User Manual
Intended Operation Environment (Including Deployment Options)
Tunneled Network Deployment
3
24 | 28
A6V11917735_en_b_41
● Use firewall to protect the PACE zone.
● A
direct
connection is established between the PACE zone with a dedicated
cable.
Novigo/Cerberus PACE – Plant
● Physically separated network or standalone station.
● Forms a PACE zone.
● Access to the PACE zone only through an external firewall.
● Configure the computer with PACE-Design as access point to the Cerberus
PACE – Plant.
Computer with PACE-Design
● It must be part of the PACE zone.
● It must not have connection to other networks or systems.
● A
direct
connection is established between the PACE zone and the component
in the protection zone.
● Can be connected to any PN2005.
Direct
means that both devices and their cable connection are visible at the same
time and thus a potential manipulation might be recognizable.
MMS Multi-homed Local Access
Local access to a Novigo/Cerberus PACE system with a multi-homed management
station (MMS):
Figure 9: MMS Multi-homed Local Access
PACE- Zone
Fire Brigade
Call Station
PT2002
Switch 1 x 8/2
PN2005
Audio Matrix
PC200X
Desk
Call Station
PT2001
B
B
A
A
A
A
Switch 1 x 8/2
PN2005
Switch 1 x 8/2
PN2005
Switch 1 x 8/2
PN2005
Audio Matrix
PC200X
Audio Matrix
PC200X
Fiber MM, SM, or Ethernet RJ45
Ethernet RJ45
A
ZBP + VPN-EP
PACE- PC
UTNW
MMS
VPN