Network configurations are implemented in SIMATIC IPC Industrial Edge Devices and can also be modified and adapted by Edge operators.
| Component | Purpose | Description |
|---|---|---|
| System Firewall | Minimize attack interfaces | Only the 443 port is opened and allowed on the system and protected by Transport Layer Security. Apps can open additional ports as needed. Only authenticated and authorized users can deploy applications. |
| Authenticated Access to the IEM | Allow only authenticated and authorized access to the IEM system | Authenticated Access to the IEM Allow only authenticated and authorized access to the IEM system. Edge services and apps use authenticated and authorized access via digitally signed certificates to the IEM system that are included in the device system. |
| Separated Network Interfaces | Provides support for separation of IT and OT networks | Devices contain more than one physical Ethernet interface to support network separation. Routing from one interface to another is disabled. |