
S7-Firewall quick start guide 6 / 9 2021/02/28 20:29
Parameter Possible setting Purpose
Connection
channel
Used channel of
the connection
In the Simatic S7 PG and OP channels are available. This channel is
used as an additional feature for identifying the sender. Both PG and
OP functions are possible on each of the two channels. Operating
units / WinCC etc. usually use OP channels. This channel is also
recommended for HMI devices. The Siemens PG software basically
uses the PG channel. Unfortunately, there is a variety of software on
the market that does not have the expertise to set this channel. This
can be found in the LOG file. A reasonable HMI software, or the
corresponding software driver, provides for the adjustability of this
channel. For example, (PG / HMI identical) from the same computer,
the PG / OP channel remains to identify the sender.
The PLC channel corresponds to the “other” or “other” channel in the
PLC
Input the PLC stations
Parameter Possible setting Purpose
Nr. automatic consecutive number
Name Free of the user Name of the Station
active
yes (x) Connections to this station are handled by the firewall
no() Connections to this station are not processed, i. They are
blocked
IP-Address IP address of the PLC station Identification of the sender
Entry required
Enter the S7 firewall connections
The connections are made up of the combination HMI / PG station and PLC station. Each HMI / PLC station
can be used several times. If the Mac or IP address is changed, this must only be changed centrally in the
HMI / PG station or PLC station. Each connection is assigned a connection rule.
If “PG full function” is selected, this connection is a full access. In the future, this access can be divided
more closely (Read / write defined blocks, PLC start / stop, reset, system data (read / write)).
Parameter Possible setting Purpose
Nr. automatic consecutive number
Name Free of the user Connection name Also serves as a “link” to open and edit the rule
script.
active yes (x) This connection is processed by the firewall
no () This connection is not processed, i. It is blocked
Allow PG Full
Function
(x) This connection is a PG connection and can carry out all functions
no ()
This connection is a Restricted Connection. Only accesses to the
shared function and data areas, as defined in the associated rule
script, are permitted.
The rule script
In the rule script, the data areas or possible accesses for the respective connection are defined. The script
can be reached via the link of the name of the connection.