Device-based firewall profile added to CIP Security to further protect Ethernet/IP networks

20 November 2023

ODVA has announced that CIP Security, the cybersecurity network extension for EtherNet/IP, has added a new device-based firewall for enhanced intrusion deterrence.

The CIP Security device-based firewall will provide users with a simple traffic filter similar to how the IP Tables program enables a firewall to be setup in Linux. The device-based firewall is enabled via a new CIP Security Device-Based Firewall Profile, which allows for flexibility to enable or disable this feature as desired. CIP Security now offers even more robust device level protections with a device-based firewall to help discourage bad actors from infiltrating EtherNet/IP industrial networks. 
 
The CIP Security device-based firewall is a mechanism to filter traffic based on IP address, port, and protocol. The device-based firewall is implemented via a new CIP object called the Ingress Egress Object, which enables an allow list of known IP addresses, configuration of available cipher suites, and routing rule definitions based on IP addresses and port numbers. This means that EtherNet/IP devices with CIP Security can determine what nodes can be safely communicated with and whether TLS or DTLS encryption is required. Additionally, the user can decide whether other devices can route CIP communications through the configured CIP Security device. The new device-based firewall adds another layer of deterrence as a part of a defence-in-depth approach to help protect physical and digital assets from harm.
 
The new CIP Security Device-Based Firewall Profile allows for only known IP addresses to communicate using standard EtherNet/IP. Additionally, permitted CIP routing can be configured based on a set of trusted IP addresses, ports, and encryption. As a result of implementing the device-based firewall, data packets without matching IP address and/or ports will be dropped and therefore won¹t be able to complete intended malicious tasks. ODVA is focused on ensuring that EtherNet/IP users have robust and continuously updated device security options available to them via CIP Security as a part of a defence-in-depth approach. 


Contact Details and Archive...

Print this page | E-mail this page