Industrial Demilitarized Zone Design Principles
Industrial Demilitarized Zone Design Principles
Industrial Demilitarized Zone Design Principles
Design Principles
Jason J. Dely, CISSP, CISM
Principal Security Consultant, Network & Security Services
jdely@ra.rockwell.com
PUBLIC INFORMATION
Course Description
There are many organizations and standards bodies that recommend separating the
enterprise zone from the industrial zones by utilizing an industrial demilitarized zone
(iDMZ).
This session will describe the basic principals and strategies of designing an iDMZ to
separate these two zones.
A prior understanding of general Ethernet concepts, or attendance of the Fundamentals
of EtherNet/IP session is recommended.
Agenda
What is a DMZ?
Methodology
Network Segmentation
Corporate Network
Back-Office Mainframes and
Servers (ERP, MES, etc.)
Control Network
Gateway
Human Machine
Interface (HMI)
Office
Applications,
Internetworking,
Data Servers,
Storage
Controller
Supervisory
Control
Phone
Controller
Robotics
Office
Applications,
Internetworking,
Data Servers,
Storage
Camera
Supervisory
Control
Robotics
Motors, Drives
Actuators
I/O
Sensors and other
Input/Output Devices
Industrial Network
Traditional 3 Tier
Industrial Network Model
Motors, Drives
Actuators
Safety
Controller
Safety
I/O
Human Machine
Interface (HMI)
Industrial Network
EtherNet/IP - Enabling/Driving
Convergence of Control and Information
Copyright 2014 Rockwell Automation, Inc. All Rights Reserved.
Link for
Patch Management
Remote Access Services
Application Mirrors
Anti-Virus Servers
Failover
Active
Standby
DMZ
Controller
Phone
Camera
Supervisory
Control
Robotics
I/O
Motors, Drives
Actuators
Safety
Controller
Safety
I/O
Human Machine
Interface (HMI)
Industrial Network
Web
Proxy
UNTRUSTED
BROKER
DMZ
TRUSTED
Enterprise Network
Router
E-Mail, Intranet, etc.
Terminal Services
Patch Management
Historian Mirror
Level 3
Level 2
FactoryTalk
Application
Server
Enterprise
Zone
FactoryTalk
Directory
Engineering
Workstation
FactoryTalk
Client
Firewall
AV
Server
Web
E-Mail
CIP
Application
Server
Firewall
Domain
Controller
Manufacturing
Zone
FactoryTalk
Client
Operator
Interface
Engineering
Workstation
Operator
Interface
Basic Control
Level 1
Level 0
Batch Control
Sensors
Discrete Control
Drives
DMZ
Drive Control
Actuators
Continuous
Process Control
Robots
Safety
Control
Cell/Area
Zone
Process
Agenda
What is a DMZ?
Methodology
Network Segmentation
Methodology
Recon Phase
Identify Assets
Or
Asset Classes
Identify Asset
Owners
ACTION
ACTION
Document Assets by
documentation,
interviews and
network scanning
Document Asset
Owners and
Schedule Interviews
Design Phase
Requirements Architectural Tech. Design
Implement
Phase
Phase
Phase
Maintain
10
11
12
13
Interview Process
Interview process identifies
how the owners and
clients of the assets
Operate
Configure
Patch
Upgrade
Identifies where the data is
produced and consumed
This process is used to
gather requirements
14
The system
components are
brought together and
tested during this
phase per the testing
plan
Technical Design
Phase
Implementation
Maintain
ACTION
ACTION
ACTION
ACTION
Produce detailed
documentation such
as drawings, switch
configurations, VLAN,
IP Address, Firewall
ACLs
Requirements are a
statement identifying
a capability, physical
characteristic or
quality factor that
bounds a product or
process problem for
which a solution will
be pursued. (Source:
IEEE Standard 12201994)
High level
architectural
recommendations
that are proposed to
meet the customer
requirements.
Requirements
Phase
Architectural
Phase
ACTION
Interview all system
owners to gather
requirements for
operations,
configuration and
maintenance.
15
16
Actor
Historian
MES
Order Entry
QC Systems
No Control Protocols
Through the Firewall(s)
Industrial
DMZ
Manufacturing
17
Actor
Order Entry
MES
Historian
Historian
Data
Mirror
Proxy
Industrial
DMZ
Manufacturing
Historian
QC Systems
18
19
Historian Mirror
20
The system
components are
brought together and
tested during this
phase per the testing
plan
Technical Design
Phase
Implementation
Maintain
ACTION
ACTION
ACTION
ACTION
Produce detailed
documentation such
as drawings, switch
configurations, VLAN,
IP Address, Firewall
ACLs
Requirements are a
statement identifying
a capability, physical
characteristic or
quality factor that
bounds a product or
process problem for
which a solution will
be pursued. (Source:
IEEE Standard 12201994)
High level
architectural
recommendations
that are proposed to
meet the customer
requirements.
Requirements
Phase
Architectural
Phase
ACTION
Interview all system
owners to gather
requirements for
operations,
configuration and
maintenance.
21
Agenda
What is a DMZ?
Methodology
Network Segmentation
22
OEMs Participation
IP Address
VLAN IDs
Access layer to Distribution
layer cooperation
Copy
Security
Availability
ERP, Email,
Wide Area Network (WAN)
Enterprise Zone
Levels 4 and 5
Demilitarized Zone (DMZ)
Patch Management
Terminal Services
Application Mirror
AV Server
Gbps Link
for Failover
Detection
Cisco
ASA 5500
Firewall
(Standby)
Firewall
(Active)
Security
Availability
VLAN 101
VLAN 41
View
Historian
AssetCentre
Transaction Manager
Catalyst
6500/4500
FactoryTalk Services
Platform
Remote
Access
Server
Directory
Security/Audit
Data Servers
Catalyst 3750
StackWise
Switch Stack
Cell/Area #1
Network Services
Rockwell Automation
Stratix 8000
Layer 2 Access Switch
Cell/Area Zones
Levels 02
Cell/Area #3
Cell/Area #2
Drive
Industrial Zone
Site Operations and Control
Level 3
Cisco
Catalyst Switch
HMI
Controller
HMI
Controller
HMI
VLAN 102
I/O
VLAN 42
I/O
Drive
Drive
I/O
Controller
VLAN 103
VLAN 43
VLAN 104
VLAN 44
VLAN 105
Copyright 2014 Rockwell Automation, Inc. All Rights Reserved.
Layer 2
HMI Block
I/O
Building
Media &
Connectors
Cell/Area Zone #1
Redundant Star Topology
Flex Links Resiliency
Availability
Catalyst 3750
StackWise
Switch Stack
Layer 3
Building Block
Rockwell Automation
Stratix 8000
Layer 2 Access Switch
Drive
Controller
Security
HMI
Layer 2
I/O
Drive
Building Level
Block
1
Controller
Controller
Cell/Area Zone #2
Ring Topology
Resilient Ethernet Protocol (REP)
Cell/Area Zones
Levels 02
Level 2 HMI
Controller
HMI
Drive
Layer 2
Building
Block
I/O
Level 0
Drive
Cell/Area Zone #3
Bus/Star Topology
The Cell/Area zone is a Layer 2 network for a functional area of the plant floor.
Key network considerations include:
Structure and hierarchy using smaller Layer 2 building blocks
Logical segmentation for traffic management and policy enforcement to accommodate timesensitive applications
Copyright 2014 Rockwell Automation, Inc. All Rights Reserved.
Machine Types
Security
Availability Requirements
Historian
OS Patch
AV Server
Workstations
Remote Session Hosts
HMI Servers
Networking, Routing
Availability
Information Requirements
Interfaces
Catalyst 3750
StackWise
Switch Stack
Cell/Area Zones
Levels 0-2
HMI
Rockwell Automation
Stratix 8000
Layer 2 Access Switch
Drive
Controller
HMI
Controller
HMI
I/O
Drive
I/O
Controller
Cell/Area Zone #1
Redundant Star Topology
Flex Links Resiliency
I/O
Cell/Area Zone #2
Ring Topology
Resilient Ethernet Protocol (REP)
Drive
I/O
Cell/Area Zone #3
Bus/Star Topology
Copyright 2014 Rockwell Automation, Inc. All Rights Reserved.
Thank you!!
4
Copyright 2014 Rockwell Automation, Inc. All Rights Reserved.
27
Questions?
PUBLIC INFORMATION