Technology News
Streamlined, compact, and simple solutions for cyber-secure machinery
Secure OT with Industrial NAT Gateway and firewall WALL IE from Helmholz.
No new machine can operate without its own machine network. Just as self-evident today should be the protection of this network against unwanted external access. At the latest with new requirements such as IEC 62443 and the European Machinery Regulation, corresponding cybersecurity measures have now become mandatory for anyone placing machinery on the market. More than ever, practical solutions for cyber-secure machines are therefore required – such as the Industrial NAT Gateway WALL IE from Helmholz.
With the rapid spread of Ethernet networking in machines and production plants, cybersecurity must also play a central role. This necessity is clearly reflected in the current standards and regulatory landscape: the international IEC 62443 standard series, most recently revised in 2023, addresses the cybersecurity of “Industrial Automation and Control Systems” (IACS) and follows a holistic approach for operators, integrators, and manufacturers. It therefore affects everyone involved in the manufacture and operation of machines and defines corresponding responsibilities for machine builders, suppliers, and end customers. The European Union has also recognized the seriousness of the situation and is responding, for example, with the NIS-2 Directive (Network and Information Security Directive, in force since 2023) and the Cyber Resilience Act (CRA).
In addition, the European Commission has revised Machinery Directive 2006/42/EC. In doing so, the directive was aligned with the New Legislative Framework (NLF). Furthermore, new technological developments such as artificial intelligence, autonomy, and networking were taken into account when updating the fundamental safety and health protection requirements. The corresponding new European Machinery Regulation 2023/1230 will apply to the placing of machinery on the market as of January 20, 2027.
Securely integrating machine networks
Not only these current requirements show that the topic of machine security now concerns everyone. At its core, the goal is to securely integrate machine networks into the overarching production network.
The key term here is “Secure OT” – meaning secure operational technology consisting of software and hardware for controlling, protecting, and monitoring industrial control systems, devices, and processes.
In the face of growing data volumes, there is no alternative to the separation or segmentation of networks. Concepts based on zones and secure zone transitions (Zones & Conduits) have proven to be particularly effective. IEC 62443 therefore also prescribes a corresponding protection concept: for large or complex systems, it is often not appropriate to apply the same protection requirements to all components, as they are exposed to different threats and risks. These differences can be represented using the concept of a “security zone”. A security zone is a logical grouping of physical assets that share the same protection requirements. The boundary of the security zone defines which components are inside and which are outside the zone. To ensure the necessary information flow into and out of a security zone, so-called communication conduits are defined. Communication outside of these conduits is not permitted.
Robust and cost-efficient protection with WALL IE
At this point, the question arises as to how such a Zones & Conduits protection concept can be implemented in practice for networked machinery.
The market offers numerous high-end solutions for this purpose, which are usually oversized for securing a single machine network.
This generally also means they are overly complex and, not least, unnecessarily expensive.
Especially medium-sized mechanical engineering companies and their customers are therefore looking for more practical solutions that are not only secure and reliable, but also lean, efficient, and easy to implement. One such solution is the WALL IE NAT gateway from Helmholz: installed once and permanently between the machine and the production network, this robust and particularly compact Ethernet component combines bridge and firewall functions to exactly the required extent.
Specifically, the device protects networks by precisely controlling which participants are allowed to exchange data with which devices. This is enabled by packet filter functionality, which restricts access between the production network and the automation cell. The simplicity and security of the solution are further enhanced by the fact that the WALL IE, together with the machine network behind it, appears in the production network as a single IP address. As a further special feature, WALL IE can be operated both in NAT mode and as a bridge. In bridge mode, it acts like a switch. Unlike conventional switches, however, packet filtering is also possible in this operating mode. This allows access to specific areas of the network to be restricted without using separate networks.
In NAT operating mode, which is used by most users, WALL IE forwards data traffic between different IPv4 networks (Layer 3) and uses packet filters to restrict access to the downstream automation network. Address translation via Network Address Translation (NAT) is supported. The use of NAT also allows several identical automation cells with the same address range to be integrated into the production network. In NAT mode, WALL IE supports two NAT functions: Basic NAT (also known as “1:1 NAT” or “Static NAT”) and NAPT (Network Address and Port Translation, also known as “1:N NAT” or “Masquerading”).
Even more possibilities through new variants
Since its market launch in 2015, WALL IE has proven itself thousands of times over.
Its functional scope has continuously expanded, largely in response to specific customer requests.
Since 2024, two new variants have complemented the previous “standard” version
(with four ports and a transmission rate of 100 Mbps).
Both feature a faster processor with Ethernet speeds of up to 1 Gbit/s,
opening up additional application areas.
The new “Compact” version is limited to two ports – one for the company network (WAN)
and one for the machine network (LAN).
The “Plus” version, on the other hand, offers eight ports.
The ports can be freely configured as LAN or WAN switches.
The advantage: smaller networks can be implemented without additional switches or even with a single device.
All three WALL IE variants share the fact that only basic networking knowledge is required for commissioning. For example, no adjustment of the LAN network configuration is necessary. Series machines with identical IP addresses can also be easily integrated.
Summary
In the networked industry of the future, the security of machines and systems is crucial for stable and reliable processes.
Network segmentation and secure access to machine networks make it possible to optimize processes efficiently.
The easily configurable NAT gateways and machine firewalls of the WALL IE series from Helmholz provide tailored protection
for sensitive data and reliably protect critical systems against cyber threats with minimal effort.