Siemens SCALANCE S industrial security appliances protect automation networks, control systems, and field devices from unauthorized access and network intrusions at the boundary between corporate IT and operational technology (OT) environments. This collection covers surplus sealed and refurbished SCALANCE S modules across both the current SC600 series and earlier legacy variants, available for facilities maintaining existing Siemens network security infrastructure or sourcing replacement units for installed equipment.
PLC Direct supplies Siemens SCALANCE S modules to customers maintaining existing OT network security infrastructure and sourcing replacement hardware across active, phase-out, and discontinued product lines. The collection covers 13 products across the current SCALANCE SC600 series and legacy SCALANCE S variants.
Where Siemens SCALANCE S Modules Are Used
Industrial networks running SIMATIC PLCs, SINAMICS drives, distributed I/O, and SCADA-connected systems operate in environments where a compromised or failed security appliance can expose the entire control network. SCALANCE S modules are deployed at cell boundaries to segment and protect OT networks, enforce firewall rules, secure remote access via VPN, and manage address translation between network zones. For legacy SCALANCE S variants that Siemens has discontinued, like-for-like replacement units are no longer available through standard distribution, making independent suppliers a primary sourcing option for facilities that are not yet ready to migrate to current-generation hardware.
Facilities and systems that depend on Siemens SCALANCE S security appliances include:
- Discrete manufacturing plants using PROFINET-based machine networks requiring cell-level firewall protection
- Process industry facilities with OT/IT network segmentation requirements across distributed control systems
- Automotive and assembly lines using SCALANCE S modules to isolate machine cells from plant networks
- Utilities and infrastructure operations with SCADA-connected field hardware requiring secure remote access
- Food and beverage processing facilities with multi-zone network architectures
- Sites using Siemens SINEMA Remote Connect for centralized remote network management
When a SCALANCE S module needs to be replaced, matching the product family and firmware generation to the installed unit is essential. Current SC600 series modules and legacy S6xx modules are not interchangeable, and network configuration may need to be updated when moving between generations.
Siemens Industrial Communication Products
This collection covers two SCALANCE S generations: the current SCALANCE SC600 series and discontinued legacy SCALANCE S modules. All product families and part numbers below are confirmed on the live PLC Direct collection page.
- SCALANCE SC600 Series: Current Industrial Security Appliances: The SC600 series is Siemens' current-generation industrial security appliance family, providing firewall and VPN protection for OT network cell protection. All SC600 units support NAT/NAPT address conversion and integration with Siemens SINEMA Remote Connect for remote network management. Confirmed variants in stock:
- SCALANCE SC615 LAN Router: 5-port switch, VPN and firewall, NAT/NAPT, 1x digital input, 1x digital output (6GK5615-0AA00-2AA2)
- SCALANCE SC622-2C: Firewall with PROFIsafe network separation, 2x combo ports RJ45 or 1000 Mbit/s SFP (6GK5622-2GS00-2AC2)
- SCALANCE SC632-2C: Firewall, 2x combo ports RJ45 or 100 Mbit/s SFP or 1000 Mbit/s SFP (6GK5632-2GS00-2AC2)
- SCALANCE SC636-2C: Firewall, 4x RJ45 ports + 2x combo ports RJ45 or 100 Mbit/s SFP or 1000 Mbit/s SFP (6GK5636-2GS00-2AC2)
- SCALANCE SC642-2C: Firewall and VPN, 2x combo ports RJ45 or 100 Mbit/s SFP or 1000 Mbit/s SFP (6GK5642-2GS00-2AC2)
- SCALANCE SC646-2C: Firewall and VPN, 4x RJ45 ports + 2x combo ports RJ45 or 100 Mbit/s SFP or 1000 Mbit/s SFP (6GK5646-2GS00-2AC2)
- Legacy SCALANCE S Series: Discontinued Modules: Earlier SCALANCE S modules, the S602, S612, S613, S623, and S627-2M, have been discontinued or cancelled by Siemens but remain installed across a large number of manufacturing, process, and infrastructure sites. These units are no longer available through authorized distribution. PLC Direct carries surplus and refurbished units for facilities sourcing replacement hardware without migrating to SC600 series equipment. Confirmed legacy variants in stock:
- SCALANCE S602: Firewall with NAT/NAPT, DHCP server, Syslog, symbolic names for IP addresses (6GK5602-0BA00-2AA3); extended variant also includes PPPoE, DynDNS, SNMP v1+v3, and global firewall rules (6GK5602-0BA10-2AA3)
- SCALANCE S612: VPN (up to 32 devices) and firewall (6GK5612-0BA00-2AA3, 6GK5612-0BA10-2AA3)
- SCALANCE S613: VPN (up to 64 devices) and firewall (6GK5613-0BA00-2AA3)
- SCALANCE S623: VPN and firewall with additional DMZ port for third-network connection (6GK5623-0BA10-2AA3)
- SCALANCE S627-2M: VPN and firewall with DMZ port, redundant ring coupling, firewall redundancy, 24 V supply (6GK5627-2BA10-2AA3)
Available at PLC Direct
- SCALANCE SC615 LAN router, firewall, and VPN, 5-port, 24 V supply
- SCALANCE SC622-2C industrial security appliance: Firewall with PROFIsafe network separation
- SCALANCE SC632-2C, SC636-2C industrial security appliances: Firewall, NAT/NAPT
- SCALANCE SC642-2C, SC646-2C industrial security appliances: Firewall and VPN, NAT/NAPT
- Legacy SCALANCE S602 modules: Firewall, two variants with differing extended feature sets
- Legacy SCALANCE S612 modules: VPN (up to 32 devices) and firewall
- Legacy SCALANCE S613 module: VPN (up to 64 devices) and firewall
- Legacy SCALANCE S623: VPN and firewall with DMZ port
- Legacy SCALANCE S627-2M: VPN, firewall, DMZ, ring redundancy
What to Know Before You Buy Siemens SCALANCE S Modules
Replacing a SCALANCE S security appliance requires matching the product generation and feature set to the installed unit. SC600 and legacy S6xx modules are not functionally interchangeable and use different configuration interfaces.
Hardware condition options: PLC Direct supplies SCALANCE S modules as surplus sealed, refurbished, and used hardware. Surplus sealed units are factory-sealed stock. Refurbished units have been tested and verified to be functional. For network security hardware, it is recommended to confirm the condition grade before purchase.
SC600 vs legacy compatibility: The current SCALANCE SC600 series modules and the discontinued S602/S612/S613/S623/S627 modules are separate product generations with different configuration methods and feature sets. SC600 units integrate with SINEMA Remote Connect; legacy modules do not. If replacing a legacy unit with an SC600 module, network reconfiguration will be required.
VPN device capacity: Within the legacy range, VPN capacity varies by model. The S612 supports up to 32 VPN-connected devices; the S613 supports up to 64. The S623 and S627-2M both add a DMZ port for connecting a third network segment. Confirm the installed model's specifications before ordering a replacement to ensure it supports the same network topology.
Part identification — S602 variants: The two S602 part numbers differ in their feature sets. The 6GK5602-0BA00-2AA3 provides a firewall with NAT/NAPT, DHCP server, Syslog, and symbolic IP address names. The 6GK5602-0BA10-2AA3 adds PPPoE, DynDNS, SNMP v1+v3, and global firewall rules. Confirm which variant matches the installed unit before ordering.
Part identification — S612 lifecycle status: The two S612 variants carry different Siemens lifecycle designations. The 6GK5612-0BA00-2AA3 is classified PM500 (Discontinued), while the 6GK5612-0BA10-2AA3 is classified PM410 (Product cancellation). Both remain available through PLC Direct as surplus and refurbished stock.
Warranty: All Siemens SCALANCE S modules purchased from PLC Direct include a standard 1-year warranty covering defects and functionality, applicable to surplus sealed, refurbished, and used products.













