System features

FactoryTalk Policy Manager
includes different features that help improve your system security.

New features

FactoryTalk Policy Manager
includes these new features:
FactoryTalk Linx Gateway support
Add
FactoryTalk® Linx Gateway
devices, which support multiple endpoint URLs exposed by a single
OPC UA
local discovery service. Then, configure specific entry points to
OPC UA
servers.
Zone CA certificates regeneration
Follow best security practices for key rotation by regenerating Certificate Authority (CA) certificates for zones. Deploy the policy model to apply the regenerated zone CA certificates to devices.
NFC
Configure the Near Field Communication (NFC) permissions for data exchange with supported devices.

Compatibility

CIP Security
features work with these
Rockwell Automation
products:
  • FactoryTalk Linx
    version 6.11 or later
  • ControlLogix®
    5580 controllers firmware revision 32.00 or later
  • ControlLogix®
    5590 controllers firmware revision 38.00 or later
  • 1756-EN4TR
    ControlLogix
    Module
  • Kinetix®
    5300 Drives
  • Kinetix
    5700 Drives
  • PowerFlex®
    755T
  • 1783-CSP CIP Security Proxy
  • CompactLogix
    5380 controllers firmware revision 34.00 or later
  • Compact GuardLogix®
    5380 controllers firmware revision 34.00 or later
  • GuardLogix®
    5580 controllers firmware revision 34.00 or later
OPC UA security policy
features work with these
Rockwell Automation
product families:
  • ControlLogix®
    5580 controllers firmware revision 36.00 or later
  • GuardLogix®
    5580 controllers firmware revision 36.00 or later
  • ControlLogix®
    5590 controllers firmware revision 38.00 or later
  • CompactLogix
    5380 controllers firmware revision 36.00 or later
  • Compact GuardLogix®
    5380 controllers firmware revision 36.00 or later
  • ControlLogix®
    Process controllers firmware revision 36.00 or later
  • CompactLogix
    Process controllers firmware revision 36.00 or later
  • FactoryTalk® Linx Gateway
    firmware revision 6.60 or later
TIP:
OPC UA security policy
features do
not
work with:
  • ControlLogix®
    and
    ControlLogix®
    Process L81 controllers
  • CompactLogix
    and Compact
    GuardLogix®
    L306 controllers
  • Redundant
    ControlLogix®
    and
    GuardLogix®
    controllers
Automatic Policy Deployment supports the following devices:
  • ControlLogix®
    5580 controllers firmware revision 34.00 or later
  • ControlLogix®
    5590 controllers firmware revision 38.00 or later
  • GuardLogix®
    5580 controllers firmware revision 34.00 or later
  • CompactLogix
    5380 controllers firmware revision 34.00 or later
  • Compact GuardLogix®
    5380 controllers firmware revision 34.00 or later
  • EtherNet/IP 1756-EN4TR communication modules firmware revision 4.001 or later
  • ControlLogix®
    5590 controllers firmware revision 38.00 or later
Redundancy system works with 1756-EN4TR adapter firmware revision 4.001 or later. The adapters must be configured for redundancy and be in the IP Swapping Mode.
These devices support
enhanced device authentication
:
  • ControlLogix®
    5580 Controllers version 35.00 or later.
  • ControlLogix®
    5580 Process Controllers version 35.00 or later.
  • ControlLogix®
    5590 Controllers firmware revision 38.00 or later
  • GuardLogix®
    5580 Controllers version 35.00 or later.
  • CompactLogix
    5380 Controllers version 35.00 or later.
  • CompactLogix
    5380 Process Controllers version 35.00 or later.
  • Compact GuardLogix®
    5380 Controllers version 35.00 or later.
  • 1756-EN4TR
    ControlLogix®
    Module.
  • FactoryTalk® Linx
    version 6.40 or later.
Mobile connectivity supports these
PowerFlex®
750-Series via Embedded EtherNet/IP devices with firmware revision 12.00 or later in zones with secure communication and certified authentication:
  • PowerFlex®
    755TL drive
  • PowerFlex®
    755TM common bus inverter
  • PowerFlex®
    755TM regenerative bus supply
  • PowerFlex®
    755TR regenerative drive
  • PowerFlex®
    755TS drive
TIP: In
FactoryTalk Policy Manager
, you cannot cut, copy, or paste devices configured for mobile connectivity. You can move such devices between zones with secure communication and certified authentication.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal