mGuard firmware
4Pages

{{requestButtons}}

Catalog excerpts

mGuard firmware - 1

protecting industrial networks Major Release 8 – The embedded security s ­ oftware for all mGuard appliances The Innominate mGuard firmware is the shared core of all extent. Sophisticated functions such as WAN redundancy mGuard network security appliances. The system, now and SIM failover ensure data transfer even when the available in major release 8, puts into practice market main connection fails. and customer requirements for the security of networked industrial systems in an innovative, yet technically mature Secure remote maintenance made easy with manner with robust functions. When used with the VPNs and mGuard secure cloud mGuard appliance models that are optimized for different The mGuard firmware makes it possible to establish environments, it provides stand-alone, customized pro- VPNs (virtual private networks) in every network mode and to every mGuard interface by using the open, globally proven IPsec Internet standard. Where available, it supports hardware-accelerated encryption for maximum VPN data throughput. IKE fragmentation support ensures that connections are established reliably, even on routes with UDP fragment loss. And mGuard VPN connections can even be tunneled using any TCP ports and web proxy servers with authentication, in cases where Internet access is restricted. Another feature is the option to apply dedicated firewall rules within each VPN tunnel to filter its respective traffic. VPN connections can either be­ (de)activated using a software interface, an electrical switch contact or SMS. This is ideal for equipping or r ­etrofitting of machines and systems for secure remote maintenance using the Internet. The connection to an tection at a local level to the systems that need it: in mGuard secure cloud now makes remote maintenance manufacturing and process industries, infrastructure for even easier. The mGuard secure cloud provides opera- transport and supply and in products of machine building tors and machine and plant construction companies with and plant construction companies. A central device man- a turn-key, complete VPN solution that is perfectly agement component, the mGuard device manager, and ­tailored to mGuard firmware. many sophisticated features ensure that the complexity of operation „Industrial network security“ can be man- Stateful packet inspection firewall aged efficiently, and remains a trouble-free „plug-n-pro- Rule-based filters can be applied to incoming and outgo- tect“ experience for the user. ing data packets in both directions, i.e. from the external network to the secure internal network and vice versa. Global connectivity Network communication can be specifically limited to a There are no more limits to connectivity when using defined level required for production, based on protocols, mGuard 3G devices that support UMTS  HSPA and /  source addresses and ports, as well as destination ad- C ­ DMA mobile telephony standards. Machinery and dresses and ports. Here, response packets to existing equipment can also be connected in locations where this authorized connections are recognized and approved was not possible until now, or only possible to a limited using connection tracking (stateful inspection principle).

Open the catalog to page 1
mGuard firmware - 2

protecting industrial networks Firewall rules can be structured in hierarchical rule sets. This substantially reduces the effort involved in the con- While OPC data traffic cannot be secured appropriately figuration of similar protocol groups between different through the use of conventional firewalls, the mGuard subnets. In addition, the mGuard firewall functionality OPC Inspector offers a solution. OPC data packages can makes it possible to (de)activate rule sets using configu- be accurately filtered by mGuard using deep packet in- rable switching events. This makes it easy to dynamically...

Open the catalog to page 2
mGuard firmware - 3

protecting industrial networks Integrity monitoring to protect against malware also be used in parallel or as a failover to Ethernet oper- Industrial automation components with Microsoft Win- ation. The external network configuration can be carried dows operating systems are widely used today. They are out via DHCP, and the mGuard system itself can also act under threat from a plethora of worms, viruses and other as a DHCP server or relay. Automatic DynDNS registra- malware in the same way as their counterparts in office tion is possible, which is useful when using dynamic IPs. networks....

Open the catalog to page 3
mGuard firmware - 4

mGuard Firmware Standard features Standard features Supported network modes Stealth, Multi Stealth, router, PPPoE, PPTP; mGuard Firmware Virtual private networks (IPsec VPNs) License or bundle required static IP or DHCP client Max. number of simultaneously active VPN External modem Hardware dependent Secondary external interface (serial) Hardware dependent Cellular network connection Hardware dependent Switch support (managed / unmanaged) Hardware dependent IPsec modes: ESP tunnel / ESP transport; DMZ support (demilitarized zone) Hardware dependent IPsec NAT-traversal IPsec tunneling via...

Open the catalog to page 4

All PHOENIX CONTACT Cyber Security AG catalogs and technical brochures

  1. mGuard eVA

    2 Pages

  2. mguard

    2 Pages

Archived catalogs