← Home

IEC 62443-3-1 Clause 6.3 – Virtual Networks

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6.3
Related: Clause 6 | Switches and VLANs | Network Segmentation | 7.3 VPN | ZCR 3

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 6 pages: Cl. 6 | 6.1 Network firewalls | 6.2 Host firewalls | 6.3 Virtual networks


What it is

Virtual networks in this clause are mainly VLANs and similar logical separation on a switched LAN. They group ports and hosts into separate broadcast domains without extra cables. They are not a substitute for a firewall between different trust levels.

Do not confuse VLANs with VPNs (encrypted tunnels) or with zone-and-conduit segmentation.


Vulnerabilities addressed

Casual mixing of office, engineering and process traffic on one flat LAN. VLANs reduce accidental crosstalk; they do not authenticate a host or stop a determined attacker with trunk access.


Typical deployment

Managed switches with VLAN IDs per function (control, historian, engineering, cameras). Trunks between switches carry multiple VLANs. Routing or a firewall is required for any inter-VLAN traffic.


Known issues and weaknesses


Use in IACS

Useful inside a zone for traffic engineering. Between zones, put a firewall or equivalent in the conduit. If enterprise or internet connectivity is required, use a gated architecture (VPN or application gateway), not flat bridging.


Recommendations