← Home
IEC 62443-3-1 Clause 6.2 – Host-Based Firewalls
Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for
learning. The technical report is informational, not a requirements standard. Confirm wording
in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.
Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6.2
Related:
Clause 6
|
6.1 Network firewalls
|
System Hardening
|
2-1 Component Security
Technology categories:
Overview
|
Cl. 5
|
Cl. 6
|
Cl. 7
|
Cl. 8
|
Cl. 9
|
Cl. 10
Clause 6 pages:
Cl. 6
|
6.1 Network firewalls
|
6.2 Host firewalls
|
6.3 Virtual networks
What it is
A host-based firewall is software on a workstation or server that filters
that host’s traffic. It is not a substitute for a network firewall at a zone boundary.
Vulnerabilities addressed
Unauthorised inbound services on a single host, and some lateral movement if the host is
compromised less completely than the network around it.
Typical deployment
OS firewalls on Windows or Unix engineering stations and servers. Rare on controllers.
Known issues and weaknesses
- Many IACS vendors prohibit extra host-firewall software on supported
images.
- Commercial host firewalls are typically unaware of MODBUS/TCP, EtherNet/IP and similar,
so they cannot inspect SCADA packets at the application layer or proxy those protocols.
- At publication the TR identified no commercial package that solved that industrial-protocol
gap on the host.
Use in IACS
Few host-based firewalls in genuine control environments. Prefer network firewalls and
industrial protocol-aware filters at the zone edge. Teaching note: some modern OT hosts ship
a vendor-supported host filter; still require written approval before adding third-party
software.
Recommendations
- Do not install host-firewall software on vendor-supported control hosts
without written vendor and asset-owner approval.
- Prefer network firewalls
and industrial protocol-aware filters at the zone edge.
- If a host firewall is used, treat it as hardening of that host, not as zone segmentation.