Security with Passion www.endian.com

Similar documents
Who s Endian?

NERC CIP Whitepaper How Endian Solutions Can Help With Compliance

Secure Communication Made Easy

Industrial Firewalls Endpoint Security

Symantec Client Management Suite 8.0

Intrusion Detection and Cyber Security Monitoring of SCADA and DCS Networks

MOBILITY & INTERCONNECTIVITY. Features SECURITY OF INFORMATION TECHNOLOGIES

Solutions for Health Insurance Portability and Accountability Act (HIPAA) Compliance

Overview and Deployment Guide. Sophos UTM on AWS

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

2X SecureRemoteDesktop. Version 1.1

BENEFITS. Capex reduction with bundling of all required features in a single appliance. Promote your brand with customized Guest Login pages.

Deploy and Manage a Highly Scalable, Worry-Free WLAN

VIA CONNECT PRO Deployment Guide

Internet Content Provider Safeguards Customer Networks and Services

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

Network Design Best Practices for Deploying WLAN Switches

Intelligent WLAN Controller with Advanced Functions

Network Management System (NMS) FAQ

Your remote sites at your fingertips?

Deploying Firewalls Throughout Your Organization

Virtualized Open-Source Network Security Appliance

Solution Brief. Secure and Assured Networking for Financial Services

State of Texas. TEX-AN Next Generation. NNI Plan

TELSTRA CLOUD SERVICES CLOUD INFRASTRUCTURE PRICING GUIDE AUSTRALIA

BYOD: BRING YOUR OWN DEVICE.

VIA COLLAGE Deployment Guide

Cisco Unified MobilityManager Version 1.2

Sophos Certified Architect Course overview

Industrial Security Solutions

Game changing Technology für Ihre Kunden. Thomas Bürgis System Engineering Manager CEE

Unified Threat Management, Managed Security, and the Cloud Services Model

Product Factsheet MANAGED SECURITY SERVICES - FIREWALLS - FACT SHEET

Payment Card Industry Data Security Standard

Quick Start Guide. WRV210 Wireless-G VPN Router with RangeBooster. Cisco Small Business

Cisco Advanced Malware Protection. Ross Shehov Security Virtual Systems Engineer March 2016

INTEGRATING SUBSTATION IT AND OT DEVICE ACCESS AND MANAGEMENT

Securing the Small Business Network. Keeping up with the changing threat landscape

AC Wireless Dual Band Gigabit Router. Highlights

MSP Dashboard. Solution Guide

DOBUS And SBL Cloud Services Brochure

Infoblox vnios Software for CISCO AXP

Cisco Fog Computing Solutions: Unleash the Power of the Internet of Things

Security. Quick Sales Guide

Check Point and Security Best Practices. December 2013 Presented by David Rawle

Table of Contents...2 Introduction...3 Mission of IT...3 Primary Service Delivery Objectives...3 Availability of Systems Improve Processes...

Sophistication of attacks will keep improving, especially APT and zero-day exploits

SA Series SSL VPN Virtual Appliances

Telecom Business Continuity Solutions FOR INTERNAL USE ONLY

RuggedCom Solutions for

Total Business Continuity with Cyberoam High Availability

McAfee Endpoint Protection Products

Endpoint Security VPN for Mac

The ForeScout Difference

Symantec Brightmail Gateway Real-time protection backed by the largest investment in security infrastructure

Opengear Technical Note

This document has for purpose to elaborate on how Secomea have addressed all these topics with a solution consisting of the three components:

10 easy steps to secure your retail network

VPN. Date: 4/15/2004 By: Heena Patel

Host-based Protection for ATM's

Cisco Wireless Control System (WCS)

FISMA / NIST REVISION 3 COMPLIANCE

Internet threats: steps to security for your small business

SVN5800 Secure Access Gateway

The Internet of Things (IoT) and Industrial Networks. Guy Denis Rockwell Automation Alliance Manager Europe 2015

BOMGAR.COM BOMGAR VS. GOTOASSIST UPDATED: 9/8/2015

Enterprise Cybersecurity Best Practices Part Number MAN Revision 006

Extending Threat Protection and Control to Mobile Workers with Cloud-Based Security Services > White Paper

SSL Encryption and Traffic Inspection ADDRESSING THE INCREASED 2048-BIT PERFORMANCE DEMANDS OF 2048-BIT SSL CERTIFICATES

Scott Lucas: I m Scott Lucas. I m the Director of Product Marketing for the Branch Solutions Business Unit.

Why Choose Integrated VPN/Firewall Solutions over Stand-alone VPNs

CradleCare Support Agreement The Peace of Mind Plan

Secure networks are crucial for IT systems and their

An Analysis of Propalms TSE and Microsoft Remote Desktop Services

Entering the cloud fray

Symantec Mobile Management 7.1

Addressing the SANS Top 20 Critical Security Controls for Effective Cyber Defense

Virtualized Network Services SDN solution for service providers

Virtualized Security: The Next Generation of Consolidation

The Future of Network Security Sophos 2012 Network Security Survey

Network Enabled Cloud

White Paper. BD Assurity Linc Software Security. Overview

N750 WiFi DSL Modem Router Premium Edition

Uninterrupted Internet:

Nighthawk AC1900 Smart WiFi Router Dual Band Gigabit

Course overview. CompTIA A+ Certification (Exam ) Official Study Guide (G188eng verdraft)

Blackboard Collaborate Web Conferencing Hosted Environment Technical Infrastructure and Security

Injazat s Managed Services Portfolio

Business Phone Systems. Managed IT Services

AC 750. Wireless Dual Band ADSL2+ Modem Router. Highlights

VDI Security for Better Protection and Performance

A guide to CLARiSUITE TM network solutions

Symantec NetBackup PureDisk Optimizing Backups with Deduplication for Remote Offices, Data Center and Virtual Machines

WhitePaper. Private Cloud Computing Essentials

Firewall and UTM Solutions Guide

Transcription:

Security with Passion www.endian.com Endian 4i Switchboard Securely Connect Users to SCADA Devices

2

Security with Passion www.endian.com Table of contents A 360 Solution to Secure Industrial Connectivity 5 The Challange 5 The Solution 5 Our Industrial Product Portfolio 5 The Challange Secure Connection of SCADA Systems 6 The Solution Endian 4i and Switchboard 7 Switchboard Key Features 8 Action Links 8 Interoperable 8 Development Access (API) 8 USB Provisioning 9 Reference Customers 9 Subnet Mapping 9 4i Edge Industrial Firewalls 10 Feature Highlights 10 Endian 4i Edge 500: The Ultimate Industrial Solution 10 Endian 4i Edge 300: DIN Rail Industrial Solution 11 Endian 4i Edge 200: Desktop Industrial Solution 11 Success Story: Instrumentation Laboratory (IL) 13 About Endian 15 3

Mobile Access: Our latest software release now supports native remote access from any ios or Android mobile device. 4 Computer to Device: Provision remote access to all of your key personnel (users, contractors, vendors, etc.) Machine to Machine (M2M): Connect all of your industrial networks together or even connect them into your IT network.

Security with Passion www.endian.com A 360 Solution to Secure Industrial Connectivity The Challange Industrial networks are rapidly changing into open and interconnected systems over the. Technicians and engineers need to be able to remotely monitor and intervene on a wide variety of SCADA equipment. However, by connecting systems to the means potentially exposing critical assets to a wide variety of malicious threats. The Solution The solution is a system capable of safeguarding control equipment, alerting key personnel and restricting access to authorized personnel only, while blocking and reporting intrusion attempts. This product has to secure and encrypt machine-tomachine communication and filter harmful traffic. The management of such a complete solution has to be really simple, as SCADA networks become increasingly distributed over large territories. Why Endian Endian 4i series, desktop or DIN rail version, provides insutrial networks with a complete set of security features, including firewalling, routing, Virtual Private Network () and Intrusion Prevention System (IPS). We assure top performance in terms of power, stability and usability for a wide variety of temperature ranges. Secure remote access is available from ios and Android devices as well, with no need to install third party applications. The Switchboard makes it possible to manage all Endian devices (as well as user/group access permissions) from a single management portal. Our Industrial Product Portfolio Endian Switchboard: Centralized Solution Switchboard Web interface for remote access 3 Rule & Role-based permissions 3 connection 3 Provide access from mobile devices 3 Can be hosted in the cloud 3 Access to any endpoint in production network 3 Prevent and signal unauthorized access 3 Encrypt communication 3 Provide no IPs collision 3 Provisioning via USB key 3 Endian 4i Edge Series Devices: SCADA Access & Security 4i edge series Firewall 3 Routing 3 Bandwith management 3 IPS 3 5

The Challange Secure Connection of SCADA Systems You need to connect your users to your remote SCADA devices on various control networks located all over the world. Each user or group of users needs specialized and/or restricted access to certain equipment that fall within their job responsiblitiy but you do not wish to allow them to access or manage any other equipment. You also have a responsiblity to ensure that only one remote user can be connected to any given device to prevent duplicate access which can cause serious business disruption. Using today s technology solving all these issues means either: 1 manually opening device access to the which presents serious security risks or 2 using point products that each have to be managed individually which causes a heavy administrative burden for your non-technical staff. 1 Manually opening device access to the which presents serious security risks Location B (SCADA) User 1 Open Port 80 User 2 Firewall Centralized Management Secure, Controlled Access 2 Using point to point products Location A (SCADA) Location B (SCADA) Device Device Centralized Management Simple Administrative Overhead 6

Security with Passion www.endian.com The Solution Endian 4i and Switchboard Simply and securely connect your various users or groups (of users) to individual devices or device groups without any client side configuration. The client just installs the software and connects to the switchboard and all their device access is available. Group your users and/or devices by job roles or device access levels to only allow the access required (and nothing more). Securely Connect Users to SCADA Devices Dallas Detroit Switchboard New York Vendor Access SCADA Monitoring & Support IT Admins Key Features Central User Management Determine which users or groups of users can access each network and define what permissions they have when connected Quick Device Configuration With distributed networks, it s difficult to deploy many edge devices. The Switchboard s USB provisioning tool makes configuration as simple as plug-n-play. Resolve Network Conflicts Routing problems result when multiple networks are assigned the same subnet -- the new Endian Switchboard can automatically resolve this issue! Benefits to IT / Control Businesses Give access to many users with different roles Quick denial of access (employee termination) Prevent remote access to critical devices Detailed user audit trail (compliance) Provide users one-click access to endpoints behind Endian (HMI, PLC, etc) Multiple locations that span a large territory Project deployment is time-sensitive Network is expanding now or will in the future Personnel at remote locations have limited networking skills Need to quickly issue a back-up due to failure Prevents massive network remapping project Reduce business IT involvement Eliminate the requirement to deploy additional hardware at remote locations Allow central management of connections 7

Switchboard Key Features Action Links Choose an action... Remote Desktop Launch App2 HMI 1 HMI 1 With Endian 4i series it is possibile to set up actions and group of actions for any device: via pre-configured hyperlinks one can launch applications to access the endpoints Switchboard (PLCs, HMIs, Web Servers, etc.) behind the firewall. Remote User 4i Client HMI 1 IT Support Development Access (API) SCADA Support Intranet Switchboard Thanks to API interface it is possible to integrate all the Switchboard functionalities on existent platforms (such as partners support portal). Vendor Support Interoperable In the event where existing endpoint devices are in place, you can use the Switchboard to manage any device that utilizes Open (SSL) technology. This helps to reduce the cost of replacing edge devices and minimizes the impact of potential downtime of the network. Switchboard 8

Security with Passion www.endian.com Switchboard Subnet Mapping IP overlapping is no longer a problem: Endian Switchboard automatically remaps redundant subnets so that a central management solution can be implemented. Subnet A Subnet A Subnet A USB Provisioning Switchboard The provisioning is implemented through a simple USB key that spreads the chosen configuration settings to the Endian 4i appliances USB HMI Servers Remote User 4i Client Reference Customers 9

4i Edge Industrial Firewalls Endian 4i Edge 515 The most robust industrial solution 59 mm 4i Edge 505 is the strongest ruggedized appliance of the new series. Its powerful hardware is conceived to work in critical conditions and under extreme temperatures. The solution guarantees an even more stable and scalable connection between head quarter and branch offices/ pro- 167 mm duction sites. DIN Rail/Wall Mount Wide Temperature: Mobile Native support -20 C -- 70 C 3G Module Highlights: Recommended for: -20 to +70 C Temperature Machine Building Simple, Secure Access Manufacturing 3G Module (optional) Infrastructure Dual Power Input 24V DC Healthcare Communications Performance Firewall Throughput: 120 Mbps Throughput: 30 Mbps IPS Throughput 20 Mbps 140 mm Feature Highlights Firewall 10 (SSL & IPsec) IPS 3G/4G Modem Support

Security with Passion www.endian.com Endian 4i Edge 313 The DIN Rail industrial solution Endian 4i Edge 200 Desktop Industrial Solution It is the ideal appliance to secure industrial networks and The 4i Edge 200 appliance is built to provide the most po- protect data exchange between branch offices. Serial werful desktop industrial solution on the market. This product over IP and Digital Input/ Output included. works great as a branch office solution or as an end- 167 mm point secure router in temperature controlled environments. Highlights: 0 to +60 C Temperature Simple, Secure Access Simple, Secure Access 3G/4G USB Modem Support 3G Module (optional) 5 Gigabit Ethernet Ports Dual Power Input 24V DC Low Power (< 5W) Recommended for: Recommended for: Machine Building Infrastructure Manufacturing Healthcare Infrastructure Communications 59 mm 37 mm 175 mm 140 mm Highlights: Edge 200 175 mm 140 mm Disaster Recovery Centralized Management Easy Drop In Reporting 11

12

Security with Passion www.endian.com Success Story: Instrumentation Laboratory (IL) The company: Instrumentation Laboratory (IL) is a Spanish company belonging to the Werfen Group. The Whole group has branches almost in every country of the world, more than 4000 employees and grosses over than 1 billion dollars. IL s core business is the production and distribution of machinery for clinical analysis (critical care, hemostasis, clinical chemistry and auto immunology). The requirement: Real-time monitoring of devices located in the users facilities, remote support and care. The solution: Simple, stable and bidirectional, to allow central management access (for daily logs exchange) Customer support portal central system connection via API Extremely granular management of access permissions (single user or groups) Automatic remapping to resolve IP overlapping 3G or WiFi connection to in-field devices Endian a complete security solution: Every end user is provided with an Endian 4i 200 appliance; the ideal solution for branch offices and secure endpoint router for controlled temperature environments. The SSL client is easy to configure and supports all the main platforms (Microsoft Windows, Mac OS X & Linux). Programmable Logic Controllers (PLC) are remotely monitored through it. This enables tools measurement, mulfunctioning scanning and troubleshooting. Mobile access is enabled via ios and Android devices, with no need to install third party software. The central management component, Endian Switchboard, has been installed on an Endian Virtual Firewall. Through its web interface, IL is able to to manage technicians, partners and end users remote access to machinery, providing them with different and granular permissions. The Switchboard also integrates with IL s customer support portal, a central management system connected via API, allowing direct access and intervention to engineers and technicians. Alternatively, the link can be made through 4iConnect, the Switchboard client. Using the Switchboard USB Provisioning tool, each Endian appliance is easily configured for quick deployment. This allows IL to efficiently set-up virtually thousands of Endian devices for central/remote management access to their diagnostic equipment around the world, while connecting the gateway to the central system with the chosen configuration settings. 13

Our Value Proposition The number of connected devices both corporate and private is increasing every day. If not properly managed, these devices can become exposed to malicious attacks, resulting in a potential breach in your system. To prevent this, your environment needs protection. What you do need is a simple solution that does not add complexity to the way in which users access the network. 14 Endian 4i was designed to be the most secure and easiest to use industrial solution for businesses of any size, allowing your company to connect and protect it s critical assets.

Security with Passion www.endian.com About Endian Endian was founded in 2003 in Appiano, Italy by a team of experienced network specialist and Linux enthusiasts. Endian s goal and mission were immediately clear: to create sophisticated Unified Threat Management (UTM) solutions using the power of open source technology. Just two years later, Endian reaches a significant milestone; the first version of Endian is ready to be distributed. The same year the community version was released and greeted with immediate success. The number of downloads to date is staggering, more than 1.2 million since its initial release. Meanwhile, the Endian team continues studying and integrating new features into the product portfolio. The HotSpot becomes the company s unique and distinguishing feature. As a result, Endian is able to help hotels (and other businesses looking to offer wireless guest access) better serve their clients all over the world! Endian s UTM solutions start emerging in the European and extra EU security markets. By year 4, the company steadily establishes itself in Germany, USA, Turkey and Japan and deployed in over 50 countries. After consolidating its position in the UTM landscape, the next challenge for Endian presented itself; secure SCADA systems. The Machine to Machine (M2M) market experiences a critical moment as the number of attacks rise significantly. In response, in 2012 Endian Launches the 4i Edge product line, enabling the company to serve the immediate needs of the industrial and control markets. 2013 opens with an exciting announcement; Endian and open source reporting company ntop, agree in principle to a partnership. Shortly after, the Switchboard is released which revolutionizes how large networks manage their users and devices. Endian enters its 10th year with a new logo and website redesign, a symbol of their commitment to face and overcome these new security challenges without adding complexity to how users interact with their networks. Endian continues to prove that great solutions come from individuals that carry the mantra Security with Passion! Endian Timeline 2003: Endian formation 2004: Endian team begins working on the UTM solution 2005: First professional and community Endian release launched. Endian sells its first appliance in Italy. 2006: Endian integrates HotSpot functionality 2007: Endian hits over 100,000 downloads of the community version 2008: Endian US formation. Endian signs exclusive distributor in Australia. Endian experiences 260% growth and ships over 1,000 units in a single year. 2009: Endian Deutschland formation and release of v2.3. Endian now distributed in over 50 countries. 2010: Over 5,000 units sold. v2.4 released. 2011: New Endian Mini (first to use ARM technology) is released. Endian begins business development in Turkey. 2012: Endian releases the 4i (For Industrial) appliances and reaches 1.2 million downloads of the community version. 2013: Endian releases v3.0 15

2013 Endian SRL. Subject to change without notice. Endian and Endian UTM are trademarks of Endian SRL. All other trademarks and registered trademarks are the property of their respective owners. Endian International Tel: +39 0471 631 763 E-mail: sales@endian.com Endian Italia Tel: +39 0471 631 763 E-mail: italy@endian.com Endian Deutschland Tel: +49 (0) 8106 30750-13 E-mail: germany@endian.com Endian US Tel:+1 832 775 8795 E-mail: us@endian.com Endian Japan Tel:+81 3 680 651 86 E-mail: japan@endian.com Endian Turkey Mobile +90 (0) 539 336 59 42 E-mail: turkey@endian.com