This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
DANGER
indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will be
used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to property
damage.
Qualified Personnel
The product/system described in this documentation may be operated only by personnel qualified for the specific
task in accordance with the relevant documentation, in particular its warning notices and safety instructions. Qualified
personnel are those who, based on their training and experience, are capable of identifying risks and avoiding
potential hazards when working with these products/systems.
Proper use of Siemens products
Note the following:
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
documentation. If products and components from other manufacturers are used, these must be recommended or
approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
Disclaimer of Liability
We have reviewed the contents of this publication to ensure consistency with the hardware and software described.
Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the information in this
publication is reviewed regularly and any necessary corrections are included in subsequent editions.
Siemens AG
Digital Industries
Postfach 48 48
90026 NÜRNBERG
GERMANY
6.1Safety when connecting up ....................................................................................................41
6.2Connecting a media module ..................................................................................................42
7Technical data ............................................................................................................................................43
7.1Construction, installation and environmental conditions ........................................................43
7.2Connectors and electrical data...............................................................................................45
Classification DescriptionTerms used
Product lineFor all devices and variants of all product groups within the
Product group For all devices and variants of a product group, only the
DeviceFor a device, only the device name is used.MM992-2SFP
VariantFor a variant of the device, the device name has the appro‐
All variants of
a device
SIMATIC NET glossary
Explanations of many of the specialist terms used in this documentation can be found in the
SIMATIC NET glossary.
You will find the SIMATIC NET glossary here:
SCALANCE X-300 product line, the term IE switches X-300
is used.
product group is used.
priate variant added to it in brackets (2x24V).
For all variants of the device, the device name has (all) added
to it.
IE switches X-300
MM900
(-)
(-)
● SIMATIC NET Manual Collection or product DVD
● On the Internet under the following address:
Security information
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions constitute one element of such a concept.
Customers are responsible for preventing unauthorized access to their plants, systems,
machines and networks. Such systems, machines and components should only be connected
to an enterprise network or the internet if and to the extent such a connection is necessary and
only when appropriate security measures (e.g. firewalls and/or network segmentation) are in
place.
For additional information on industrial security measures that may be implemented, please
visit
https://www.siemens.com/industrialsecurity (http://www.siemens.com/industrialsecurity)
Siemens’ products and solutions undergo continuous development to make them more secure.
Siemens strongly recommends that product updates are applied as soon as they are available
and that the latest product versions are used. Use of product versions that are no longer
supported, and failure to apply the latest updates may increase customers’ exposure to cyber
threats.
To stay informed about product updates, subscribe to the Siemens Industrial Security RSS
Feed under
https://www.siemens.com/industrialsecurity (http://www.siemens.com/industrialsecurity)
Device defective
If a fault develops, please send the device to your SIEMENS service center for repair. Repairs
on-site are not possible.
Recycling and disposal
The products are low in pollutants, can be recycled and meet the requirements of the WEEE
directive 2012/19/EU for the disposal of electrical and electronic equipment.
Do not dispose of the products at public disposal sites.
For environmentally friendly recycling and the disposal of your old device contact a certified
disposal company for electronic scrap or your Siemens contact (Product return (https://
Note the following safety notices. These relate to the entire working life of the device.
You should also read the safety notices relating to handling in the individual sections,
particularly in the sections "Installation" and "Connecting up".
CAUTION
To prevent injury, read the manual before use.
Safety notices on use in hazardous areas
General safety notices relating to protection against explosion
WARNING
EXPLOSION HAZARD
2
Do not open the device when the supply voltage is turned on.
Safety notices when using the device according to Hazardous Locations (HazLoc) and FM.
If you use the device under HazLoc or FM conditions you must also keep to the following safety
notices in addition to the general safety notices for protection against explosion:
This equipment is suitable for use in Class I, Division 2, Groups A, B, C and D or non-hazardous
locations only.
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations only.
Connect to the device and change the standard passwords for the users "admin" and "user"
before you operate the device. To be able to change passwords you need to be logged in with
write access to the configuration data.
To prevent unauthorized access, note the following security recommendations.
General
● You should make regular checks to make sure that the device meets these
recommendations and/or other security guidelines.
● Evaluate your plant as a whole in terms of security. Use a cell protection concept with
suitable products (https://www.industry.siemens.com/topics/global/en/industrial-security/
pages/default.aspx).
● When the internal and external network are disconnected, an attacker cannot access
internal data from the outside. Therefore operate the device only within a protected network
area.
3
● For communication via non-secure networks use additional devices with VPN functionality
to encrypt and authenticate the communication.
● Restrict physical access to the device to qualified personnel because the plug-in data
medium can contain sensitive data.
● Lock unused physical interfaces on the device. Unused interfaces can be used to gain
access to the plant without permission.
Software (security functions)
● Keep the firmware up to date. Check regularly for security updates for the device. You can
find information on this at the Industrial Security (https://www.siemens.com/
industrialsecurity) website.
● Inform yourself regularly about security recommendations published by Siemens
ProductCERT (https://www.siemens.com/cert/en/cert-security-advisories.htm).
● Only activate protocols that you require to use the device.
● Restrict access to the management of the device with rules in an access control list (ACL).
● The option of VLAN structuring provides protection against DoS attacks and unauthorized
access. Check whether this is practical or useful in your environment.
● Use a central logging server to log changes and accesses. Operate your logging server
within the protected network area and check the logging information regularly.
Passwords
● Define rules for the assignment of passwords.
● Regularly change your passwords to increase security.
● Use passwords with a high password strength.
● Make sure that all passwords are protected and inaccessible to unauthorized persons.
● Do not use the same password for different users and systems.
Certificates and keys
● On the device there is a preset SSL certificate with key. Replace this certificate with a selfmade certificate with key. We recommend that you use a certificate signed either by a
reliable external or by an internal certification authority.
● Use a certification authority including key revocation and management to sign certificates.
● Make sure that user-defined private keys are protected and inaccessible to unauthorized
persons.
● It is recommended that you use password-protected certificates in the PKCS #12 format
● Verify certificates and fingerprints on the server and client to prevent "man in the middle"
attacks.
● It is recommended that you use certificates with a key length of at least 2048 bits.
● Change certificates and keys immediately, if there is a suspicion of compromise.
● Avoid or disable non-secure protocols, for example Telnet and TFTP. For historical reasons,
these protocols are available, however not intended for secure applications. Use nonsecure protocols on the device with caution.
● Check whether use of the following protocols and services is necessary:
– Non authenticated and unencrypted ports
– MRP, HRP
– LLDP
– DHCP Options 66/67
The following protocols provide secure alternatives:
– HTTP → HTTPS
– TFTP → FTPS
– Telnet → SSH
– SNTP → NTP
– SNMPv1/v2c → SNMPv3
Check whether use of SNMPv1/v2c. is necessary. SNMPv1/v2c are classified as nonsecure. Use the option of preventing write access. The device provides you with suitable
setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
Use the authentication and encryption mechanisms of SNMPv3.
Recommendations on network security
● Use secure protocols when access to the device is not prevented by physical protection
measures.
● If you require non-secure protocols and services, operate the device only within a protected
network area.
● Restrict the services and protocols available to the outside to a minimum.
● For the DCP function, enable the "DCP read-only" mode after commissioning.
Note
Type designation and labeling of a media module differ
Example: The device with article number 6GK5 992‑2AS00‑8AA0 is called "MM992‑2SFP", the
labeling on the device is "9922AS".
The labeling on the devices is shown in bold in the following table following the [article numbers].
Note
Media modules for SFP transceivers
Only the media modules MM992-2SFP andMM992-2SFP (C) may be fitted with approved SFP
transceivers. These SFP media modules can be fitted with up to two SFPs.
Note
Supplement (C) in the type name
Media modules with the supplement (C) in the type name have varnished printed circuit boards
(conformal coating).
4
Media modulePropertiesArticle number
Labeling on the device
MM992-2CUC2 x 10/100/1000 Mbps, RJ-45 ports electrical with securing collar6GK5 992-2GA00-8AA0
9922GA
MM992-2CUC (C)2 x 10/100/1000 Mbps, RJ-45 ports electrical with securing collar, var‐
nished
MM992-2CU2 x 10/100/1000 Mbps, RJ-45 port electrical without securing collar6GK5 992-2SA00-8AA0
MM992-2M12 (C)2 x 10/100/1000 Mbps, GE M12 connector electrical, varnished6GK5 992-2HA00-0AA0
MM992-2VD2 x 10/100/1000 Mbps, RJ-45 ports electrical with securing collar, varia‐
ble distance
MM992-2SFP2 x 100/1000 Mbps, SFP media module6GK5 992-2AS00-8AA0
MM992-2SFP (C)2 x 100/1000 Mbps, SFP media module, varnished6GK5 992-2AS00-8FA0
MM991-2 (BFOC)2 x 100 Mbps, BFOC port optical, for glass FO cable (multimode), up to
The type designation of an MM900 media module is made up of several parts that have the
following meaning:
InterfaceProperty
[-]BFOC port 100 Mbps multimode FO cable
LDBFOC port 100 Mbps single mode FO cable
(SC)SC port 100 Mbps multimode FO cable (up to max. 5 km)
LD (SC)SC port 100 Mbps single mode FO cable (up to max. 26 km)
LH+ (SC)SC port 100 Mbps single mode FO cable (up to max. 70 km)
SCALANCE MM900
Interface
Number of ports
1000 Mbps
MM992-2
Device description
4.1 Product overview
InterfaceProperty
PSC RJ port 100 Mbps POF or PCF
FMBFOC port 100 Mbps multimode FO cable with diagnostics
InterfaceProperty
CURJ-45 port electrical 10/100/1000 Mbps without securing collar
CUCRJ-45 port electrical 10/100/1000 Mbps with securing collar
M12M12 connection electrical 10/100/1000 Mbps
VDRJ-45 port electrical 10/100/1000 Mbps with securing collar (up to max. 1000 m)
[-]SC port 1000 Mbps multimode FO cable (up to max. 750 m)
LDSC port 1000 Mbps single mode FO cable (up to max. 10km)
LHSC port 1000 Mbps single mode FO cable (up to max. 40 km)
LH+SC port 1000 Mbps single mode FO cable (up to max. 70 km)
ELHSC port 1000 Mbps single mode FO cable (up to max. 120 km)
SFPSFP media module
Ethernet standards of the media modules
The following table shows which Ethernet standards according to IEEE 802.3 the individual
media modules comply with.
Media moduleIEEE 802.3 standard
MM992-2CUC1000Base-TX