indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
maintenance are required to ensure that the products operate safely and without any problems. The permissible
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
A Approvals ............................................................................................................................................. 79
Index .................................................................................................................................................... 87
6.1 Safety when connecting up .................................................................................................... 55
These operating instructions support you when installing and connecting up devices of the
SCALANCE XM-400 product group.
The configuration and the integration of the device in a network are not described in these
operating instructions.
These operating instructions apply to the following devices:
● SCALANCE XM408-4C
● SCALANCE XM408-8C
● SCALANCE XM416-4C
Unless mentioned otherwise, the descriptions in these operating instructions refer to all
devices of the SCALANCE XM-400 product group named above in the section on validity.
Product line The product line includes all devices and variants of all product groups.
If information applies to all product groups within the product line, the
Product group If information applies to all devices and variants of a product group, the
Device If information relates to a specific device, the device name is used. SCALANCE XM408-4C
In the system manuals "Industrial Ethernet / PROFINET Industrial Ethernet" and "Industrial
Ethernet / PROFINET passive network components", you will find information on other
SIMATIC NET products that you can operate along with the devices of this product line in an
Industrial Ethernet network.
There, you will find among other things optical performance data of the communications
partner that you require for the installation.
You will find the system manuals here:
● On the data medium that ships with some products:
– Product CD / product DVD
– SIMATIC NET Manual Collection
● On the Internet pages of Siemens Industry Online Support:
– Industrial Ethernet / PROFINET Industrial Ethernet System Manual
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions constitute one element of such a concept.
Customers are responsible for preventing unauthorized access to their plants, systems,
machines and networks. Such systems, machines and components should only be
connected to an enterprise network or the internet if and to the extent such a connection is
necessary and only when appropriate security measures (e.g. firewalls and/or network
segmentation) are in place.
For additional information on industrial security measures that may be implemented, please
visit
https://www.siemens.com/industrialsecurity (https://www.siemens.com/industrialsecurity
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends that product updates are applied as soon as they are
available and that the latest product versions are used. Use of product versions that are no
longer supported, and failure to apply the latest updates may increase customers’ exposure
to cyber threats.
)
To stay informed about product updates, subscribe to the Siemens Industrial Security RSS
Feed under
https://www.siemens.com/industrialsecurity (https://www.siemens.com/industrialsecurity
You will find the article numbers for the Siemens products of relevance here in the following
catalogs:
● SIMATIC NET Industrial Communication / Industrial Identification, catalog IK PI
● SIMATIC Products for Totally Integrated Automation and Micro Automation, catalog
ST 70
● Industry Mall - catalog and ordering system for automation and drive technology, Online
catalog
The products are low in pollutants, can be recycled and meet the requirements of the WEEE
directive 2012/19/EU for the disposal of electrical and electronic equipment.
Do not dispose of the products at public disposal sites.
For environmentally friendly recycling and the disposal of your old device contact a certified
disposal company for electronic scrap or your Siemens contact (Product return
(https://support.industry.siemens.com/cs/ww/en/view/109479891
)).
Note the different national regulations.
The following and possibly other names not identified by the registered trademark sign ® are
registered trademarks of Siemens AG:
General safety notices relating to protection against explosion
WARNING
EXPLOSION HAZARD
Safety notices when using the device according to Hazardous Locations (HazLoc)
Note the following safety notices. These relate to the entire working life of the device.
You should also read the safety notices relating to handling in the individual sections,
particularly in the sections "Installation" and "Connecting up".
To prevent injury, read the manual before use.
Do not open the device when the supply voltage is turned on.
If you use the device under HazLoc conditions you must also keep to the following safety
notices in addition to the general safety notices for protection against explosion:
This equipment is suitable for use in Class I, Division 2, Groups A, B, C and D or nonhazardous locations only.
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations
only.
● Keep the firmware up to date. Check regularly for security updates for the device. You
can find information on this at the Industrial Security
(https://www.siemens.com/industrialsecurity
● Inform yourself regularly about security recommendations published by Siemens
ProductCERT (https://www.siemens.com/cert/en/cert-security-advisories.htm
● Only activate protocols that you require to use the device.
● Restrict access to the management of the device with rules in an access control list
(ACL).
● The option of VLAN structuring provides protection against DoS attacks and unauthorized
access. Check whether this is practical or useful in your environment.
● Use a central logging server to log changes and accesses. Operate your logging server
within the protected network area and check the logging information regularly.
) website.
).
● Define rules for the assignment of passwords.
● Regularly change your passwords to increase security.
● Use passwords with a high password strength.
● Make sure that all passwords are protected and inaccessible to unauthorized persons.
● Do not use the same password for different users and systems.
● On the device there is a preset SSL certificate with key. Replace this certificate with a
● Use a certification authority including key revocation and management to sign certificates.
● Make sure that user-defined private keys are protected and inaccessible to unauthorized
● It is recommended that you use password-protected certificates in the PKCS #12 format
● Verify certificates and fingerprints on the server and client to prevent "man in the middle"
● It is recommended that you use certificates with a key length of at least 2048 bits.
● Change certificates and keys immediately, if there is a suspicion of compromise.
self-made certificate with key. We recommend that you use a certificate signed either by
a reliable external or by an internal certification authority.
● Avoid or disable non-secure protocols and services, for example HTTP, Telnet and TFTP.
For historical reasons, these protocols are available, however not intended for secure
applications. Use non-secure protocols on the device with caution.
● Check whether use of the following protocols and services is necessary:
– Non authenticated and unencrypted ports
– MRP, HRP
– IGMP snooping
– LLDP
– Syslog
– RADIUS
– DHCP Options 66/67
– TFTP
– GMRP and GVRP
● The following protocols provide secure alternatives:
– HTTP → HTTPS
– Telnet → SSH
– SNMPv1/v2c → SNMPv3
Check whether use of SNMPv1/v2c. is necessary. SNMPv1/v2c is classified as nonsecure. Use the option of preventing write access. The device provides you with
suitable setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
Use the authentication and encryption mechanisms of SNMPv3.
● Use secure protocols when access to the device is not prevented by physical protection
measures.
● If you require non-secure protocols and services, operate the device only within a
protected network area.
● Restrict the services and protocols available to the outside to a minimum.
● For the DCP function, enable the "Read Only" mode after commissioning.
● If you use RADIUS for management access to the device, activate secure protocols and
services.
● Disable unused interfaces.
● Use IEEE 802.1X for interface authentication.
● Use the function "Locked Ports" to block interfaces for unknown nodes.
The product group SCALANCE XM-400 consists of basic devices (compact switches) and
extenders (port extenders and function extender).
The SCALANCE XM-400 basic devices are modular compact switches with fixed RJ-45
ports (10/100/1000 Mbps) and SFP transceiver slots that can be equipped individually. The
SFP transceiver slots are combo ports.
A SCALANCE XM-400 can manage a maximum of 24 ports with 10/100/1000 Mbps.
The following components exist only on the basic device:
● CPU
● Power supply
● Signaling contact
● Out-of-band port
● Serial interface
● "SELECT / SET" button
The basic devices can be expanded with additional ports and functions by using an
extender. The extenders are connected to the side of the basic device. Each basic device
has an expansion interface to the left for function extenders and to the right an expansion
interface for port extenders.
Depending on the number of ports of the basic device (10/100/1000 Mbps) up to 2 port
extenders can be added. Further port extenders are not supplied with power. There is no
particular order in which the port extenders need to be added.
Example:
● The basic device SCALANCE XM408-8C has 8 ports. It can therefore be expanded by 2
port extenders each with 8 ports.
● The basic device SCALANCE XM416-4C has 16 ports. It can therefore be expanded by
Port extenders function only in conjunction with a basic device.
Function Extender BUS ANALYZER Agent XM-400
4.1 Properties and functions
Port extenders are modular network components with RJ-45 ports (10/100/1000 Mbps) or
SFP transceiver slots. To the left they have an expansion interface to connect to the basic
device or to another port extender and to the right they have an expansion interface for
additional port extenders. Each port extender functions with every basic device.
Function extenders are modular network components, that expand the range of functions of
the basic device.
To the right they have an expansion interface to connect to the basic device. Function
extenders can be used with every basic device.
The BUS ANALYZER Agent XM-400 can be used as a function extender for SCALANCE
XM-400.
As a function extender the BUS ANALYZER Agent XM-400 is a modular network component
with 4 internal monitor ports for port mirroring. On the internal ports of the BUS ANALYZER
Agent XM-400, ports of the basic device can be mirrored and their data traffic recorded. The
BUS ANALYZER Agent XM-400 has an expansion interface to the right to connect to the
basic device. It can be used with every basic device.
In standalone mode, the BUS ANALYZER Agent XM-400 is an independent hardware
module for recording and sending Ethernet and PROFINET data without any consequences.
You will find detailed information in the operating instructions of the BUS ANALYZER Agent
XM-400, see section "Introduction (Page 5)", subsection "Additional documentation".
* Cannot be operated in SFP+ slots.
Pluggable transceivers with the supplement (C) in the type name have varnished printed circuit boards
(conformal coating).
Note
Restriction for pluggable transceivers
The maximum ambient temperature changes if you use pluggable transceivers:
•
•
For the values of the ambient temperature without pluggable transceiver
section "
Bidirectional plug-in transceiver SFP
Type
Properties
Article number
nm, receives at 1310 nm
nm, receives at 1550 nm
Port extender
Type
Properties
Article number
PE408PoE
8 x 10/100/1000 Mbps, RJ-45 ports with PoE
6GK5 408-0PA00-8AP2
PE400-8SFP
8 x 100/1000 Mbps, SFP ports
6GK5 400-8AS00-8AP2
4.3 Accessories
SFP992-1LH+ 1 x 1000 Mbps LC port optical for glass FO
SFP992-1ELH 1 x 1000 Mbps LC port optical for glass FO
cable (single mode) up to max. 120 km
6GK5 992-1AP00-8AA0
6GK5 992-1AQ00-8AA0
If you use transceivers of the types multimode and LD, the maximum ambient
temperature is reduced to 60 °C.
If you use transceivers of the types LH, LH+, ELH or ELH200, the maximum ambient
temperature is reduced to 50 °C.
You can only use up to 4 pluggable transceivers of the types LH, LH+, ELH or ELH200 in
the basic device.
s, refer to the
Technical specifications (Page 67)".
Bidirectional plug-in transceivers feature only one fiber connection. They transmit and
receive on two different wavelengths. To establish a connection, you need two matching
bidirectional SFPs. The connected SFPs must respectively transmit on the wavelength at
which the connection partner receives.
SFP992-1BXMT 1 x 1000 Mbps LC port optical for glass FO
(multimode) with max. 500 m, transmits at 1550
SFP992-1BXMR 1 x 1000 Mbps LC port optical for glass FO
(multimode) with max. 500 m, transmits at 1310
PE408 8 x 10/100/1000 Mbps RJ-45 ports 6GK5 408-0GA00-8AP2