A firewall only protects as well as it is planned, configured, tested, deployed and maintained. This page covers a practical five-phase lifecycle for industrial Automation and Control System (IACS) firewalls: Plan, Configure, Test, Deploy and Manage.
For firewall types, IACS protocol inspection and Clause 6 recommendations, see IEC 62443-3-1 Clause 6.1 – Network Firewalls. For data diodes and device selection, see network security devices. For DMZ and three-tier placement, see network segmentation.
Related: IEC 62443-3-1 Clause 6.1 Network Firewalls | Network Security Devices | Network Segmentation | Defence in Depth | SPE 3 Network and Communications Security | FR 5 Restricted Data Flow | TCP/IP Fundamentals
Use the risk assessment to understand the threats each firewall must address. Review architecture diagrams to place devices for defence in depth — typically at IT/OT boundaries, DMZ edges and ahead of high-value control assets — without adding needless points of failure.
Select the firewall type and class for each location (packet filter, stateful, proxy, DPI / industrial) and match features to the zone or conduit. Coordinate with stakeholders, set a schedule and communicate milestones.
Many layouts are valid; choose against risk, complexity and operations — not fashion.
Physically install hardware, software and firmware; apply patches and updates. Configure administrative users and access. Synchronise time between devices. Enable logging and alerts. Comply with organisational policy.
On greenfield sites (new networks with no prior plant network), you may need to defer full firewall tightening until control systems are stabilised — then lock down.
Effectiveness depends more on policy than on the box. Define which traffic approved applications need (protocols, sources, destinations), including traffic the firewall itself requires for management and health.
Many industrial firewalls provide GUIs and protocol libraries that simplify rule authoring compared with classic CLI ACLs. Principles stay the same: least privilege and documented intent. See also the short policy list on network security devices.
Test a prototype in a lab or controlled environment before production. Goals: functionality, performance, scalability, security and interoperability.
Exercise at least:
After go-live, maintain the platform: security updates, firmware, rule reviews, log monitoring and operational support. When requirements or architecture change significantly, return to Plan and repeat the lifecycle.