We need help in designing our substation network and connecting it to our corporate LAN. The substation network consists of Ethernet radios connecting approximately 25 substations in a 30 mile radius. We have several different systems operating at each station such as SCADA and AMR. We need to segregate each of these networks and route them to different servers at headquarters. We would also like to have access to the corporate network for remote email and internet connections. At each substation the Ethernet radio will drop a TX connection to a hub, switch or router. We will connect the SCADA processor, AMR processor and maybe a computer to this device. Back at the office we bring the TX connection to either a layer3 switch or router to direct the traffic as needed. Our LAN is already protected via firewalls and such from the outside world so I don?t see a need in another firewall. My two major concerns are routing the traffic correctly and blocking users from plugging in a computer at a substation and accessing the LAN. Please give advice on what equipment is necessary to reach our goals and how to block any computer from plugging in at a station and having complete access (maybe we need to use a VPN or something)
This is a tough one. Electric utilities are evaluating their security in and around routable protocols for control system networks to meet the requirements of NERC CIP. Your design should/must be based on the requirements that you fall under, based upon your NERC/FERC role.
Segregation is key. I have a utility network that is compliant and can offer you some help. Can you offer some insight as to the need to remote email and internet from the substation applications?
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...