Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6.3
Related:
Clause 6
|
Switches and VLANs
|
Network Segmentation
|
7.3 VPN
|
ZCR 3
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 6 pages: Cl. 6 | 6.1 Network firewalls | 6.2 Host firewalls | 6.3 Virtual networks
Virtual networks in this clause are mainly VLANs and similar logical separation on a switched LAN. They group ports and hosts into separate broadcast domains without extra cables. They are not a substitute for a firewall between different trust levels.
Do not confuse VLANs with VPNs (encrypted tunnels) or with zone-and-conduit segmentation.
Casual mixing of office, engineering and process traffic on one flat LAN. VLANs reduce accidental crosstalk; they do not authenticate a host or stop a determined attacker with trunk access.
Managed switches with VLAN IDs per function (control, historian, engineering, cameras). Trunks between switches carry multiple VLANs. Routing or a firewall is required for any inter-VLAN traffic.
Useful inside a zone for traffic engineering. Between zones, put a firewall or equivalent in the conduit. If enterprise or internet connectivity is required, use a gated architecture (VPN or application gateway), not flat bridging.