking on the . Expand the "ModBus Port NP ModBus TCP Master Port" branch on the I/O Configuration Form by clicking on the . Expand the Nodes branch on the I/O Configuration Toolbox by .