EasyManuals Logo
Home>Siemens>Switch>SIMATIC NET SCALANCE XR-300

Siemens SIMATIC NET SCALANCE XR-300 User Manual

Siemens SIMATIC NET SCALANCE XR-300
114 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #16 background imageLoading...
Page #16 background image
Authentication
Note
Accessibility risk - Risk of data loss
Do not lose the passwords for the device. Access to the device can only be restored by resetting
the device to factory settings which completely removes all con󹪝guration data.
Replace the default passwords for all user accounts, access modes and applications (if
applicable) before you use the device.
De󹪝ne rules for the assignment of passwords.
Use passwords with a high password strength. Avoid weak passwords, (e.g. password1,
123456789, abcdefgh) or recurring characters (e.g. abcabc).
This recommendation also applies to symmetrical passwords/keys con󹪝gured on the device.
Make sure that passwords are protected and only disclosed to authorized personnel.
Do not use the same passwords for multiple user names and systems.
Store the passwords in a safe location (not online) to have them available if they are lost.
Regularly change your passwords to increase security.
A password must be changed if it is known or suspected to be known by unauthorized
persons.
When user authentication is performed via RADIUS, make sure that all communication takes
place within the security environment or is protected by a secure channel.
Watch out for link layer protocols that do not o󹪜er their own authentication between
endpoints, such as ARP or IPv4. An attacker could use vulnerabilities in these protocols to
attack hosts, switches and routers connected to your layer 2 network, for example, through
manipulation (poisoning) of the ARP caches of systems in the subnet and subsequent
interception of the data tra󹪟c. Appropriate security measures must be taken for non-secure
layer 2 protocols to prevent unauthorized access to the network. Physical access to the local
network can be secured or secure, higher layer protocols can be used, among other things.
Certi󹪝cates and keys
There is a preset SSL/TLS (RSA) certi󹪝cate with 4096 bit key length in the device. Replace this
certi󹪝cate with a user-generated, high-quality certi󹪝cate with key. Use a certi󹪝cate signed by
a reliable external or internal certi󹪝cation authority. You can install the certi󹪝cate via the
WBM ("System > Load and Save").
Use certi󹪝cates with a key length of 4096 bits.
Use the certi󹪝cation authority including key revocation and management to sign the
certi󹪝cates.
Make sure that user-de󹪝ned private keys are protected and inaccessible to unauthorized
persons.
If there is a suspected security violation, change all certi󹪝cates and keys immediately.
Use password-protected certi󹪝cates in the format "PKCS #12".
Security recommendations
3.1Security recommendations
SCALANCE XR-300
16 Operating Instructions, 03/2023, C79000-G8976-C586-02

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Siemens SIMATIC NET SCALANCE XR-300 and is the answer not in the manual?

Siemens SIMATIC NET SCALANCE XR-300 Specifications

General IconGeneral
BrandSiemens
ModelSIMATIC NET SCALANCE XR-300
CategorySwitch
LanguageEnglish

Related product manuals