ConneXium Tofino Firewall protects EtherNet/IP communications

Belden Inc. is announcing that Schneider Electric has expanded its ConneXium Network and Security offer with the addition of EtherNet/IP Deep Packet Inspection (DPI) to the ConneXium Tofino Firewall. The addition of DPI for the popular Ethernet/IP protocol allows Schneider Electric's customers to further harden their industrial control systems against network incidents and cyberattacks. It also allows easier enforcement of company policies for network and device access. The result is improved operational security, reliability and performance.

Ken Mikelinich, product manager for industrial security devices at Schneider Electric, says: "Cyberattacks on manufacturing and process control facilities are increasing. They are also becoming more sophisticated. Enhanced security, along with the tangible business benefits of enforcing corporate security and compliance policies are a must. The extension of the ConneXium Tofino Firewall to include superior protection of EtherNet/IP communications is another important way we are helping customers mitigate risk and support plant policy using security devices."

The ConneXium Tofino Firewall inspects and secures network traffic to and from Schneider Electric automation devices, providing protection from traffic storms, malformed messages and deliberate hacking attempts. In addition, the technology can be used to enforce plant procedure. For example, it can be used to block inappropriate modification or programming of critical devices and controllers, preventing costly mistakes and improving overall network uptime and reliability.

Frank Williams, senior product manager for Security at Belden, remarks: "We are pleased to be expanding our relationship with Schneider Electric with this additional product, and providing their customers with an easy-to-deploy industrial grade firewall that works seamlessly with Schneider Electric's systems."

The central functionality of the ConneXium Tofino Firewall is a security appliance / firewall that inspects each network message that passes through it, ensuring that only the right network messages from the right computers can be sent to critical controllers. Hacking attempts, deliberately corrupted messages and even network traffic storms are effectively prevented.

Deploying and configuring the product is made easy for engineers who are not generally security experts through the use of Tofino's patented Plug-n-Protect technologies. This includes expert technology that looks for common mistakes in firewall programming and corrects them with a single mouse click. Specific Schneider Electric product know-how is also built in, with pre-configured firewall templates for major Schneider Electric automation products.

Better decisions

Advanced protection is provided through DPI technology. Traditional IT firewalls examine TCP/IP headers in network messages and then make decisions whether to allow or block a message based on this limited information. DPI technology allows the firewall to dig deep into the SCADA and ICS protocols that sit on top of TCP/IP. The firewall then determines exactly what the protocol is being used for and makes better decisions on what should be allowed or blocked.

ConneXium Tofino Firewall's 2012 release included DPI for the Modbus TCP protocol. This year, the capability has been expanded to include DPI for the EtherNet/IP protocol. This includes special functionality for EtherNet/IP communications:

  • Support for all Common Industrial Protocol (CIP) objects and services with pre-configured GUI elements according to ODVA specifications
  • Validity checking of both CIP and EtherNet/IP message headers to prevent common hacking techniques, such as buffer overflow attacks
  • An "Advanced" option which allows engineers to select specifically allowed Services and Objects for a firewall rule from a pre-configured drop-down list

Eric Byres, chief technology officer at Tofino Security, comments: "The ConneXium Tofino Firewall is unique in that it makes an easy to deploy security technology even easier by including smarts about Schneider Electric products. It then combines this ease-of-use with advanced firewall features that are specific to industrial needs. The result is a pragmatic and robust security solution for the plant floor."

The ConneXium Tofino Firewall with EtherNet/IP protection is part of the Schneider Electric ConneXium family of industrial communications and security products. In 2012 the ConneXium Industrial Firewall was released, providing boundary protection and encryption for industrial facilities. The ConneXium Tofino Firewall was also introduced that year, providing plant floor protection of automation systems from network incidents and cyberattacks. The ConneXium Tofino Firewall is available for order now from Schneider Electric.

Please visit www.belden.com for further information about industrial control systems and security.

Belden

Edisonstraat 9
Postus 9
5928 PG Venlo
5900 AA
NETHERLANDS

+31 77 387 8555

venlo.salesinfo@belden.com

www.belden.com

More from Belden

Alliance to secure industrial automation and control networks

Posted 2 years ago

Belden publishes "˜Time-sensitive Networking for Dummies'

Posted 3 years ago

Belden releases Industrial Cyber Security for Dummies

Posted 4 years ago

Multiprotocol I/O modules simplify machines for global markets

Posted 4 years ago

Belden demonstrate "TSN Ready" switches at Hannover Messe

Posted 4 years ago

TSN software update for Hirschmann switches RSPE35 and RSPE37

Posted 4 years ago

Belden's BAT867-R Wireless Access Point is compact and rugged

Posted 4 years ago

Belden's MSP40 switch offers flexible port options

Posted 4 years ago

Reduce risk and maximise uptime with Industrial HiVision 7.0

Posted 4 years ago

Belden launches OWL LTE M12 cellular router

Posted 4 years ago

The changing face of future automation networks

Posted 4 years ago

Belden launches additions to Lumberg LioN-Power System

Posted 4 years ago

Time-sensitive networking: a key automation network technology

Posted 4 years ago

Belden's connectivity technology meets future PROFINET Standard

Posted 4 years ago

Belden joins industry effort for time-sensitive networking

Posted 4 years ago

Belden to highlight tomorrow's technologies at SPS/IPC/Drives

Posted 5 years ago

New space-saving Hirschmann OCTOPUS switch from Belden

Posted 5 years ago

Belden offers secure remote access for industrial networks

Posted 5 years ago

Belden delivers complete industrial LAN for Saudi pharma plant

Posted 5 years ago

Two new lines of switches for cost-effective data transfer

Posted 5 years ago

Mid-range Gigabit speed switch for industrial networks

Posted 5 years ago

Hirschmann OCTOPUS Gigabit Switch offers Power over Ethernet

Posted 5 years ago

TRUMPF customers enjoy guaranteed communication availability

Posted 5 years ago

Belden enhances security OS to better secure industrial networks

Posted 5 years ago

Hirschmann and Secomea sign Partnership Agreement

Posted 5 years ago

Cordsets deliver reliability in confined automation settings

Posted 5 years ago

Multiprotocol I/O modules boost flexibility and convenience

Posted 5 years ago

Belden unmanaged switch: send data over long distances

Posted 5 years ago

ICS Security Guide to Hirschmann Switches

Posted 6 years ago

Belden to highlight innovations at SPS/IPC/Drives 2015

Posted 6 years ago

Belden contributes to standards for time-sensitive networks

Posted 6 years ago

Industrial HiVision software now offers comprehensive security

Posted 6 years ago

Belden is a Development Partner for Connected Industry Platform

Posted 6 years ago

Belden and Weidmüller present modular infrastructure box

Posted 6 years ago

Belden router streamlines management of industrial networks

Posted 6 years ago

WLAN software enables secure and reliable wireless connections

Posted 6 years ago

Belden joins AVnu Alliance to support IoT

Posted 6 years ago

Flexible, entry-level Ethernet switch for industrial networks

Posted 6 years ago

Gigabit switch redesigned: improved uptime in harsh environments

Posted 6 years ago

Moulded cord sets support high-speed network connections

Posted 6 years ago

Belden's multi-port industrial firewalls gain added flexibility

Posted 7 years ago

Versatile new industrial router and security appliance

Posted 7 years ago

Cord sets designed for extreme wash-down environments

Posted 7 years ago

Industrial Ethernet switches for future-proof network design

Posted 7 years ago

Tofino Xenon and Configurator 2.0 for control system security

Posted 7 years ago

Belden introduces EMEA-wide network certification program

Posted 7 years ago

Entry-level industrial Ethernet switches for harsh environments

Posted 7 years ago

"˜Near wired' reliability for industrial wireless devices

Posted 7 years ago

Less complexity for managed switches for industrial networks

Posted 7 years ago

Monitor Hirschmann switch status with new HiMobile App

Posted 7 years ago

Industrial HiVision 5.1 can increase network availability

Posted 7 years ago

Belden to show Industry 4.0 live demo at Hanover Fair 2014

Posted 7 years ago

DataTuff Industrial Ethernet cables and connectivity

Posted 7 years ago

Belden offers efficient option for power over Ethernet

Posted 7 years ago

Industrial Ethernet infrastructure design seminar with Belden

Posted 7 years ago

Belden launches 24/7 technical support plan in EMEA

Posted 7 years ago

Network protection with EAGLE One industrial security router

Posted 7 years ago

WLAN firmware extends useful life of industrial wireless devices

Posted 7 years ago

Belden launches Industrial HiVision v5.0 with free trial

Posted 8 years ago

Hirschmann Brand OBR40 optical bypass relay

Posted 8 years ago

Complete Lumberg Automation connector portfolio from Belden

Posted 8 years ago

New service for automatic update of Industrial HiVision

Posted 8 years ago

Hirschmann field-attachable valve connectors from Belden Inc.

Posted 8 years ago

Belden extends its Lumberg Automation LioN-R Series

Posted 8 years ago

Belden adds Hirschmann PowerMICE switch for DIN rail mounting

Posted 8 years ago

Lumberg Automation I/O modules for PROFINET and EtherNet/IP

Posted 8 years ago

OCTOPUS PoE switches with integrated power supply

Posted 8 years ago

New Lumberg automation robotic product programme from Belden

Posted 8 years ago

OCTOPUS Train-BP, a new Hirschmann brand managed IP67 switch

Posted 8 years ago

New Lumberg Automation wash-down connectors from Belden

Posted 8 years ago

ConneXium Tofino: a simple way to secure automation systems

Posted 8 years ago

Optical communications technology for tunnel-boring machines

Posted 8 years ago

The Connectivity Center speeds up customer-specific developments

Posted 8 years ago

Belden adds Hirschmann and Lumberg Automation brands

Posted 12 years ago

Wolfgang Babel named new president of Belden EMEA

Posted 13 years ago

Belden launches new distributor programme

Posted 13 years ago

New DataBus cables for Fieldbus applications

Posted 13 years ago

Specialist cables for factory and process automation

Posted 13 years ago

Belden to exhibit new products at GITEX 2007

Posted 14 years ago

Belden to exhibit at INTERKAMA 2007

Posted 14 years ago

Belden publishes 500-page connectivity catalogue

Posted 14 years ago

PAT becomes Hirschmann's Electronic Control Systems division

Posted 15 years ago

Hirschmann Automation and Control founds joint venture in China

Posted 15 years ago

More products

Login / Sign up