Empowering the System Network Hardening with Unyielding Defense
Achieving Network Security for Industrial Automation
To optimize operational efficiency for modern industrial automation systems, network convergence between OT and IT is imperative. While streamlining your OT/IT networks unlocks the potential of your industrial systems, it also raises network security concerns. It is a particular concern for OT systems that were air gapped but must still protect network communications without interrupting operations. As a leader in industrial networking for over 35 years, Moxa is committed to developing secure and reliable networking solutions that proactively identify and mitigate cyberthreats in OT environments. To realize this commitment, Moxa strictly follows secure-by-design practices, utilizes distributed OT intrusion prevention systems capabilities, and provides a wide range of rugged networking portfolios to perfect defending industrial applications in depth.

Identify Network Status
Enhance the visibility and management of your network status, device security levels, and remote connections.

Secure Network Infrastructure
Build security boundaries with an orchestrated network topology design to enhance network security.

Secure Edge Connectivity
Secure your edge connectivity at every stage from initial deployment to daily maintenance.
- Abnormal disconnections or intrusion threats may not be detected if the network status cannot be visualized.
- Network devices lacking self-secure capabilities are vulnerable to attackers who can easily alter the configurations, such as disabling redundant features or enabling remote operation mode.
Visualize Device and Network Security Status
The Moxa MXview One next-generation network management software is designed for monitoring and diagnosing devices in industrial networks. It provides an integrated management platform for discovering network devices and SNMP/IP devices installed on the subnet. Network devices can be managed anytime, anywhere, whether at a local or remote site, or even through a web browser.
Solution: Real-time Network Visibility
- Speed up troubleshooting with real-time visibility.
- Built-in dashboards allow you to review network topology, traffic, incidents, and roaming logs at any time.
- Visualizing network management enables faster response times to ensure that the network runs smoothly without interruptions.
- Using unmanaged switches extensively on production lines increases the risk of intrusion
- Unauthorized individuals can cause system instability by maliciously altering network settings through physical network ports
- Unable to identify unauthorized remote connections within the network
- Cyber attacks, such as ransomware, are spreading across the network
Protect Industrial Networks and Critical Assets
You need secure network infrastructure to ensure continuous industrial operations. Moxa’s product portfolio not only provides powerful secure routers to build solid network segmentation, but also offers industrial cybersecurity solutions to strengthen protection for your industrial networks and critical assets.
Solution: Co-defense by Network Segmentation with Secure Routers
Establish Zones and Conduits
- Firewalls : Moxa’s devices help administrators establish conduits in the network to only allow permitted traffic and packets to transfer from one zone to another.
- NAT: Moxa’s devices help administrators establish a private local zone to hide internal network information from external probing.
- IPS: Moxa’s devices prevent exploitation of known vulnerabilities on Windows systems and help protect legacy Windows devices that have no support with patch updates.
- IDS: Moxa’s devices can identify cyberattacks and contain them within certain zones; also, they notify administrators by utilizing IPS pattern matching.
Network Security Control
- VLAN ID or MAC Addresses: Moxa’s devices only allow users to access data and networks based on their roles.
- IP Addresses and Ports: Moxa’s devices only allow permitted traffic on the network.
- Deep Packet Inspection: Moxa’s devices check the content of each packet payload to ensure only approved content is transmitted on the networks.
Our EDR-G9010 Series of industrial secure routers allow you to flexibly design defense-in-depth security architecture by leveraging its all-in-one firewall/NAT/VPN/switch functions. It features OT deep packet inspection technology to provide advanced network protection. Furthermore, with the addition of IDS/IPS, the EDR-G9010 Series is an industrial next-generation firewall, equipped with threat detection and prevention capabilities to further protect critical infrastructure from cybersecurity attacks.
Solution: Access Control with Security-hardened Switches
Switch
- VLAN: Restricting user access to specific data and network segments to enhance security and improve network efficiency.
- ACL: Allowing or blocking network traffic based on predefined rules to protect critical resources from unauthorized access.
- Port-lock: Limiting device connections to the network by allowing only authorized devices, reducing the risk of unauthorized access.
With the security-hardened EDS-G4014 Series ethernet switches, you can segregate traffic between different network segments using a VLAN and utilize Access Control Lists (ACL) at the port level, helping you improve VLAN security when data enters your networks through Ethernet switches.
- Networks without access restrictions allows rogue devices to join freely, opening doors to external parties.
- A flat network with mixed traffic can cause poor privilege separation and inefficient traffic management.
- Networks without access restrictions allows rogue devices to join freely, opening doors to external parties.
- A flat network with mixed traffic can cause poor privilege separation and inefficient traffic management.
Secure Edge Connectivity in Every Aspect
A Secure Edge-Connectivity Solution should focus on two essential elements. The first is trusted access and network optimization. This includes using port locks to restrict physical ports, ensuring that only authorized devices can connect. Additionally, implementing VLANs and Quality of Service (QoS) helps segment traffic and prioritize critical packets, maximizing available bandwidth. The second essential is secure data transmission, which can be achieved through end-to-end encryption. By utilizing SSL or SSH, all traffic is protected during the collection and forwarding of data, ensuring security throughout the process.
Solution: Co-defense by Network Segmentation with Smart Switches
- VLAN: Moxa’s devices help administrators restrict users access to only data and parts of the network necessary for them to perform their duties.
- Port-lock: Limiting access to the network and ensuring only authorized devices can connect. This helps reduce the attack surface by preventing unauthorized or malicious devices from gaining access.
Solution: Ensure Data Integrity and Confidentiality
- Ensuring the integrity of data transmission is a top priority when connecting serial devices to the network for various applications. The NPort® 6000 supports SSL and SSH protocols to encrypt data before transmitting over the network.