SlideShare a Scribd company logo
Building Resilient Networks
November
Agenda
 Introductions
 Who is Westermo
 Defining Network Resiliency
 Hardware Redundancy
 Microsegmentation
 Configuration Backups
3
Introductions
Dakota Diehl
Network Application Engineer
dakota.diehl@westermo.us
847.453.3899
Benjamin Campbell
Technical Support Engineer
benjamin.campbell@westermo.us
847.453.3896
4
Westermo Group 2020
 Founded in 1975
 Industry leading software and hardware
development force
 Own production in Sweden with
state of the art process control
 Own sales and support units in 12 key countries,
distribution partners in many others
How To Build a Resilient
Network
6
 Resilience in computer networks is the “ability to provide and maintain an acceptable
level of service in the face of faults and challenges to normal operation.”
 This is a very wide definition, as it covers everything from packet loss to complete failure
of a node or link.
 Also includes the ability to defend against and respond to cybersecurity attacks, whether
malicious or unintended misconfigurations.
 The more resilient a network is, the more tolerant it is to faults or errors across the
network and can maintain uptime.
 Because of the wide definition, there are also a multitude of ways to improve your
network’s resilience.
Resiliency – What is it?
Hardware Redundancy
8
 One of the most straightforward ways to improve resiliency is to add redundancy
 If one node or link suffers a catastrophic failure, redundant connections keep the
network running without impacting performance.
 Unfortunately, not as simple as just dropping in another switch to the network!
 Layer 2 protocols such as FRNT or RSTP manage ring topologies, adding extra paths to
nodes without causing debilitating Broadcast Storms.
 Layer 3 protocols such as OSPF and VRRP can automatically designate a route between
networks and failover in the event of broken links.
Hardware Redundancy
9
 Built in functions to avoid uncontrolled broadcast storms.
 Link integrity control.
 Non-FRNT ports are not allowed to communicate with FRNT ports.
 Default FRNT alarm signaling via SNMP, LED, Digital-Out and Syslog.
 Very fast fail-over of Multicast traffic, no need to wait for IGMP timeouts.
 Supports different medias fiber optic, copper and SHDSL, although fiber optic links allows for best fail-
over performance.
 Extremely fast convergence time of 20ms means little impact to network in the event of a link failure.
This translates to high resilience!
Layer 2 Redundancy
FRNT
10
Layer 2 Redundancy: FRNT Ring Coupling
FRNT
Master
Ring
FRNT
Sub
Ring
FRNT
Sub
Ring
FRNT
Sub
Ring
11
Layer 2 Redundancy: FRNT Ring Coupling
X
X
X
FRNT
Master Ring
FRNT
Sub Ring
FRNT
Sub Ring
12
 Within the Network Layer, there are many options to add resiliency to a network:
 RIP
 OSPF
 VRRP
 RIP and OSPF are what are called “Dynamic Routing Protocols” which can automatically
determine best paths between networks, for automatic convergence in the event of a
network outage.
 VRRP or “Virtual Router Redundancy Protocol” will automatically designate a router as a
default gateway, with multiple routers configured as backups.
Layer 3 Resiliency: Routing Protocols
13
Routing Protocols create resiliency on L3, between L2 Networks
Dynamic Routing Protocols
FRNT
VRRP
VRRP VRRP
FRNT FRNT
OSPF
OSPF
OSPFOSPF
14
Combining Layer 2 and Layer 3 resilience functionality allows for
extremly high availablity.
FRNT Super Ring
FRNT Sub Ring FRNT Sub Ring
RiCo Node
RiCo Node RiCo Node
RiCo Node
CORE-Network
X
X
X
Link Failure
FRNT Ring Failover
Link Failure
Ring Coupling Failover X
X
Link Failure
FRNT Ring Failover
Link Failure
Ring Coupling Failover
FRNT Ring Failover
Distribution Layer,
Rack/Control rooms
Layer 3
Layer 2
XOSPF Failover OSPF Routing Protocol
Microsegmentation
16
Hybrid L2/L3 Network
L2 ring topology 20-30ms
re-convergence time
L3 routing and FW at each
node creates a Zone
X Dynamic routing protocol (OSPF) used to advertise
location of subnets only, not used for re-convergence
17
Efficient Routing to Minimize Network Delay
Network backbone
Router firewall Router firewall Router firewall
Messages are only ever routed twice
• Once into the backbone
• Second time when leaving backbone
• Messages pass though the FW when entering and leaving the network backbone
18
Multiple Zones
Backbone Fibre
ZONE 1
10.10.10.0/28
ZONE 2
10.20.20.0/28
Traffic cannot pass
between zones
unless it is allowed
to do so
XObject controller
/smart IO
19
Maintainer’s Sandbox Connection
Backbone Fibre
ZONE 1
10.10.10.0/28
ZONE 2
10.20.20.0/28
Traffic cannot pass
between zones
unless it is allowed
to do so
XObject controller
/smart IO
ZONE 3
192.20.20.0/28
Maintainers sandbox entry point,
access to network is FW, if 802.1x
configured only valid
users/machines can join the
network
Configuration Backups
21
Getting Control of the Assets
 Using common UN and PW are an open
door to cyber actors
 Maintainers leave taking the common
credentials with them
 Almost impossible to change UN and PW
across a large user population
 Maintaining a large user DB on each
device is equally difficult
 Solution is to use RADIUS or TACACS+
User Authentication
 Effort required initially, much tighter
control and lower ownership cost long-
term
Authentication
server
22

More Related Content

What's hot

Introducing the next generation industrial switch platform
Introducing the next generation industrial switch platformIntroducing the next generation industrial switch platform
Introducing the next generation industrial switch platform
Westermo Network Technologies
 
4 Easy Steps for Increased Industrial Cybersecurity
4 Easy Steps for Increased Industrial Cybersecurity4 Easy Steps for Increased Industrial Cybersecurity
4 Easy Steps for Increased Industrial Cybersecurity
Westermo Network Technologies
 
SELTA Access Network Portfolio
SELTA Access Network PortfolioSELTA Access Network Portfolio
SELTA Access Network Portfolio
SELTA
 
Profibus commissioning and maintenance - Richard Needham
Profibus commissioning and maintenance - Richard NeedhamProfibus commissioning and maintenance - Richard Needham
Profibus commissioning and maintenance - Richard Needham
PROFIBUS and PROFINET InternationaI - PI UK
 
Ap8163 datasheet
Ap8163 datasheetAp8163 datasheet
Ap8163 datasheet
Advantec Distribution
 
SIS_LineCard_2016
SIS_LineCard_2016SIS_LineCard_2016
SIS_LineCard_2016
Melanie Miller
 
ComNet NWK3 Data Sheet
ComNet NWK3 Data SheetComNet NWK3 Data Sheet
ComNet NWK3 Data Sheet
JMAC Supply
 
Copper cables an alternative to fibre - Extending Industrial Ethernet
Copper cables an alternative to fibre - Extending Industrial EthernetCopper cables an alternative to fibre - Extending Industrial Ethernet
Copper cables an alternative to fibre - Extending Industrial Ethernet
Westermo Network Technologies
 
PI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
PI UK Seminar (Nov 2021) - PROFINET Implementation and TestingPI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
PI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
PROFIBUS and PROFINET InternationaI - PI UK
 
Siemens & TPP Collaboration
Siemens & TPP CollaborationSiemens & TPP Collaboration
Siemens & TPP Collaboration
telemetria
 
ZTE Intelligent Campus Network Solution
ZTE Intelligent Campus Network SolutionZTE Intelligent Campus Network Solution
ZTE Intelligent Campus Network Solution
ZTE Enterprise
 
Zte channel marketing product reference guide 201505(read version)
Zte channel marketing product reference guide 201505(read version)Zte channel marketing product reference guide 201505(read version)
Zte channel marketing product reference guide 201505(read version)
逸云 张
 
PROFINET network diagnostics and support - May 2020 - Peter Thomas
PROFINET network diagnostics and support - May 2020 - Peter ThomasPROFINET network diagnostics and support - May 2020 - Peter Thomas
PROFINET network diagnostics and support - May 2020 - Peter Thomas
PROFIBUS and PROFINET InternationaI - PI UK
 
Jio practical training
Jio  practical training Jio  practical training
Jio practical training
Rasid Khan
 
PI UK Seminar (Nov 2021) - Update on APL
PI UK Seminar (Nov 2021) - Update on APLPI UK Seminar (Nov 2021) - Update on APL
PI UK Seminar (Nov 2021) - Update on APL
PROFIBUS and PROFINET InternationaI - PI UK
 
RUGGEDCOM WIN5100 wimax
RUGGEDCOM WIN5100 wimaxRUGGEDCOM WIN5100 wimax
RUGGEDCOM WIN5100 wimax
ashwini reliserv
 
Ap 6511 ss_0610
Ap 6511 ss_0610Ap 6511 ss_0610
Ap 6511 ss_0610
Advantec Distribution
 
Profinet implementation and testing - Dave Tomlin and Xing Ye
Profinet implementation and testing - Dave Tomlin and Xing YeProfinet implementation and testing - Dave Tomlin and Xing Ye
Profinet implementation and testing - Dave Tomlin and Xing Ye
PROFIBUS and PROFINET InternationaI - PI UK
 
Wifi wimax
Wifi wimaxWifi wimax
Wifi wimax
varun1929
 
Chapter 14 : vlan
Chapter 14 : vlanChapter 14 : vlan
Chapter 14 : vlan
teknetir
 

What's hot (20)

Introducing the next generation industrial switch platform
Introducing the next generation industrial switch platformIntroducing the next generation industrial switch platform
Introducing the next generation industrial switch platform
 
4 Easy Steps for Increased Industrial Cybersecurity
4 Easy Steps for Increased Industrial Cybersecurity4 Easy Steps for Increased Industrial Cybersecurity
4 Easy Steps for Increased Industrial Cybersecurity
 
SELTA Access Network Portfolio
SELTA Access Network PortfolioSELTA Access Network Portfolio
SELTA Access Network Portfolio
 
Profibus commissioning and maintenance - Richard Needham
Profibus commissioning and maintenance - Richard NeedhamProfibus commissioning and maintenance - Richard Needham
Profibus commissioning and maintenance - Richard Needham
 
Ap8163 datasheet
Ap8163 datasheetAp8163 datasheet
Ap8163 datasheet
 
SIS_LineCard_2016
SIS_LineCard_2016SIS_LineCard_2016
SIS_LineCard_2016
 
ComNet NWK3 Data Sheet
ComNet NWK3 Data SheetComNet NWK3 Data Sheet
ComNet NWK3 Data Sheet
 
Copper cables an alternative to fibre - Extending Industrial Ethernet
Copper cables an alternative to fibre - Extending Industrial EthernetCopper cables an alternative to fibre - Extending Industrial Ethernet
Copper cables an alternative to fibre - Extending Industrial Ethernet
 
PI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
PI UK Seminar (Nov 2021) - PROFINET Implementation and TestingPI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
PI UK Seminar (Nov 2021) - PROFINET Implementation and Testing
 
Siemens & TPP Collaboration
Siemens & TPP CollaborationSiemens & TPP Collaboration
Siemens & TPP Collaboration
 
ZTE Intelligent Campus Network Solution
ZTE Intelligent Campus Network SolutionZTE Intelligent Campus Network Solution
ZTE Intelligent Campus Network Solution
 
Zte channel marketing product reference guide 201505(read version)
Zte channel marketing product reference guide 201505(read version)Zte channel marketing product reference guide 201505(read version)
Zte channel marketing product reference guide 201505(read version)
 
PROFINET network diagnostics and support - May 2020 - Peter Thomas
PROFINET network diagnostics and support - May 2020 - Peter ThomasPROFINET network diagnostics and support - May 2020 - Peter Thomas
PROFINET network diagnostics and support - May 2020 - Peter Thomas
 
Jio practical training
Jio  practical training Jio  practical training
Jio practical training
 
PI UK Seminar (Nov 2021) - Update on APL
PI UK Seminar (Nov 2021) - Update on APLPI UK Seminar (Nov 2021) - Update on APL
PI UK Seminar (Nov 2021) - Update on APL
 
RUGGEDCOM WIN5100 wimax
RUGGEDCOM WIN5100 wimaxRUGGEDCOM WIN5100 wimax
RUGGEDCOM WIN5100 wimax
 
Ap 6511 ss_0610
Ap 6511 ss_0610Ap 6511 ss_0610
Ap 6511 ss_0610
 
Profinet implementation and testing - Dave Tomlin and Xing Ye
Profinet implementation and testing - Dave Tomlin and Xing YeProfinet implementation and testing - Dave Tomlin and Xing Ye
Profinet implementation and testing - Dave Tomlin and Xing Ye
 
Wifi wimax
Wifi wimaxWifi wimax
Wifi wimax
 
Chapter 14 : vlan
Chapter 14 : vlanChapter 14 : vlan
Chapter 14 : vlan
 

Similar to How to build resilient industrial networks

Comparative Study of Lora & Sigfox
Comparative Study of Lora & SigfoxComparative Study of Lora & Sigfox
Comparative Study of Lora & Sigfox
Keshav
 
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
Đồng Quốc Vương
 
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
Jiunn-Jer Sun
 
Brk 135 t-ccna_switching
Brk 135 t-ccna_switchingBrk 135 t-ccna_switching
Brk 135 t-ccna_switching
parthasn83
 
Designing 5G NR (New Radio)
Designing 5G NR (New Radio)Designing 5G NR (New Radio)
Designing 5G NR (New Radio)
Qualcomm Research
 
5G network architecture progress
5G network architecture progress5G network architecture progress
5G network architecture progress
Mohammad Anwarul Islam
 
Field mobile tetra flex fmt ver 1 0 highres
Field mobile tetra flex   fmt ver  1 0 highresField mobile tetra flex   fmt ver  1 0 highres
Field mobile tetra flex fmt ver 1 0 highres
сергей пехов
 
UNIT III- 1.RPL.pptx
UNIT III- 1.RPL.pptxUNIT III- 1.RPL.pptx
UNIT III- 1.RPL.pptx
Sangeetha Prakash
 
Allied Telesis IE510-28GSX
Allied Telesis IE510-28GSXAllied Telesis IE510-28GSX
Allied Telesis IE510-28GSX
alliedtelesisnetwork
 
Tendencias de Uso y Diseño de Redes de Interconexión en Computadores Paralel...
Tendencias de Uso y Diseño de Redes de Interconexión  en Computadores Paralel...Tendencias de Uso y Diseño de Redes de Interconexión  en Computadores Paralel...
Tendencias de Uso y Diseño de Redes de Interconexión en Computadores Paralel...
Facultad de Informática UCM
 
Ccna 4 Chapter 1 V4.0 Answers
Ccna 4 Chapter 1 V4.0 AnswersCcna 4 Chapter 1 V4.0 Answers
Ccna 4 Chapter 1 V4.0 Answers
ccna4discovery
 
IoT_standards
IoT_standardsIoT_standards
IoT_standards
João Santos
 
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
PROIDEA
 
Some important networking questions
Some important networking questionsSome important networking questions
Some important networking questions
Srikanth
 
wp233
wp233wp233
Nwk assignment body copy
Nwk assignment body   copyNwk assignment body   copy
Nwk assignment body copy
Tonny Michael
 
Network Level Redundancy for Campus LAN
Network Level Redundancy for Campus LANNetwork Level Redundancy for Campus LAN
Network Level Redundancy for Campus LAN
ijtsrd
 
dan-web5g.pptx
dan-web5g.pptxdan-web5g.pptx
dan-web5g.pptx
UtkarshMishra600872
 
Network interview questions
Network interview questionsNetwork interview questions
Network interview questions
rajasekar1712
 
14th rio wireless alberto boaventura oi v1.0
14th rio wireless   alberto boaventura oi v1.014th rio wireless   alberto boaventura oi v1.0
14th rio wireless alberto boaventura oi v1.0
Alberto Boaventura
 

Similar to How to build resilient industrial networks (20)

Comparative Study of Lora & Sigfox
Comparative Study of Lora & SigfoxComparative Study of Lora & Sigfox
Comparative Study of Lora & Sigfox
 
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
Www ccnav5 net_ccna_1_chapter_4_v5_0_exam_answers_2014
 
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
Broadcast Storm - The Root Causes And The Solutions - Whitepaper 2012
 
Brk 135 t-ccna_switching
Brk 135 t-ccna_switchingBrk 135 t-ccna_switching
Brk 135 t-ccna_switching
 
Designing 5G NR (New Radio)
Designing 5G NR (New Radio)Designing 5G NR (New Radio)
Designing 5G NR (New Radio)
 
5G network architecture progress
5G network architecture progress5G network architecture progress
5G network architecture progress
 
Field mobile tetra flex fmt ver 1 0 highres
Field mobile tetra flex   fmt ver  1 0 highresField mobile tetra flex   fmt ver  1 0 highres
Field mobile tetra flex fmt ver 1 0 highres
 
UNIT III- 1.RPL.pptx
UNIT III- 1.RPL.pptxUNIT III- 1.RPL.pptx
UNIT III- 1.RPL.pptx
 
Allied Telesis IE510-28GSX
Allied Telesis IE510-28GSXAllied Telesis IE510-28GSX
Allied Telesis IE510-28GSX
 
Tendencias de Uso y Diseño de Redes de Interconexión en Computadores Paralel...
Tendencias de Uso y Diseño de Redes de Interconexión  en Computadores Paralel...Tendencias de Uso y Diseño de Redes de Interconexión  en Computadores Paralel...
Tendencias de Uso y Diseño de Redes de Interconexión en Computadores Paralel...
 
Ccna 4 Chapter 1 V4.0 Answers
Ccna 4 Chapter 1 V4.0 AnswersCcna 4 Chapter 1 V4.0 Answers
Ccna 4 Chapter 1 V4.0 Answers
 
IoT_standards
IoT_standardsIoT_standards
IoT_standards
 
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
PLNOG 8: Emil Gągała - DATA CENTER FABRIC COOKBOOK
 
Some important networking questions
Some important networking questionsSome important networking questions
Some important networking questions
 
wp233
wp233wp233
wp233
 
Nwk assignment body copy
Nwk assignment body   copyNwk assignment body   copy
Nwk assignment body copy
 
Network Level Redundancy for Campus LAN
Network Level Redundancy for Campus LANNetwork Level Redundancy for Campus LAN
Network Level Redundancy for Campus LAN
 
dan-web5g.pptx
dan-web5g.pptxdan-web5g.pptx
dan-web5g.pptx
 
Network interview questions
Network interview questionsNetwork interview questions
Network interview questions
 
14th rio wireless alberto boaventura oi v1.0
14th rio wireless   alberto boaventura oi v1.014th rio wireless   alberto boaventura oi v1.0
14th rio wireless alberto boaventura oi v1.0
 

More from Westermo Network Technologies

Westermo Technologie Webinar WeOS4 und WeOS5
Westermo Technologie Webinar WeOS4 und WeOS5Westermo Technologie Webinar WeOS4 und WeOS5
Westermo Technologie Webinar WeOS4 und WeOS5
Westermo Network Technologies
 
Westermo Webinar - Geroutete Redundanzen
Westermo Webinar - Geroutete RedundanzenWestermo Webinar - Geroutete Redundanzen
Westermo Webinar - Geroutete Redundanzen
Westermo Network Technologies
 
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdfWebinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
Westermo Network Technologies
 
Webinar WeConfig - State of the Art NCM
Webinar WeConfig - State of the Art NCMWebinar WeConfig - State of the Art NCM
Webinar WeConfig - State of the Art NCM
Westermo Network Technologies
 
Webinar Serial-over-IP
Webinar Serial-over-IPWebinar Serial-over-IP
Webinar Serial-over-IP
Westermo Network Technologies
 
Webinar - Protokollkonvertierung
Webinar - ProtokollkonvertierungWebinar - Protokollkonvertierung
Webinar - Protokollkonvertierung
Westermo Network Technologies
 
OpenWRT - Überblick
OpenWRT - ÜberblickOpenWRT - Überblick
OpenWRT - Überblick
Westermo Network Technologies
 
DHCP
DHCPDHCP
Switchkonfiguration
SwitchkonfigurationSwitchkonfiguration
Switchkonfiguration
Westermo Network Technologies
 
PoE & Lösungen.pdf
PoE & Lösungen.pdfPoE & Lösungen.pdf
PoE & Lösungen.pdf
Westermo Network Technologies
 
VPN&Verschlüsselung
VPN&VerschlüsselungVPN&Verschlüsselung
VPN&Verschlüsselung
Westermo Network Technologies
 
Mobilfunkanbindungen
MobilfunkanbindungenMobilfunkanbindungen
Mobilfunkanbindungen
Westermo Network Technologies
 
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
Westermo Network Technologies
 
Netzwerkmonitoring.pdf
Netzwerkmonitoring.pdfNetzwerkmonitoring.pdf
Netzwerkmonitoring.pdf
Westermo Network Technologies
 
Firewall.pdf
Firewall.pdfFirewall.pdf
WeOS 4.32.0 und WeConfig 1.15.pdf
WeOS 4.32.0 und WeConfig 1.15.pdfWeOS 4.32.0 und WeConfig 1.15.pdf
WeOS 4.32.0 und WeConfig 1.15.pdf
Westermo Network Technologies
 
WLAN
WLANWLAN
Merlin - Die neue Mobilfunkrouterserie
Merlin - Die neue MobilfunkrouterserieMerlin - Die neue Mobilfunkrouterserie
Merlin - Die neue Mobilfunkrouterserie
Westermo Network Technologies
 
We os 4.31.0 und weconfig 1.14.0
We os 4.31.0 und weconfig 1.14.0We os 4.31.0 und weconfig 1.14.0
We os 4.31.0 und weconfig 1.14.0
Westermo Network Technologies
 
Layer 2 Redundanzen
Layer 2 RedundanzenLayer 2 Redundanzen
Layer 2 Redundanzen
Westermo Network Technologies
 

More from Westermo Network Technologies (20)

Westermo Technologie Webinar WeOS4 und WeOS5
Westermo Technologie Webinar WeOS4 und WeOS5Westermo Technologie Webinar WeOS4 und WeOS5
Westermo Technologie Webinar WeOS4 und WeOS5
 
Westermo Webinar - Geroutete Redundanzen
Westermo Webinar - Geroutete RedundanzenWestermo Webinar - Geroutete Redundanzen
Westermo Webinar - Geroutete Redundanzen
 
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdfWebinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
Webinar - WeOS 4.33.0 und WeConfig 1.19.0.pdf
 
Webinar WeConfig - State of the Art NCM
Webinar WeConfig - State of the Art NCMWebinar WeConfig - State of the Art NCM
Webinar WeConfig - State of the Art NCM
 
Webinar Serial-over-IP
Webinar Serial-over-IPWebinar Serial-over-IP
Webinar Serial-over-IP
 
Webinar - Protokollkonvertierung
Webinar - ProtokollkonvertierungWebinar - Protokollkonvertierung
Webinar - Protokollkonvertierung
 
OpenWRT - Überblick
OpenWRT - ÜberblickOpenWRT - Überblick
OpenWRT - Überblick
 
DHCP
DHCPDHCP
DHCP
 
Switchkonfiguration
SwitchkonfigurationSwitchkonfiguration
Switchkonfiguration
 
PoE & Lösungen.pdf
PoE & Lösungen.pdfPoE & Lösungen.pdf
PoE & Lösungen.pdf
 
VPN&Verschlüsselung
VPN&VerschlüsselungVPN&Verschlüsselung
VPN&Verschlüsselung
 
Mobilfunkanbindungen
MobilfunkanbindungenMobilfunkanbindungen
Mobilfunkanbindungen
 
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
450 MHz – Das neue Medium in OT-Netzwerken der Energiewirtschaft
 
Netzwerkmonitoring.pdf
Netzwerkmonitoring.pdfNetzwerkmonitoring.pdf
Netzwerkmonitoring.pdf
 
Firewall.pdf
Firewall.pdfFirewall.pdf
Firewall.pdf
 
WeOS 4.32.0 und WeConfig 1.15.pdf
WeOS 4.32.0 und WeConfig 1.15.pdfWeOS 4.32.0 und WeConfig 1.15.pdf
WeOS 4.32.0 und WeConfig 1.15.pdf
 
WLAN
WLANWLAN
WLAN
 
Merlin - Die neue Mobilfunkrouterserie
Merlin - Die neue MobilfunkrouterserieMerlin - Die neue Mobilfunkrouterserie
Merlin - Die neue Mobilfunkrouterserie
 
We os 4.31.0 und weconfig 1.14.0
We os 4.31.0 und weconfig 1.14.0We os 4.31.0 und weconfig 1.14.0
We os 4.31.0 und weconfig 1.14.0
 
Layer 2 Redundanzen
Layer 2 RedundanzenLayer 2 Redundanzen
Layer 2 Redundanzen
 

Recently uploaded

Oracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptxOracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptx
Remote DBA Services
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
Neo4j
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Neo4j
 
APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)
Boni García
 
openEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain SecurityopenEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain Security
Shane Coughlan
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Undress Baby
 
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise EditionWhy Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Envertis Software Solutions
 
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
Alina Yurenko
 
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
kalichargn70th171
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Łukasz Chruściel
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate
 
Webinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for EmbeddedWebinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for Embedded
ICS
 
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
mz5nrf0n
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
Fermin Galan
 
Fundamentals of Programming and Language Processors
Fundamentals of Programming and Language ProcessorsFundamentals of Programming and Language Processors
Fundamentals of Programming and Language Processors
Rakesh Kumar R
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
Hornet Dynamics
 
Artificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension FunctionsArtificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension Functions
Octavian Nadolu
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
Adele Miller
 

Recently uploaded (20)

Oracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptxOracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptx
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
 
APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)
 
openEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain SecurityopenEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain Security
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
 
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise EditionWhy Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
 
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
 
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
 
Webinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for EmbeddedWebinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for Embedded
 
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
 
Fundamentals of Programming and Language Processors
Fundamentals of Programming and Language ProcessorsFundamentals of Programming and Language Processors
Fundamentals of Programming and Language Processors
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
 
Artificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension FunctionsArtificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension Functions
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
 

How to build resilient industrial networks

  • 2. Agenda  Introductions  Who is Westermo  Defining Network Resiliency  Hardware Redundancy  Microsegmentation  Configuration Backups
  • 3. 3 Introductions Dakota Diehl Network Application Engineer dakota.diehl@westermo.us 847.453.3899 Benjamin Campbell Technical Support Engineer benjamin.campbell@westermo.us 847.453.3896
  • 4. 4 Westermo Group 2020  Founded in 1975  Industry leading software and hardware development force  Own production in Sweden with state of the art process control  Own sales and support units in 12 key countries, distribution partners in many others
  • 5. How To Build a Resilient Network
  • 6. 6  Resilience in computer networks is the “ability to provide and maintain an acceptable level of service in the face of faults and challenges to normal operation.”  This is a very wide definition, as it covers everything from packet loss to complete failure of a node or link.  Also includes the ability to defend against and respond to cybersecurity attacks, whether malicious or unintended misconfigurations.  The more resilient a network is, the more tolerant it is to faults or errors across the network and can maintain uptime.  Because of the wide definition, there are also a multitude of ways to improve your network’s resilience. Resiliency – What is it?
  • 8. 8  One of the most straightforward ways to improve resiliency is to add redundancy  If one node or link suffers a catastrophic failure, redundant connections keep the network running without impacting performance.  Unfortunately, not as simple as just dropping in another switch to the network!  Layer 2 protocols such as FRNT or RSTP manage ring topologies, adding extra paths to nodes without causing debilitating Broadcast Storms.  Layer 3 protocols such as OSPF and VRRP can automatically designate a route between networks and failover in the event of broken links. Hardware Redundancy
  • 9. 9  Built in functions to avoid uncontrolled broadcast storms.  Link integrity control.  Non-FRNT ports are not allowed to communicate with FRNT ports.  Default FRNT alarm signaling via SNMP, LED, Digital-Out and Syslog.  Very fast fail-over of Multicast traffic, no need to wait for IGMP timeouts.  Supports different medias fiber optic, copper and SHDSL, although fiber optic links allows for best fail- over performance.  Extremely fast convergence time of 20ms means little impact to network in the event of a link failure. This translates to high resilience! Layer 2 Redundancy FRNT
  • 10. 10 Layer 2 Redundancy: FRNT Ring Coupling FRNT Master Ring FRNT Sub Ring FRNT Sub Ring FRNT Sub Ring
  • 11. 11 Layer 2 Redundancy: FRNT Ring Coupling X X X FRNT Master Ring FRNT Sub Ring FRNT Sub Ring
  • 12. 12  Within the Network Layer, there are many options to add resiliency to a network:  RIP  OSPF  VRRP  RIP and OSPF are what are called “Dynamic Routing Protocols” which can automatically determine best paths between networks, for automatic convergence in the event of a network outage.  VRRP or “Virtual Router Redundancy Protocol” will automatically designate a router as a default gateway, with multiple routers configured as backups. Layer 3 Resiliency: Routing Protocols
  • 13. 13 Routing Protocols create resiliency on L3, between L2 Networks Dynamic Routing Protocols FRNT VRRP VRRP VRRP FRNT FRNT OSPF OSPF OSPFOSPF
  • 14. 14 Combining Layer 2 and Layer 3 resilience functionality allows for extremly high availablity. FRNT Super Ring FRNT Sub Ring FRNT Sub Ring RiCo Node RiCo Node RiCo Node RiCo Node CORE-Network X X X Link Failure FRNT Ring Failover Link Failure Ring Coupling Failover X X Link Failure FRNT Ring Failover Link Failure Ring Coupling Failover FRNT Ring Failover Distribution Layer, Rack/Control rooms Layer 3 Layer 2 XOSPF Failover OSPF Routing Protocol
  • 16. 16 Hybrid L2/L3 Network L2 ring topology 20-30ms re-convergence time L3 routing and FW at each node creates a Zone X Dynamic routing protocol (OSPF) used to advertise location of subnets only, not used for re-convergence
  • 17. 17 Efficient Routing to Minimize Network Delay Network backbone Router firewall Router firewall Router firewall Messages are only ever routed twice • Once into the backbone • Second time when leaving backbone • Messages pass though the FW when entering and leaving the network backbone
  • 18. 18 Multiple Zones Backbone Fibre ZONE 1 10.10.10.0/28 ZONE 2 10.20.20.0/28 Traffic cannot pass between zones unless it is allowed to do so XObject controller /smart IO
  • 19. 19 Maintainer’s Sandbox Connection Backbone Fibre ZONE 1 10.10.10.0/28 ZONE 2 10.20.20.0/28 Traffic cannot pass between zones unless it is allowed to do so XObject controller /smart IO ZONE 3 192.20.20.0/28 Maintainers sandbox entry point, access to network is FW, if 802.1x configured only valid users/machines can join the network
  • 21. 21 Getting Control of the Assets  Using common UN and PW are an open door to cyber actors  Maintainers leave taking the common credentials with them  Almost impossible to change UN and PW across a large user population  Maintaining a large user DB on each device is equally difficult  Solution is to use RADIUS or TACACS+ User Authentication  Effort required initially, much tighter control and lower ownership cost long- term Authentication server
  • 22. 22