保护本地Profinet网络Protecting local Profinet network

尊敬的各位:, 也许对你来说,这是一个简单的问题。 在客户现场,有带PLC、HMI和VFD的控制柜,所有这些都在profinet中。问题是,自动化网络是与办公子网络结合在一起的。每当办公网络发生故障时,profinet子网络也会在一个本地机柜中出现更高级别的连接问题故障。你可以在图1上看到我的意思。 我的想法是在每个机柜上添加路由器(操作系统或其他东西),给它另一个子地址,但仍然需要与VPN和Sc...

问题描述

尊敬的各位:,

Dear all,

也许对你来说,这是一个简单的问题。

Probably for You it is simple problem.

在客户现场,有带PLC、HMI和VFD的控制柜,所有这些都在profinet中。问题是,自动化网络是与办公子网络结合在一起的。每当办公网络发生故障时,profinet子网络也会在一个本地机柜中出现更高级别的连接问题故障。你可以在图1上看到我的意思。

On customer site there are control cabinets with PLCs, HMIs, VFDs all in profinet. The problem is, the automation network is together with office subnetwork. Whenever there is a crash on office network also the profinet subnetwork is giving faults of higher level connection problem accress one local cabinet. You can see on drawing 1 what I mean.

我的想法是在每个机柜上添加路由器(操作系统或其他东西),给它另一个子地址,但仍然需要与VPN和Scada连接。缺点是我无法访问服务器计算机,需要询问IT。

My idea is to add router (os something else) add give it another sub addressses on every cabinet, but still need to have connection with VPN and Scada to all. The disadvantage is that I do not have access to server computer and need to ask ITs.

如果它能解决网络崩溃的问题,你能给我建议吗?

Can You advice me if it solve the issues with network crash?

如何配置路由器,使其将我转发到本地地址?

How to configure router so it forwards me to the local address?

致以最诚挚的问候

best regards 

推荐答案2

您好,

hi,

是的,这可能是一个解决方案。

yes, this could be a solution.

更好的、既定的做法是在CPU上有单独的接口,使用像CP343-1这样的以太网CP。更大的S7-1500 CPU有两个板载接口,可以处理这个问题。其中一个接口是处理Profinet通信和HMI。另一个接口用于与办公网络和VPN进行通信。

Better, and established practice, would be to have seperate interefaces on the CPU, with a Ethernet CP like CP343-1. The bigger S7-1500 CPUs have 2 interfaces on-board, which can handle this.One interface is handling the Profinet communication and HMI. The other interface is for communication with the office network and VPN.

希望这能有所帮助,

hope this helps,

问候,

regards,

推荐答案3

这是很有帮助的建议。

That is helpful advice.

然而,解决方案有一个小问题需要处理,因此必须有路由。并不是所有的CPU都允许在网络之间进行路由。

However the solution has one small chalange to cope with, it is esential to have routing. Not all CPUs allow routing in between networks.

正如我所看到的,S7-1200不支持路由。

As I see the S7-1200 do not support routing.

S7-1510SP CPU中有路由,但怀疑其ETH(S7-1510SPCPU)/ETH(CP1542SP-1)是否能工作

There is a routing in S7-1510SP CPU, but have doubts if its ETH (S7-1510SP CPU)/ETH (CP1542SP-1) will work

我可以用于您的解决方案吗?

Can I use for Your solution?

6ES7510-1DJ01-0AB0+6GK7542-6ux-00-xe0

6ES7510-1DJ01-0AB0 + 6GK7542-6UX00-0XE0

推荐答案4

你好

Hello,

定义路由!

define Routing!

没有西门子PLC-CP允许IP路由,只有S7路由是可能的!

No SIEMENS PLC - CP allow a IP Routing, only S7 Routing is possible!


致问候


Regards

克里斯托夫

Christoph

推荐答案5

我的错,我的意思是profinet路由/

My fault, I did meant profinet routing/

我需要从VPN->带CP模块的PLC->vfd(G120 profinet,HMI profinet,IOdevices profinet…)或其他方式VPN->带PLC的CP模块->vfd

I need S7 routing from VPN -> PLC with CP Module -> vfd (G120 profinet, HMI profinet, IOdevices profinet...) or other way VPN ->CP Module with PLC -> vfd (G120 profinet, HMI profinet, IOdevices profinet...)

1200及其CP中是否有路由支持?

Is there routing support in 1200 and its CPs?

我的最后一次配置有效吗?

Will my last configurotion work?

推荐答案6

你好

Hello,

在这里,您可以找到CP和PLC支持S7路由的概述

here you find a overview which CP and PLC support S7 Routing

https://support.industry.siemens.com/cs/ww/en/view/584459

https://support.industry.siemens.com/cs/ww/en/view/584459

推荐答案7

当办公室子网引起问题时,为什么要更改profinet侧?我会找出导致办公网络出现故障的原因,并首先解决这个问题。如果不可能,将所有办公室连接放在一个交换机上,并在需要时仅将流量路由到profinet。网络组件都支持profinet芯片吗?还是只支持标准交换机、路由器等?

Why change the profinet side, when the office subnet is causing issues? I would find out what causes the office network to get faulty and get rid off this issue first. If not possible, put all office connection on one switch and route only traffic to profinet when needed. Do the network components all support profinet chips or are they only std. switches, routers and so on?

推荐答案8

它都是标准的交换机和路由器

It is all standard switches and routers. 

不可能在一个交换机中断开与子网的连接。在维护期间,我需要VPN连接,而无需每次都要求插入/拔出插头。此外,管理人员对流程也有自己的看法。

It is not possible to disconnect from the subnets in one switch. I need VPN connection during mainatnace without asking to push in/pull out plug every time. Also managers have their own view to the process.

故障非常罕见,而且可以快速修复,但我不能让工厂的流程在任何情况下都停止,因为这是利润网。大多数网络都是通过profibus完成的,但最近西门子只支持profinet连接。Profibus系统有优点也有缺点,但从未给我带来压力。然而,当使用profinet(S71500+5xET200SP+20xG120-profinet)时,它会与办公网络一起崩溃。

The failures are vary rare and quickly repaired but I cannot let the factory process stop in any situation only because it is profinet. Most network is done with profibus but lately siemens supports only profinet connections. Profibus systems has advantages and disadvanteges but never caused me stress. However when profinet used (S71500 + 5xET200SP + 20xG120 - profinet) it crashes together with office network.

这就是为什么我想将可视化/维护/办公室网络与流程网络分离/路由等。

That is why I would like to separete/route etc. the Visualization/Maintance/Office network from Process network.

问题是如何做到简单?

The question is how to make it simply done?

6ES7510-1DJ01-0AB0+6GK7542-6UX00-0XE0是否可以实现profinet/profinet路由?两者都是为了支持路由,但如果是profinet/profnet还是profinet/pprofibus?

Is there route profinet/profinet possible with 6ES7510-1DJ01-0AB0 + 6GK7542-6UX00-0XE0 ? Both is mentiond to support routing, but if it's profinet/profinet or if it means profinet/profibus?

推荐答案9

你好

Hello,

你需要VPN到什么
是去办公电脑还是只去橱柜

实现最多的解决方案是:

you need VPN to what?
To the Office Computers or only to the cabinets?

The most implemented Solution is:

带2个网卡的VPN PC

VPN PC with 2 Network-Cards

卡1在办公室局域网中

Card 1 is in Office LAN

卡2在生产局域网中

Card 2 is in Production LAN

VPN连接是通过VNC PC建立的,然后是到第二个NIC的路由,以连接生产LAN。

The VPN Connection is established with the VNC PC and then a route to the second NIC to connect the Production LAN.

她的路由器是VPN PC,局域网区域是物理分离的。只与另一个IP范围分离对我来说不是一个解决方案,并且在没有任何物理边界的情况下混合办公和生产网络是错误的方式!

问候
Christoph

Her the router is the VPN PC , the LAN Areas are physical separated. Only seperate with another IP Range is not a solution for me, and a mix of Office and production Network without any physical border is the wrong way ! 

Regards
Christoph

推荐答案10

我需要机柜的VPN,远程连接到所有设备,以防更改逻辑、参数和警报。管理人员需要从本地网络访问SCADA

I need VPN for cabinets, remote connection to all devices in case for changing logic, params, alarms. SCADA needs to be accessed out of local network by managers

不幸的是,不久前,办公网络和控制网络连接在一起。现在我需要停止重复同样的错误。我需要进程网络能够自由崩溃

unfortunately some time ago the office network and control network was connected together. Now I need to stop repaeting the same mistake. I need the process network to be free form crashes. 

在新项目中,有plc/hmi/3xg120/1x3rw44,我需要将其从办公网络中分离出来,并且仍然可以路由到设备。问题是添加主pofibus模块还是另一个以太网模块是一种好的做法。

In new project there is plc/hmi/3xg120/1x3rw44 and I need to separate it from office network and still have routing to the devices. The question is if it is good practice to add master pofibus module or another ethernet module.

我不想只制作另一个子网络。我的想法是用另一个路由器将其分离,或者像以前建议的那样,通过CPU将其路由到子网profibus或profinet本地机柜。

I do not want to just make another sub network. My idea was to separate it with another router or as recomended before, by routing it throug CPU to sub network profibus or profinet local cabinet.

推荐答案11

通常Profinet使用带有芯片组的特殊硬件,以保持实时协议的有效性。如果你只在Profinet上使用普通的TCP/IP,我会研究EWS、Moros等硬件vpn,并以这种方式分离办公网络。你或你的经理通过vpn从办公室局域网连接到路由器的一侧,它会将你路由到机器之外的内部独立网络。这样,办公室局域网就不会干扰机器,但您仍然可以像机器前面一样连接,并连接到X120、profinet或类似设备

Normally Profinet uses special hardware with chipsets which keep realtime protocoll alive. If you only use normal TCP/IP over Profinet I would look into hardware vpns like EWS, Moros and alike and separate the office network this way. You or your managers connect from office lan via vpn to the one side off the router and it routs you through to the internal separate network off the machines. That way office lan does not interfer with the machines, but you are still able to connect just like you where infront off the machine and connect to X120, profinet or alike. 

你可能感兴趣的文章

python-snap7标志!继电器控制

...辑:我刚刚查阅了天狼星法案的开关。看起来他们确实有Profinet接口,但我不确定,你是否可以用LOGO来称呼他们 EDIT: I just looked up the Sirius Act switches. Seems they do have a Profinet interface, but I'm not sure, if you can address them with a LOGO!推荐答...

  • 发布于 2022-10-11 07:12
  • 阅读 ( 54 )

阻止远程停止

...:如何保护CPU414-2DP(6ES7414-2XK05-0AB0),使其免受连接到ProfiNet的PG改变操作模式的影响出于安全原因,CPU只能从硬件开关停止。我尝试使用本文中的写保护: Does anybody know: how can I protect CPU414-2DP (6ES7414-2XK05-0AB0) from change operation mo...

  • 发布于 2022-10-12 02:27
  • 阅读 ( 56 )

S7-400安全SIL3 IO模块

...00F系统的F-IO模块通过Profibus与IM 153-2(Profibus)或IM 153-4(Profinet)接口模块集成,属于S7-300系列(SM 326)。查看以下应用程序示例,展示如何通过网络使用S7-400FH和SM326 F-IO设置SIL3应用程序: The S7-400 family does not support Failsafe IO mod...

  • 发布于 2022-10-12 02:40
  • 阅读 ( 59 )

工业以太网

...ave a look at the throughput and reaction time of this network.如果您有PROFINET通信,这些数据包都有优先级标记(802.1p/q),因此您可以轻松对其进行优先级排序。PLC之间的其他(普通TCP)通信大多不是那么关键,所以您不需要划分优先级。 I...

  • 发布于 2022-10-12 12:16
  • 阅读 ( 53 )

办公网络中的profinet

问题描述我有21个CPU 317 2PN DP和所有CPU通过profinet与同一个其他CPU通信。我使用了13个X208交换机进行连接,一个x204IRT环形管理交换机和一个额外的x613安全交换机。(这个设备6年前安装到我的工厂) I have 21 peice CPU 317 2PN DP and all cp...

  • 发布于 2022-10-12 13:25
  • 阅读 ( 57 )

什么是PROFINET?在简短视频中获得介绍(教程)

...ello,在youtube中,您可以找到一些小视频,了解在哪里使用PROFINET。这些视频概括地解释了PROFINET: in youtube you can find small videos to get an introduction where to use PROFINET. The videos are explaining PROFINET in general:1.PROFINET技术简介:http://www.youtube...

  • 发布于 2022-10-12 14:28
  • 阅读 ( 65 )

检查网络Profinet设备的存在。

...he presence of the slave, and generate an alarm if one is not seen anymore.Profinet设备的等效功能有哪些? What can be the equivalent functions for Profinet devices?推荐答案2检查以下诊断包 Check the following Diagnostic package用于PROFIBUS DP和PROFINET IO诊断评估的诊断...

  • 发布于 2022-10-12 14:35
  • 阅读 ( 53 )

环冗余网络中X204-2的故障

...tomatically)?我想你用的是MRP。您是否更改设备IO控制器上的PROFINET更新时间和监控时间? You use MRP, I think. Do you change the PROFINET Update TIme and monitoring time on IO-Controller for the devices?当环打开时,重新配置时间约为200ms。您必须更改PROFINE...

  • 发布于 2022-10-17 08:22
  • 阅读 ( 59 )

S7-1500上的13 CM PtP模具数量…本地还是分布式?

...he same rack as the CPU将13个CM PtP模块分布在四个ET200 MP模块,ProfiNET连接回CPU Distribute the 13 CM PtP modules across four ET200 MP modules with ProfiNET connection back to the CPU关注点:在选项2中,我会遇到ProfiNet连接限制问题吗因为所有与PtP模块的通信...

  • 发布于 2022-10-18 08:31
  • 阅读 ( 57 )

尝试使用GET/PUT块通过Profinet与多个315-2PN/DP通信1518

问题描述HI全部 HI All我正在尝试使用GET/PUT块通过Profinet与多个315-2PN/DP通信1518 I am trying to communicate 1518 to multiple 315-2PN/DP over Profinet using GET/PUT BlocksGET指令成功读取数据并执行,但PUT块返回错误代码0004。 GET Instruction is reading Data suc...

  • 发布于 2022-10-18 09:10
  • 阅读 ( 55 )