Problem Definition: Unauthorized PG/PC ONLINE Access from Plant LAN
A redundant SIMATIC S7-400H system built around the CPU 414-4H (6ES7 414-4HM14-0AB0 or later) is fitted with two CP 443-1 EX20 communications processors (order number 6GK7 443-1EX20-0XE0) configured for PROFINET / S7 communication. The two CP cards hold the IP addresses 192.168.0.81 and 192.168.0.82 on the private automation subnet 192.168.0.0/24. The same subnet carries a Real-Time Information Portal (RTIP) server that publishes plant data as web pages. The plant-wide corporate LAN uses 172.21.0.0/16 and serves approximately eight engineering / operations clients that need read-only access to the published web data.
Both networks are bridged through a 24-port manageable Layer-2 switch that sits between the 8-port unmanaged switch at the CPU rack and the corporate LAN uplink. The unintended consequence of this topology is that any client on 172.21.0.0/16 with a copy of STEP 7 V5.5 (SIMATIC Manager) installed can resolve 192.168.0.81 or 192.168.0.82, scan the MPI/TCP subnet, and open an ONLINE session against the CPU 414-4H. Because the H-CPU shares the same backplane and STEP 7 project as both redundant CPs, a single ONLINE connection from a non-authorized subnet is sufficient to download hardware configuration, force variables, modify the user program, or stop the CPU — a hard violation of IEC 62443 zone-and-conduit principles and of the typical plant security policy that separates OT and IT domains.
The remediation is delivered at two layers:
-
CP 443-1 EX20 layer: configure the IP Access Control List (ACL) inside the CP to reject PG/OP connections originating from
172.21.0.0/16. -
Managed-switch layer: configure static ACL / port-security rules on the 24-port switch so that
172.21.x.xMAC/IP pairs cannot traverse the uplink to the automation subnet.
This article documents both layers, the verification procedure, the firmware prerequisites, and the troubleshooting matrix for the most common field failures.
CP 443-1 EX20 Hardware Identification
Confirm that the CP fitted in the S7-400H rack is the variant that supports the IP ACL feature. The relevant catalog numbers and firmware baselines are listed below.
| Order Number (MLFB) | Product Name | Integrated Switch | Min. Firmware for IP ACL | Released STEP 7 Version |
|---|---|---|---|---|
| 6GK7 443-1EX20-0XE0 | CP 443-1 (EX20) | 4-port unmanaged | V3.2.x (recommended V3.2.9 or later) | STEP 7 V5.5 + SP4 / HF7 |
| 6GK7 443-1EX30-0XE0 | CP 443-1 (EX30) | 4-port unmanaged | V3.2.x (shipped with V3.2.7+) | STEP 7 V5.5 + SP4 / HF7 |
| 6GK7 443-1GX30-0XE0 | CP 443-1 (GX30, 1 Gbit) | 4-port unmanaged | V3.2.x | STEP 7 V5.5 + SP4 / HF7 |
Older CP 443-1 variants (e.g. 6GK7 443-1EX11-0XE0) require a firmware upgrade to a minimum of V2.6 before the IP ACL dialog becomes available in HW Config. Siemens published the firmware update package on the support portal under entry ID 27013555 — CP 443-1 manuals and firmware.
Security Architecture of the CP 443-1 EX20
The CP 443-1 EX20 enforces access protection through three independent mechanisms, evaluated in the order shown:
- Port filter: blocks unused TCP/UDP ports so only S7 (port 102), PNIO (port 34962/34963), SNMP (port 161), and explicitly enabled services respond.
- IP access control list (ACL): an explicit allow / deny table indexed by (source IP, source mask, destination IP, destination mask, protocol, port). Up to 32 entries can be configured per CP. The first matching rule wins; if no rule matches, the packet is accepted by default unless a global "Block all" rule is placed at the bottom of the table.
- S7 password protection: protects the CPU against any ONLINE connection that has passed the ACL but lacks the configured CPU password (in HW Config → CPU → Protection).
It is critical to understand the default behavior: if no ACL rule is defined, the CP accepts every incoming connection on the allowed ports. Therefore the ACL must be configured even when the network appears "private" behind a managed switch — defense-in-depth requires that the CP itself enforce the policy.
Prerequisites
- STEP 7 V5.5 + SP4 or later installed on the engineering station.
- SIMATIC Manager project with both CP 443-1 EX20 objects present in HW Config (rack 0 / rack 1 for the H-system).
- CPU password known (write it down before starting; if the password is lost the SD card must be reformatted).
- Source IP ranges documented in CIDR notation:
- Allowed (authorized HMI / engineering stations):
192.168.0.0/24minus CP addresses, e.g.192.168.0.50–192.168.0.70. - Denied (plant LAN):
172.21.0.0/16. - RTIP server (allowed):
192.168.0.100.
- Allowed (authorized HMI / engineering stations):
- Managed switch documentation (vendor / model / firmware) — typical candidates are SCALANCE XC-216, SCALANCE XR-324, Cisco IE-3300, or Hirschmann RS20/RS30.
- PG/PC interface set to
TCP/IP → Intel Etherneton the engineering station.
Network Topology — Reference Diagram
The diagram below summarizes the topology assumed by the configuration steps that follow. The 8-port unmanaged switch is replaced by a SCALANCE XB208 (managed) when defense-in-depth is required; the example below shows both layers.
+-----------------+ +----------------------+ +----------------------+
| CPU 414-4H #0 | | 24-port Managed | | Plant LAN |
| (rack 0) +------+ Switch (uplink) +------+ 172.21.0.0/16 |
| | | VLAN 10 = OT | | ~ 8 clients |
| CP443-1 EX20 | | VLAN 20 = IT | +----------+-----------+
| 192.168.0.81 +------+ ACL: deny VLAN 20 → | |
+-----------------+ | VLAN 10 | |
+----------+-----------+ |
+-----------------+ | |
| CPU 414-4H #1 | | |
| (rack 1) | +---------v-----------+ |
| | | 8-port switch | |
| CP443-1 EX20 +------+ (managed XB208) | |
| 192.168.0.82 | | IP ACL on CP | |
+-----------------+ +---------------------+ |
| |
+---------v--------+ |
| RTIP Server | |
| 192.168.0.100 | |
+------------------+ |
(plant LAN 172.21.x.x clients reach RTIP via L3 routing;
ACL on CP443-1 blocks them from 192.168.0.81 / .82 PG/OP port)
Step-by-Step: Configure the IP ACL inside the CP 443-1 EX20
- Open SIMATIC Manager and load the S7-400H project.
- Open HW Config and double-click the CP 443-1 EX20 in slot 4 of rack 0 (the second CP lives in slot 4 of rack 1).
- Select the Properties dialog, then the tab Access Protection (German: Zugriffsschutz). If this tab is missing, the CP firmware is below V3.2 — perform a firmware update first.
- In the Access Control List (ACL) table enter the rules shown below. Each rule row accepts or denies traffic based on source IP and destination IP. The "Protocol / Port" column is left at
TCP / 102for S7 ONLINE blocking.
| # | Source IP | Source Mask | Dest. IP | Dest. Mask | Protocol | Port | Action | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 192.168.0.50 | 255.255.255.255 | 192.168.0.81 | 255.255.255.255 | TCP | 102 | Permit | Engineering PG #1 |
| 2 | 192.168.0.51 | 255.255.255.255 | 192.168.0.81 | 255.255.255.255 | TCP | 102 | Permit | Engineering PG #2 |
| 3 | 192.168.0.100 | 255.255.255.255 | 192.168.0.81 | 255.255.255.255 | TCP | 102 | Permit | RTIP server (read-only OPC) |
| 4 | 172.21.0.0 | 255.255.0.0 | 192.168.0.81 | 255.255.255.255 | TCP | 102 | Deny | Plant LAN block |
| 5 | 192.168.0.82 | 255.255.255.255 | 0.0.0.0 | 0.0.0.0 | TCP | 102 | Permit | Redundant CP (sync) |
| 99 | 0.0.0.0 | 0.0.0.0 | 192.168.0.81 | 255.255.255.255 | TCP | 102 | Deny | Default deny (catch-all) |
Repeat the same set of rules for destination 192.168.0.82 (second CP in the H-rack) — duplicate the table and change the destination IP. The CP processes the ACL per destination interface, so both CPs must be configured independently.
- Click Apply, then OK. Repeat for the second CP in rack 1.
- Save & compile the HW Config (Station → Save and Compile).
- Download the HW Config to the H-system. During download, both CPs reset their TCP/IP stack for approximately 5–10 s; the S7-400H keeps running because the redundancy link is unaffected.
0.0.0.0 / 0.0.0.0 → CP-IP / 255.255.255.255 deny rule.Step-by-Step: Configure the Managed-Switch Layer
The CP-side ACL protects only S7 traffic destined for the CP. Other OT protocols (PROFINET, NTP, SNMP, DNS, HTTP to the RTIP) still flow between the subnets. Use the managed switch to restrict L2 / L3 forwarding between VLAN 10 (OT, 192.168.0.0/24) and VLAN 20 (IT, 172.21.0.0/16). The example below uses a SCALANCE XC-216; adapt the commands for Cisco / Hirschmann equivalents.
- Create VLAN 10 (OT) and VLAN 20 (IT). Assign port 1 (uplink to plant LAN) to VLAN 20 untagged, and ports 2–8 (CP + RTIP) to VLAN 10 untagged. The trunk port (uplink to corporate core) carries both VLANs tagged.
- Enable IP routing on the switch (Layer-3 option in SCALANCE) only for traffic that must traverse subnets — typically none if RTIP and CP are on the same VLAN 10.
- Define an ACL that blocks TCP/102 from VLAN 20 to VLAN 10:
! SCALANCE XC-216 example (CLI)
acl 100 deny tcp 172.21.0.0 0.0.255.255 192.168.0.0 0.0.0.255 eq 102
acl 100 permit ip any any
interface gigabitethernet 0/1
ip access-group 100 in
- Enable 802.1X port-based authentication on the plant-LAN uplink so that only RADIUS-authorized MACs can join VLAN 20.
- Enable storm control and BPDU guard on all access ports to prevent loop-bridge injection from the IT side.
- Disable DTP, CDP, and LLDP-MED on ports facing the OT network (information leakage).
For Cisco IE-3300 industrial switches the equivalent access list is:
ip access-list extended OT-SEGMENT
deny tcp 172.21.0.0 0.0.255.255 192.168.0.0 0.0.0.255 eq 102
deny udp 172.21.0.0 0.0.255.255 host 192.168.0.81 eq snmp
deny udp 172.21.0.0 0.0.255.255 host 192.168.0.82 eq snmp
permit ip any any
interface GigabitEthernet1/0/1
ip access-group OT-SEGMENT in
Password Protection and PG/OP Authorization on the CPU
The IP ACL stops the TCP connection at the CP; the CPU password stops the connection at the CPU itself. Both layers should be enabled so that a misconfigured ACL does not immediately expose the CPU.
- HW Config → CPU 414-4H → Protection tab.
- Set the protection level to Write-protection for F-blocks or higher. Choose level 2 ("Write-protection") for normal operation, level 3 ("Read/write protection") when the plant is in a maintenance shutdown.
- Enter a CPU password (8 characters minimum, alphanumeric). Siemens stores the password in the SD card; a forgotten password requires card re-format and full project reload.
- Also configure the CP 443-1 → Security tab → PG/PC access with the same password so that S7 routing from the engineering station is also authenticated.
Level 1 — Operating mode selector only (no password).
Level 2 — Password required for write operations (F-block / DB / OB modification).
Level 3 — Password required for read AND write (most restrictive).
Level 4 — Position of mode selector + password (cannot download without physical key).
Verification Procedure
Run the checks below before declaring the configuration complete. Each test exercises one of the protection layers.
-
Authorized ONLINE: from
192.168.0.50open SIMATIC Manager → Accessible Nodes → confirm192.168.0.81and.82appear. Open the project and force a DB variable — must succeed. -
Unauthorized ONLINE: from
172.21.5.42open SIMATIC Manager → Accessible Nodes. The scan must NOT return the CP IP. If the CP is still visible, the ACL on the switch is forwarding the S7-TSAP broadcast. -
RTIP web access: from
172.21.5.42open a browser and reachhttp://192.168.0.100(RTIP web portal). The HTTP/80 path must remain open — the ACL on TCP/102 must not interfere. - CP diagnostics: in STEP 7 → CP443-1 → Diagnostics → Connection Statistics. The counters Denied TCP connections and ACL rejects must increment during step 2.
- SNMP trap: enable SNMP trap on the CP for ACL-deny events; configure the SCALANCE to forward the trap to the central SIEM.
Diagnostics — Reading the CP Event Log
The CP 443-1 EX20 stores ACL-related events in its diagnostic buffer, accessible via STEP 7 → CP → Diagnostics → Diagnostic Buffer. The most relevant event IDs:
| Event ID | Byte 4 / 5 | Meaning | Action |
|---|---|---|---|
| 0x0001 | — | CP startup completed | Informational |
| 0x0103 | 0x13 | IP ACL entry triggered (deny) | Verify rule list, confirm deny was intentional |
| 0x0104 | 0x14 | IP ACL entry triggered (permit) | Informational |
| 0x0301 | 0x0A | Wrong CPU password (S7 access) | Check protection level on CPU |
| 0x0502 | 0x02 | Firmware download / configuration mismatch | Re-download HW Config |
| 0x0A0F | 0x0F | PG/PC connection refused (port 102 closed) | Check "Enable PG/PC Communication" flag in CP properties |
For detailed byte-level decoding refer to the CP 443-1 Diagnostics Manual in entry 27013555.
Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Remediation |
|---|---|---|---|
| Plant LAN client can still scan and find CP IP | ACL configured but no default-deny (#99) rule | Open CP → Access Protection → verify last rule | Add 0.0.0.0/0.0.0.0 → CP-IP/32 → TCP/102 → Deny rule |
| Authorized PG cannot connect after ACL applied | Source IP of PG missing from permit list | From PG, ping the CP; check arp -a
|
Add specific permit rule for the PG IP |
| RTIP web page no longer reachable from plant LAN | Switch ACL too broad — blocked all VLAN 20 → VLAN 10 | Test with curl http://192.168.0.100 from plant LAN |
Restrict switch ACL to tcp eq 102 only, permit HTTP |
| CPU password dialog appears every time | Protection level set to 3 + password forgotten on PG side | Confirm password stored in Set PG/PC Interface | Re-enter password or use level 2 for engineering |
| Both CPs report "connection interrupted" after download | ACL applied to both CPs but redundant link uses port 102 | Check ACL rule #5 (192.168.0.82 → 0.0.0.0 permit) | Ensure rule allows CP-to-CP S7 sync |
| Switch logs ACL deny storm from same source | Brute-force attempt from plant LAN | Identify source MAC via show mac address-table
|
Apply port-security / 802.1X on the access port |
Browser from plant LAN cannot reach 192.168.0.100
|
Local Network Privacy (LNP) in modern browsers / OS blocks 192.168.0.0/24 as "local" | Check browser console for "private network request" warning | Enable Chrome flag chrome://flags/#private-network-requests-respect-anchor-origins, or use IE11 / Firefox ESR on the RTIP server |
Firmware and Compatibility Notes
The IP ACL feature is firmware-version dependent. Verify the version reported under HW Config → CP → Module Information → Firmware before commissioning.
| CP Variant | FW Version | ACL Support | Recommended Action |
|---|---|---|---|
| CP 443-1 EX11 | ≤ V2.5 | None | Upgrade to ≥ V2.6 |
| CP 443-1 EX20 | V3.0.x | Limited (no per-port granularity) | Upgrade to V3.2.x |
| CP 443-1 EX20 | V3.2.x | Full ACL + password + SNMPv3 | Stay on latest V3.2.x service pack |
| CP 443-1 EX30 | V3.2.x | Full ACL + password + SNMPv3 + TLS | Recommended for new installations |
Firmware files are distributed by Siemens as *.upd packages and loaded via STEP 7 → PLC → Update Firmware. Do not downgrade from V3.2.x to V3.0.x — the ACL table is stored in a different NVM region and a downgrade will discard it.
Local Network Privacy and Modern Browsers
A side effect observed when the RTIP server is accessed from a plant-LAN client is the modern browser's Local Network Privacy (LNP) enforcement. Chrome, Edge, and Firefox block sub-resource fetches to 192.168.0.0/16 when the top-level page is served from a public or different private range, unless the browser receives a CORS Access-Control-Allow-Private-Network: true header from the RTIP server. This is unrelated to the CP access protection but often surfaces during the same troubleshooting session.
Remediation steps for the RTIP server side:
- Add the header
Access-Control-Allow-Private-Network: trueon the RTIP web responses. - If the browser still blocks, enable the Chrome flag
chrome://flags/#private-network-requests-respect-anchor-originsas a temporary measure. - On the engineering station running the browser, ensure the corporate firewall allows
172.21.x.x → 192.168.0.x:80,443at L4.
Commissioning Checklist
- [ ] CP 443-1 EX20 firmware ≥ V3.2.x on both racks.
- [ ] IP ACL configured with explicit permit list for authorized PGs / RTIP.
- [ ] Default-deny rule (#99) placed at the bottom of each CP's ACL table.
- [ ] CPU 414-4H protection level ≥ 2 with non-default password.
- [ ] Managed switch ACL mirrors the CP rule (block TCP/102 from 172.21.0.0/16 to 192.168.0.0/24).
- [ ] 802.1X / port-security enabled on plant-LAN access ports.
- [ ] SNMP traps enabled for ACL-deny events, forwarded to SIEM.
- [ ] Backup of HW Config (.s7f / .s7p) stored offline.
- [ ] Verification report signed by OT and IT stakeholders.
FAQ
Does the CP 443-1 EX20 support per-MAC filtering in addition to IP ACL?
No. The EX20 only supports IP-based ACL on TCP/UDP port numbers. MAC filtering must be enforced on the managed switch (802.1X or port-security). Refer to the S7-CP manual entry ID 8770665, chapter 3.4.5.
What is the maximum number of IP ACL entries per CP 443-1 EX20?
The CP firmware V3.2.x supports 32 ACL entries per CP interface. If more granular rules are required, segment the automation subnet into smaller /27 or /28 ranges to keep each CP under the 32-rule limit.
Will enabling the IP ACL break H-CPU redundancy synchronization?
No, as long as the ACL contains an explicit permit rule for the peer CP IP (192.168.0.82 ↔ 192.168.0.81) on TCP/102. Rule #5 in the example table above is mandatory; without it the redundant link will report "connection interrupted" within 30 s of the link-down test.
Can the ACL be configured online without an H-CPU STOP?
Yes. HW Config download of the CP 443-1 EX20 runs in RUN and resets only the TCP/IP stack of the CP. The S7-400H remains in RUN because the program execution lives on the CPU, not the CP. Expect a 5–10 s interruption of S7 connections during the download.
Is there a CLI alternative to HW Config for the ACL?
No. Siemens does not expose the IP ACL through the CP's Telnet/SSH CLI on the EX20. The ACL must be edited in SIMATIC Manager HW Config and downloaded to the CP. For audit purposes keep the *.s7f project file under version control.