5 network security/vpn device – GE Industrial Solutions Entellisys 5.0 Administrator Manual User Manual

Page 45

Advertising
background image

Network security/VPN device

45

7

7.5 Network security/VPN device

NOTE: GE requires that your Entellisys Low Voltage Switchgear system must be equipped with
a VPN/Firewall device if it is connected to a LAN that is also used for other purposes or any of
the Remote HMIs are also connected to a LAN. Failure to do so could result in virus attacks or
unauthorized access to the control and settings functions of the circuit breakers.

In addition to the standard username and password administrative functions for Entellisys,
accessibility to control functions and parameter settings must be considered from the network
point of view. The provisions for securing the network on which Entellisys communicates to HMI
Control Stations and other SCADA systems depends greatly on how the network over which they
communicate is configured.

GE provides a mechanical mounting assembly compatible with Juniper Networks NetScreen-
5GT VPN/Firewall Appliance. Since configuration of the device is mostly dependent on the
specific network architecture of the facility in which it is installed, please consult the NetScreen
documentation for assistance in configuring this device, or contact your local IT department or
network service provider.

GE recommends that the VPN/Firewall appliance be configured to only permit communications
between the devices in the switchgear instrument compartment and the external devices that
are intended to communicate with them.

Contact GE Post Sales Service for the latest VPN/Firewall appliance application and
configuration guide. See

How to contact us on page 2

.

Advertising