Design World

  • Home
  • Technologies
    • ELECTRONICS • ELECTRICAL
    • Fastening • joining
    • FLUID POWER
    • LINEAR MOTION
    • MOTION CONTROL
    • SENSORS
    • TEST & MEASUREMENT
    • Factory automation
    • Warehouse automation
    • DIGITAL TRANSFORMATION
  • Learn
    • Tech Toolboxes
    • Learning center
    • eBooks • Tech Tips
    • Podcasts
    • Videos
    • Webinars • general engineering
    • Webinars • Automated warehousing
    • Voices
  • LEAP Awards
  • 2025 Leadership
    • 2024 Winners
    • 2023 Winners
    • 2022 Winners
    • 2021 Winners
  • Design Guides
  • Resources
    • Subscribe
    • 3D Cad Models
      • PARTsolutions
      • TraceParts
    • Digital Issues
      • Design World
      • EE World
    • Engineering diversity
    • Trends
  • Supplier Listings
  • Advertise
  • Subscribe

Successful Protection for Industrial Networks

By Michael Jermann | January 15, 2014

Edited by Michael Jermann, Assistant Editor

Ethernet-based production systems are becoming increasingly well-established. Easy integration into Intranet and Internet, the high bandwidth of up to Gigabits per second, and decreasing costs of industrially specified cables, connectors, switches, and routers are the reasons behind this development. The other side of the coin, though, is an increased risk of malfunctions and production interruptions due to security loopholes in industrial networks.

For this reason, Volkswagen AG conducted an internal risk analysis at its car body production plant in Emden, Germany. The audit scrutinized the security of multiple systems, including their control technology. The result: sensitive production systems were insufficiently protected against unauthorized access because attacks can be triggered by malware, inadvertent access or unintentional mis-entries during internal network operations. In addition, preventing these issues through centralized firewalls is complex and not cost-effective.

sensitive-production-systems

Sensitive production systems tend to be inadequately protected. Imported malware or unintentional incorrect misentries on the internal network cannot be prevented by central

For example, employees of third-party companies who access the network using their laptops during service operations or for hardware and software installations can unintentionally spread malware that are deemed a potential risk. The analysis also identified unintentional mis-entries as problematic weaknesses. Jens Hoofdmann, bodywork maintenance specialist, cited one problematic issue arising from the analysis: “A typical example is the installation of a server which subsequently sends ping packets to the entire network at short intervals. Such permanent requests can disrupt or even crash an industrial controller.”

An action item matrix was developed based on the risk assessment, encompassing organizational changes, network segmentation and the introduction of distributed industrial firewalls. When it came to selecting suitable hardening and security measures, Volkswagen AG‘s Emden plant opted for industrial routers with an integrated firewall. The distributed industrial firewall/router solution segments the production network in the car body construction plant at Emden into 15 isolated subnetworks. For central protection featuring comparable granularity, all systems and sub-networks would need star layout network cabling with a high-capacity firewall in a complex configuration. Given the typical distances between network nodes at industrial plants, this proves particularly expensive and inefficient which is why these environments are virtually dominated by tree-shaped and linear cable topologies and therefore better suited to a distributed firewall approach.

The central IT department was also involved in the preliminary discussions regarding implementing the new structure, the technical evaluation and start-up monitoring. The production-related IT department ultimately assumed responsibility for addressing the planning, installation, commissioning and administration tasks.

The system network had already been successfully planned and put into operation in conjunction with Phoenix Contact, an automation company based in Blomberg, Germany. The experience gained from the project and the knowledge acquired of the systems also proved beneficial during the network protection operations. The company used FL mGuard industrial firewall/router modules from Phoenix Contact and Innominate.

The mGuard modules are based on an embedded Linux and integrate four coordinated security components: a bidirectional stateful inspection firewall, a flexible NAT router, a secure VPN gateway, and protection against malware as an option.

The fact that the mGuard security appliance is self-sufficient and can be integrated into existing production networks without reconfiguring end devices using its stealth mode of operation proved to be advantageous. In networking terms, this means the firewall behaves transparently as a bridge.

jens-hoofdmann

“Our experience with MGUARD industrial firewalls is nothing but positive. All unauthorized access is blocked and the systems are now better protected against malware,” reported Jens Hoofdmann, bodywork maintenance specialist at Volkswagen AG’s Emden plant.

From Jens Hoofdmann‘s perspective, installing, setting up and integrating the industrial firewalls was easy. The devices were used in a distributed manner in control cabinets for every uplink connection. In hardware terms, Volkswagen AG was able to mount the 24-V DIN rail devices directly into the control cabinets and allow its own staff members to start them up based on the existing network structure and without any re-cabling operations.

A very pragmatic approach was adopted towards setting up the firewall rules. In the first instance, all data traffic was permitted and access to the subnetworks was only logged. The log files were subsequently evaluated and recorded in the form of rules governing which type of access should be permitted in the future. The rules were tested, revised and finally defined in their present form.

During this phase, the company relied on the experience of Innominate, a fully owned Phoenix Contact subsidiary. Jens Hoofdmann stated: “We benefited from Innominate‘s expertise in industrial networks, protocols, and firewall rules and were able to optimize the structure of the installations.”

The mGuard Device Manager (MDM) central management system features a template mechanism facilitating central configuration and management of all mGuard devices. The parameters for firewall rules and NAT settings are directly configured in IDM without the need to define abstract security policies. Volkswagen can use the upload function to upload the rules to all the listed devices and configure them in one step. The IDM enabled special rules to be implemented between the subnetworks, subgroups and user groups and then distributed to all firewalls.

According to the maintenance team at Volkswagen Emden, device management has been greatly facilitated by the central management system. Generating a new firewall rule within five minutes in order to grant a member of the service team access is no longer an issue.

Robots, PLCs, panel PCs, laser technology, welding systems, controllers and the driverless transport system have since been protected by distributed firewalls on the Emden car bodywork production network. Jens Hoofdmann reports that there have been no security incidents since the firewalls were installed. However, they have been able to identify infected devices from other production sectors based on the log files. In one of these instances, a virus had attempted to spread to other devices. However, the mGuard blocked access to the protected computers, making it possible to advise the other sectors of the malicious malware.

Reprint info >>

Phoenix Contact
www.phoenixcontact.com

You Might Also Like


Filed Under: CONNECTIVITY • fieldbuses • networks • gateways, PLCs + PACs
Tagged With: phoenixcontact
 

LEARNING CENTER

Design World Learning Center
“dw
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest info on technologies, tools and strategies for Design Engineering Professionals.
Motor University

Design World Digital Edition

cover

Browse the most current issue of Design World and back issues in an easy to use high quality format. Clip, share and download with the leading design engineering magazine today.

EDABoard the Forum for Electronics

Top global problem solving EE forum covering Microcontrollers, DSP, Networking, Analog and Digital Design, RF, Power Electronics, PCB Routing and much more

EDABoard: Forum for electronics

Sponsored Content

  • Sustainability, Innovation and Safety, Central to Our Approach
  • Why off-highway is the sweet spot for AC electrification technology
  • Looking to 2025: Past Success Guides Future Achievements
  • North American Companies Seek Stronger Ties with Italian OEMs
  • Adapt and Evolve
  • Sustainable Practices for a Sustainable World
View More >>
Engineering Exchange

The Engineering Exchange is a global educational networking community for engineers.

Connect, share, and learn today »

Design World
  • About us
  • Contact
  • Manage your Design World Subscription
  • Subscribe
  • Design World Digital Network
  • Control Engineering
  • Consulting-Specifying Engineer
  • Plant Engineering
  • Engineering White Papers
  • Leap Awards

Copyright © 2025 WTWH Media LLC. All Rights Reserved. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of WTWH Media
Privacy Policy | Advertising | About Us

Search Design World

  • Home
  • Technologies
    • ELECTRONICS • ELECTRICAL
    • Fastening • joining
    • FLUID POWER
    • LINEAR MOTION
    • MOTION CONTROL
    • SENSORS
    • TEST & MEASUREMENT
    • Factory automation
    • Warehouse automation
    • DIGITAL TRANSFORMATION
  • Learn
    • Tech Toolboxes
    • Learning center
    • eBooks • Tech Tips
    • Podcasts
    • Videos
    • Webinars • general engineering
    • Webinars • Automated warehousing
    • Voices
  • LEAP Awards
  • 2025 Leadership
    • 2024 Winners
    • 2023 Winners
    • 2022 Winners
    • 2021 Winners
  • Design Guides
  • Resources
    • Subscribe
    • 3D Cad Models
      • PARTsolutions
      • TraceParts
    • Digital Issues
      • Design World
      • EE World
    • Engineering diversity
    • Trends
  • Supplier Listings
  • Advertise
  • Subscribe
We use cookies to personalize content and ads, to provide social media features, and to analyze our traffic. We share information about your use of our site with our social media, advertising, and analytics partners who may combine it with other information you’ve provided to them or that they’ve collected from your use of their services. You consent to our cookies if you continue to use this website.OkNoRead more