08-31-2023 04:44 AM
Rockwell's FactoryTalk services (Platform, Networking Manager, View Software, Policy Manager, System Services) as a product group achieve device authentication, data integrity and data confidentiality, by means of certification, cryptographic protocols, HMAC and data encryption. For those of you that are in the space already, or have working experience with Industrial Network devices, what scenario / use-case would require a Cell / Area based Industrial Firewall (Cisco in this case), given (from my understanding) that the Firewalls are stateless, and act as a whitelist / ACL filter in essence, which similarly, Rockwell's FactoryTalk architecture is able to deliver? Defense in-depth is always a consideration, with overlapping security layers, I am curious to hear of real world use cases.
My thoughts;
- Supplicant / endpoint / cell requires additional routing to an SSL / TLS proxy for Cloud based communications?
- Additional micro-segmentation, off-loading / dropping packets at the cell border, rather than traffic hitting a distribution switch, network manager and identity services?
- Where a Cell / Zone is larger, with it's own Network Services internal to the Cell?
Many thanks
Solved! Go to Solution.
08-31-2023 06:59 AM
Your question would probably be better answered here: https://community.cisco.com/t5/internet-of-things-iot/ct-p/iot
08-31-2023 06:39 AM
Not really sure what you are asking here? Maybe its my ignorance of industrial networking requirements. https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356
08-31-2023 06:51 AM - edited 08-31-2023 06:54 AM
Thanks for replying.
My questions is; - if a top level Firewall / Security Appliance (Rockwell in this scenario) has the ability to encrypt data, provide traditional, Certificate verification, segmentation, ACLs etc. what purpose is a Firewall at Levels 0-2 of the Purdue / Converged Ethernet models? Which by design is downstream of the Level 3 Firewall.
08-31-2023 06:59 AM
Your question would probably be better answered here: https://community.cisco.com/t5/internet-of-things-iot/ct-p/iot
08-31-2023 07:05 AM
Thanks, I have moved my post.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide