User Guide
Table Of Contents
System Security Guidelines
Protected System Configuration
3
A6V11979523_en_b
13 | 26
3.2.1 Zone Boundary Protection
NK823x system is a safety-related system that must be protected from attacks and
unauthorized access from untrusted networks, for example, the Internet.
The plant operator is responsible for network planning and design, including the
zone boundary protection.
NK823x system is a physically separated network that forms a Protected Zone.
The zone boundary protection has the function Inbound Protection/Outbound
Protection for the Protected Zone. A separate VLAN does not meet the
requirements for zone boundaries protection (ZBP).
For any connection to external networks or other systems the corresponding
protection must be provided at the border of the Protected Zone.
Local connections to the system do not require additional protective measures if
the system accessing the Protected Zone is stand-alone and thus has no
interfaces to other systems.
For systems remotely accessing the Protected Zone (see Tunneled Network
Deployment [➙ 21]), protective measures are required.
Fig. 3: Protected Zone
AlgoRex
CS11 STT11/20
DF8000
Sintony
SI410
Protected Zone
ZBP + VPN-EP
FS20