VPN with INSYS routers Connecting two Siemens S7-300 in different networks Configuration Guide
Pos: 1 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/1 Einführung: Prinzipschaltbild und Ziel/1-0 h1 --- Einführung --- @ 5\mod_1243351890374_91.doc @ 20029 @ 1 Introduction Copyright 2013 INSYS MICROELECTRONICS GmbH Any duplication of this üublication is prohibited. All rights on this publication and the devices are with INSYS MICROELECTRONICS GmbH Regensburg. Trademarks The use of a trademark not shown below is not an indication that it is freely available for use. MNP is a registered trademark of Microcom Inc. IBM PC, AT, XT are registered trademarks of International Business Machine Corporation. Windows is a registered trademark of Microsoft Corporation. Linux is a registered trademark of Linus Torvalds. INSYS is a registered trademark of INSYS MICROELECTRONICS GmbH. The principles of this publication may be transferred to similar combinations. INSYS MICROELECTRONICS GmbH does not assume liability or provide support in this case. Moreover, it cannot be excluded that other effects or results than described here are produced, if other, similar components are combined and used. INSYS MICROELECTRONICS GmbH is not liable for possible damages. Publisher INSYS MICROELECTRONICS GmbH Hermann-Köhl-Str. 22 D-93049 Regensburg Germany Phone +49 941 58692 0 Fax +49 941 58692 45 E-mail info@insys-icom.com URL http://www.insys-icom.com Print 31. Jul. 2013 Item No. - Version 1.0 Language EN 2 Connecting two Siemens S7-300 in different networks EN Vers. 1.0 31. Jul. 2013 www.insys-icom.com
Pos: 2 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/1 Einführung: Prinzipschaltbild und Ziel/1-1 TE Ziel allgemein @ 5\mod_1259744063976_91.doc @ 22643 @ Pos: 3 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/1-1 TE Ziel: Verbinden zweier Siemens S7-300 über einen VPN-Tunnel @ 7\mod_1339665519927_91.doc @ 32138 @ Pos: 4 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/1-2 TE Prinzipschaltbild: Verbinden zweier Siemens S7-300 über einen VPN-Tunnel @ 7\mod_1339665521221_91.doc @ 32144 @ Pos: 5 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/2 Kurzfassung/2-00 h1 --- Kurzfassung --- @ 5\mod_1259746860297_91.doc @ 22649 @ 1 Introduction 1 Introduction General The present publication refers to a combination of selected hardware and software components of INSYS MICROELECTRONICS GmbH as well as other manufacturers. All components have been combined with the target to realize certain results and effects for certain applications in the field of professional data transfer. All components have been prepared, configured and used as described in this publication. Thus, the desired results and effects have been achieved. The exact descriptions of all used components, to which this publication refers, are described in the tables Hardware, Accessories and Software at the end of this publication. The symbols and formattings used in this publication are explained in the correspondent section at the end of this publication. Some configurations or preparations, which are precondition in this publication, are described in other publications. Therefore, always refer to the related device manuals. INSYS devices with web interface provide you with helpful information about the configuration possibilities, if you click on "display help text" in the header. Target of this Publication Two PLCs Siemens S7-300 at different locations are to be connected via Internet. Usually, the sender address of one control is replaced by the router address for communication (NAT). Then, the remote control sends its response to this router address. In case of the S7-300, the local control rejects any further communication, because this new target address of the response does not match its original sender address. Use this publication to find out how to establish a secure VPN connection using two INSYS routers in order to realise such a connection nevertheless by disabling NAT (Network Address Translation) for incoming packets and route the packets without change through a VPN tunnel. Figure 1: Connecting two Siemens S7-300 via a VPN tunnel Connecting two Siemens S7-300 in different networks 3 www.insys-icom.com 31. Jul. 2013 Vers. 1.0 EN
Pos: 6 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/2-10 TÄ Kurzfassung: Verbinden zweier Siemens S7-300 über einen VPN-Tunnel @ 7\mod_1339674138447_91.doc @ 32187 @ Pos: 7 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/3 Konfiguration/3-0 h1 --- Konfiguration --- @ 4\mod_1239201153573_91.doc @ 18709 @ 1 Summary 2 Summary Configuration of a VPN Connection Without NAT How to configure an INSYS router for a VPN connection without NAT. You will find detailed step by step instructions in the following section. 1. Open in the menu Dial-In / Dial-Out / LAN (ext) the page Routing 2. Disable "Activate NAT for incoming packets" 3. Save settings 4. In case of OpenVPN connections, open in the menu Dial-In / Dial-Out / LAN (ext) the page OpenVPN client/server 5. Disable "Masquerade packets before tunnelling" 6. Save settings 7. Open in the menu System the page Reset 8. Select "Restart" and restart the device 4 Connecting two Siemens S7-300 in different networks EN Vers. 1.0 31. Jul. 2013 www.insys-icom.com
Pos: 8 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/3 Konfiguration/3-00 TÄ Vorbereitungen @ 5\mod_1249050937179_91.doc @ 21049 @ Pos: 10 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/3-05 HA Verbinden zweier Siemens S7-300 über einen VPN-Tunnel @ 7\mod_1339674493504_91.doc @ 32199 @ Configuration 3 Configuration Provisions Please prepare the following items before starting the configuration: Pos: 9 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/3-01 HA Vorbereitungen @ 7\mod_1339674493082_91.doc @ 32193 @ Both controls are connected to their INSYS routers and ready for operation. Both INSYS routers are connected to power supply and ready for operation. You have access to each INSYS router via your web browser. Both INSYS routers are configured ready for operation for a connection via the WAN interface. Both INSYS routers are configured ready for operation for a VPN connection. Information and instructions about this can be found in the appropriate manuals and other Configuration Guides, which describe further necessary steps to establish a VPN connection, e.g. creating certificates or configuring server/client, under http://www.insys-icom.com/cg. Configuring an INSYS Router for a VPN Connection Without NAT How to disable Network Address Translation (NAT) for the VPN connection and masking the packets through the VPN tunnel. The networks, in which both controls are located, must have different network address ranges. The following settings must be made for both INSYS routers. 1. Select in the menu the page Routing. This page is under the menu item Dial-In, Dial-Out, or LAN (ext) depending on the used INSYS router. 2. Remove the checkmark in the checkbox "Activate NAT for incoming packets". Connecting two Siemens S7-300 in different networks 5 www.insys-icom.com 31. Jul. 2013 Vers. 1.0 EN
Pos: 11 /Datenkommunikation/Configuration Guide/=== ORGA - Module ===/5 Verwendete Komponenten / Weiterführende Informationen/5-0 h1 --- Verwendete Komponenten --- @ 5\mod_1253000236681_91.doc @ 21647 @ 1 Configuration 3. Click OK at "Confirm all" to save the settings. If you use an OpenVPN connection, you must also disable masking of the packets before tunnelling. This step is not necessary in case of an IPsec connection. 4. Select in the menu the page OpenVPN client. This page is under the menu item Dial-In, Dial-Out, or LAN (ext) depending on the used INSYS router. If the currently configured INSYS router acts as an OpenVPN server, the OpenVPN server page must be selected here. 5. Remove the checkmark in the checkbox "Masquerade packets before tunnelling". 6. Click OK at "Confirm all" to save the settings. 7. Select in the menu the page System Reset. 8. Select the option "Restart" and click on OK. NAT is disabled for the VPN connection after the restart with this. 6 Connecting two Siemens S7-300 in different networks EN Vers. 1.0 31. Jul. 2013 www.insys-icom.com
Pos: 13 /Datenkommunikation/Notizen - Leere Seite zum Auffüllen auf Seitenumfang "x mal 4" @ 5\mod_1242998978108_91.doc @ 19977 @ Used Components 4 Used Components Pos: 12 /Datenkommunikation/Configuration Guide/MoRoS/Verbinden zweier S7-300/5-1 TE Verwendete Komponenten @ 7\mod_1339674494393_91.doc @ 32211 @ Please observe: The power supply units required to operate devices are not listed here in detail. Take care for a provision at the site, if they are not part of the scope of delivery. Hardware Description Manufacturer Type Version Router INSYS MoRoS PRO or MLR from firmware 2.2.0 PLC Siemens S7-300 - Table 1: Used hardware Software Description Manufacturer Type Version Operating system Microsoft Windows XP Pro latest Browser Mozilla Firefox latest Table 2: Used software Connecting two Siemens S7-300 in different networks 7 www.insys-icom.com 31. Jul. 2013 Vers. 1.0 EN
Germany INSYS MICROELECTRONICS GmbH Hermann-Köhl-Str. 22 93049 Regensburg Germany Phone +49 941 58692 0 Fax +49 941 58692 45 E-mail info@insys-icom.com URL www.insys-icom.com Great Britain INSYS MICROELECTRONICS UK Ltd. The Venture Centre Univ. of Warwick Science Park Sir William Lyons Road Coventry, CV4 7EZ Great Britain Phone +44 2476 323 237 Fax +44 2276 323 236 E-mail info@insys-icom.co.uk URL www.insys-icom.co.uk Czech Repulic INSYS MICROELECTRONICS CZ, s.r.o. Slovanská alej 1993 / 28a 326 00 Plzen-Východní Předměstí Czech Republic Phone +420 377 429 952 Fax +420 377 429 952 Mobile +420 777 651 188 E-mail info@insys-icom.cz URL www.insys-icom.cz