Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6
Related:
IEC 62443-3-1 overview
|
FR 5 Restricted Data Flow
|
Network Segmentation
|
Firewall Planning and Lifecycle
|
Network Security Devices
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 6 pages: Cl. 6 | 6.1 Network firewalls | 6.2 Host firewalls | 6.3 Virtual networks
Filtering and blocking technologies control what traffic may cross a boundary between networks or hosts. In an IACS they implement zone and conduit policy: deny by default, permit only what the process needs.
The IACS constraint is protocol blindness. Many industrial protocols are not understood by generic IT filters, so a firewall that cannot inspect MODBUS/TCP or EtherNet/IP can only filter on address and port — not on function code or register write.