By Jacques Terblanche Johnson Matthey

Slides:



Advertisements
Similar presentations
This course is designed for system managers/administrators to better understand the SAAZ Desktop and Server Management components Students will learn.
Advertisements

FILEMAKER SERVER SOFTWARE & REMOTE ADMINISTRATION
Which server is right for you? Get in Contact with us
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Understand Virtualized Clients Windows Operating System Fundamentals LESSON 2.4.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 12: Managing and Implementing Backups and Disaster Recovery.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Terminal Services Terminal Services is the modern equivalent of mainframe computing, in which servers perform most of the processing and clients are relatively.
Welcome Course 20410B Module 0: Introduction Audience
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
VMware vCenter Server Module 4.
AMG Attendance System Product Description Copyright © 2009 AMG Employee Management, Inc.AMG Employee Management, Inc.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW Understand the difference between service.
11 SYSTEMS ADMINISTRATION AND TERMINAL SERVICES Chapter 12.
The Magical World of Chocolate Manufacture
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW  Understand the difference between service.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Chapter 7 Installing and Using Windows XP Professional.
Purpose Intended Audience and Presenter Contents Proposed Presentation Length Intended audience is all distributor partners and VARs Content may be customized.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.

Production visibility: KPI’s in Real-time BASF – The Chemical Company
Module 13: Configuring Availability of Network Resources and Content.
Chapter 14: Remote Server Administration BAI617. Chapter Topics Configure Windows Server 2008 R2 servers for remote administration Remotely connect to.
Remote Desktop Services Remote Desktop Connection Remote Desktop Protocol Remote Assistance Remote Server Administration T0ols.
1 Guide to Novell NetWare 6.0 Network Administration Chapter 11.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Using the WDK for Windows Logo and Signature Testing Craig Rowland Program Manager Windows Driver Kits Microsoft Corporation.
Week #7 Objectives: Secure Windows 7 Desktop
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Chapter Fourteen Windows XP Professional Fault Tolerance.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Module 7: Fundamentals of Administering Windows Server 2008.
Security Planning and Administrative Delegation Lesson 6.
By Rashid Khan Lesson 10-From Here to There: Remote Installation of the Windows XP Professional Client.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
Windows Small Business Server 2003 Setting up and Connecting David Overton Partner Technical Specialist.
70-270: MCSE Guide to Microsoft Windows XP Professional 1 Windows XP Professional User Accounts Designed for use as a network client for: Windows NT Windows.
Computer Emergency Notification System (CENS)
Module 5: Configuring Internet Explorer and Supporting Applications.
1 Week #10Business Continuity Backing Up Data Configuring Shadow Copies Providing Server and Service Availability.
Remote Administration Remote Desktop Remote Desktop Gateway Remote Assistance Windows Remote Management Service Remote Server Administration Tools.
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. PUBLIC PUBLIC CO900G L03 - Design, Implement, and Manage FactoryTalk Security.
Chapter 10 Chapter 10: Managing the Distributed File System, Disk Quotas, and Software Installation.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Module 8: Managing Software Distribution. Collections Packages Programs Advertisements Collections Packages Programs Advertisements How Software.
Administering Microsoft Windows Server 2003 Chapter 2.
Virtualization Technology and Microsoft Virtual PC 2007 YOU ARE WELCOME By : Osama Tamimi.
WEEK 11 – TOPOLOGIES, TCP/IP, SHARING & SECURITY IT1001- Personal Computer Hardware System & Operations.
Chapter 4- Part3. 2 Implementing User Profiles A local user profile is automatically created at the local computer when you log on with an account for.
1 Active Directory Service in Windows 2000 Li Yang SID: November 2000.
By Daniel Grim. What Is Windows NT? IPSEC/Windows Firewall NTFS File System Registry Permissions Managing User Accounts Conclusion Outline.
Managing Servers Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Using Remote DesktopPlan server management strategies 2.1 Delegating.
Windows Certification Paths OR MCSA Windows Server 2012 Installing and Configuring Windows Server 2012 Exam (20410) Administering Windows Server.
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
Welcome! Thank you for joining us. We’ll get started in a few minutes.
MCSA VCE
To Join the Teleconference
Introduction to Group Policy
Security Planning and Administrative Delegation
Presentation transcript:

By Jacques Terblanche Johnson Matthey How to secure your Rockwell PLC’s and enforce Software Change Management using MDT AutoSave By Jacques Terblanche Johnson Matthey

Introduction Project Solution Agenda Benefits Considerations Summary

Background to the Project This project shows how to secure your Rockwell PLC’s at no additional cost using out the box solutions and how to implement software change management on PLC code using MDT’s AutoSave.

Project Goals Secure all Rockwell SLC and CLX PLC’s from: Unauthorised online changes Unauthorised access from a 3’rd party’s PC running PLC Development software Provide easy configuration to change security access Implement Software Change Management on PLC Code

Introduction Project Solution Agenda Benefits Considerations Summary

Why AutoSave A need was identified to perform Software Change Management on all PLC code and to secure all PLC’s from unauthorised access A comparison was done between MDT AutoSave and Rockwell’s Factory Talk Asset Centre to determine the best solution to provide Change Management as well as securing PLC Processors

Which solution? AutoSave or Asset Centre? AutoSave Change Management Archive of changes Scheduled Compares Locked programs AutoSave InTouch Plugin Archestra Plug-in

Why Software Change Management? Where is your latest backup C:\Projects\PLC001 or z:\PLC Backups\PLC001 Which file is the latest change 05_03_09_PLC001 or 06_03_09_PLC001 What was changed? Uhm can’t remember, that was 2 weeks ago

AutoSave Central location of all backups Resides on AutoSave Server Use normal IT backup methods to backup my backup Central Location to access all projects Launch AutoSave Client Configured in tree structure to easily access projects Provides a revision history with comments Enforces comment

New features in AutoSave 5.04 Spaces Rearrange tree structure by moving areas and programs Why is this important Current structure is flat Move option allows restructuring of Plant model to represent a S95 model type

FactoryTalk Services Platform Where to find the Services Platform RSLinx Classic Optional steps Install FactoryTalk(R) Services Platform What is installed Administration Console Directory Configuration Wizard Security Configuration Emulator Specify Directory Location

FactoryTalk Administration Console Used to configure either Local or Network Security Provides central place to configure: Users and Groups Use Local users or Active Directory Groups Networks and Devices Configure for entire network Configure individually Computers Add PC Nodes which will be used for Development as well as nodes used to perform remote connections Policies

Configuring Security Logix 5000 Logix 500 Set Administrator to configure Controller Secure Set Logical Name Set Controller Security Logix 500

Enabling Security for Logix 5000 Install Emulator Must be installed on all Development PC’s Enable Security Key Run SetSectKeys and Enable RSLogix 5000 Security Controller Properties Change Security Setting to RSI Security Server Can be done Online to PLC

Enabling Security for Logix 500 New install Select Enable FactoryTalk Security during install Current Install Run setup again and select Security option Securing the Controller Convert old Logix 500 projects to version 7 or later Enable Processor Secured from Controller Properties Download converted project to PLC

Configuring AutoSave for Security Services Open AutoSave Client Logon to AutoSave Server Select PLC Launch Project NO CONFIGURATION REQUIRED

What now? Windows user authenticated to Security Server Local Users Domain users User with development privileges User with read only privileges

Topology - Software The AutoSave system consists of: AutoSave Agents AutoSave Server 2003 Server SQL 2000 SP4 AutoSave 5.04 FactoryTalk Services Platform – Network Security AutoSave Agents Logix 500 and 5000 One Logix 5000 agent and one Logix 500 agent FactoryTalk Services Platform – Referencing AutoSave Server AutoSave Development clients XP SP2 Pro

Topology - Network

Topology – Use of Agents Remote connection enabled User starts a Terminal Session Allows multiple users access to AutoSave Less development software installations

Introduction Project Solution Agenda Benefits Considerations Summary

Benefits / Goals Achieved Were the initial goals achieved? Secure all Rockwell PLC’s – YES Provide Software Change Management - YES What benefits? PLC Online connection is read only No Online changes possible No offline changes possible No access via unauthorised Development software

Introduction Project Solution Agenda Benefits Considerations Summary

Lessons Learned SLC projects must be converted to the latest Logix 500 version Cannot access PLC’s if Security Server is unavailable Install and configure secondary security server for emergencies

Introduction Project Solution Agenda Benefits Considerations Summary

Conclusions It is essential to have the correct tools available to perform Software Change Management MDT AutoSave provides an easy interface with all the functionality. Securing your Rockwell PLC’s is quick and easy using the Factory Talk Service Platform

The End....