Network configurations are implemented in SIMATIC IPC Industrial Edge Devices, also possible to modify and be customized by edge users.
| Component | Purpose | Description |
|---|---|---|
| System Firewall | Minimize attack interfaces | Only port 443 is opened and protected through Transport Layer Security. Apps can open additional ports as needed. Only authenticated and authorized users can deploy apps. |
| Authenticated Access to the IEM | Allow only authenticated and authorized access to the IEM system | Edge services and apps use authenticated and authorized access via digitally signed certificates included in the device system. |
| Separated Network Interfaces | Support separation of IT and OT networks | Devices include more than one physical ethernet interface to support network separation. Routing from one interface to another is disabled. You shall not use the device for network segmentation if one of those networks is used for safety function. As only officially certified devices can do network segmentation. |