SEL-3622 Security Gateway

SEL-3622 Security Gateway
1 / 12 PagesView full catalog

SEL-3622 Security Gateway

Product catalog summary
Major Features and Benefits
The SEL-3622 is a compact security device that functions as a router, VPN endpoint, and firewall. It is designed to secure communication with intelligent electronic devices (IEDs) using a stateful deny-by-default firewall, strong cryptographic protocols, and centralized user-based authentication. Key features include exe-GUARD® whitelist antivirus, LDAP or RADIUS centralized user access, automated IED password management, and security proxy services. Additional security measures include physical tamper detection, detailed connection reports, and secure Ethernet communication via IPsec, SSH, and TLS.
Product Overview
The SEL-3622 offers security proxy services for serial and Ethernet-based IEDs, utilizing a deny-by-default firewall to filter traffic. It supports IPsec VPNs for secure site-to-site communication and provides single sign-on access to protected IEDs. User activities are logged for auditing, and centralized authentication and authorization are supported.
Applications
The device is suitable for routing, message encryption, packet authentication, and user authentication. It secures communication over untrusted networks using IPsec VPN tunnels and supports network address translation (NAT) for dynamic network applications. It also facilitates Ethernet-to-serial conversions and manages IED passwords with audit capabilities.
Functional Description
The SEL-3622 ensures cryptographic message protection through IPsec VPNs, using AES and 3DES encryption algorithms. Device authentication is supported via X.509 certificates or pre-shared keys, with OCSP used for certificate status verification. Event logging is done using the syslog format, and SNMP is supported for state information queries and notifications.
Centralized, User-Based Access Control
The device provides user-based access to protected serial and Ethernet IEDs, ensuring secure and accountable user interactions.
Overview
The SEL-3622 is a security gateway for managing access to IEDs in substations. It verifies user credentials, logs user activity, and offers multiple access methods including SSH and Telnet.
Access and Security
Users must provide credentials verified by a centralized server. The device logs all user activities for auditing and generates syslog messages for session alerts. It features a stateful firewall that denies all traffic by default, requiring explicit permission for allowed traffic.
Management Interface
Configuration is done through a secure web management interface using HTTPS and TLS. It supports two user roles: administrator and technician, with varying levels of access. The web interface provides graphical configuration pages and a command-line interface for configuration automation.
Mechanical and Compliance
The device complies with IEC 60255-27 standards for mechanical strength and protection. It is designed under an ISO 9001 certified quality management system and complies with FCC Class A digital device standards.
Networking and Protocols
The SEL-3622 supports various protocols including IPsec, SSH, and TLS. It allows for static routing, NAT, and supports up to four VLANs per network interface.
Specifications
The device operates in temperatures from -40°C to +85°C, supports up to 256 local accounts, and has a 10-year warranty. It features a 333 MHz processor, 512 MB memory, and 2 GB storage.
Environmental and Electrical Ratings
The SEL-3622 is tested for various environmental conditions including vibration, shock, and temperature extremes. It supports a wide range of input voltages and has specific ratings for DC and AC outputs.
RFI and Interference Tests
The device meets various EMC immunity standards, including electrostatic discharge and magnetic field immunity, ensuring reliable operation in harsh environments.
Specifications
The document outlines various electromagnetic compatibility (EMC) standards and severity levels for different types of immunity and emissions.
Fast Transient Immunity
According to IEC 61000-4-18:2006 + A1:2010, the severity levels are specified as 2.5 kV for common-mode, 1.0 kV for differential-mode, and 1 kV for common-mode on communication ports.
Surge Immunity
As per IEC 61000-4-5:2005, the severity levels are 1 kV line-to-line, 2 kV line-to-earth, and 2 kV for communication ports.
Conducted RF Immunity
IEC 61000-4-6:2008 specifies a severity level of 10 Vrms.
Digital Radio Telephone RF Immunity
ENV 50204:1995 sets the severity level at 10 V/m at frequencies of 900 MHz and 1.89 GHz.
EMC Emissions
The document references standards for radiated and conducted emissions, including CISPR 11:2009+A1:2010, CISPR 22:2008, and ANSI C63.4-2014, with a classification of Class A.
See more

Catalog excerpts

SEL-3622 Security Gateway-1

Major Features and Benefits The SEL-3622 is a compact router, virtual private network (VPN) endpoint, and firewall device that can perform security proxy services for serial and Ethernet-based intelligent electronic devices (IEDs). The small size and low power consumption of the SEL-3622 make it suitable for use in small enclosures such as pole cabinets. Like the SEL-3620, the SEL-3622 helps create an audit trail by using strong, centralized, user-based authentication and authorization to communicate with modern and legacy IEDs. The SEL-3622 secures your control system communication with a stateful deny-by-default firewall, strong cryptographic protocols, and logs for system awareness. The SEL-3622 also manages protected IED passwords, ensuring that passwords are changed regularly and conform to complexity rules for stronger security. The integrated security proxy also provides user-based, single sign-on access to Ethernet and serial connected IEDs. ➤ Secure Architecture and Malware Protection. Maximize reliability with integrated exe-GUARD® whitelist antivirus and other malware protections, eliminating costly patch management and signature updates. ➤ Centralized User-Based Access to Protected IEDs. Provide strong, centralized access control and user accountability to all protected devices with Lightweight Directory Access Protocol (LDAP) or Remote Authentication Dial-In User Service (RADIUS). Simplify compliance with accurate logging. ➤ Automated Management of IED Passwords. Migrate from shared passwords and accounts by using the SEL-3622 as a password manager for protected devices. ➤ Security Proxy Services. Connect securely with identity-based access controls to command line interfaces. ➤ Physical Tamper Detection. Detect and report physical tampering with the built in light sensor, accelerometer, and input contact. ➤ Detailed Connection Reports. Receive detailed connection reports for user activity audits. ➤ Secure Ethernet Communication. Use Internet Protocol Security (IPsec), Secure Shell (SSH), and Transport Layer Security (TLS) to provide confidential communication and maintain message integrity among devices. ➤ Stateful Deny-by-Default Firewall. Prevent unauthorized traffic from entering or exiting your private network. Log all successful or blocked connections to the firewall, and receive alerts indicating the presence of unauthorized network communication attempts. Schweitzer Engineering Laboratories, Inc.

 Open the catalog to page 1
SEL-3622 Security Gateway-2

Syslog. Log events for speedy alerts, consistency, compatibility, and centralized collection. For slow communications links, the SEL-3622 can throttle the number of outgoing syslog messages. Integrated Port Switch. Map one or more of the serial ports to any other serial port, or to Ethernet TCP or UDP connections. Script Engine. Perform command-driven tasks with a single push of a button, and restrict users to specific scripted tasks. X.509 Certificates. Ensure strong authentication with third party validation of incoming connection requests over the IPsec VPN, Active Directory connection, or...

 Open the catalog to page 2
SEL-3622 Security Gateway-3

An integrated, stateful, deny-by-default firewall prevents unauthorized communication from entering or exiting the protected network. The SEL-3622 filters incoming and outgoing TCP, UDP, ICMP, AH, and ESP communication based on a user-configurable set of rules. Trusted Network Malicious Traffic Authorized Traffic Deny-by-Default Firewall User-based accounts increase log granularity and make password management easy and effective. The SEL-3622 includes support for centralized authentication and authorization to simplify management of user accounts, passwords, and user privileges for all your protected...

 Open the catalog to page 3
SEL-3622 Security Gateway-4

Ethernet-to-Serial Conversions The SEL-3622 forwards communication among separate Ethernet networks. Any device that has access to the SEL-3622 can use it to forward Ethernet packets to a destination on a different network. Gain Ethernet-based access to your serial devices through the SEL-3622. The SEL-3622 performs both bitand byte-based serial-to-Ethernet media conversions for Telnet, SSH, Raw TCP, and UDP protocols. The SEL-3622 supports Network Address Translation (NAT) for a wide variety of dynamic network applications. Port forwarding enables the use of similar remote address space without...

 Open the catalog to page 4
SEL-3622 Security Gateway-5

Physical Tamper Detection Detect and report physical tampering or intrusions to the SEL-3622 installation with the built in accelerometer, light sensor, and input contact. The SEL-3622's accelerometer can detect and alert on both impacts and tilt events to the SEL-3622 or its enclosure. The light sensor detects changes in ambient light levels; useful for reporting enclosure door open or close events. The input contact can also be wired to a door contact or motion detector as an alternate method of reporting intrusions. Time Distribution Synchronize all your devices with the SEL-3622, regardless...

 Open the catalog to page 5
SEL-3622 Security Gateway-6

Substation Engineering Access Security Gateway Domain Controller Communications Processor Provide access Request credentials Provide credentials Verify credentials Credentials verified and authorization Successful authentication Request IED access Connect to communications processor Connect to IED Authenticated, authorized, and recorded session Central User Authentication Syslog The SEL-3622 uses the syslog format to log events. These logs contain several fields that indicate event severity, event origin, event type, and details regarding the cause of the event. Additionally, the event message...

 Open the catalog to page 6
SEL-3622 Security Gateway-7

Multiple Access Methods Users have multiple methods of accessing IEDs to provide flexibility for various types of software. SSH and Telnet provide a command line interface to protected devices through the SEL-3622. You can also map specific TCP and UDP ports to physical serial ports. Firewall To protect your private network from malicious traffic, the stateful firewall in the SEL-3622 denies all traffic by default. Explicitly identifying traffic that the SEL-3622 permits makes it far less likely that the SEL-3622 will overlook specific types of traffic. Secure Management Configuration of the...

 Open the catalog to page 7

All Schweitzer Engineering Laboratories catalogs and technical brochures

  1. SEL-C662

    1  Page

  2. 2019 CATALOG

    248  Pages

  3. 2018 CATALOG

    374  Pages

  4. 2017 SEL Catalog

    373  Pages

*Prices are pre-tax. They exclude delivery charges and customs duties and do not include additional charges for installation or activation options. Prices are indicative only and may vary by country, with changes to the cost of raw materials and exchange rates.