User Manual

3
Network Security Controls
22
Siemens Application Note
Smart Infrastructure
Subsystem Connectivity
Outbound Connections (ports used by the host to connect to automation systems)
Field
System
Hosts
Component / Process
Port
Port Configuration
Comment
Protocol
APOGEE
P2
Main Server,
FEP
APOGEE P2 driver
WCCOAApogeeDrv.exe
2)
TCP: 3001
UDP: 3001
APOGEE Network
SnapIn
Required for APOGEE Ethernet
Microserver (AEM)
APOGEE
P2
Main Server,
FEP
APOGEE P2 Driver
WCCOAApogeeDrv.exe
2)
TCP: 5033
UDP: 5033
APOGEE Network
SnapIn
Required for APOGEE Ethernet
networks
APOGEE
P2
Main Server,
FEP
APOGEE P2 Driver
WCCOAApogeeDrv.exe
2)
TCP: 5441
UDP: 5441
no
Required for APOGEE Ethernet
networks (diagnostic channel)
BACnet Main Server,
FEP
BACnet Driver
WCCOAGmsBACnet.exe
2)
UDP:
47808
3)
BACnet SnapIn
Communication with BACnet
field systems (APOGEE BACnet,
Desigo PX, Desigo TRA, FS20)
BACnet/IP
Modbus MainServer,
FEP
Modbus Driver
WCCOAmod.exe
1)
TCP: 502 Modbus SnapIn
Communication with Modbus
TCP devices
Modbus/TCP
OPC Main Server OPC Driver
WCCOAopc.exe
1)
TCP: 135
UDP: 135
no
OPC/TCP
OPC Main Server OPC Driver
WCCOAopc.exe
1)
TCP:
variable
5)
Windows Registry
OPC/TCP
Simatic S7 Main Server,
FEP
Simatic S7 Driver
WCCOAs7.exe
1)
TCP: 102 no
Communication with S7 PLC
(also for Siclimat-S7 devices)
Simatic S7
Protocol
SNMP Main Server,
FEP
SNMP Driver
WCCOAsnmp.exe
1)
UPD: 161
4)
SNMP Network
Configuration
SnapIn
SNMP/IP
SPC Main Server,
FEP
SPC Driver
WCCOASPC.exe
2)
TCP: 50000
UDP: 50000
SPC Driver SnapIn
EDP Receiver Id Port
XNET Main Server,
FEP
XNET Driver
NCCGMS.exe
2)
TCP: 1977
XNET Driver
SnapIn
1) File located in C:\Siemens\WinCC_OA\3.13\bin\
A Modbus subsystem uses the underlying Modbus Driver from WinCC OA. It uses Modbus protocol over TCP. During the import,
the field engineer must specify the IP Address and the port number for communicating with the device. If the port number field is
kept empty, then the Modbus Importer applies the default value of 502. However, after import, the user can modify both IP Ad-
dress and port numbers from the Desigo CC Client.
2) File located in [Installation Directory]\GMSMainProject\bin\
3) Default port for the first BACnet driver is UDP: 47808. Port can get changed; every additional driver needs another UDP port.
4) Default port for the first SNMP network is UDP: 161. Port can get changed; every additional network needs another UDP port.
5) 4 ports for OPC Client/Server communication, default variable in range 1024...5000 (set via registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet)