indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
for the specific
10/2016 Subject to change
Preface
Purpose of the Operating Instructions
Validity of the manual
Naming of the devices
Classification
Description
Terms used
term M81x is used.
M816
Further documentation
These compact operating instructions contain information with which you will be able to
install and connect up a device of the SCALANCE M -800 product line. The configuration
and the integration of the device in a network are not described in these instructions.
These operating instructions apply to the following devices:
● SCALANCE M812-1
● SCALANCE M816-1
Product line For all devices and variants in the product line, the term M-
Device family For all devices and variants in the device family line, the
Device If information relates to a specific device, the device name
● System manual "Industrial Ethernet"
The system manual contains information on other SIMATIC NET products that you can
operate along with the devices of this product line in an Industrial Ethernet network.
There, you will find among other things optical performance data of the communications
partner that you require for the installation.
The "SIMATIC NET Industrial Ethernet" system manual can be found on the Internet
pages of Siemens Industry Online Support under the following entry ID:27069465
(http://support.automation.siemens.com/WW/view/wn/27069465)
● "Passive network components" system manual
This system manual contains installation instructions for several of the most common
components and guidelines for setting up networked automation plants in buildings.
The "Passive Network Components" system manual can be found on the Internet pages
of Siemens Industry Online Support under the following entry ID:84922825
(http://support.automation.siemens.com/WW/view/en/84922825)
Read the license conditions for open source software carefully before using the product.
SIMATIC NET glossary
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions only form one element of such a concept.
Customer is responsible to prevent unauthorized access to its plants, systems, machines
and networks. Systems, machines and components should only be connected to the
enterprise network or the internet if and to the extent necessary and with appropriate security
measures (e.g. use of firewalls and network segmentation) in place.
Additionally, Siemens’ guidance on appropriate security measures should be taken into
account. For more information about industrial security, please visit
Link: (http://www.siemens.com/industrialsecurity)
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends to apply product updates as soon as available and to
always use the latest product versions. Use of product versions that are no longer supported,
and failure to apply latest updates may increase customer’s exposure to cyber threats.
To stay informed about product updates, subscribe to the Siemens Industrial Security RSS
Feed under
Link: (http://www.siemens.com/industrialsecurity).
The following and possibly other names not identified by the registered trademark sign ® are
registered trademarks of Siemens AG:
SCALANCE, SINEMA, KEY-PLUG, C-PLUG
You will find license conditions in the following documents on the supplied data medium:
● OSS_ScalanceM-800_S615_86.htm
Explanations of many of the specialist terms used in this documentation can be found in the
SIMATIC NET glossary.
You will find the SIMATIC NET glossary on the Internet at the following address:
4 Connecting up ....................................................................................................................................... 39
A Approvals .............................................................................................................................................. 59
Index .................................................................................................................................................... 71
A.1 EU declaration of conformity .................................................................................................. 61
● Keep the software up to date. Check regularly for security updates of the product.
You will find information on this on the Internet pages "Industrial Security
(http://www.siemens.com/industrialsecurity)".
● Inform yourself regularly about security advisories and bulletins published by Siemens
ProductCERT (http://www.siemens.com/cert/en/cert-security-advisories.htm).
● Only activate protocols that you really require to use the device.
● The option of VLAN structuring provides good protection against DoS attacks and
unauthorized access. Check whether this is practical or useful in your environment.
● Restrict access to the device by firewall, VPN (IPsec, OSINEMA RC) and NAT.
● Use a central logging server to log changes and accesses. Operate your logging server
within the protected network area and check the logging information regularly.
● Define rules for the use of devices and assignment of passwords.
● Regularly update passwords and keys to increase security.
● Change all default passwords for users before you operate the device.
● Only use passwords with a high password strength. Avoid weak passwords for example
● Make sure that all passwords are protected and inaccessible to unauthorized personnel.
● Do not use the same password for different users and systems or after it has expired.
This section deals with the security keys and certificates you require to set up SSL, VPN
(IPsec, OpenVPN) and SINEMA RC.
● The device contains a pre-installed SSL certificate with key. Replace this certificate with a
● Use the certification authority including key revocation and management to sign the
● Make sure that user-defined private keys are protected and inaccessible to unauthorized
● Verify certificates and fingerprints on the server and client to prevent "man in the middle"
password1, 123456789, abcdefgh.
self-made certificate with key. We recommend that you use a certificate signed by a
reliable external or internal certification authority.
certificates.
persons.
attacks.
● It is recommended that you use password-protected certificates in the PKCS #12 format
● It is recommended that you use certificates with a key length of at least 2048 bits.
● Change keys and certificates immediately, if there is a suspicion of compromise.
● Avoid or disable non-secure protocols, for example Telnet and TFTP. For historical
reasons, these protocols are still available, however not intended for secure applications.
Use non-secure protocols on the device with caution.
● Avoid or disable non-secure protocols. Check whether use of the following protocols is
necessary:
– Broadcast pings
– Non authenticated and unencrypted interfaces
– ICMP (redirect)
– LLDP
– Syslog
– DHCP Options 66/67
– TFTP
● The following protocols provide secure alternatives:
– SNMPv1/v2 → SNMPv3
Check whether use of SNMPv1 is necessary. SNMPv1 is classified as non-secure.
Use the option of preventing write access. The product provides you with suitable
setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
– HTTP → HTTPS
– Telnet → SSH
● Use secure protocols when access to the device is not prevented by physical protection
measures.
● To prevent unauthorized access to the device or network, take suitable protective
measures against non-secure protocols.
● If you require non-secure protocols and services, activate these at interfaces that are
located within a protected network area.
● Using a firewall, restrict the services and protocols available to the outside to a minimum.
● For the DCP function, enable the "DCP read-only" mode after commissioning.
The following list provides you with an overview of the open ports on this device. Keep this in
mind when configuring a firewall.
Specifies whether or not the protocol is authenticated during access.
With some protocols the port can be open but access is prevented by a predefined IP
package filter rule. You will find further information on the predefined IP package rules in
"Security > Firewall > Predefined IPv4"
You will find further information on the accessories program for the M812 and M816 in the
Industry Mall
(https://eb.automation.siemens.com/goos/WelcomePage.aspx?regionUrl=/de&language=en)
.
C-PLUG Exchangeable storage medium (32 MB) for the
Exchangeable storage medium (256 MB) for
the configuration data
KEY-PLUG SINEMA RC Exchangeable storage medium (256 MB) to
enable the connection functionality to SINEMA
Remote Connect and for storing configuration
Desktop pedestal SCALANCE M-800 desktop pedestal for table