Sunteți pe pagina 1din 4

New Product Bulletin

NP 310

Belden® Introduces the


Hirschmann™ EAGLE Tofino
Line of Switches

The Ultimate Zone Level


Security™ Switch for your control
network

Protect Your Control System You may not be attacked by a serious hacker, EAGLE Tofino™ Key Benefits
but conventional control networks are extremely
Against Network Problems • No IT knowledge required
vulnerable to simple day to day security issues.
and Cyber Threats Poor network segmentation, unprotected points
of entry into the network, “soft“ targets such as • Enhanced security and safety
unpatched PCs and vulnerable PLCs, and human
- Extend Cyber Security down into the
error can result in significant production losses
control network
and even safety issues.
• Simplified regulatory and standards
The Tofino Industrial Security Solution is a compliance
distributed security solution that quickly and
cost-effectively implements cyber security --FERC / NERC CIP
protection within your control network.
-- ANSI / ISA-99
Tofino’s flexible architecture allows you to create
-- IEC 62443
security zones - Zone Level Security - throughout
your control network to protect critical system
components. Tofino helps you meet and exceed
NERC CIP requirements and ANSI/ISA-99
Standards. And best of all, it helps you avoid
expensive down time and achieve optimal
performance in your plant.
Central Management Platform and Loadable Security Modules

Design your security system in EAGLE Tofino™ EAGLE Tofino™ Firewall


four easy steps Central Management Platform

Step One: Configure and manage security for your Take control of your network traffic
entire control network from one location
The vast majority of control networks have little
Determine where to place Tofino Security
Traditional security devices force you to or no isolation between different subsystems.
Determine where Tofino Security Appliances configure them one at a time. This quickly If a device misconfiguration, hardware failure,
need to be placed to create Zone Level becomes un-manageable as the number of or virus causes a problem in one part of the
Security™ for the devices in your network. devices increases. What‘s worse, this device- network, it can spread throughout the entire
centric view provides no way to see what is network in seconds and bring your whole plant
Note: the ANSI/ISA-99 Standards recommend happening at the system level, so diagnosing down. Even redundant backup systems can fail
containing communication in control sub- and correcting security issues is time- simultaneously if their network connections are
systems known as “zones”. consuming, error-prone, and expensive. not protected.

Step Two: The Tofino Central Management Platform (CMP) The Tofino Firewall LSM is a traffic control
software enables configuration, management cop for industrial networks, checking all
and monitoring of all your Tofino Security communications on your control network
Determine which Tofino LSMs are required
Appliances from one workstation. against a list of traffic “rules“ defined by your
to secure each hardware location
control engineers. Any communication that is
Do you require “radar“ sweeping your network Using the Tofino CMP you can quickly create not on the “allowed“ list will be blocked and
to track every existing and incoming device a model of your entire control network. Visual reported by the Tofino Firewall.
communicating through a specific Tofino drag-and-drop editing tools help you create,
edit, and test your Tofino configuration. And, Traffic rules are created using terms and
Security Appliance? Then load the Tofino Secure concepts that are already familiar to control
Asset Management LSM. after you commission your security system, the
Tofino CMP lets you see the status of the entire specialists. And, the unique “test“ mode of
Do you require a “traffic control cop“ system at a glance and respond to cyber threats Tofino lets you test your rules without any risk
for industrial networks checking all in a coordinated manner. to plant operation.
communications against a list of traffic rules
and blocking and reporting traffic that does not Saves you money through: Saves you money through:
match the rules? Then load the Tofino Stateful
Firewall Module. • Increased network availability • Simplifying compliance to safety and security
standards
Do you require a “border guard“ inspecting • Rapid network security deployment
• Reduced down time and production losses
every Modbus command and response, blocking • Fast fault finding
and reporting function codes or register • Improved system reliability and stability
addresses not on the “allowed“ list? Then • Lower training and staffing costs
load the Tofino Modbus TCP Deep Packet Features
Inspection LSM. Features
• Traffic rules are defined by your control
Do you require secure communications • Configure, manage and monitor all Tofino engineer, specifying which devices may
“tunnels“ over your corporate network or the Security Appliances from one workstation communicate using what protocols
Internet? Then load the Tofino VPN Client and • Built-in Network Editor to quickly model
Server LSMs. • Rule definition is simple using a graphical
your control network drag-and-drop editor
Step Three: • Visual drag-and-drop editors for quick and • Traffic that does not match the rules is
easy configuration of security rules automatically blocked and reported
Choose the best server or workstation for • Pre-defined templates for more than 50 • Over 50 pre-defined IT and industrial
the Tofino Central Management Platform industrial communication protocols and over communication protocols
25 families of industrial controllers
The Tofino Central Management Platform • Over 25 pre-defined controller templates
software enables configuration, management
Applications • Pre-defined “special rules“ for advanced
and monitoring of all your Tofino Security
Appliances from one workstation. • Process control traffic filtering and vulnerability protection

• SCADA systems Applications


Step Four:
• Discrete control • Isolate critical devices from threat sources
For product and ordering details, go to
www.hirschmann.com • Separate control network into security
“zones“, restricting communications between
zones
• Protect controllers with known vulnerabilities

2
EAGLE Tofino™ EAGLE Tofino™ EAGLE Tofino™ VPN Server and Client
Secure Asset Management Secure Asset Management
Securely track network devices and easily Advanced cyber threat and safety protection A VPN system that is easy to deploy and does
create firewall rules for your Modbus devices not risk industrial processes
Before you can protect a control system, Did you know that any device with a network Industrial facilities often want to utilize
you need to know exactly what devices are connection to a Modbus controller can high-speed Internet connectivity in order to
on the network and how they communicate potentially change any of the controller’s I/O integrate control systems and/or people from
with each other. Seems obvious - but with points or register values? Many controllers can multiple locations. How can you take advantage
today‘s complex systems, getting complete even be reset, disabled, or loaded with new of this cost-effective technology without
and accurate information about the installed logic or firmware. risking viruses or inappropriate access to your
devices and protocols can consume a huge control and SCADA systems?
amount of effort. The Tofino Modbus TCP Enforcer is a content
inspector for Modbus communications, The Tofino VPN solution creates secure “tunnels“
Like radar, Tofino‘s Secure Asset Management checking every Modbus command and response of communication over untrusted networks,
(SAM) and Loadable Security Module (LSM) against a list of “allowed“ commands defined by such as the Internet or corporate business
tracks every device that communicates through your control engineers. networks. Unlike other VPNs, the Tofino VPN is
your Tofino Security Appliance. However, it easy to deploy, test, and manage. This ensures
does it without using traditional scanning Saves you money through: that good security is not compromised because
techniques. Tofino SAM identifies devices of configuration errors.
so you can easily create traffic rules using • Simplifying compliance to safety and security
definitions from the Tofino CMP’s database. If standards The Tofino VPN also supports legacy automation
you need to modify traffic rules during testing, devices and protocols, and is industrially
• Reduced down time and production losses hardened. Best of all, it can be combined with
Tofino SAM’s rule wizard guides you using data
gathered from Tofino’s security alerts. • Lower maintenance costs other Tofino LSMs, such as the Tofino Firewall
LSM or the Tofino Modbus TCP Enforcer LSM, to
Saves you money through: • Improved system reliability and stability provide a comprehensive security solution.

• Increased reliability due to improved security Features


• Simplified regulatory and security standards • First-ever application of content inspection
• Reduced time and effort to get up-to-date technology to industrial protocols
inventory lists • Control specialist defines list of allowed
• Lower engineering and IT costs due to ease of Modbus commands, registers and coils
firewall rule creation • Automatically blocks and reports any traffic
• Reduced commissioning time that does not match your rules
• Protocol “Sanity Check“ blocks any traffic not
Features conforming to the Modbus standard
• Locates network devices without any process • Supports multiple master and slave devices
disruption using Passive Asset Discovery
• Simple configuration and monitoring using
• Identifies equipment and suggests firewall the Tofino CMP
rules using a built-in control device database
• Certified Modbus compliant by Modbus-IDA
• Guides the creation of firewall rules using
“blocked traffic“ reports and the Assisted Applications
Rule Generation wizard
• Oil & Gas custody transfer
• Reports newly-discovered assets as security
alerts • Safety instrumentation systems

• Provides current and detailed inventory lists • Managing PLC programming stations
• Display-only HMI panels
Applications
• Partner access to telemetry data
• Tofino installation, deployment and testing
• Quickly and safely identify network devices
• ISA-99 and NERC compliance via asset and define traffic rules
inventory lists and continuous monitoring
• Detection of non-approved devices (e.g.
laptops) on the control network

3
www.hirschmann-usa.com

EAGLE20 Tofino™ Security Appliance

Protect your control system against network


problems and cyber threats
The electrical, environmental and operational
requirements of SCADA and control systems
make IT-focused security solutions unsuitable
for use in industrial networks. As a result, the
vast majority of these systems are operating
with little or no protection against accidental
or malicious cyber attacks. Even a single
infected USB key can shut down an entire
plant.
The EAGLE20 Tofino Security Appliance
provides leading-edge Zone Level Security™ -
tailored protection for groups of PLCs, DCSs,
RTUs and HMIs, as recommended in ANSI/
ISA-99 Standards. Tofino can be installed and
implemented in a live network with no special
training, no pre-configuration, and most
importantly, with no system downtime. Central Management Platform
Tofino is designed from the ground up with a
rugged environment, staff skills and needs of
industry in mind, and it protects better and Order Information
is easier to install than IT firewalls and other
security products. Designation Part No. Product Description

EAGLE Tofino Central Management Platform 943 987-900 Central management platform for EAGLE Tofino

EAGLE Tofino Firewall LSM 943 987-910 Firewall Loadable Security Module for EAGLE Tofino

EAGLE Tofino Security Asset Management LSM 943 987-911 Security Asset Management Loadable Security Module for EAGLE Tofino

EAGLE Tofino Modbus TCP Enforcer LSM 943 987-912 Modbus TCP Enforcer Loadable Security Module for EAGLE Tofino

EAGLE Tofino VPN Server LSM 943 987-913 Virtual Private Network Server Loadable Security Module for EAGLE Tofino

EAGLE Tofino VPN Client LSM 943 987-914 Virtual Private Network Client Loadable Security Module for EAGLE Tofino

EAGLE Tofino Event Logger LSM 943 987-915 Event Logger Loadable Security Module for EAGLE Tofino

EAGLE Tofino VPN PC Client License 943 987-916 Virtual Private Network PC Client license for EAGLE Tofino

EAGLE20 Tofino TX/TX 943 987-501 EAGLE20 Tofino: Untrusted port - TX, trusted port - TX

EAGLE20 Tofino TX/MM 943 987-502 EAGLE20 Tofino: Untrusted port - TX, trusted port - MM

EAGLE20 Tofino MM/TX 943 987-504 EAGLE20 Tofino: Untrusted port - MM, trusted port - TX

EAGLE20 Tofino MM/MM 943 987-505 EAGLE20 Tofino: Untrusted port - MM, trusted port - MM

Always the Right Solution

Belden is the world’s leading supplier of We welcome the opportunity to speak with
signal transmission solutions including you about our extensive industry portfolio and
cable, connectivity and active components Belden’s worldwide service. Further information
for mission-critical applications ranging and technical data are available online at
from industrial automation to data centers, www.hirschmann-usa.com
broadcast studios, and aerospace. Belden offers
an extensive and highly specialized product You can also contact our sales team directly at
portfolio of signal transmission solutions for 1-717-217-2299.
EAGLE20 Tofino Security Appliance information, control and field levels, which
the company produces and markets under its
proprietary Belden®, Hirschmann™ and Lumberg
Automation™ brands.

© Copyright 2009 Belden, Inc.


Printed in U.S.A
4 NP 310-EAGLE Tofino 122009

S-ar putea să vă placă și