Make Every Endpoint Your Strongest Link
Futureproof Your Industrial Network Security
In today’s connected industrial environments, device hardening is essential to defend against evolving cyber threats. Moxa’s long-standing expertise and certified solutions ensure your operations stay resilient, secure, and uninterrupted.

Built-In Security by Design
Moxa devices feature safeguard critical edge components.

Proven Cybersecurity Credentials
Moxa is among the first globally to achieve both IEC 62443-4-1 and 62443-4-2 certifications.

Reliable Solutions
Our secure products are engineered to minimize risk, maximize uptime, and protect network integrity in even the harshest environments.
Find the Secure Netowrking Products That Match Your Demands
| Secure Switches |
MDS-G4000 |
RKS-G4028 |
EDS-G4000 |
EDS-500E |
SDS-3000 |
| Ports | Up to 4 10GbE + 24 GbE | Up to 28 GbE | Up to 6 2.5GbE + 8 GbE | Up to 4 GbE + 24 FE | Up to 16 GbE |
| Security Features | HTTPS, SSL/SSH, ACL, IEEE 802.1X, Port Security, DHCP Snooping, Secure Boot*1 | HTTPS, SSL/SSH, ACL, IEEE 802.1X, Port Security, DHCP Snooping, Secure Boot | HTTPS, SSL/SSH, ACL*2, IEEE 802.1X | HTTPS, SSL, Port Lock | |
| Redundancy Protocols | Turbo Ring, Turbo Chain, RSTP/STP, MRP, VRRP (L3 Model) | Turbo Ring, Turbo Chain, RSTP/STP, MRP | RSTP/STP, MRP | ||
| Software Management | MXview One | ||||
| Industrial Certifications | IEC 61850-3, IEEE 1613, EN 50121-4, NEMA TS2, ATEX*3, CID2*3 | IEC 62443-4-2 SL2, IEC 61850-3, IEEE 1613, EN 50121-4, NEMA TS2 | IEC 62443-4-2 SL2, IEC 61850-3, IEEE 1613 (Class 1), DNV*4, ABS*4, NK*4, LR*4, EN 50121-4, NEMA TS2, ATEX*5, CID2*5, IECEx*5 | IEC 61850-3, IEEE 1613, DNV*6, ABS*6, NK*6, LR*6, EN 50121-4*6, NEMA TS2*6, ATEX*6, CID2*6 | |
*1. Only available for -4XGS models.
*2. Only available for 18 and 28 port models.
*3. Only available for the non-4XGS models.
*4. Only available for -LV and PoE models.
*5. Only available for -LV models.
*6. Only available for 10 and 18 port models.
| Secure Routers |
EDR-G9010 |
EDR-G9004 |
EDR-8010 |
NAT-102 |
NAT-108 |
| Ports | 2 2.5GbE + 8 GbE*1 | Up to 2 2.5GbE + 2 GbE (1/2 DMZ/WAN ports) | 2 GbE + 8 FE*1 | 2 FE | 8 FE |
| NAT | 1-to-1, N-to-1, NAT loopback, Port forwarding, IP Twins Mapping*4 | ||||
| Firewalls | DDoS, Ethernet protocols, ICMP, IP address, MAC address, Ports | IP address, MAC address (Device Lockdown), Ports | |||
| IPS/IDS | Requires an additional license | - | - | ||
| DPI | DNP3, EtherNet/IP, IEC 60870-5-104, IEC 61850 MMS, Modbus TCP, Modbus UDP, Omron FINS, Siemens S7 Comm., Siemens S7 Comm. Plus, OPC UA, MELSEC communication protocol | - | - | ||
| VPN | Up to 250 IPsec VPN tunnels | Up to 50 IPsec VPN tunnels | - | - | |
| Routing Throughput (based on RFC 2544) | Max. 350K packets per second / 2 Gbps | Max. 50K packets per second / 500 Mbps | Max. 15K packets per second /100 Mbps | ||
| Redundancy Protocols | VRRP, Turbo Ring, Turbo Chain, RSTP/STP | VRRP | VRRP, Turbo Ring, Turbo Chain, RSTP/STP | - | - |
| Software Management | MXview One, MXview Security*3, MXsecurity | MXview One, MXview Security*3, MXsecurity | MXview One, MXview Security*3, MXsecurity | MXview One | MXview One |
| Industrial Certifications | IEC 62443-4-2 SL2, IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX*2, CID2*2, EN 50121-4*2, NEMA TS2*2, DNV*2, DNV IEC 61162-460 Edition 3.0*2, DNV security profile 2*2, IACS UR E27 Rev.1*2, IEC 60945*2 | IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX, CID2, IECEx, EN 50121-4, NEMA TS2, DNV | IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX, CID2, IECEx, EN 50121-4, NEMA TS2, DNV, DNV IEC 61162-460 Edition 3.0, DNV security profile 2, IACS UR E27 Rev.1, IEC 60945 | EN 50121-4, NEMA TS2, ATEX, CID2 | - |
| LAN Firewalls |
EDF-G1002-BP |
| Ports | 2 GbE (Gen3 LAN Bypass) |
| Firewalls | DDoS, Ethernet protocols, ICMP, IP address, MAC address, Ports |
| IPS/IDS | Enabled by default. IPS pattern update functionality requires an additional license. |
| DPI | DNP3, EtherNet/IP, IEC 60870-5-104, IEC 61850 MMS, Modbus TCP, Modbus UDP, Omron FINS, Siemens S7 Comm., Siemens S7 Comm. Plus, OPC UA, MELSEC communication protocol |
| Software Management | MXview One, MXview Security*1, MXsecurity |
| Industrial Certifications | NEMA TS2, EN 50121-4, CID2, ATEX, IECEx, DNV |
| Key Features |
NPort 5000/5000A Series*1 Serial Device Servers |
NPort 6000 Series Secure Terminal Servers |
MGate MB3000/5000 Series*2 Protocol Gateways |
ioThinx 4510 Series Modular Remote I/Os |
| User Authentication & Authorization | Password protection (length, character enforcement) | Password protection (length, character enforcement) Authentication servers (RACIUS/TACACS+) Customized privilege for different user groups | Password protection (length, character enforcement) | Password protection (length, character enforcement) |
| Device Integrity | Check CRC code before update the device | |||
| Device Least Functionality | Security Hardening Guide Unused services can be disabled Telnet console default disabled | Security Hardening Guide Unused services can be disabled Telnet console default disabled | Security Hardening Guide (MGate MB3000/5000 Series) Unused services can be disabled Disabled the default setting of the Telnet console | Security Hardening Guide Unused services can be disabled |
| Communication Integrityt | HTTPS (TLS 1.2 embedded with self-signed certificate) SNMPv3 | HHTTPS (TLS 1.2 embedded with self-signed certificate, also supports public certificate import) SSH/SNMPv3 ECC 256 (RSA-4096) | HTTPS (TLS 1.2 embedded with self-signed certificate), also support public certificate import SNMPv3 | HTTPS (TLS 1.2 embedded with self-signed certificate, and can be exported) SNMPv3 |
| Network Access Control | Accessible IP List Access Control List (ACL) | |||
| Securing Your Devices in Daily Maintenance | ||||
| Configuration Management | GUI type of MXconfig CLI type of MCC tools | |||
| Device Management | Syslog Manageable via MXview Network Management Software | |||
| Vulnerability Management | Dedicated Cybersecurity Response Team for handling vulnerability Perform Nessus Scan | |||
Make Secure Network Infrastructure Easier to Deploy and Maintain
The Security Check function in MXview One can automatically scan device configurations, detect security gaps, and provide actionable hardening recommendations, making it easier to build a resilient, self-protecting industrial network.
- System Network Hardening: Visualizes redundant link status and device roles in network redundancy protocols. A centralized dashboard offers a quick overview of overall network status.
- Device Hardening: Displays the security status of network devices in accordance with industrial security standards, helping ensure compliance and improved protection.
MDS-G4000
RKS-G4028
EDS-G4000
EDS-500E
SDS-3000
EDR-G9010
EDR-G9004
EDR-8010
NAT-102
NAT-108
EDF-G1002-BP
NPort 5000/5000A Series*1 Serial Device Servers
NPort 6000 Series Secure Terminal Servers
MGate MB3000/5000 Series*2 Protocol Gateways
ioThinx 4510 Series Modular Remote I/Os