SlideShare a Scribd company logo
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 1Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 2Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
PUBLIC
Building Converged Plantwide
Ethernet Architectures
Converged Plantwide Ethernet (CPwE) Architectures
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 3Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Abstract
 Learn why and how to use reference architectures to build a scalable,
reliable, safe, secure and future-ready network infrastructure. This
discussion provides an overview of the Cisco and Rockwell Automation®
Converged Plantwide Ethernet (CPwE) architectures. Learn what defines a
reference architecture, why they’re important and how these architectures
combined with products, services and solutions support successful
deployment of The Connected Enterprise. A prior understanding of general
Ethernet concepts, or attendance of the fundamentals of EtherNet/IP
network technology is recommended.
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 4Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Agenda
 What’s Driving This?
 Why are Reference Architectures Important?
 OT-IT Similarities and Differences
 CPwE Architectures
 Cisco and Rockwell Automation Alliance
 What Makes Up CPwE
 Convergence-Ready Network Solutions
 Additional Material
 Training Resources
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 5Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 6Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Application
Software
Network
What’s Driving This?
Reliable, Safe and Secure Architectures for The Connected Enterprise
A reliable, secure architecture is
critical to building a connected
enterprise
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 7Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Reliable, Safe and Secure Architectures for The Connected Enterprise
Industrial IoT
Operational Technology
Industrial IT
Information Technology
Physical or Virtualized Servers
• FactoryTalk® Application Servers and
Services Platform
• Network & Security Services – DNS,
AD, DHCP, Identity Services (AAA)
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Distribution
Switch Stack
Cell/Area Zone - Levels 0–2
Redundant Star Topology - Flex Links Resiliency
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Cell/Area Zone - Levels 0–2
Linear/Bus/Star Topology
Autonomous Wireless LAN
(Lines, Machines, Skids, Equipment)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4-5
Industrial Zone
Levels 0–3
(Plant-wide Network)
Core
Switches
Phone
Controller
Camera
Safety
Controller
Soft
Starter
Cell/Area Zone - Levels 0–2
Ring Topology - Device Level Ring (DLR) Protocol
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Plant Firewalls
• Active/Standby
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Safety
I/O
Instrumentation
Level 3 - Site Operations
(Control Room)
HMI
Active
AP
SSID
5 GHz
WGB
Safety
I/O
Controller
WGB
LWAP
SSID
5 GHz
WGB
LWAP
Controller
LWAP
SSID
2.4 GHz
Standby
Wireless
LAN Controller
(WLC)
Cell/Area Zone
Levels 0–2
Cell/Area Zone
Levels 0–2
Drive
Distribution
Switch Stack
Wide Area Network (WAN)
Data Center - Virtualized Servers
• ERP - Business Systems
• Email, Web Services
• Security Services - Active Directory (AD), Identity Services (AAA)
• Network Services – DNS, DHCP
• Call Manager
Enterprise
Identity Services
Identity Services
External DMZ/
Firewall
Cloud
Access
Switches
Access
Switches
IFW
IFW
Drive I/O Drive I/O
I/O I/O I/O Robot
Servo
Drive
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 8Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
People Convergence
Technology
Convergence
Network
Convergence
Organizational
Convergence
Ethernet and IP
Wide Deployment
Cultural
Convergence
Increasing Business
Pressures
• Sharing of engineering best practices
between Control System Engineers (OT)
and IT Network Engineers:
– Standardization of design and technology
– Reference architectures, reference models,
industry and technology standards
Industrial IoT
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 9Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Technology and Cultural Convergence - Similarities and Differences
Criteria Industrial OT Network Enterprise IT Network
Environment • Plant-floor
• Control Room
• Control Panel, Industrial Distribution Frame (IDF)
• Carpeted Space, Data Center
• Data Communication or Wiring Closet, Intermediate
Distribution Frame (IDF)
Switches • Managed and unmanaged
• Layer 2 is predominant
• DIN rail or panel mount is predominant
• Managed
• Layer 2 and Layer 3
• Rack mount
Wireless • Autonomous (locally managed) – point solutions
• Mobile equipment (emerging) and personnel
(prevalent)
• Unified (centrally managed) solutions
• Mobile personnel – corporate provided or BYOD
• Guest access
Computing • Industrial Hardened Panel Mount Computers and
Monitors
• Desktop, Notebook
• 19” Rack Server
• Virtualization - becoming prevalent
• Hardening – Sporadic patching and white listing
• Desktop, Notebook
• Tablets
• 19” Rack Server and Blade Server
• Unified Computing Systems (UCS)
• Virtualization – widespread
• Hardening - Patching and white listing
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 10Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Technology and Cultural Convergence - Similarities and Differences
Criteria Industrial OT Network Enterprise IT Network
Network
Technology
• Standard IEEE 802.3 Ethernet and proprietary
(non-standard) versions
• Standard IETF Internet Protocol (IPv4) and
proprietary (non-standard) alternatives
• Sporadic use of standard Layer 2 and Layer 3
network and security services
• Standard IEEE 802.3 Ethernet
• Standard IETF Internet Protocol (IPv4 and IPv6)
• Pervasive use of standard Layer 2 and Layer 3
network and security services
Network
Availability
• Switch-Level and Device-Level topologies
• Ring topology is predominant for both,
Redundant Star for switch topologies is emerging
• Standard IEEE, IEC and vendor specific Layer 2
resiliency protocols
• Switch-Level topologies
• Redundant star topology is predominant
• Standard IEEE, IETF, and vendor specific Layer 2
and Layer 3 resiliency protocols
Service level
agreement (SLA)
• Mean time to recovery (MTTR) - Minutes, Hours • Mean time to recovery (MTTR) - Hours, Days
IP Addressing • Mostly Static • Mostly Dynamic
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 11Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Technology and Cultural Convergence - Similarities and Differences
Criteria Industrial OT Network Enterprise IT Network
Traffic Type • Primarily local – traffic between local assets
• Information, control, safety, motion, time
synchronization, energy management
• Smaller frames for control traffic
• Industrial application layer protocols: CIP, Profinet,
IEC 61850, Modbus TCP, etc.
• Primarily non-local – traffic to remote assets
• Voice, Video, Data
• Larger packets and frames
• Standard application layer protocols: HTTP,
SNMP, DNS, RTP, SSH, etc.
Performance • Low Latency, Low Jitter
• Data Prioritization – QoS – Layer 2 & 3
• Low Latency, Low Jitter
• Data Prioritization – QoS – Layer 3
Security • Open by default, must secure by configuration and
architecture
• Industrial security standards – e.g. IEC, NIST
• Inconsistent deployment of security policies
• No line-of-sight to the Enterprise or to the Internet
• Pervasive
• Enterprise security best practices
• Strong security policies
• Line-of-sight across the Enterprise and to the
Internet
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 12Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Security Policies - Similarities and Differences
Criteria Industrial OT Network Enterprise IT Network
Focus 24/7 operations, high OEE
Helping to protect intellectual property and company
assets
Precedence of Priorities
Availability
Integrity
Confidentiality
Confidentiality
Integrity
Availability
Types of Data Traffic
Converged network of data,
control, information, safety and motion
Converged network of data,
voice and video
Access Control
Strict physical access
Simple network device access
Strict network authentication
and access policies
Implications of a
Device Failure
Production is down
($$’s/hour … or worse)
Workaround or wait
Threat Protection Isolate threat but keep operating
Shut down access to
detected threat
Upgrades Scheduled during downtime Automatically pushed during uptime
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 13Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Smart Devices, Smart Machines,
Smart Manufacturing
 Standard Network and Security
Services; Standard Network Tools
 Customer choice of best-in-class
products through Industrial IoT
device coexistence and
interoperability
 Pervasive Asset Optimization
and Utilization
 Common infrastructure devices and tools
 Human assets: knowledge, experience,
training
 Better Analytics
 Device/Machine, System/Plant,
Enterprise
 Enables Innovative Technologies
 Mobility – Personnel and Equipment
 Cloud –On Premise and Off Premise
What’s Driving This?
Business Outcomes – Industrial IoT / Industrial IT (Bridging OT-IT)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 14Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
What’s Driving This?
Application Requirements
Source: ARC
Advisory Group
What is real-time? What is resilient? What is secure?
Loss Critical
Multi-axis Motion Control
Hardware and Software
solutions, e.g. integrated
motion on the EtherNet/IP
network, PTP
Synchronization of multiple axes:
printing presses, wire drawing,
web making, picking and placing
Subset of Discrete automation
100 µs to 10 ms
Loss CriticalDiscrete Automation
Industrial Protocols - CIP
1 ms to 100 ms
Material handling, filling, labeling,
palletizing, packaging; welding,
stamping, cutting, metalforming,
soldering, sorting
Auto, food and beverage,
semiconductor, metals,
pharmaceutical
Process Automation
Information Integration,
Slower Process Automation
.Net, DCOM, TCP/IP
10 ms to 1 second or longer
Pumps, compressors,
mixers; monitoring of
temperature, pressure, flow
Oil and gas, chemicals,
energy, water
Process Automation
Function
Comm. Technology
Period
Applications
Industries
Time-critical
Discrete Automation
Discrete Automation
Application
dependent …..
Only you can
define what this
means for your
application.
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 15Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 16Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Cisco – Rockwell Automation®
Strategic Alliance Program
 10 Years of Collaboration
 10 Tested and Validated
Architectures
 Design Considerations
 Best Practices
 Documented Test Results
 Documented Configurations
 Proven Architectures
 Enables OT-IT Convergence
 Industrial IT (bridging OT-IT)
 Industrial IoT
 Helps customer to reduce costs
 Simplified Design
 Quicker Deployment
 Reduced risk in deploying newer
technologies
Key Takeaways
Converged Plantwide Ethernet (CPwE) Architectures
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 17Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Cisco and Rockwell Automation® Alliance
Technology, Network, Cultural and Organizational Convergence
Stratix® 5900 Services Router, Stratix® 5950 Industrial Firewall, Stratix® 5100 Wireless Access Point/
Workgroup Bridge, and Stratix® 5000/Stratix® 8000 families of managed industrial Ethernet switches, which
combine the best of both Rockwell Automation® and Cisco.
Collection of tested and validated architectures developed by subject matter authorities at Cisco and
Rockwell Automation®. The content of CPwE is relevant to both Operational Technology (OT) and
Information Technology (IT) disciplines and consists of documented architectures, best practices, guidance
and configuration settings to help manufacturers with design and deployment of a scalable, reliable, safe,
secure and future-ready plant-wide industrial network infrastructure.
A single scalable architecture, using open and standard Ethernet and IP networking technologies, such as
EtherNet/IP, enabling the Industrial Internet of Things to help achieve the flexibility, visibility and efficiency
required in a competitive manufacturing environment.
Education and services to facilitate OT and IT convergence, assist with successful architecture
deployment, and enable efficient operations that allow critical resources to focus on increasing
innovation and productivity.
People and Process Optimization:
Common Technology View:
Converged Plantwide Ethernet (CPwE) Architectures:
Joint Product Collaboration:
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 18Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Tested, validated and documented reference architectures
 Comprised of a collection of Cisco and Rockwell Automation® validated architectures,
following the Cisco Validated Design (CVD) program
 Developed from application and technology use cases
 Industry neutral, one-to-many approach, customers adapt to meet their application needs
 Tested for performance, availability, repeatability, scalability and security by subject matter
authorities at Cisco and Rockwell Automation® CPwE test labs
 Built on technology and industry standards (IEC, IEEE, IETF)
 “Future-ready” network and security design
 Content relevant to both OT and IT Engineers
 Deliverables
 White Papers, Design & Implementation Guides - architectures
design considerations, best practices, documented test results with configuration settings
 Proven architectures:
 Helps customers to reduce their costs by simplifying their designs, accelerating their
deployments, and reducing their risk in deploying new technology
Converged Plantwide Ethernet (CPwE)
Industrial IoT / Industrial IT (Bridging OT-IT)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 19Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Valued resource
 To help us with our own OT-IT
convergence – Industrial IT
 Proven architectures – cost reduction,
risk reduction
 We’ve come to expect it
 Architectural collaboration between
Cisco and Rockwell Automation®
 We adapt CPwE into our global
standards
 Unique in the industry
 No other company, organization or
consortia provides the level of testing,
validation and documentation that CPwE
provides
 We use CPwE to help us justify
network and security projects
 Architectural Framework
 Best practices
 Design and Implementation Guidance
CPwE – Proven Architectures
Customer (OT-IT) Value Statements
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 20Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE – Proven Architectures
Customer (OT-IT) Value Statements
 We have adopted 7 of the 10 CPwE tested and validated architectures into our
global network design and specifications for our plants and OEMs
 CPwE Architectures :
 Baseline – CPwE Model/Framework, Industrial Network Security Framework
 WLAN – Unified Architecture for Mobile Maintenance Personnel
 NAT – Cloning of OEM Applications
 ISE – Identity Services PAN and PSN within Plant Network – Wired and Wireless
 IDMZ – ASA Firewall Policies between OT and IT Networks
 Resiliency – Stratix® 5700 switch with Redundant Star (EtherChannel), Catalyst 3850, Catalyst 4500-X
with VSS
 IFW - Firewall Policies for ASA, they do not currently use Stratix® 5950 security appliance
 We value the OT-IT collaboration between Rockwell Automation® and Cisco
 We standardized on Stratix® industrial Ethernet switches due to CPwE
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 21Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Collection of Cisco and Rockwell Automation® Tested & Validated Designs
Key Requirements:
 Scalable
 Reliable
 Safe
 Secure
 Future-ready
Key Tenets:
 Smart Endpoints
 Segmentation (Zoning)
 Managed Infrastructure
 Resiliency
 Time-critical Data
 Wireless - Mobility
 Holistic Defense-in-Depth Security
 Convergence-ready
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 22Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Collection of Cisco and Rockwell Automation® Tested & Validated Designs
Key Tenets:
• Smart Endpoints
• Segmentation
(Zoning)
• Managed
Infrastructure
• Resiliency
• Time-critical Data
• Wireless - Mobility
• Holistic Defense-in-
Depth Security
• Convergence-ready
Physical or Virtualized Servers
• FactoryTalk® Application Servers and
Services Platform
• Network & Security Services – DNS,
AD, DHCP, Identity Services (AAA)
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Distribution
Switch Stack
Cell/Area Zone - Levels 0–2
Redundant Star Topology - Flex Links Resiliency
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Cell/Area Zone - Levels 0–2
Linear/Bus/Star Topology
Autonomous Wireless LAN
(Lines, Machines, Skids, Equipment)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4-5
Industrial Zone
Levels 0–3
(Plant-wide Network)
Core
Switches
Phone
Controller
Camera
Safety
Controller
Soft
Starter
Cell/Area Zone - Levels 0–2
Ring Topology - Device Level Ring (DLR) Protocol
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Plant Firewalls
• Active/Standby
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Safety
I/O
Instrumentation
Level 3 - Site Operations
(Control Room)
HMI
Active
AP
SSID
5 GHz
WGB
Safety
I/O
Controller
WGB
LWAP
SSID
5 GHz
WGB
LWAP
Controller
LWAP
SSID
2.4 GHz
Standby
Wireless
LAN Controller
(WLC)
Cell/Area Zone
Levels 0–2
Cell/Area Zone
Levels 0–2
Drive
Distribution
Switch Stack
Wide Area Network (WAN)
Data Center - Virtualized Servers
• ERP - Business Systems
• Email, Web Services
• Security Services - Active Directory (AD), Identity Services (AAA)
• Network Services – DNS, DHCP
• Call Manager
Enterprise
Identity Services
Identity Services
External DMZ/
Firewall
Cloud
Access
Switches
Access
Switches
IFW
IFW
Drive I/O Drive I/O
I/O I/O I/O Robot
Servo
Drive
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 23Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Collection of Cisco and Rockwell Automation® Tested & Validated Designs
CPwE
REP
June 2014
CPwE
WLAN
Nov. 2014
CPwE
IDMZ
May 2017
CPwE
Baseline
Sept. 2011
CPwE
NAT
June 2015
CPwE
ISE
Sept. 2017
CPwE
Migration
Jan. 2016
CPwE
VPN
March 2016
CPwE
Ind. Firewall
Dec. 2016
CPwE
Resiliency
July 2017
CPwE Test Labs
 Rockwell Automation® – Mayfield Heights,
OH
 Cisco – Raleigh, NC (RTP)
 Panduit – Tinley Park, IL
CPwE
DLR
August. 2017
NS06
NS07
NS08
NS16
NS02
NS16
NS06NS06
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 24Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Collection of Cisco and Rockwell Automation® Tested & Validated Designs
 Converged Plantwide Ethernet (CPwE) is a collection of tested
and validated architectures that are developed by subject
matter authorities at Cisco and Rockwell Automation® and that
follow the Cisco Validated Design (CVD) program.
 The content of CPwE, which is relevant to both Operational
Technology (OT) and Informational Technology (IT) disciplines,
consists of documented architectures, best practices, guidance
and configuration settings to help manufacturers with design
and deployment of a scalable, reliable, secure and future-ready
plant-wide industrial network infrastructure.
 CPwE also helps manufacturers achieve the benefits of cost
reductions using proven designs that can help lead to quicker
deployment and reduced risk in deploying new technology.
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 25Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Collection of Cisco and Rockwell Automation® Tested & Validated Designs
 CPwE follows the Cisco Validated Design (CVD) Program
 Provide the foundation for systems design based on common use cases or current
engineering system priorities. They incorporate a broad set of technologies, features, and
applications to address customer needs. Each CPwE CVD has been comprehensively
tested, validated and documented by Cisco and Rockwell Automation® subject matter
authorities to maintain faster, more reliable, and fully predictable deployment
 CPwE CVDs are organized by solution areas with customer collateral
published using various types of documents:
 Design & Implementation Guides (DIGs)
 White Papers
 Application Guides
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 26Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
OT Standards
 Operational Levels
 ISA 95, Purdue – Levels 0-5
 Level 0 Sensor/Actuators, Level 1
Controller, Level 2 Local Supervisor,
Level 3 Site Operations, Level 4-5
Enterprise
 Functional / Security Zones
 IEC-62443, NIST 800-82, ICS-CERT
 Enterprise, Industrial, IDMZ
 Industrial Subzones – Cell/Area, Site
Operations
IT Standards
 Network Technology
 OSI Reference Model – 7 Layers
 IEEE 802.1, 802.3, 802.11
 IETF TCP, UDP, IP
 Network Switch Hierarchy
 Campus Network Model
 Layer 2 Access
 Layer 3 Distribution/Aggregation
 Layer 3 Core
CPwE Architectures
Built on Technology and Industry Standards
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 27Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Logical Model
OT Standards - Operational Levels - Functional / Security Zones
Level 5
Level 4
Level 3
Level 2
Level 1
Level 0
Remote Desktop
Gateway Services
Patch
Management
AV
Server
Application
Mirror
Web Services
Operations
Reverse
Proxy
Enterprise Network
Site Business Planning and Logistics NetworkEmail, Intranet, etc.
FactoryTalk®
Application
Server
FactoryTalk®
Directory
Engineering
Workstation
Remote
Access
Server
FactoryTalk®
Client
Operator
Interface
FactoryTalk®
Client
Engineering
Workstation
Operator
Interface
Batch
Control
Discrete
Control
Drive
Control
Continuous
Process
Control
Safety
Control
Sensors Drives Actuators Robots
Enterprise Security Zone
Levels 4-5
Industrial DMZ
Level 3.5
Industrial Security Zone(s)
Levels 0-3
Cell/Area Zones(s)
Levels 0-2
Web
Email
CIP
Firewall
Firewall
Site Operations
Area
Supervisory
Control
Basic Control
Process
• Levels – ISA 95, Purdue Reference Model
• Zones – IEC 62443, NIST 800-82, ICS-CERT Recommended Practices
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 28Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Plant-wide Zoning
OT Standards - Functional / Security Zones
Plant-wide Zoning
• Functional / Security Areas
• Smaller Connected LANs
– Smaller Broadcast Domains
– Smaller Fault Domains
– Smaller Domains of Trust
• Industrial IoT Technology
• Building Block Approach for
Scalability
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 29Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
OSI 7-Layer Reference Model
OT-IT Standards
CIP - IEC 61158Application
Presentation
Session
Transport
Network
Data Link
Physical
Layer 7
Layer 6
Layer 5
Layer 4
Layer 3
Layer 2
Layer 1
Network Services to User App
Encryption/Other processing
Manage Multiple Applications
Reliable End-to-End Delivery Error Correction
Packet Delivery, Routing
Framing of Data, Error Checking
Signal type to transmit bits, pinouts, cable type
IETF TCP/UDP
IETF IP
IEEE 802.3/802.1/802.11
TIA - 1005
Layer NameLayer No. Function Examples
Routers
Switches
Cabling/RF
IES
Open Systems
Interconnection
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 30Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Campus Network Model
IT Standards – Network Switch Hierarchy
 Hierarchal, modular and scalable building blocks
 Smaller Connected LANs - clear demarcations and segmentation
 Fault domain (e.g. Layer 2 loops), broadcast domain, domains of trust (security)
 Easier to grow, understand and troubleshoot
 Multi-tier switch model
 Core – Layer 3
 Aggregates distribution switches
 Backbone of network
 Industrial DMZ connectivity
 Distribution / Aggregation – Layer 3
 Aggregates access switches
 Provides Layer 3 services
 Access – Layer 2
 Aggregates industrial automation and
control system (IACS) devices
 Provides Layer 2 services
Access
Distribution
Core
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 31Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Logical Zoning - Segmentation
CPwE Logical Framework – Modular Building Blocks
Levels 0-2
Phone
Controller
Safety
Controller
Camera
Safety
I/O
Instrumentation
HMI
Industrial Zone
Levels 0-3
Media &
Connectors
Cell/Area Zone #1
Redundant Star Topology
Cell/Area Zone #2
Ring Topology
MCC Soft
Starter
Level 2 HMI
Level 0 Drive
I/O
Level 1 Controller
Servo
Drive
Levels 0-2Levels 0-2
Cell/Area Zone #3
Linear/Bus/Star Topology
Layer 2
Access Switch
Layer 2
Building Block
Layer 3
Distribution
Switch Layer 3
Building Block
Layer 2
Building Block
Layer 2
Building Block
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 32Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Logical Zoning - Segmentation
CPwE Logical Framework – Modular Building Blocks
Key Tenets:
• Smart Endpoints
• Segmentation
(Zoning)
• Managed
Infrastructure
• Resiliency
• Time-critical Data
• Wireless - Mobility
• Holistic Defense-in-
Depth Security
• Convergence-ready
Physical or Virtualized Servers
• FactoryTalk® Application Servers and
Services Platform
• Network & Security Services – DNS,
AD, DHCP, Identity Services (AAA)
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Distribution
Switch Stack
Cell/Area Zone - Levels 0–2
Redundant Star Topology - Flex Links Resiliency
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Cell/Area Zone - Levels 0–2
Linear/Bus/Star Topology
Autonomous Wireless LAN
(Lines, Machines, Skids, Equipment)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4-5
Industrial Zone
Levels 0–3
(Plant-wide Network)
Core
Switches
Phone
Controller
Camera
Safety
Controller
Soft
Starter
Cell/Area Zone - Levels 0–2
Ring Topology - Device Level Ring (DLR) Protocol
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Plant Firewalls
• Active/Standby
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Safety
I/O
Instrumentation
Level 3 - Site Operations
(Control Room)
HMI
Active
AP
SSID
5 GHz
WGB
Safety
I/O
Controller
WGB
LWAP
SSID
5 GHz
WGB
LWAP
Controller
LWAP
SSID
2.4 GHz
Standby
Wireless
LAN Controller
(WLC)
Cell/Area Zone
Levels 0–2
Cell/Area Zone
Levels 0–2
Drive
Distribution
Switch Stack
Wide Area Network (WAN)
Data Center - Virtualized Servers
• ERP - Business Systems
• Email, Web Services
• Security Services - Active Directory (AD), Identity Services (AAA)
• Network Services – DNS, DHCP
• Call Manager
Enterprise
Identity Services
Identity Services
External DMZ/
Firewall
Cloud
Access
Switches
Access
Switches
IFW
IFW
Drive I/O Drive I/O
I/O I/O I/O Robot
Servo
Drive
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 33Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Logical Model – Modular Building Blocks
Enterprise-wide
Business Systems
Plant-wide
Operation Systems
Level 3 - Site Operations
Data Center
Industrial Zone
Levels 0-3
(Plant-wide Network)
Enterprise Zone
Levels 4 - 5
Cell/Area Zone
Levels 0-2
Cell/Area Zone
Levels 0-2
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 34Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Logical Model – Modular Building Blocks
Line #1
Labeling Filling Packaging
Line #2
Labeling Filling Packaging
Line #3
Labeling Filling Packaging
Plant-wide
Operation Systems
Level 3 - Site Operations
Packaging Cell/Area Zone
Levels 0-2
Industrial Zone
Levels 0-3
(Plant-wide Network)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 35Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Logical Framework – Modular Building Blocks
Line #2
Labeling Filling Packaging
Plant-wide
Operation Systems
Line
Controller
VFD
Drive
HMI
I/O I/O
Controller Servo
Drive Packaging /
Section 1
VFD
Drive
HMI
I/O I/O
Controller Servo
Drive Packaging /
Section 2
VFD
Drive
HMI
I/O I/O
Controller Servo
Drive Packaging /
Section 3
VFD
Drive
HMI I/O I/O
Controller Servo
DriveFilling
VFD
Drive
HMI I/O I/O
Controller Servo
DriveLabeling
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 36Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Logical Framework – Modular Building Blocks
Level 3 - Site Operations
Packaging Cell/Area Zone
Levels 0-2
Line #1 Line #2 Line #3
Plant-wide
Operation Systems
Industrial Zone
Levels 0-3
(Plant-wide Network)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 37Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Structure and Hierarchy
CPwE Logical Model - Modular Building Blocks
Physical or Virtualized Servers
• Application Servers &
Services Platform
• Network Services – e.g. DNS, AD,
DHCP, AAA
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Link
for Failover
Detection
Firewall
(Active)
Firewall
(Standby)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4 - 5
Core
Switches
Plant Firewalls
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Wide Area Network (WAN)
Physical or Virtualized Servers
• ERP, Email
• Active Directory (AD), AAA –
Radius
• Call Manager
Enterprise
Level 3 - Site Operations
(Control Room)
Internet
External DMZ/
Firewall
Wireless
LAN Controller
(WLC)
Active
Standby
RADIUS
(AAA) Server
Packaging Cell/Area Zone
Levels 0-2
Line #1 Line #2 Line #3
Cell/Area Zone
Levels 0-2
Industrial Zone
Levels 0-3
(Plant-wide Network)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 38Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Convergence-Ready Network Solutions
Design and Implementation Considerations
Partner Solution(s)
e.g. Process Skid Plant-wide Industrial
Automation & Control System
Partner Solution(s)
e.g. Machine Plant-wide Industrial
Automation & Control System
Design and deployment considerations that a partner (e.g. OEM, SI, Contractor) has to take into
account to achieve seamless integration of their solution (e.g. equipment, skid, machine) into their
customers’ plant-wide/site-wide network infrastructure.
Early, open and two-way
OT-IT dialogue is critical!
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 39Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Risk management policies and
overall tolerance to risk
 Business practices
 Corporate / local standards
 Application requirements
 Applicable industry standards
– e.g. NERC CIP
 Government regulations and
compliance
 Enterprise and industrial policies
(safety and security), procedures,
access control (avoidance of back
doors) and network ownership
 Alignment with industrial safety
standards such as IEC 61508 – SIL 3
and EN 954-1 - Cat 4
 Alignment with industrial security
standards such as IEC-62443 (formerly
ISA99), NIST 800-82 and ICS-CERT
 Network capabilities (zone segmentation
into domains of trust)
Convergence-Ready Network Solutions
Alignment with End User Stance on Safety, Security and Availability
Early, open and two-way
OT-IT dialogue is critical! “one-size-fits-all”
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 40Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Convergence-Ready Network Solutions
Alignment with End User - Network Services:
 Use of a common industrial network technology that fully uses standard Ethernet and IP networking
technology as the multi-discipline industrial network infrastructure.
 IP addressing schema
 Who manages? End User (OT/IT) or OEM?
 Address range (class), subnet, default gateway (routability)
 Implementation conventions – static/dynamic, hardware/software configurable, NAT/DNS
 Use Common Layer 2 and Layer 3 Network Services
 Switches - managed vs. unmanaged, industrial vs. COTS, system vs. component approach
 Segmentation, data prioritization
 Topologies - switch-level, device-level, hybrid
 Availability – loop prevention, redundant path topologies with resiliency protocols
 Time Synchronization Services
 IEEE 1588 Precision Time Protocol (PTP w/E2E) – first fault, SOE, Motion
The OEM Guide to Networking
ENET-RM001_-EN-P
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 41Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Industrial Security Framework
MCC
Enterprise Zone: Levels 4-5
Soft
Starter
I/O
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Level 0 - ProcessLevel 1 - Controller
Level 3 – Site Operations
Controller
Drive
Level 2 – Area Supervisory Control
FactoryTalk
®
Client
Controller
Industrial Demilitarized Zone (IDMZ)
Industrial Zone: Levels 0-3
LWAP
SSID
2.4 GHz
SSID
5 GHz
WGB
I/O
Active
Wireless LAN
Controller (WLC)
Standby
Core
Switches
Distribution
Switch Stack
Enterprise
Identity Services
External DMZ/
Firewall
Cloud
IFW
Control System
Engineers (OT)
Control System Engineers
in Collaboration with IT
Network Engineers
(Industrial IT)
IT Security Architects in
Collaboration with Control
Systems Engineers
Defense-in-Depth
- Architecture Best Practices
IEC 62443
- Zones & Conduits
- Availability, Integrity,
Confidentiality
NIST 800-82
- cyber security Framework
- Identify, Protect, Detect,
Respond, Recover
ICS-CERT
- Recommended Practices
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 42Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Physical or Virtualized Servers
• FactoryTalk® Application Servers and
Services Platform
• Network & Security Services – DNS,
AD, DHCP, Identity Services (AAA)
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Distribution
Switch Stack
Cell/Area Zone - Levels 0–2
Redundant Star Topology - Flex Links Resiliency
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Cell/Area Zone - Levels 0–2
Linear/Bus/Star Topology
Autonomous Wireless LAN
(Lines, Machines, Skids, Equipment)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4-5
Industrial Zone
Levels 0–3
(Plant-wide Network)
Core
Switches
Phone
Controller
Camera
Safety
Controller
Soft
Starter
Cell/Area Zone - Levels 0–2
Ring Topology - Device Level Ring (DLR) Protocol
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Plant Firewalls
• Active/Standby
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Safety
I/O
Instrumentation
Level 3 - Site Operations
(Control Room)
HMI
Active
AP
SSID
5 GHz
WGB
Safety
I/O
Controller
WGB
LWAP
SSID
5 GHz
WGB
LWAP
Controller
LWAP
SSID
2.4 GHz
Standby
Wireless
LAN Controller
(WLC)
Cell/Area Zone
Levels 0–2
Cell/Area Zone
Levels 0–2
Drive
Distribution
Switch Stack
Wide Area Network (WAN)
Data Center - Virtualized Servers
• ERP - Business Systems
• Email, Web Services
• Security Services - Active Directory (AD), Identity Services (AAA)
• Network Services – DNS, DHCP
• Call Manager
Enterprise
Identity Services
Identity Services
External DMZ/
Firewall
Cloud
Access
Switches
Access
Switches
IFW
IFW
Drive I/O Drive I/O
I/O I/O I/O RobotServo
Drive
CPwE Architectures
Panduit Physical Layer Solutions for the CPwE Logical Framework
Industrial Data Center
(IDC)
Main Distribution Frame (MDF)
Industrial
Distribution Frame
(IDF)
IDF
Physical Network
Zone System (PNZS)
PNZS Control Panel (CP)
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 43Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
CPwE Architectures
Industrial IoT / Industrial IT (Bridging OT-IT)
Operational Technology
Industrial IoT
Industrial IT
Information Technology
Physical or Virtualized Servers
• FactoryTalk® Application Servers and
Services Platform
• Network & Security Services – DNS,
AD, DHCP, Identity Services (AAA)
• Storage Array
Remote
Access
Server
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Distribution
Switch Stack
Cell/Area Zone - Levels 0–2
Redundant Star Topology - Flex Links Resiliency
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Cell/Area Zone - Levels 0–2
Linear/Bus/Star Topology
Autonomous Wireless LAN
(Lines, Machines, Skids, Equipment)
Industrial
Demilitarized Zone
(IDMZ)
Enterprise Zone
Levels 4-5
Industrial Zone
Levels 0–3
(Plant-wide Network)
Core
Switches
Phone
Controller
Camera
Safety
Controller
Soft
Starter
Cell/Area Zone - Levels 0–2
Ring Topology - Device Level Ring (DLR) Protocol
Unified Wireless LAN
(Lines, Machines, Skids, Equipment)
Plant Firewalls
• Active/Standby
• Inter-zone traffic segmentation
• ACLs, IPS and IDS
• VPN Services
• Portal and Remote Desktop Services proxy
Safety
I/O
Instrumentation
Level 3 - Site Operations
(Control Room)
HMI
Active
AP
SSID
5 GHz
WGB
Safety
I/O
Controller
WGB
LWAP
SSID
5 GHz
WGB
LWAP
Controller
LWAP
SSID
2.4 GHz
Standby
Wireless
LAN Controller
(WLC)
Cell/Area Zone
Levels 0–2
Cell/Area Zone
Levels 0–2
Drive
Distribution
Switch Stack
Wide Area Network (WAN)
Data Center - Virtualized Servers
• ERP - Business Systems
• Email, Web Services
• Security Services - Active Directory (AD), Identity Services (AAA)
• Network Services – DNS, DHCP
• Call Manager
Enterprise
Identity Services
Identity Services
External DMZ/
Firewall
Cloud
Access
Switches
Access
Switches
IFW
IFW
Drive I/O Drive I/O
I/O I/O I/O Robot
Servo
Drive
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 44Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Lessons Learned From Your Peers
 Corporate culture change takes time
 People, Process, and Technology
changes are required for Industrial IoT
transformation
 The Network is foundational
 Create an OT-IT convergence plan early
 Early Engagement of Operations Staff
 Define business outcomes early in the
process with KPIs to measure success
 Communicate and Celebrate Successes
between locations
 A robust archiving framework and
strategy is needed
 Behavior changes will be necessary to deliver
success
 Good technology will be trumped by bad
processes
 Good technology will be trumped by bad data
 Process experts should be engaged early
 Data Governance framework and teams must
be in place before beginning
 Provide enough runway and scheduling for
Knowledge Transfer
 Define out-of-scope processes and
applications
 Develop a mitigation plan early
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 45Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Additional Material
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 46Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Additional Material
Network Architecture Icon Key
Layer 2 Access Link (EtherNet/IP Device Connectivity)
Layer 2 Interswitch Link/802.1Q Trunk
Layer 3 Link
Layer 2 Access Switch, Catalyst 2960
Multi-Layer Switch - Layer 2 and Layer 3,
Stratix® 8300, Stratix® 5700, Stratix® 5400, Stratix® 5410
Layer 3 Router, Stratix® 5900
Autonomous Wireless Access Point (AP),
Stratix® 5100 as Autonomous AP
Layer 2 IES with NAT, Stratix® 5700, Stratix® 5400
Layer 2 IES with NAT and Connected Routing,
Stratix® 5700, Stratix® 5400
NAT
NAT - CR
Layer 3 Distribution Switch Stack,
Catalyst 3750-X, Catalyst 3850
Layer 3 Core Switch,
Catalyst 4500, 4500-X, 6500, 6800
Layer 3 Core Switch with Virtual Switching System (VSS)
Catalyst 4500-X, 6500, 6800
Firewall, Adaptive Security Appliance (ASA) 55xx
Wireless workgroup bridge (WGB),
Stratix® 5100 as workgroup bridge (WGB)
Unified Wireless Lightweight Access Point (LWAP),
Catalyst 3602E LWAP
Unified Wireless LAN Controller (WLC), Cisco 5508 WLC
Unified Computing System (UCS), UCS-C series
Identity Services Engine (ISE) for Authentication,
ISE - PAN/PSN/MnT
Layer 2 Access, Industrial Ethernet Switch (IES),
Stratix® 2500, Stratix® 5700, Stratix® 5400, Stratix® 8000IES IFW
Layer 3 Router with Zone-based Firewall, Stratix® 5900
Industrial Firewall, Stratix® 5950
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 47Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Website:
 http://www.odva.org/
 EtherNet/IP
 https://www.odva.org/Technology-
Standards/EtherNet-
IP/OverviewSecuring EtherNet/IP
Networks
 EtherNet/IP Network
Infrastructure Guide
 https://www.odva.org/Portals/0/Library
/Publications_Numbered/PUB00035R
0_Infrastructure_Guide.pdf
 Common Industrial Protocol (CIP)
 https://www.odva.org/Technology-
Standards/Common-Industrial-Protocol-
CIP/Overview
 The Family of CIP Networks
 https://www.odva.org/Portals/0/Library/Public
ations_Numbered/PUB00123R1_Common-
Industrial_Protocol_and_Family_of_CIP_Net
works.pdf
 CIP Security
 https://www.odva.org/Technology-
Standards/Common-Industrial-Protocol-
CIP/CIP-Security
Additional Material
ODVA
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 48Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Additional Material
CPwE Architectures - Cisco and Rockwell Automation®
 CPwE website
 Overview Documents
 Alliance Profile
 Top 10 Recommendations for
Plant-wide EtherNet/IP
Deployments
 Design Considerations for
Securing Industrial Automation
and Control System Networks
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 49Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Additional Material
CPwE Architectures - Cisco and Rockwell Automation®
Topic Design Guide Whitepaper
Design Considerations for Securing IACS Networks — ENET-WP031A-EN-P
Converged Plantwide Ethernet – Baseline Document ENET-TD001E-EN-P —
Resilient Ethernet Protocol in a CPwE Architecture ENET-TD005B-EN-P ENET-WP033A-EN-P
Deploying 802.11 Wireless LAN Technology within a CPwE Architecture ENET-TD006A-EN-P ENET-WP034A-EN-P
Deploying Identity Services within a CPwE Architecture ENET-TD008A-EN-P ENET-WP037A-EN-P
Securely Traversing IACS Data Across the Industrial Demilitarized Zone (IDMZ) ENET-TD009A-EN-P ENET-WP038A-EN-P
Deploying Network Address Translation within a CPwE Architecture ENET-TD007A-EN-P ENET-WP036A-EN-P
Migrating Legacy IACS Networks to a CPwE Architecture ENET-TD011A-EN-P ENET-WP040A-EN-P
Deploying A Resilient Converged Plantwide Ethernet Architecture ENET-TD010A-EN-P ENET-WP039B-EN-P
Site-to-site VPN to a CPwE Architecture ENET-TD012A-EN-P —
Deploying Industrial Firewalls within a CPwE Architecture ENET-TD002A-EN-P ENET-WP011B-EN-P
Deploying Device Level Ring within a CPwE Architecture ENET-TD015A-EN-P ENET-WP016A-EN-P
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 50Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Ethernet Design Considerations
Reference Manual
 ENET-RM002C-EN-P
 EtherNet/IP Overview, Ethernet
Infrastructure Components, EtherNet/IP
Protocol, Predict System Performance
 EtherNet/IP IntelliCENTER®
Reference Manual (MCC-RM001)
 The OEM Guide to Networking
 ENET-RM001A-EN-P
 This guide is intended to help OEMs
understand relevant technologies, networking
capabilities and other considerations that
could impact them as they develop
EtherNet/IP solutions for the machines, skids
or equipment they build
 Segmentation Methods Within the
Cell/Area Zone ENET-AT004B-EN-E
Additional Material
Rockwell Automation® Reference Documents
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 51Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
 Integrated Architecture® Builder (IAB)
 Updates and additions to better-reflect
CPwE structure, hierarchy and best
practices
 Improved Switch Wizard for distribution
(e.g. Stratix® 5410 switch) and access (e.g.
Stratix® 5700 switch)
 Easier to create a large EtherNet/IP
network with many topologies
 CIP traffic is measured per segment, not
just controller scanner and adapter centric
 EtherNet/IP Capacity Tool
 Popular Configuration Drawings
(PCDs)
 Updates and additions to better reflect
CPwE recent enhancements
Additional Material
Rockwell Automation® Automaton Tools
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 52Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 53Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Education - Industrial IoT / Industrial IT (Bridging OT-IT)
 A ‘go-to’ resource for training and educational
information on standard Internet Protocol (IP),
security, wireless and other emerging technologies
for industrial applications
 Led by Cisco, Panduit, and Rockwell Automation®
 Receive monthly e-newsletters with
articles and videos on the latest trends
 Scenario-based training on topics such as: logical
topologies, protocols, switching, routing, wireless and
physical cabling
Network Design eLearning course available at promotional price for TechEd Attendees!
Earn PDHs by signing up today at www.industrial–ip.org with code “EVENTS2017”
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 54Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Education - Industrial IoT / Industrial IT (Bridging OT-IT)
Four eLearning courses cover key aspects of implementing networked, industrial
control systems. 20-30 minute interactive, scenario-based courses cover automation
controls and physical infrastructure considerations.
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 55Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Education - Industrial IoT / Industrial IT (Bridging OT-IT)
 Courses 1 and 2: Designing for the Cell/Area Zone
 Design secure, robust, future-ready networks for cells, machines, skids and other functional units
by implementing reference architectures and standard IP.
 Course 3: Designing for the Industrial Zone
 Learn design principles on line integration, high-availability networks and wireless architectures to
optimize plant networks.
 Course 4: IT/OT Integration
 Understand how to effectively converge a smart manufacturing facility with IT and OT
stakeholders.
EtherNet/IP Topologies Security Wireless
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 56Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Training and Certification – Industrial IoT / Industrial IT (Bridging OT-IT)
• Cisco Industrial Networking
Specialist Training and
Certification
– Classroom training
• Managing Industrial Networks with
Cisco Networking Technologies
(IMINS)
– Exam: 200-401 IMINS
– CPwE Design Considerations
and Best Practices
• CCNA Industrial Training and
Certification
– Classroom training
• Managing Industrial Networks for
Manufacturing with Cisco
Technologies (IMINS2)
– Exam: 200-601 IMINS2
– CPwE Design Considerations
and Best Practices
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 57Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Training and Certification – Industrial IoT / Industrial IT (Bridging OT-IT)
Industrial Networking Specialist
Module 1
Industrial Networking Solutions and
Products
Module 2
Industrial Network Documentation and
Deployment Considerations
Module 3
Installing Industrial Network Switches,
Routers, and Cabling
Module 4 Deploying Industrial Ethernet Devices
Module 5
Maintaining Industrial Ethernet
Networks
Module 6
Troubleshooting Industrial Ethernet
Networks
CCNA Industrial
Module 1
Industrial Networking Concepts and
Components
Module 2 General Troubleshooting Issues
Module 3 EtherNet/IP
Module 4 Troubleshooting EtherNet/IP
Module 5 PROFINET
Module 6 Configuring PROFINET
Module 7 Troubleshooting PROFINET
Module 8 Exploring Security Concerns
Module 9 802.11 Industrial Ethernet Wireless Networking
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 58Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Rockwell Automation® - Webinars
 Industrial Automation Webinars
 On Demand Webinars
 Introduction to Building a Robust, Secure and Future-ready Network
Infrastructure
 Increase Business Agility by Converging Manufacturing and
Business Systems
 The Power of Building a Secure Network Infrastructure
 Design Considerations for Building a Secure Network Infrastructure
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 59Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Training Resources
Cisco Training & Certifications
ICND1 ICND2
Cisco
Certification
Track
PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 60Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
Please take a moment to complete the brief session survey
on our mobile app and let us know how we’re doing!
Username: Last name
Password: Email address used to register
 Locate the session in the “Schedule” icon
 Click on the “Survey” icon in the lower right corner of the session details
 Complete survey & submit
 Download the ROKTechED app and login:
Thank you!
Complete A Survey
www.rockwellautomation.com
Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 61Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
PUBLIC
Thank You!

More Related Content

What's hot

IoT vs IIoT vs Industry 4.0
IoT vs IIoT vs Industry 4.0IoT vs IIoT vs Industry 4.0
IoT vs IIoT vs Industry 4.0
SMACAR Solutions
 
IoT and m2m
IoT and m2mIoT and m2m
IoT and m2m
pavan penugonda
 
IoT Communication Protocols
IoT Communication ProtocolsIoT Communication Protocols
IoT Communication Protocols
Pradeep Kumar TS
 
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
Edureka!
 
LoRaWAN for IoT
LoRaWAN for IoTLoRaWAN for IoT
LoRaWAN for IoT
Stavros Kalapothas
 
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet ArchitecturesRA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
Rockwell Automation
 
Protocols for IoT
Protocols for IoTProtocols for IoT
Protocols for IoT
Amit Dev
 
Cyber-Physical Systems
Cyber-Physical SystemsCyber-Physical Systems
Cyber-Physical Systems
Sinem Coleri Ergen
 
Next Generation Network Automation
Next Generation Network AutomationNext Generation Network Automation
Next Generation Network Automation
Laurent Ciavaglia
 
Internet of things cisco
Internet of things   ciscoInternet of things   cisco
Internet of things cisco
moldovaictsummit2016
 
Unit 4
Unit 4Unit 4
netconf and yang
netconf and yangnetconf and yang
netconf and yang
pavan penugonda
 
Big Data Analytics for the Industrial Internet of Things
Big Data Analytics for the Industrial Internet of ThingsBig Data Analytics for the Industrial Internet of Things
Big Data Analytics for the Industrial Internet of Things
Anthony Chen
 
Lecture 1 - Introduction to IoT
Lecture 1 - Introduction to IoTLecture 1 - Introduction to IoT
Lecture 1 - Introduction to IoT
Alexandru Radovici
 
Artificial intelligence and IoT
Artificial intelligence and IoTArtificial intelligence and IoT
Artificial intelligence and IoT
Veselin Pizurica
 
IoT architecture
IoT architectureIoT architecture
IoT architecture
Sumit Sharma
 
Internet of things startup basic
Internet of things  startup basicInternet of things  startup basic
Internet of things startup basic
Mathan kumar
 
Security issues and solutions : IoT
Security issues and solutions : IoTSecurity issues and solutions : IoT
Security issues and solutions : IoT
Jinia Bhowmik
 
From SCADA to IoT
From SCADA to IoTFrom SCADA to IoT
From SCADA to IoT
Rich Hunzinger
 
Industrial IoT and OT/IT Convergence
Industrial IoT and OT/IT ConvergenceIndustrial IoT and OT/IT Convergence
Industrial IoT and OT/IT Convergence
Michelle Holley
 

What's hot (20)

IoT vs IIoT vs Industry 4.0
IoT vs IIoT vs Industry 4.0IoT vs IIoT vs Industry 4.0
IoT vs IIoT vs Industry 4.0
 
IoT and m2m
IoT and m2mIoT and m2m
IoT and m2m
 
IoT Communication Protocols
IoT Communication ProtocolsIoT Communication Protocols
IoT Communication Protocols
 
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
IoT Tutorial for Beginners | Internet of Things (IoT) | IoT Training | IoT Te...
 
LoRaWAN for IoT
LoRaWAN for IoTLoRaWAN for IoT
LoRaWAN for IoT
 
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet ArchitecturesRA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
 
Protocols for IoT
Protocols for IoTProtocols for IoT
Protocols for IoT
 
Cyber-Physical Systems
Cyber-Physical SystemsCyber-Physical Systems
Cyber-Physical Systems
 
Next Generation Network Automation
Next Generation Network AutomationNext Generation Network Automation
Next Generation Network Automation
 
Internet of things cisco
Internet of things   ciscoInternet of things   cisco
Internet of things cisco
 
Unit 4
Unit 4Unit 4
Unit 4
 
netconf and yang
netconf and yangnetconf and yang
netconf and yang
 
Big Data Analytics for the Industrial Internet of Things
Big Data Analytics for the Industrial Internet of ThingsBig Data Analytics for the Industrial Internet of Things
Big Data Analytics for the Industrial Internet of Things
 
Lecture 1 - Introduction to IoT
Lecture 1 - Introduction to IoTLecture 1 - Introduction to IoT
Lecture 1 - Introduction to IoT
 
Artificial intelligence and IoT
Artificial intelligence and IoTArtificial intelligence and IoT
Artificial intelligence and IoT
 
IoT architecture
IoT architectureIoT architecture
IoT architecture
 
Internet of things startup basic
Internet of things  startup basicInternet of things  startup basic
Internet of things startup basic
 
Security issues and solutions : IoT
Security issues and solutions : IoTSecurity issues and solutions : IoT
Security issues and solutions : IoT
 
From SCADA to IoT
From SCADA to IoTFrom SCADA to IoT
From SCADA to IoT
 
Industrial IoT and OT/IT Convergence
Industrial IoT and OT/IT ConvergenceIndustrial IoT and OT/IT Convergence
Industrial IoT and OT/IT Convergence
 

Similar to Building Converged Plantwide Ethernet

Cisco: Solutions for Industrial IT
Cisco: Solutions for Industrial ITCisco: Solutions for Industrial IT
Cisco: Solutions for Industrial IT
Rockwell Automation
 
Deploy Secure Network Architectures for The Connected Enterprise
Deploy Secure Network Architectures for The Connected EnterpriseDeploy Secure Network Architectures for The Connected Enterprise
Deploy Secure Network Architectures for The Connected Enterprise
Rockwell Automation
 
Fundamentals of ethernet ip osi and cip
Fundamentals of ethernet ip osi and cipFundamentals of ethernet ip osi and cip
Fundamentals of ethernet ip osi and cipRoutecoMarketing
 
How to Build the Connectivity Architecture for the Industrial Internet of Thi...
How to Build the Connectivity Architecture for the Industrial Internet of Thi...How to Build the Connectivity Architecture for the Industrial Internet of Thi...
How to Build the Connectivity Architecture for the Industrial Internet of Thi...
Real-Time Innovations (RTI)
 
Internet of Things - structured approach to the physical plant network - Rock...
Internet of Things - structured approach to the physical plant network - Rock...Internet of Things - structured approach to the physical plant network - Rock...
Internet of Things - structured approach to the physical plant network - Rock...
Carotek
 
Fundamentals of ether netip i iot network technology
Fundamentals of ether netip i iot network technologyFundamentals of ether netip i iot network technology
Fundamentals of ether netip i iot network technology
IntelligentManufacturingInstitute
 
Smart Devices: Helping Design, Operate and Maintain The Connected Enterprise
Smart Devices: Helping Design, Operate and Maintain The Connected EnterpriseSmart Devices: Helping Design, Operate and Maintain The Connected Enterprise
Smart Devices: Helping Design, Operate and Maintain The Connected Enterprise
Rockwell Automation
 
Smart Devices - Design ,Operate and Maintain
Smart Devices - Design ,Operate and MaintainSmart Devices - Design ,Operate and Maintain
Smart Devices - Design ,Operate and Maintain
softconsystem
 
Unified industrial wireless networks (cisco)
Unified industrial wireless networks (cisco)Unified industrial wireless networks (cisco)
Unified industrial wireless networks (cisco)Luis Atencio
 
Blueprint for the Industrial Internet: The Architecture
Blueprint for the Industrial Internet: The ArchitectureBlueprint for the Industrial Internet: The Architecture
Blueprint for the Industrial Internet: The Architecture
Real-Time Innovations (RTI)
 
October Southern CA Road Shows - Build Safe and Secure Distributed Systems
October Southern CA Road Shows -  Build Safe and Secure Distributed SystemsOctober Southern CA Road Shows -  Build Safe and Secure Distributed Systems
October Southern CA Road Shows - Build Safe and Secure Distributed Systems
Real-Time Innovations (RTI)
 
What is Your Edge From the Cloud to the Edge, Extending Your Reach
What is Your Edge From the Cloud to the Edge, Extending Your ReachWhat is Your Edge From the Cloud to the Edge, Extending Your Reach
What is Your Edge From the Cloud to the Edge, Extending Your Reach
SUSE
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
ssuser52b751
 
The International standards landscape for IoT in SmartHome
The International standards landscape for IoT in SmartHomeThe International standards landscape for IoT in SmartHome
The International standards landscape for IoT in SmartHome
ir. Carmelo Zaccone
 
Devising a practical approach to the Internet of Things
Devising a practical approach to the Internet of ThingsDevising a practical approach to the Internet of Things
Devising a practical approach to the Internet of ThingsGordon Haff
 
Ti k2 e for mission critical applications
Ti k2 e for mission critical applicationsTi k2 e for mission critical applications
Ti k2 e for mission critical applications
Hitesh Jani
 
Rockwell PSP
Rockwell PSP Rockwell PSP
Rockwell PSP
Johan Basson
 
BRKIOT-2108.pdf
BRKIOT-2108.pdfBRKIOT-2108.pdf
BRKIOT-2108.pdf
JokaTek
 
Internet of Things (IoT) Costs, Connectivity, Resources and Software
Internet of Things (IoT) Costs, Connectivity, Resources and SoftwareInternet of Things (IoT) Costs, Connectivity, Resources and Software
Internet of Things (IoT) Costs, Connectivity, Resources and Software
Real-Time Innovations (RTI)
 
Introduction to roof computing by Nishant Krishna
Introduction to roof computing by Nishant KrishnaIntroduction to roof computing by Nishant Krishna
Introduction to roof computing by Nishant Krishna
CodeOps Technologies LLP
 

Similar to Building Converged Plantwide Ethernet (20)

Cisco: Solutions for Industrial IT
Cisco: Solutions for Industrial ITCisco: Solutions for Industrial IT
Cisco: Solutions for Industrial IT
 
Deploy Secure Network Architectures for The Connected Enterprise
Deploy Secure Network Architectures for The Connected EnterpriseDeploy Secure Network Architectures for The Connected Enterprise
Deploy Secure Network Architectures for The Connected Enterprise
 
Fundamentals of ethernet ip osi and cip
Fundamentals of ethernet ip osi and cipFundamentals of ethernet ip osi and cip
Fundamentals of ethernet ip osi and cip
 
How to Build the Connectivity Architecture for the Industrial Internet of Thi...
How to Build the Connectivity Architecture for the Industrial Internet of Thi...How to Build the Connectivity Architecture for the Industrial Internet of Thi...
How to Build the Connectivity Architecture for the Industrial Internet of Thi...
 
Internet of Things - structured approach to the physical plant network - Rock...
Internet of Things - structured approach to the physical plant network - Rock...Internet of Things - structured approach to the physical plant network - Rock...
Internet of Things - structured approach to the physical plant network - Rock...
 
Fundamentals of ether netip i iot network technology
Fundamentals of ether netip i iot network technologyFundamentals of ether netip i iot network technology
Fundamentals of ether netip i iot network technology
 
Smart Devices: Helping Design, Operate and Maintain The Connected Enterprise
Smart Devices: Helping Design, Operate and Maintain The Connected EnterpriseSmart Devices: Helping Design, Operate and Maintain The Connected Enterprise
Smart Devices: Helping Design, Operate and Maintain The Connected Enterprise
 
Smart Devices - Design ,Operate and Maintain
Smart Devices - Design ,Operate and MaintainSmart Devices - Design ,Operate and Maintain
Smart Devices - Design ,Operate and Maintain
 
Unified industrial wireless networks (cisco)
Unified industrial wireless networks (cisco)Unified industrial wireless networks (cisco)
Unified industrial wireless networks (cisco)
 
Blueprint for the Industrial Internet: The Architecture
Blueprint for the Industrial Internet: The ArchitectureBlueprint for the Industrial Internet: The Architecture
Blueprint for the Industrial Internet: The Architecture
 
October Southern CA Road Shows - Build Safe and Secure Distributed Systems
October Southern CA Road Shows -  Build Safe and Secure Distributed SystemsOctober Southern CA Road Shows -  Build Safe and Secure Distributed Systems
October Southern CA Road Shows - Build Safe and Secure Distributed Systems
 
What is Your Edge From the Cloud to the Edge, Extending Your Reach
What is Your Edge From the Cloud to the Edge, Extending Your ReachWhat is Your Edge From the Cloud to the Edge, Extending Your Reach
What is Your Edge From the Cloud to the Edge, Extending Your Reach
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
 
The International standards landscape for IoT in SmartHome
The International standards landscape for IoT in SmartHomeThe International standards landscape for IoT in SmartHome
The International standards landscape for IoT in SmartHome
 
Devising a practical approach to the Internet of Things
Devising a practical approach to the Internet of ThingsDevising a practical approach to the Internet of Things
Devising a practical approach to the Internet of Things
 
Ti k2 e for mission critical applications
Ti k2 e for mission critical applicationsTi k2 e for mission critical applications
Ti k2 e for mission critical applications
 
Rockwell PSP
Rockwell PSP Rockwell PSP
Rockwell PSP
 
BRKIOT-2108.pdf
BRKIOT-2108.pdfBRKIOT-2108.pdf
BRKIOT-2108.pdf
 
Internet of Things (IoT) Costs, Connectivity, Resources and Software
Internet of Things (IoT) Costs, Connectivity, Resources and SoftwareInternet of Things (IoT) Costs, Connectivity, Resources and Software
Internet of Things (IoT) Costs, Connectivity, Resources and Software
 
Introduction to roof computing by Nishant Krishna
Introduction to roof computing by Nishant KrishnaIntroduction to roof computing by Nishant Krishna
Introduction to roof computing by Nishant Krishna
 

More from Rockwell Automation

RA TechED 2019 - PR03 - Implementation of PlantPAx Systems
RA TechED 2019 - PR03 - Implementation of PlantPAx SystemsRA TechED 2019 - PR03 - Implementation of PlantPAx Systems
RA TechED 2019 - PR03 - Implementation of PlantPAx Systems
Rockwell Automation
 
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
Rockwell Automation
 
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's SucceedRA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
Rockwell Automation
 
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured ObjectsRA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
Rockwell Automation
 
RA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
RA TechED 2019 - SY22 - The Future of Software Purchase and MaintenanceRA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
RA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
Rockwell Automation
 
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
Rockwell Automation
 
RA TechED 2019 - SS16 - Security Where and Why do I start
RA TechED 2019 - SS16 - Security Where and Why do I startRA TechED 2019 - SS16 - Security Where and Why do I start
RA TechED 2019 - SS16 - Security Where and Why do I start
Rockwell Automation
 
RA TechED 2019 - SS14 - Electronic Lockout Tagout Management Systems
RA TechED 2019 - SS14 - Electronic Lockout  Tagout Management SystemsRA TechED 2019 - SS14 - Electronic Lockout  Tagout Management Systems
RA TechED 2019 - SS14 - Electronic Lockout Tagout Management Systems
Rockwell Automation
 
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
Rockwell Automation
 
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
Rockwell Automation
 
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
Rockwell Automation
 
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
Rockwell Automation
 
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
Rockwell Automation
 
RA TechED 2019 - CL05 Reduce Waste with Logixai
RA TechED 2019 - CL05 Reduce Waste with LogixaiRA TechED 2019 - CL05 Reduce Waste with Logixai
RA TechED 2019 - CL05 Reduce Waste with Logixai
Rockwell Automation
 
RA TechED 2019 - CL02 - Integrated Architecture System Software What's New
RA TechED 2019 - CL02 -  Integrated Architecture System Software What's NewRA TechED 2019 - CL02 -  Integrated Architecture System Software What's New
RA TechED 2019 - CL02 - Integrated Architecture System Software What's New
Rockwell Automation
 
RA TechED 2019 - CL01 - Integrated Architecture System Hardware - what's new
RA TechED 2019 -  CL01 - Integrated Architecture System Hardware - what's newRA TechED 2019 -  CL01 - Integrated Architecture System Hardware - what's new
RA TechED 2019 - CL01 - Integrated Architecture System Hardware - what's new
Rockwell Automation
 
Robert Murphy Driving Value from Smart Manufacturing
Robert Murphy Driving Value from Smart ManufacturingRobert Murphy Driving Value from Smart Manufacturing
Robert Murphy Driving Value from Smart Manufacturing
Rockwell Automation
 
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
Rockwell Automation
 
Designing Machine-level HMI with Studio 5000 View Designer® Demonstration
Designing Machine-level HMI with Studio 5000 View Designer® DemonstrationDesigning Machine-level HMI with Studio 5000 View Designer® Demonstration
Designing Machine-level HMI with Studio 5000 View Designer® Demonstration
Rockwell Automation
 
FactoryTalk® AssetCentre: Overview
FactoryTalk® AssetCentre: OverviewFactoryTalk® AssetCentre: Overview
FactoryTalk® AssetCentre: Overview
Rockwell Automation
 

More from Rockwell Automation (20)

RA TechED 2019 - PR03 - Implementation of PlantPAx Systems
RA TechED 2019 - PR03 - Implementation of PlantPAx SystemsRA TechED 2019 - PR03 - Implementation of PlantPAx Systems
RA TechED 2019 - PR03 - Implementation of PlantPAx Systems
 
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
RA TechED - DE10 - Simulation and Optimization of Lines using RAPID, Line Bal...
 
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's SucceedRA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
RA TechED 2019 - PR24 - FactoryTalk Brew Designed to Help Large Brewer's Succeed
 
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured ObjectsRA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
RA TechED 2019 - SY07- Next-Gen Device Library of Preconfigured Objects
 
RA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
RA TechED 2019 - SY22 - The Future of Software Purchase and MaintenanceRA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
RA TechED 2019 - SY22 - The Future of Software Purchase and Maintenance
 
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
RA TechED 2019 - SY08 - Developing Information Ready Applications using Smart...
 
RA TechED 2019 - SS16 - Security Where and Why do I start
RA TechED 2019 - SS16 - Security Where and Why do I startRA TechED 2019 - SS16 - Security Where and Why do I start
RA TechED 2019 - SS16 - Security Where and Why do I start
 
RA TechED 2019 - SS14 - Electronic Lockout Tagout Management Systems
RA TechED 2019 - SS14 - Electronic Lockout  Tagout Management SystemsRA TechED 2019 - SS14 - Electronic Lockout  Tagout Management Systems
RA TechED 2019 - SS14 - Electronic Lockout Tagout Management Systems
 
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
 
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
RA TechED 2019 - IN12 Microsoft - Digitalize Your Production to Capitalize on...
 
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
RA TechED 2019 - IN10 - What Machine Learning can do for you using FactoryTal...
 
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
RA TechED 2019 - IN03 - Develop Analytics That Scale Using FactoryTalk Innova...
 
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
RA TechED 2019 - IN02 - Empower Your Connected Enterprise with FactoryTalk In...
 
RA TechED 2019 - CL05 Reduce Waste with Logixai
RA TechED 2019 - CL05 Reduce Waste with LogixaiRA TechED 2019 - CL05 Reduce Waste with Logixai
RA TechED 2019 - CL05 Reduce Waste with Logixai
 
RA TechED 2019 - CL02 - Integrated Architecture System Software What's New
RA TechED 2019 - CL02 -  Integrated Architecture System Software What's NewRA TechED 2019 - CL02 -  Integrated Architecture System Software What's New
RA TechED 2019 - CL02 - Integrated Architecture System Software What's New
 
RA TechED 2019 - CL01 - Integrated Architecture System Hardware - what's new
RA TechED 2019 -  CL01 - Integrated Architecture System Hardware - what's newRA TechED 2019 -  CL01 - Integrated Architecture System Hardware - what's new
RA TechED 2019 - CL01 - Integrated Architecture System Hardware - what's new
 
Robert Murphy Driving Value from Smart Manufacturing
Robert Murphy Driving Value from Smart ManufacturingRobert Murphy Driving Value from Smart Manufacturing
Robert Murphy Driving Value from Smart Manufacturing
 
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
Exploring the Functionality of the Rockwell Automation® Library of Process Ob...
 
Designing Machine-level HMI with Studio 5000 View Designer® Demonstration
Designing Machine-level HMI with Studio 5000 View Designer® DemonstrationDesigning Machine-level HMI with Studio 5000 View Designer® Demonstration
Designing Machine-level HMI with Studio 5000 View Designer® Demonstration
 
FactoryTalk® AssetCentre: Overview
FactoryTalk® AssetCentre: OverviewFactoryTalk® AssetCentre: Overview
FactoryTalk® AssetCentre: Overview
 

Recently uploaded

OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
takuyayamamoto1800
 
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Globus
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
Ortus Solutions, Corp
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
RISE with SAP and Journey to the Intelligent Enterprise
RISE with SAP and Journey to the Intelligent EnterpriseRISE with SAP and Journey to the Intelligent Enterprise
RISE with SAP and Journey to the Intelligent Enterprise
Srikant77
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
e20449
 
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Mind IT Systems
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
Max Andersen
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
Tier1 app
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Globus
 
SOCRadar Research Team: Latest Activities of IntelBroker
SOCRadar Research Team: Latest Activities of IntelBrokerSOCRadar Research Team: Latest Activities of IntelBroker
SOCRadar Research Team: Latest Activities of IntelBroker
SOCRadar
 
top nidhi software solution freedownload
top nidhi software solution freedownloadtop nidhi software solution freedownload
top nidhi software solution freedownload
vrstrong314
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
Globus
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
Donna Lenk
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
Globus
 
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdfEnhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
Jay Das
 
Enhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdfEnhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdf
Globus
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
Matt Welsh
 

Recently uploaded (20)

OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
 
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
RISE with SAP and Journey to the Intelligent Enterprise
RISE with SAP and Journey to the Intelligent EnterpriseRISE with SAP and Journey to the Intelligent Enterprise
RISE with SAP and Journey to the Intelligent Enterprise
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
 
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
 
Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
 
SOCRadar Research Team: Latest Activities of IntelBroker
SOCRadar Research Team: Latest Activities of IntelBrokerSOCRadar Research Team: Latest Activities of IntelBroker
SOCRadar Research Team: Latest Activities of IntelBroker
 
top nidhi software solution freedownload
top nidhi software solution freedownloadtop nidhi software solution freedownload
top nidhi software solution freedownload
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
 
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdfEnhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
Enhancing Project Management Efficiency_ Leveraging AI Tools like ChatGPT.pdf
 
Enhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdfEnhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdf
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
 

Building Converged Plantwide Ethernet

  • 1. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 1Rockwell Automation TechED 2017 @ROKTechED #ROKTechED
  • 2. Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 2Rockwell Automation TechED 2017 @ROKTechED #ROKTechED PUBLIC Building Converged Plantwide Ethernet Architectures Converged Plantwide Ethernet (CPwE) Architectures
  • 3. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 3Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Abstract  Learn why and how to use reference architectures to build a scalable, reliable, safe, secure and future-ready network infrastructure. This discussion provides an overview of the Cisco and Rockwell Automation® Converged Plantwide Ethernet (CPwE) architectures. Learn what defines a reference architecture, why they’re important and how these architectures combined with products, services and solutions support successful deployment of The Connected Enterprise. A prior understanding of general Ethernet concepts, or attendance of the fundamentals of EtherNet/IP network technology is recommended.
  • 4. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 4Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Agenda  What’s Driving This?  Why are Reference Architectures Important?  OT-IT Similarities and Differences  CPwE Architectures  Cisco and Rockwell Automation Alliance  What Makes Up CPwE  Convergence-Ready Network Solutions  Additional Material  Training Resources
  • 5. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 5Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This?
  • 6. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 6Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Application Software Network What’s Driving This? Reliable, Safe and Secure Architectures for The Connected Enterprise A reliable, secure architecture is critical to building a connected enterprise
  • 7. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 7Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Reliable, Safe and Secure Architectures for The Connected Enterprise Industrial IoT Operational Technology Industrial IT Information Technology Physical or Virtualized Servers • FactoryTalk® Application Servers and Services Platform • Network & Security Services – DNS, AD, DHCP, Identity Services (AAA) • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Distribution Switch Stack Cell/Area Zone - Levels 0–2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN (Lines, Machines, Skids, Equipment) Cell/Area Zone - Levels 0–2 Linear/Bus/Star Topology Autonomous Wireless LAN (Lines, Machines, Skids, Equipment) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4-5 Industrial Zone Levels 0–3 (Plant-wide Network) Core Switches Phone Controller Camera Safety Controller Soft Starter Cell/Area Zone - Levels 0–2 Ring Topology - Device Level Ring (DLR) Protocol Unified Wireless LAN (Lines, Machines, Skids, Equipment) Plant Firewalls • Active/Standby • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Safety I/O Instrumentation Level 3 - Site Operations (Control Room) HMI Active AP SSID 5 GHz WGB Safety I/O Controller WGB LWAP SSID 5 GHz WGB LWAP Controller LWAP SSID 2.4 GHz Standby Wireless LAN Controller (WLC) Cell/Area Zone Levels 0–2 Cell/Area Zone Levels 0–2 Drive Distribution Switch Stack Wide Area Network (WAN) Data Center - Virtualized Servers • ERP - Business Systems • Email, Web Services • Security Services - Active Directory (AD), Identity Services (AAA) • Network Services – DNS, DHCP • Call Manager Enterprise Identity Services Identity Services External DMZ/ Firewall Cloud Access Switches Access Switches IFW IFW Drive I/O Drive I/O I/O I/O I/O Robot Servo Drive
  • 8. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 8Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? People Convergence Technology Convergence Network Convergence Organizational Convergence Ethernet and IP Wide Deployment Cultural Convergence Increasing Business Pressures • Sharing of engineering best practices between Control System Engineers (OT) and IT Network Engineers: – Standardization of design and technology – Reference architectures, reference models, industry and technology standards Industrial IoT
  • 9. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 9Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Technology and Cultural Convergence - Similarities and Differences Criteria Industrial OT Network Enterprise IT Network Environment • Plant-floor • Control Room • Control Panel, Industrial Distribution Frame (IDF) • Carpeted Space, Data Center • Data Communication or Wiring Closet, Intermediate Distribution Frame (IDF) Switches • Managed and unmanaged • Layer 2 is predominant • DIN rail or panel mount is predominant • Managed • Layer 2 and Layer 3 • Rack mount Wireless • Autonomous (locally managed) – point solutions • Mobile equipment (emerging) and personnel (prevalent) • Unified (centrally managed) solutions • Mobile personnel – corporate provided or BYOD • Guest access Computing • Industrial Hardened Panel Mount Computers and Monitors • Desktop, Notebook • 19” Rack Server • Virtualization - becoming prevalent • Hardening – Sporadic patching and white listing • Desktop, Notebook • Tablets • 19” Rack Server and Blade Server • Unified Computing Systems (UCS) • Virtualization – widespread • Hardening - Patching and white listing
  • 10. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 10Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Technology and Cultural Convergence - Similarities and Differences Criteria Industrial OT Network Enterprise IT Network Network Technology • Standard IEEE 802.3 Ethernet and proprietary (non-standard) versions • Standard IETF Internet Protocol (IPv4) and proprietary (non-standard) alternatives • Sporadic use of standard Layer 2 and Layer 3 network and security services • Standard IEEE 802.3 Ethernet • Standard IETF Internet Protocol (IPv4 and IPv6) • Pervasive use of standard Layer 2 and Layer 3 network and security services Network Availability • Switch-Level and Device-Level topologies • Ring topology is predominant for both, Redundant Star for switch topologies is emerging • Standard IEEE, IEC and vendor specific Layer 2 resiliency protocols • Switch-Level topologies • Redundant star topology is predominant • Standard IEEE, IETF, and vendor specific Layer 2 and Layer 3 resiliency protocols Service level agreement (SLA) • Mean time to recovery (MTTR) - Minutes, Hours • Mean time to recovery (MTTR) - Hours, Days IP Addressing • Mostly Static • Mostly Dynamic
  • 11. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 11Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Technology and Cultural Convergence - Similarities and Differences Criteria Industrial OT Network Enterprise IT Network Traffic Type • Primarily local – traffic between local assets • Information, control, safety, motion, time synchronization, energy management • Smaller frames for control traffic • Industrial application layer protocols: CIP, Profinet, IEC 61850, Modbus TCP, etc. • Primarily non-local – traffic to remote assets • Voice, Video, Data • Larger packets and frames • Standard application layer protocols: HTTP, SNMP, DNS, RTP, SSH, etc. Performance • Low Latency, Low Jitter • Data Prioritization – QoS – Layer 2 & 3 • Low Latency, Low Jitter • Data Prioritization – QoS – Layer 3 Security • Open by default, must secure by configuration and architecture • Industrial security standards – e.g. IEC, NIST • Inconsistent deployment of security policies • No line-of-sight to the Enterprise or to the Internet • Pervasive • Enterprise security best practices • Strong security policies • Line-of-sight across the Enterprise and to the Internet
  • 12. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 12Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Security Policies - Similarities and Differences Criteria Industrial OT Network Enterprise IT Network Focus 24/7 operations, high OEE Helping to protect intellectual property and company assets Precedence of Priorities Availability Integrity Confidentiality Confidentiality Integrity Availability Types of Data Traffic Converged network of data, control, information, safety and motion Converged network of data, voice and video Access Control Strict physical access Simple network device access Strict network authentication and access policies Implications of a Device Failure Production is down ($$’s/hour … or worse) Workaround or wait Threat Protection Isolate threat but keep operating Shut down access to detected threat Upgrades Scheduled during downtime Automatically pushed during uptime
  • 13. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 13Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Smart Devices, Smart Machines, Smart Manufacturing  Standard Network and Security Services; Standard Network Tools  Customer choice of best-in-class products through Industrial IoT device coexistence and interoperability  Pervasive Asset Optimization and Utilization  Common infrastructure devices and tools  Human assets: knowledge, experience, training  Better Analytics  Device/Machine, System/Plant, Enterprise  Enables Innovative Technologies  Mobility – Personnel and Equipment  Cloud –On Premise and Off Premise What’s Driving This? Business Outcomes – Industrial IoT / Industrial IT (Bridging OT-IT)
  • 14. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 14Rockwell Automation TechED 2017 @ROKTechED #ROKTechED What’s Driving This? Application Requirements Source: ARC Advisory Group What is real-time? What is resilient? What is secure? Loss Critical Multi-axis Motion Control Hardware and Software solutions, e.g. integrated motion on the EtherNet/IP network, PTP Synchronization of multiple axes: printing presses, wire drawing, web making, picking and placing Subset of Discrete automation 100 µs to 10 ms Loss CriticalDiscrete Automation Industrial Protocols - CIP 1 ms to 100 ms Material handling, filling, labeling, palletizing, packaging; welding, stamping, cutting, metalforming, soldering, sorting Auto, food and beverage, semiconductor, metals, pharmaceutical Process Automation Information Integration, Slower Process Automation .Net, DCOM, TCP/IP 10 ms to 1 second or longer Pumps, compressors, mixers; monitoring of temperature, pressure, flow Oil and gas, chemicals, energy, water Process Automation Function Comm. Technology Period Applications Industries Time-critical Discrete Automation Discrete Automation Application dependent ….. Only you can define what this means for your application.
  • 15. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 15Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures
  • 16. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 16Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Cisco – Rockwell Automation® Strategic Alliance Program  10 Years of Collaboration  10 Tested and Validated Architectures  Design Considerations  Best Practices  Documented Test Results  Documented Configurations  Proven Architectures  Enables OT-IT Convergence  Industrial IT (bridging OT-IT)  Industrial IoT  Helps customer to reduce costs  Simplified Design  Quicker Deployment  Reduced risk in deploying newer technologies Key Takeaways Converged Plantwide Ethernet (CPwE) Architectures
  • 17. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 17Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Cisco and Rockwell Automation® Alliance Technology, Network, Cultural and Organizational Convergence Stratix® 5900 Services Router, Stratix® 5950 Industrial Firewall, Stratix® 5100 Wireless Access Point/ Workgroup Bridge, and Stratix® 5000/Stratix® 8000 families of managed industrial Ethernet switches, which combine the best of both Rockwell Automation® and Cisco. Collection of tested and validated architectures developed by subject matter authorities at Cisco and Rockwell Automation®. The content of CPwE is relevant to both Operational Technology (OT) and Information Technology (IT) disciplines and consists of documented architectures, best practices, guidance and configuration settings to help manufacturers with design and deployment of a scalable, reliable, safe, secure and future-ready plant-wide industrial network infrastructure. A single scalable architecture, using open and standard Ethernet and IP networking technologies, such as EtherNet/IP, enabling the Industrial Internet of Things to help achieve the flexibility, visibility and efficiency required in a competitive manufacturing environment. Education and services to facilitate OT and IT convergence, assist with successful architecture deployment, and enable efficient operations that allow critical resources to focus on increasing innovation and productivity. People and Process Optimization: Common Technology View: Converged Plantwide Ethernet (CPwE) Architectures: Joint Product Collaboration:
  • 18. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 18Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Tested, validated and documented reference architectures  Comprised of a collection of Cisco and Rockwell Automation® validated architectures, following the Cisco Validated Design (CVD) program  Developed from application and technology use cases  Industry neutral, one-to-many approach, customers adapt to meet their application needs  Tested for performance, availability, repeatability, scalability and security by subject matter authorities at Cisco and Rockwell Automation® CPwE test labs  Built on technology and industry standards (IEC, IEEE, IETF)  “Future-ready” network and security design  Content relevant to both OT and IT Engineers  Deliverables  White Papers, Design & Implementation Guides - architectures design considerations, best practices, documented test results with configuration settings  Proven architectures:  Helps customers to reduce their costs by simplifying their designs, accelerating their deployments, and reducing their risk in deploying new technology Converged Plantwide Ethernet (CPwE) Industrial IoT / Industrial IT (Bridging OT-IT)
  • 19. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 19Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Valued resource  To help us with our own OT-IT convergence – Industrial IT  Proven architectures – cost reduction, risk reduction  We’ve come to expect it  Architectural collaboration between Cisco and Rockwell Automation®  We adapt CPwE into our global standards  Unique in the industry  No other company, organization or consortia provides the level of testing, validation and documentation that CPwE provides  We use CPwE to help us justify network and security projects  Architectural Framework  Best practices  Design and Implementation Guidance CPwE – Proven Architectures Customer (OT-IT) Value Statements
  • 20. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 20Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE – Proven Architectures Customer (OT-IT) Value Statements  We have adopted 7 of the 10 CPwE tested and validated architectures into our global network design and specifications for our plants and OEMs  CPwE Architectures :  Baseline – CPwE Model/Framework, Industrial Network Security Framework  WLAN – Unified Architecture for Mobile Maintenance Personnel  NAT – Cloning of OEM Applications  ISE – Identity Services PAN and PSN within Plant Network – Wired and Wireless  IDMZ – ASA Firewall Policies between OT and IT Networks  Resiliency – Stratix® 5700 switch with Redundant Star (EtherChannel), Catalyst 3850, Catalyst 4500-X with VSS  IFW - Firewall Policies for ASA, they do not currently use Stratix® 5950 security appliance  We value the OT-IT collaboration between Rockwell Automation® and Cisco  We standardized on Stratix® industrial Ethernet switches due to CPwE
  • 21. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 21Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Collection of Cisco and Rockwell Automation® Tested & Validated Designs Key Requirements:  Scalable  Reliable  Safe  Secure  Future-ready Key Tenets:  Smart Endpoints  Segmentation (Zoning)  Managed Infrastructure  Resiliency  Time-critical Data  Wireless - Mobility  Holistic Defense-in-Depth Security  Convergence-ready
  • 22. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 22Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Collection of Cisco and Rockwell Automation® Tested & Validated Designs Key Tenets: • Smart Endpoints • Segmentation (Zoning) • Managed Infrastructure • Resiliency • Time-critical Data • Wireless - Mobility • Holistic Defense-in- Depth Security • Convergence-ready Physical or Virtualized Servers • FactoryTalk® Application Servers and Services Platform • Network & Security Services – DNS, AD, DHCP, Identity Services (AAA) • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Distribution Switch Stack Cell/Area Zone - Levels 0–2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN (Lines, Machines, Skids, Equipment) Cell/Area Zone - Levels 0–2 Linear/Bus/Star Topology Autonomous Wireless LAN (Lines, Machines, Skids, Equipment) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4-5 Industrial Zone Levels 0–3 (Plant-wide Network) Core Switches Phone Controller Camera Safety Controller Soft Starter Cell/Area Zone - Levels 0–2 Ring Topology - Device Level Ring (DLR) Protocol Unified Wireless LAN (Lines, Machines, Skids, Equipment) Plant Firewalls • Active/Standby • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Safety I/O Instrumentation Level 3 - Site Operations (Control Room) HMI Active AP SSID 5 GHz WGB Safety I/O Controller WGB LWAP SSID 5 GHz WGB LWAP Controller LWAP SSID 2.4 GHz Standby Wireless LAN Controller (WLC) Cell/Area Zone Levels 0–2 Cell/Area Zone Levels 0–2 Drive Distribution Switch Stack Wide Area Network (WAN) Data Center - Virtualized Servers • ERP - Business Systems • Email, Web Services • Security Services - Active Directory (AD), Identity Services (AAA) • Network Services – DNS, DHCP • Call Manager Enterprise Identity Services Identity Services External DMZ/ Firewall Cloud Access Switches Access Switches IFW IFW Drive I/O Drive I/O I/O I/O I/O Robot Servo Drive
  • 23. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 23Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Collection of Cisco and Rockwell Automation® Tested & Validated Designs CPwE REP June 2014 CPwE WLAN Nov. 2014 CPwE IDMZ May 2017 CPwE Baseline Sept. 2011 CPwE NAT June 2015 CPwE ISE Sept. 2017 CPwE Migration Jan. 2016 CPwE VPN March 2016 CPwE Ind. Firewall Dec. 2016 CPwE Resiliency July 2017 CPwE Test Labs  Rockwell Automation® – Mayfield Heights, OH  Cisco – Raleigh, NC (RTP)  Panduit – Tinley Park, IL CPwE DLR August. 2017 NS06 NS07 NS08 NS16 NS02 NS16 NS06NS06
  • 24. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 24Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Collection of Cisco and Rockwell Automation® Tested & Validated Designs  Converged Plantwide Ethernet (CPwE) is a collection of tested and validated architectures that are developed by subject matter authorities at Cisco and Rockwell Automation® and that follow the Cisco Validated Design (CVD) program.  The content of CPwE, which is relevant to both Operational Technology (OT) and Informational Technology (IT) disciplines, consists of documented architectures, best practices, guidance and configuration settings to help manufacturers with design and deployment of a scalable, reliable, secure and future-ready plant-wide industrial network infrastructure.  CPwE also helps manufacturers achieve the benefits of cost reductions using proven designs that can help lead to quicker deployment and reduced risk in deploying new technology.
  • 25. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 25Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Collection of Cisco and Rockwell Automation® Tested & Validated Designs  CPwE follows the Cisco Validated Design (CVD) Program  Provide the foundation for systems design based on common use cases or current engineering system priorities. They incorporate a broad set of technologies, features, and applications to address customer needs. Each CPwE CVD has been comprehensively tested, validated and documented by Cisco and Rockwell Automation® subject matter authorities to maintain faster, more reliable, and fully predictable deployment  CPwE CVDs are organized by solution areas with customer collateral published using various types of documents:  Design & Implementation Guides (DIGs)  White Papers  Application Guides
  • 26. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 26Rockwell Automation TechED 2017 @ROKTechED #ROKTechED OT Standards  Operational Levels  ISA 95, Purdue – Levels 0-5  Level 0 Sensor/Actuators, Level 1 Controller, Level 2 Local Supervisor, Level 3 Site Operations, Level 4-5 Enterprise  Functional / Security Zones  IEC-62443, NIST 800-82, ICS-CERT  Enterprise, Industrial, IDMZ  Industrial Subzones – Cell/Area, Site Operations IT Standards  Network Technology  OSI Reference Model – 7 Layers  IEEE 802.1, 802.3, 802.11  IETF TCP, UDP, IP  Network Switch Hierarchy  Campus Network Model  Layer 2 Access  Layer 3 Distribution/Aggregation  Layer 3 Core CPwE Architectures Built on Technology and Industry Standards
  • 27. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 27Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Logical Model OT Standards - Operational Levels - Functional / Security Zones Level 5 Level 4 Level 3 Level 2 Level 1 Level 0 Remote Desktop Gateway Services Patch Management AV Server Application Mirror Web Services Operations Reverse Proxy Enterprise Network Site Business Planning and Logistics NetworkEmail, Intranet, etc. FactoryTalk® Application Server FactoryTalk® Directory Engineering Workstation Remote Access Server FactoryTalk® Client Operator Interface FactoryTalk® Client Engineering Workstation Operator Interface Batch Control Discrete Control Drive Control Continuous Process Control Safety Control Sensors Drives Actuators Robots Enterprise Security Zone Levels 4-5 Industrial DMZ Level 3.5 Industrial Security Zone(s) Levels 0-3 Cell/Area Zones(s) Levels 0-2 Web Email CIP Firewall Firewall Site Operations Area Supervisory Control Basic Control Process • Levels – ISA 95, Purdue Reference Model • Zones – IEC 62443, NIST 800-82, ICS-CERT Recommended Practices
  • 28. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 28Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Plant-wide Zoning OT Standards - Functional / Security Zones Plant-wide Zoning • Functional / Security Areas • Smaller Connected LANs – Smaller Broadcast Domains – Smaller Fault Domains – Smaller Domains of Trust • Industrial IoT Technology • Building Block Approach for Scalability
  • 29. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 29Rockwell Automation TechED 2017 @ROKTechED #ROKTechED OSI 7-Layer Reference Model OT-IT Standards CIP - IEC 61158Application Presentation Session Transport Network Data Link Physical Layer 7 Layer 6 Layer 5 Layer 4 Layer 3 Layer 2 Layer 1 Network Services to User App Encryption/Other processing Manage Multiple Applications Reliable End-to-End Delivery Error Correction Packet Delivery, Routing Framing of Data, Error Checking Signal type to transmit bits, pinouts, cable type IETF TCP/UDP IETF IP IEEE 802.3/802.1/802.11 TIA - 1005 Layer NameLayer No. Function Examples Routers Switches Cabling/RF IES Open Systems Interconnection
  • 30. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 30Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Campus Network Model IT Standards – Network Switch Hierarchy  Hierarchal, modular and scalable building blocks  Smaller Connected LANs - clear demarcations and segmentation  Fault domain (e.g. Layer 2 loops), broadcast domain, domains of trust (security)  Easier to grow, understand and troubleshoot  Multi-tier switch model  Core – Layer 3  Aggregates distribution switches  Backbone of network  Industrial DMZ connectivity  Distribution / Aggregation – Layer 3  Aggregates access switches  Provides Layer 3 services  Access – Layer 2  Aggregates industrial automation and control system (IACS) devices  Provides Layer 2 services Access Distribution Core
  • 31. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 31Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Logical Zoning - Segmentation CPwE Logical Framework – Modular Building Blocks Levels 0-2 Phone Controller Safety Controller Camera Safety I/O Instrumentation HMI Industrial Zone Levels 0-3 Media & Connectors Cell/Area Zone #1 Redundant Star Topology Cell/Area Zone #2 Ring Topology MCC Soft Starter Level 2 HMI Level 0 Drive I/O Level 1 Controller Servo Drive Levels 0-2Levels 0-2 Cell/Area Zone #3 Linear/Bus/Star Topology Layer 2 Access Switch Layer 2 Building Block Layer 3 Distribution Switch Layer 3 Building Block Layer 2 Building Block Layer 2 Building Block
  • 32. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 32Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Logical Zoning - Segmentation CPwE Logical Framework – Modular Building Blocks Key Tenets: • Smart Endpoints • Segmentation (Zoning) • Managed Infrastructure • Resiliency • Time-critical Data • Wireless - Mobility • Holistic Defense-in- Depth Security • Convergence-ready Physical or Virtualized Servers • FactoryTalk® Application Servers and Services Platform • Network & Security Services – DNS, AD, DHCP, Identity Services (AAA) • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Distribution Switch Stack Cell/Area Zone - Levels 0–2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN (Lines, Machines, Skids, Equipment) Cell/Area Zone - Levels 0–2 Linear/Bus/Star Topology Autonomous Wireless LAN (Lines, Machines, Skids, Equipment) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4-5 Industrial Zone Levels 0–3 (Plant-wide Network) Core Switches Phone Controller Camera Safety Controller Soft Starter Cell/Area Zone - Levels 0–2 Ring Topology - Device Level Ring (DLR) Protocol Unified Wireless LAN (Lines, Machines, Skids, Equipment) Plant Firewalls • Active/Standby • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Safety I/O Instrumentation Level 3 - Site Operations (Control Room) HMI Active AP SSID 5 GHz WGB Safety I/O Controller WGB LWAP SSID 5 GHz WGB LWAP Controller LWAP SSID 2.4 GHz Standby Wireless LAN Controller (WLC) Cell/Area Zone Levels 0–2 Cell/Area Zone Levels 0–2 Drive Distribution Switch Stack Wide Area Network (WAN) Data Center - Virtualized Servers • ERP - Business Systems • Email, Web Services • Security Services - Active Directory (AD), Identity Services (AAA) • Network Services – DNS, DHCP • Call Manager Enterprise Identity Services Identity Services External DMZ/ Firewall Cloud Access Switches Access Switches IFW IFW Drive I/O Drive I/O I/O I/O I/O Robot Servo Drive
  • 33. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 33Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Logical Model – Modular Building Blocks Enterprise-wide Business Systems Plant-wide Operation Systems Level 3 - Site Operations Data Center Industrial Zone Levels 0-3 (Plant-wide Network) Enterprise Zone Levels 4 - 5 Cell/Area Zone Levels 0-2 Cell/Area Zone Levels 0-2
  • 34. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 34Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Logical Model – Modular Building Blocks Line #1 Labeling Filling Packaging Line #2 Labeling Filling Packaging Line #3 Labeling Filling Packaging Plant-wide Operation Systems Level 3 - Site Operations Packaging Cell/Area Zone Levels 0-2 Industrial Zone Levels 0-3 (Plant-wide Network)
  • 35. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 35Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Logical Framework – Modular Building Blocks Line #2 Labeling Filling Packaging Plant-wide Operation Systems Line Controller VFD Drive HMI I/O I/O Controller Servo Drive Packaging / Section 1 VFD Drive HMI I/O I/O Controller Servo Drive Packaging / Section 2 VFD Drive HMI I/O I/O Controller Servo Drive Packaging / Section 3 VFD Drive HMI I/O I/O Controller Servo DriveFilling VFD Drive HMI I/O I/O Controller Servo DriveLabeling
  • 36. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 36Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Logical Framework – Modular Building Blocks Level 3 - Site Operations Packaging Cell/Area Zone Levels 0-2 Line #1 Line #2 Line #3 Plant-wide Operation Systems Industrial Zone Levels 0-3 (Plant-wide Network)
  • 37. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 37Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Structure and Hierarchy CPwE Logical Model - Modular Building Blocks Physical or Virtualized Servers • Application Servers & Services Platform • Network Services – e.g. DNS, AD, DHCP, AAA • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Link for Failover Detection Firewall (Active) Firewall (Standby) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4 - 5 Core Switches Plant Firewalls • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Wide Area Network (WAN) Physical or Virtualized Servers • ERP, Email • Active Directory (AD), AAA – Radius • Call Manager Enterprise Level 3 - Site Operations (Control Room) Internet External DMZ/ Firewall Wireless LAN Controller (WLC) Active Standby RADIUS (AAA) Server Packaging Cell/Area Zone Levels 0-2 Line #1 Line #2 Line #3 Cell/Area Zone Levels 0-2 Industrial Zone Levels 0-3 (Plant-wide Network)
  • 38. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 38Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Convergence-Ready Network Solutions Design and Implementation Considerations Partner Solution(s) e.g. Process Skid Plant-wide Industrial Automation & Control System Partner Solution(s) e.g. Machine Plant-wide Industrial Automation & Control System Design and deployment considerations that a partner (e.g. OEM, SI, Contractor) has to take into account to achieve seamless integration of their solution (e.g. equipment, skid, machine) into their customers’ plant-wide/site-wide network infrastructure. Early, open and two-way OT-IT dialogue is critical!
  • 39. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 39Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Risk management policies and overall tolerance to risk  Business practices  Corporate / local standards  Application requirements  Applicable industry standards – e.g. NERC CIP  Government regulations and compliance  Enterprise and industrial policies (safety and security), procedures, access control (avoidance of back doors) and network ownership  Alignment with industrial safety standards such as IEC 61508 – SIL 3 and EN 954-1 - Cat 4  Alignment with industrial security standards such as IEC-62443 (formerly ISA99), NIST 800-82 and ICS-CERT  Network capabilities (zone segmentation into domains of trust) Convergence-Ready Network Solutions Alignment with End User Stance on Safety, Security and Availability Early, open and two-way OT-IT dialogue is critical! “one-size-fits-all”
  • 40. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 40Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Convergence-Ready Network Solutions Alignment with End User - Network Services:  Use of a common industrial network technology that fully uses standard Ethernet and IP networking technology as the multi-discipline industrial network infrastructure.  IP addressing schema  Who manages? End User (OT/IT) or OEM?  Address range (class), subnet, default gateway (routability)  Implementation conventions – static/dynamic, hardware/software configurable, NAT/DNS  Use Common Layer 2 and Layer 3 Network Services  Switches - managed vs. unmanaged, industrial vs. COTS, system vs. component approach  Segmentation, data prioritization  Topologies - switch-level, device-level, hybrid  Availability – loop prevention, redundant path topologies with resiliency protocols  Time Synchronization Services  IEEE 1588 Precision Time Protocol (PTP w/E2E) – first fault, SOE, Motion The OEM Guide to Networking ENET-RM001_-EN-P
  • 41. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 41Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Industrial Security Framework MCC Enterprise Zone: Levels 4-5 Soft Starter I/O Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Level 0 - ProcessLevel 1 - Controller Level 3 – Site Operations Controller Drive Level 2 – Area Supervisory Control FactoryTalk ® Client Controller Industrial Demilitarized Zone (IDMZ) Industrial Zone: Levels 0-3 LWAP SSID 2.4 GHz SSID 5 GHz WGB I/O Active Wireless LAN Controller (WLC) Standby Core Switches Distribution Switch Stack Enterprise Identity Services External DMZ/ Firewall Cloud IFW Control System Engineers (OT) Control System Engineers in Collaboration with IT Network Engineers (Industrial IT) IT Security Architects in Collaboration with Control Systems Engineers Defense-in-Depth - Architecture Best Practices IEC 62443 - Zones & Conduits - Availability, Integrity, Confidentiality NIST 800-82 - cyber security Framework - Identify, Protect, Detect, Respond, Recover ICS-CERT - Recommended Practices
  • 42. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 42Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Physical or Virtualized Servers • FactoryTalk® Application Servers and Services Platform • Network & Security Services – DNS, AD, DHCP, Identity Services (AAA) • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Distribution Switch Stack Cell/Area Zone - Levels 0–2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN (Lines, Machines, Skids, Equipment) Cell/Area Zone - Levels 0–2 Linear/Bus/Star Topology Autonomous Wireless LAN (Lines, Machines, Skids, Equipment) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4-5 Industrial Zone Levels 0–3 (Plant-wide Network) Core Switches Phone Controller Camera Safety Controller Soft Starter Cell/Area Zone - Levels 0–2 Ring Topology - Device Level Ring (DLR) Protocol Unified Wireless LAN (Lines, Machines, Skids, Equipment) Plant Firewalls • Active/Standby • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Safety I/O Instrumentation Level 3 - Site Operations (Control Room) HMI Active AP SSID 5 GHz WGB Safety I/O Controller WGB LWAP SSID 5 GHz WGB LWAP Controller LWAP SSID 2.4 GHz Standby Wireless LAN Controller (WLC) Cell/Area Zone Levels 0–2 Cell/Area Zone Levels 0–2 Drive Distribution Switch Stack Wide Area Network (WAN) Data Center - Virtualized Servers • ERP - Business Systems • Email, Web Services • Security Services - Active Directory (AD), Identity Services (AAA) • Network Services – DNS, DHCP • Call Manager Enterprise Identity Services Identity Services External DMZ/ Firewall Cloud Access Switches Access Switches IFW IFW Drive I/O Drive I/O I/O I/O I/O RobotServo Drive CPwE Architectures Panduit Physical Layer Solutions for the CPwE Logical Framework Industrial Data Center (IDC) Main Distribution Frame (MDF) Industrial Distribution Frame (IDF) IDF Physical Network Zone System (PNZS) PNZS Control Panel (CP)
  • 43. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 43Rockwell Automation TechED 2017 @ROKTechED #ROKTechED CPwE Architectures Industrial IoT / Industrial IT (Bridging OT-IT) Operational Technology Industrial IoT Industrial IT Information Technology Physical or Virtualized Servers • FactoryTalk® Application Servers and Services Platform • Network & Security Services – DNS, AD, DHCP, Identity Services (AAA) • Storage Array Remote Access Server Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Distribution Switch Stack Cell/Area Zone - Levels 0–2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN (Lines, Machines, Skids, Equipment) Cell/Area Zone - Levels 0–2 Linear/Bus/Star Topology Autonomous Wireless LAN (Lines, Machines, Skids, Equipment) Industrial Demilitarized Zone (IDMZ) Enterprise Zone Levels 4-5 Industrial Zone Levels 0–3 (Plant-wide Network) Core Switches Phone Controller Camera Safety Controller Soft Starter Cell/Area Zone - Levels 0–2 Ring Topology - Device Level Ring (DLR) Protocol Unified Wireless LAN (Lines, Machines, Skids, Equipment) Plant Firewalls • Active/Standby • Inter-zone traffic segmentation • ACLs, IPS and IDS • VPN Services • Portal and Remote Desktop Services proxy Safety I/O Instrumentation Level 3 - Site Operations (Control Room) HMI Active AP SSID 5 GHz WGB Safety I/O Controller WGB LWAP SSID 5 GHz WGB LWAP Controller LWAP SSID 2.4 GHz Standby Wireless LAN Controller (WLC) Cell/Area Zone Levels 0–2 Cell/Area Zone Levels 0–2 Drive Distribution Switch Stack Wide Area Network (WAN) Data Center - Virtualized Servers • ERP - Business Systems • Email, Web Services • Security Services - Active Directory (AD), Identity Services (AAA) • Network Services – DNS, DHCP • Call Manager Enterprise Identity Services Identity Services External DMZ/ Firewall Cloud Access Switches Access Switches IFW IFW Drive I/O Drive I/O I/O I/O I/O Robot Servo Drive
  • 44. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 44Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Lessons Learned From Your Peers  Corporate culture change takes time  People, Process, and Technology changes are required for Industrial IoT transformation  The Network is foundational  Create an OT-IT convergence plan early  Early Engagement of Operations Staff  Define business outcomes early in the process with KPIs to measure success  Communicate and Celebrate Successes between locations  A robust archiving framework and strategy is needed  Behavior changes will be necessary to deliver success  Good technology will be trumped by bad processes  Good technology will be trumped by bad data  Process experts should be engaged early  Data Governance framework and teams must be in place before beginning  Provide enough runway and scheduling for Knowledge Transfer  Define out-of-scope processes and applications  Develop a mitigation plan early
  • 45. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 45Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Additional Material
  • 46. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 46Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Additional Material Network Architecture Icon Key Layer 2 Access Link (EtherNet/IP Device Connectivity) Layer 2 Interswitch Link/802.1Q Trunk Layer 3 Link Layer 2 Access Switch, Catalyst 2960 Multi-Layer Switch - Layer 2 and Layer 3, Stratix® 8300, Stratix® 5700, Stratix® 5400, Stratix® 5410 Layer 3 Router, Stratix® 5900 Autonomous Wireless Access Point (AP), Stratix® 5100 as Autonomous AP Layer 2 IES with NAT, Stratix® 5700, Stratix® 5400 Layer 2 IES with NAT and Connected Routing, Stratix® 5700, Stratix® 5400 NAT NAT - CR Layer 3 Distribution Switch Stack, Catalyst 3750-X, Catalyst 3850 Layer 3 Core Switch, Catalyst 4500, 4500-X, 6500, 6800 Layer 3 Core Switch with Virtual Switching System (VSS) Catalyst 4500-X, 6500, 6800 Firewall, Adaptive Security Appliance (ASA) 55xx Wireless workgroup bridge (WGB), Stratix® 5100 as workgroup bridge (WGB) Unified Wireless Lightweight Access Point (LWAP), Catalyst 3602E LWAP Unified Wireless LAN Controller (WLC), Cisco 5508 WLC Unified Computing System (UCS), UCS-C series Identity Services Engine (ISE) for Authentication, ISE - PAN/PSN/MnT Layer 2 Access, Industrial Ethernet Switch (IES), Stratix® 2500, Stratix® 5700, Stratix® 5400, Stratix® 8000IES IFW Layer 3 Router with Zone-based Firewall, Stratix® 5900 Industrial Firewall, Stratix® 5950
  • 47. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 47Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Website:  http://www.odva.org/  EtherNet/IP  https://www.odva.org/Technology- Standards/EtherNet- IP/OverviewSecuring EtherNet/IP Networks  EtherNet/IP Network Infrastructure Guide  https://www.odva.org/Portals/0/Library /Publications_Numbered/PUB00035R 0_Infrastructure_Guide.pdf  Common Industrial Protocol (CIP)  https://www.odva.org/Technology- Standards/Common-Industrial-Protocol- CIP/Overview  The Family of CIP Networks  https://www.odva.org/Portals/0/Library/Public ations_Numbered/PUB00123R1_Common- Industrial_Protocol_and_Family_of_CIP_Net works.pdf  CIP Security  https://www.odva.org/Technology- Standards/Common-Industrial-Protocol- CIP/CIP-Security Additional Material ODVA
  • 48. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 48Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Additional Material CPwE Architectures - Cisco and Rockwell Automation®  CPwE website  Overview Documents  Alliance Profile  Top 10 Recommendations for Plant-wide EtherNet/IP Deployments  Design Considerations for Securing Industrial Automation and Control System Networks
  • 49. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 49Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Additional Material CPwE Architectures - Cisco and Rockwell Automation® Topic Design Guide Whitepaper Design Considerations for Securing IACS Networks — ENET-WP031A-EN-P Converged Plantwide Ethernet – Baseline Document ENET-TD001E-EN-P — Resilient Ethernet Protocol in a CPwE Architecture ENET-TD005B-EN-P ENET-WP033A-EN-P Deploying 802.11 Wireless LAN Technology within a CPwE Architecture ENET-TD006A-EN-P ENET-WP034A-EN-P Deploying Identity Services within a CPwE Architecture ENET-TD008A-EN-P ENET-WP037A-EN-P Securely Traversing IACS Data Across the Industrial Demilitarized Zone (IDMZ) ENET-TD009A-EN-P ENET-WP038A-EN-P Deploying Network Address Translation within a CPwE Architecture ENET-TD007A-EN-P ENET-WP036A-EN-P Migrating Legacy IACS Networks to a CPwE Architecture ENET-TD011A-EN-P ENET-WP040A-EN-P Deploying A Resilient Converged Plantwide Ethernet Architecture ENET-TD010A-EN-P ENET-WP039B-EN-P Site-to-site VPN to a CPwE Architecture ENET-TD012A-EN-P — Deploying Industrial Firewalls within a CPwE Architecture ENET-TD002A-EN-P ENET-WP011B-EN-P Deploying Device Level Ring within a CPwE Architecture ENET-TD015A-EN-P ENET-WP016A-EN-P
  • 50. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 50Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Ethernet Design Considerations Reference Manual  ENET-RM002C-EN-P  EtherNet/IP Overview, Ethernet Infrastructure Components, EtherNet/IP Protocol, Predict System Performance  EtherNet/IP IntelliCENTER® Reference Manual (MCC-RM001)  The OEM Guide to Networking  ENET-RM001A-EN-P  This guide is intended to help OEMs understand relevant technologies, networking capabilities and other considerations that could impact them as they develop EtherNet/IP solutions for the machines, skids or equipment they build  Segmentation Methods Within the Cell/Area Zone ENET-AT004B-EN-E Additional Material Rockwell Automation® Reference Documents
  • 51. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 51Rockwell Automation TechED 2017 @ROKTechED #ROKTechED  Integrated Architecture® Builder (IAB)  Updates and additions to better-reflect CPwE structure, hierarchy and best practices  Improved Switch Wizard for distribution (e.g. Stratix® 5410 switch) and access (e.g. Stratix® 5700 switch)  Easier to create a large EtherNet/IP network with many topologies  CIP traffic is measured per segment, not just controller scanner and adapter centric  EtherNet/IP Capacity Tool  Popular Configuration Drawings (PCDs)  Updates and additions to better reflect CPwE recent enhancements Additional Material Rockwell Automation® Automaton Tools
  • 52. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 52Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources
  • 53. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 53Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Education - Industrial IoT / Industrial IT (Bridging OT-IT)  A ‘go-to’ resource for training and educational information on standard Internet Protocol (IP), security, wireless and other emerging technologies for industrial applications  Led by Cisco, Panduit, and Rockwell Automation®  Receive monthly e-newsletters with articles and videos on the latest trends  Scenario-based training on topics such as: logical topologies, protocols, switching, routing, wireless and physical cabling Network Design eLearning course available at promotional price for TechEd Attendees! Earn PDHs by signing up today at www.industrial–ip.org with code “EVENTS2017”
  • 54. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 54Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Education - Industrial IoT / Industrial IT (Bridging OT-IT) Four eLearning courses cover key aspects of implementing networked, industrial control systems. 20-30 minute interactive, scenario-based courses cover automation controls and physical infrastructure considerations.
  • 55. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 55Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Education - Industrial IoT / Industrial IT (Bridging OT-IT)  Courses 1 and 2: Designing for the Cell/Area Zone  Design secure, robust, future-ready networks for cells, machines, skids and other functional units by implementing reference architectures and standard IP.  Course 3: Designing for the Industrial Zone  Learn design principles on line integration, high-availability networks and wireless architectures to optimize plant networks.  Course 4: IT/OT Integration  Understand how to effectively converge a smart manufacturing facility with IT and OT stakeholders. EtherNet/IP Topologies Security Wireless
  • 56. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 56Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Training and Certification – Industrial IoT / Industrial IT (Bridging OT-IT) • Cisco Industrial Networking Specialist Training and Certification – Classroom training • Managing Industrial Networks with Cisco Networking Technologies (IMINS) – Exam: 200-401 IMINS – CPwE Design Considerations and Best Practices • CCNA Industrial Training and Certification – Classroom training • Managing Industrial Networks for Manufacturing with Cisco Technologies (IMINS2) – Exam: 200-601 IMINS2 – CPwE Design Considerations and Best Practices
  • 57. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 57Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Training and Certification – Industrial IoT / Industrial IT (Bridging OT-IT) Industrial Networking Specialist Module 1 Industrial Networking Solutions and Products Module 2 Industrial Network Documentation and Deployment Considerations Module 3 Installing Industrial Network Switches, Routers, and Cabling Module 4 Deploying Industrial Ethernet Devices Module 5 Maintaining Industrial Ethernet Networks Module 6 Troubleshooting Industrial Ethernet Networks CCNA Industrial Module 1 Industrial Networking Concepts and Components Module 2 General Troubleshooting Issues Module 3 EtherNet/IP Module 4 Troubleshooting EtherNet/IP Module 5 PROFINET Module 6 Configuring PROFINET Module 7 Troubleshooting PROFINET Module 8 Exploring Security Concerns Module 9 802.11 Industrial Ethernet Wireless Networking
  • 58. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 58Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Rockwell Automation® - Webinars  Industrial Automation Webinars  On Demand Webinars  Introduction to Building a Robust, Secure and Future-ready Network Infrastructure  Increase Business Agility by Converging Manufacturing and Business Systems  The Power of Building a Secure Network Infrastructure  Design Considerations for Building a Secure Network Infrastructure
  • 59. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 59Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Training Resources Cisco Training & Certifications ICND1 ICND2 Cisco Certification Track
  • 60. PUBLIC Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 60Rockwell Automation TechED 2017 @ROKTechED #ROKTechED Please take a moment to complete the brief session survey on our mobile app and let us know how we’re doing! Username: Last name Password: Email address used to register  Locate the session in the “Schedule” icon  Click on the “Survey” icon in the lower right corner of the session details  Complete survey & submit  Download the ROKTechED app and login: Thank you! Complete A Survey
  • 61. www.rockwellautomation.com Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. 61Rockwell Automation TechED 2017 @ROKTechED #ROKTechED PUBLIC Thank You!