View
548
Download
1
Category
Tags:
Preview:
DESCRIPTION
EtherNet/IP provides a single network technology for motion, safety, discrete, drives, and process applications streamlining machine network design and decreasing wiring costs. In this session, you will learn about security considerations and best practices for integration of these machines with end user networks. We will discuss trade offs and options for remote connectivity approaches, infrastructure features and segmentation methods.
Citation preview
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
PUBLIC INFORMATION
Security Considerations for Machine Builders
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Agenda
3
Infrastructure Features
Remote Connectivity
Segmentation Approaches
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Advantages Disadvantages
Managed
Switches
Unmanaged
Switches
Embedded
Switches
• Segmentation services (VLANs)
• Diagnostic information
• Security services
• Prioritization services (QoS)
• Multicast management services
• Network resiliency
• Loop prevention
• Inexpensive
• Simple to set up
• More expensive
• Requires some level of support and configuration to start up
• No management capabilities
• No security
• No diagnostic information
• Difficult to troubleshoot
• No resiliency support
• No loop prevention
• Diagnostic information
• Prioritization services (QoS)
• Time Sync Services (1588 Transparent Clock)
• Network resiliency
• Loop prevention
• Limited management capabilities
• May require minimal configuration
Switch Considerations
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Topology Flexibility with EtherNet/IP
EtherNet/IP is topology neutral for maximum flexibility
HYBRID – Obtain maximum flexibility
LINEAR - Simplify cable management STAR– Connect broad range of devices
RING – Maximum availability
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Why Managed Switches for Machine Networks?
Robust/future proof the control network:
Reduce risk from interference from other devices on the network
Customer support & satisfaction
Security features for Network access to the Control System:
Enabler for remote access
Customer support/satisfaction
Equipment differentiation
Diagnostic Capability:
Reduce TTM
Increase equipment differentiation
Improve customer support/satisfaction and reduce risk
6
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 7 7
Logix Interface
Rockwell Software Studio 5000® • Configuration (stored as part of project)
• Status
• Product identification
• I/O connection
• Port Status
• Alarms
• Maintenance - Save and restore
Logix Predefined Tags • Link Status
• Unauthorized device
• Threshold exceeded
• Bandwidth utilization
• Alarm relays
• Port Control
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Infrastructure Security Considerations
Physical Access Security Disable unused switch ports Lock a port to only allow specific devices to be
connected Change passwords from default settings
Access Control Lists and Firewall Features Limit access to secure areas of the network. Limit access to secure services on the network Block remote access to secured devices
VLANs Simplify security enforcement by creating function
groups Segment Network by function, by user, by location, etc.
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Machine Switch Best Practices
9
Best practices to improve
machine level Infrastructure
Security:
• Apply port security to protect open
ports on the switch
• Apply password to the switches to
prevent unauthorized changes
• Limit the size of broadcast domain
with segmentation
• Apply Security Policies to
communications coming into the
machine from outside
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Machine Network Segmentation for the Plant Network
ArmorBlock® I/O
PanelView™ Plus EOI
POINT I/O™
Plant Network CompactLogix™ L36ERM
Stratix 5700™
Cisco 3750 or Stratix 8300™
PowerFlex® 525
Kinetix® 5500
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Cell/Area Zone #3 Cell/Area Zone #4 Cell/Area Zone #1 Cell/Area Zone #2
Industrial Zone
DMZ
Enterprise Zone Enterprise
Network
Mobile User
Lightweight AP (LWAP)
AP as Workgroup Bridge (WGB)
ERP, Email, Wide Area Network (WAN)
Catalyst 2960 Series PoE-8
SYST
DUPLX
SPEED
MODE
COC IS
1 2
POWER OVER ETHERNET
13X
14X
11X
12X
23X
24X
STAT
RPS
PoE
1X
2X
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
Catalyst 2960 Series PoE-8
SYST
DUPLX
SPEED
MODE
COC IS
1 2
POWER OVER ETHERNET
13X
14X
11X
12X
23X
24X
STAT
RPS
PoE
1X
2X
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
CISCO ASA 5510
POWER STATUS ACTIVE VPN FLASH
Adaptive Security Appliance
SERIES
CISCO ASA 5510
POWER STATUS ACTIVE VPN FLASH
Adaptive Security Appliance
SERIES
Cisco 4400 Series
WIRELESS LAN CONTROLLER
MODEL 4402 12 APCONSOLE
STATUS
ALARM
PS1
PS2
LINK ACT
SERVICE
LINK ACT
UTILITY 1 2
LINK
ACT
2
.Rx
-Tx
. 4
A
G
H z
ANTENNA
2
. Rx -Tx
.4
A
GH
zANTENNA
2
. Rx -Tx
.4
B
GH
zANTENNA
2
. Rx -Tx
.4
C
GH
zANTENNA
2
.Rx
-Tx
. 4
C
G
H z
ANTENNA
2
.Rx
-Tx
. 4
B
G
H z
ANTENNA
STATUS RADIOETHERNET
C OCIS
2
.Rx
-Tx
. 4
A
G
H z
ANTENNA
2
. Rx -Tx
.4
A
GH
zANTENNA
2
. Rx -Tx
.4
B
GH
zANTENNA
2
. Rx -Tx
.4
C
GH
zANTENNA
2
.Rx
-Tx
. 4
C
G
H z
ANTENNA
2
.Rx
-Tx
. 4
B
G
H z
ANTENNA
STATUS RADIOETHERNET
C OCIS
MODE
STACKSPEEDDUPLXSTATMASTRRPSSYST
Catalyst 3750 SERIES
1 2 3 4 5 6 7 8 9 10 11 12
1X
2X
11X
12X
13 14 15 16 17 18 19 20 21 22 23 24
13X
14X
23X
24X
1 2 3 4
MODE
STACKSPEEDDUPLXSTATMASTRRPSSYST
Catalyst 3750 SERIES
1 2 3 4 5 6 7 8 9 10 11 12
1X
2X
11X
12X
13 14 15 16 17 18 19 20 21 22 23 24
13X
14X
23X
24X
1 2 3 4
Converged Network Segmentation
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Network Address Translation
Machine 1 NAT
10.104.x.x :
192.168.1.x
Machine 2 NAT 10.104.x.x : 192.168.1.x
192.168.1.104 192.168.1.104
10.104.100.23
192.168.1.100
Within a Machine Between Machine and Line Network
Send message
to Machine 2
CMX 10.104.2.100
192.168.1.100
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Connectivity to Plant Network Virtual vs. Physical Segmentation
13
PowerFlex 4/40 AC Drive
PV+ or PV+ Compact
Plant VLAN
10.10.10.10
CompactLogix 5370 L3 PowerFlex 4/40 AC Drive
PV+ or PV+ Compact
Plant
10.10.10.10 192.168.1.2
Virtual
Pros:
• Little/No machine level switch configuration needed
• Removes “single point of failure” plant network
connectivity
• Designed to allow network services (SNMP, VPN,
DNS, DHCP)
Cons:
• IP addressing must be unique at the machine level
Physical
Pros:
• IP Addresses private to machine (not visible
outside of machine network)
• Clear Demarcation
Cons:
• Additional cost
• Some additional complexity and management
• Multiple network identities for a single device
Machine VLAN
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Remote Access Approaches
14
Direct to ICS
Inside-Out Terminal Services
Outside-In
modems
VPN Technology
Through IT Infrastructure
Inside-Out
Conferencing technology (WebEx)
Terminal Services
Outside-In VPN Technology
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Remote Access/Asset “Technology Recommendation” Process
15
Technology Recommendation
Risk Mitigation
Techniques and Policies
Business Case
Risk
Assessment
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Strategic Planning and Justification
16
Cost of Downtime
Cost to train someone locally/run a dedicated line to remote asset
# of assets exposed to remote access
Functions exposed to remote access
Safety risk/reward? If someone got this access they could potentially do this and cause
a safety issue. If I have to send someone out to this unmanned location it would pose a
risk to their safety (confined spaces, other hazards present, etc.)
Productivity improvement potential
MTTR reduction potential
Cost of Hardware
Maintenance cost
What confidential information may be at risk and how can I mitigate that risk
Impact to operations in the event of a breech and how to mitigate/recover from that
Compliance and regulatory obligations
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 17
Remote Access Technology Considerations
Speed Security Features
IT Involvement and support
Firewall Setup Needs
Unmanned Site
Hardware Costs
Service Costs Application
Needs Auditing
Capabilities
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 18
Common Technology Approaches
Application
Presentation
Session
Transport
Network
Data Link
Physical
Layer 7
Layer 6
Layer 5
Layer 4
Layer 3
Layer 2
Layer 1
TCP - UDP
IP
IEEE 802.3
TIA - 1005
Layer Name Layer No. Function
CIP
Application Layers
Data Transport Layers
SSH
SSL/TLS
IPSec
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Additional Material Rockwell Automation
19
Networks Website: http://www.ab.com/networks/
EtherNet/IP Website: http://www.ab.com/networks/ethernet/
Publications:
ENET-UM001-EN-P EtherNet/IP Network Configuration
ENET-AP005-EN-P Embedded Switch application guide
ENET-RM002-EN-P EtherNet/IP Design Considerations
Network and Security Services Website:
http://www.rockwellautomation.com/services/networks/
http://www.rockwellautomation.com/services/security/
ODVA Website
http://www.odva.org
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Additional Material Cisco and Rockwell Automation Alliance
20
Website
http://www.ab.com/networks/architectures.html
Design Guides
CPwE DIG
Education Series
Whitepapers
Securing Manufacturing Computer and
Controller Assets
Production Software within Manufacturing
Reference Architectures
Achieving Secure Remote Access to Plant Floor
Applications and Data
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Additional Material Cisco and Rockwell Automation Alliance
21
Education Series Webcasts
The Trend - Network Technology and Cultural Convergence
What every IT professional should know about Plant Floor Networking
What every Plant Floor Controls Engineer should know about working with IT
Industrial Ethernet: Introduction to Resiliency
Fundamentals of Secure Remote Access
for Plant Floor Applications and Data
Securing Architectures and Applications
for Network Convergence
Available Online
http://www.ab.com/networks/architectures.html
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
We care what you think!
On the mobile app:
1. Locate session using
Schedule or Agenda Builder
2. Click on the thumbs up icon on
the lower right corner of the
session detail
3. Complete survey
4. Click the Submit Form button
22
Please take a couple minutes to complete a quick session survey to tell us how we’re doing.
2
3
4
1
Thank you!!
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
www.rsteched.com
Follow RSTechED on Facebook & Twitter. Connect with us on LinkedIn.
PUBLIC INFORMATION
Questions?
Recommended