EasyManua.ls Logo

Allen-Bradley Stratix 5950 User Manual

Allen-Bradley Stratix 5950
130 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Stratix 5950 Security Appliance
Catalog Numbers 1783-SAD4T0SBK9, 1783-SAD4T0SPK9, 1783-SAD2T2SBK9, 1783-SAD2T2SPK9
User Manual
Original Instructions

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Allen-Bradley Stratix 5950 and is the answer not in the manual?

Allen-Bradley Stratix 5950 Specifications

General IconGeneral
SeriesStratix 5950
CategorySecurity Appliance
MountingDIN Rail
Switching Capacity20 Gbps
Power SupplyRedundant DC input
Operating Temperature70 °C
Security FeaturesFirewall, VPN, IPS
ManagementWeb-based, CLI, SNMP
Ports8 x 10/100/1000Base-T RJ45 ports, 2 x 100/1000Base-X SFP ports

Summary

Preface

Chapter 1 About the Security Appliance

Overview

Provides a general introduction to the Stratix 5950 Security Appliance and its key features.

Hardware Features

Details the physical components, ports, and specifications of the Stratix 5950 Security Appliance.

Status Indicators

Describes the status indicators for the Stratix 5950 Security Appliance, including EIP ModStatus, Ports, and Power Inputs.

Installation and Setup

Explains how to install the security appliance and use the Express Setup button for initial configuration.

Chapter 2 Industrial Firewall Use Cases

Industrial Firewall Technology Overview

Introduces industrial firewall technology and its role in securing industrial automation networks.

Logical Framework

Presents a logical overview of the industrial firewall (IFW) components: ASA and FirePOWER modules.

Network Protection

Discusses how firewalls segment networks and prevent unauthorized traffic entry or exit.

Intrusion Prevention and Detection

Explains Deep Packet Inspection (DPI) and how FirePOWER provides Intrusion Prevention Systems (IPS) and IDS.

Firewall Modes and Configurations

Covers Transparent Mode, Routed Mode, and NAT configurations for industrial firewalls.

Cell/Area Zone Protection

Describes architectures for Redundant Star and Ring Cell/Area Zone Protection using firewalls.

Time Synchronization

Details the process for configuring time synchronization using NTP for firewall and FirePOWER components.

Chapter 3 Configure the Security Appliance

Prerequisites and Initial Setup

Lists prerequisites and outlines initial setup steps including Ethernet devices, device setup, and startup wizard.

Configure FirePOWER Administrative Settings

Guides through configuring administrative settings for the FirePOWER module using PuTTY.

Configure HTTPS Certificate Information

Details the steps to configure HTTPS certificate information for secure access.

Test Policy for CIP Traffic

Explains how to create a test policy to block CIP administrative traffic and verify DPI functionality.

Change Device to Blocking Mode

Describes how to switch the security appliance from Monitor Mode to Full Blocking Configuration.

Configure Precision Time Protocol (PTP)

Provides instructions for configuring Precision Time Protocol (PTP) to synchronize device clocks.

Chapter 4 Monitor the Security Appliance

Status Indicators

Describes the various status indicators on the Stratix 5950 Security Appliance and their meanings.

Chapter 5 Centralized Management

Overview

Discusses the benefits and approach of centralized management for multiple security appliances.

FireSIGHT Management Center

Explains how FireSIGHT Management Center manages the FirePOWER module for comprehensive security.

Cisco Security Manager (CSM)

Details Cisco Security Manager's role in scalable, centralized management of the firewall component.

Management Recommendations

Provides recommendations for managing the IFW, favoring centralized management for most deployments.

Chapter 6 Hardware Bypass

Hardware Bypass Overview

Explains hardware bypass relay support, triggered by power failure or manual CLI commands.

ASA CLI Commands for Hardware Bypass

Lists ASA CLI commands to support hardware bypass feature configuration and status checking.

Hardware Bypass Limitations

Discusses considerations and limitations when enabling the hardware bypass feature.

Chapter 7 CIP Inspection

CIP Preprocessor

Describes the CIP preprocessor's role in interpreting the CIP protocol for policy rule authoring.

CIP Access Control Policies

Recommends using CIP Application Categories to configure CIP rules in Access Control Policies.

CIP Intrusion Policies

Details specifying CIP protocol parameters for granular traffic identification using IDS preprocessor rules.

Chapter 8 Firewall Modes

Firewall Modes Overview

Explains the two ASA firewall modes: Routed and Transparent, and FirePOWER module modes.

Industrial Firewall Deployment Considerations

Discusses placement and deployment options (inline, passive) based on policy enforcement and risk tolerance.

Inline Transparent Mode

Describes the 'bump in the wire' transparent mode where traffic is inspected by the firewall.

Inline Transparent Monitor-only Mode

Explains monitor-only mode for evaluating traffic without impacting the network, logging events only.

Inline Routed Mode

Covers routed mode where the ASA acts as a layer 3 router hop in the network.

Passive Monitor-only Mode

Details passive monitor-only mode for non-impacting traffic monitoring via SPAN ports.

Machine/Skid Protection

Describes use cases for separating machines/skids from higher-level networks for security.

Redundant Star Cell/Area Zone Protection

Explains firewall placement for redundant star network configurations supporting Layer 2 EtherChannel links.

Chapter 9 Updating the Device

Updating ASDM Software

Step-by-step guide to update the ASDM software image from a local computer.

Updating ASA Software

Instructions for updating the ASA software image using the ASDM Home dialog.

Backup and Update Procedures

Covers backing up controls license and installing SFR updates via CLI.

Reset Device to Factory Defaults

Procedure to reset the device to factory defaults, involving software installation.

Uninstall and Reinstall SFR Module

Guides on uninstalling an old SFR module and reinstalling it via the command line.

Install SFR 5.4.1.4/5.4.1.6 Updates

Instructions for installing specific SFR patch updates (5.4.1.4 and 5.4.1.6).

Final Reset

Steps to perform a final reset on the system using the ASA CLI.

Chapter 10 Troubleshoot

Obtain Current Software Versions

Methods for obtaining the current running software versions (ASDM and ASA console) for troubleshooting.

Reset Device to Factory Defaults

Procedure to reset the device to factory defaults, involving software installation.

Uninstall and Reinstall SFR Module

Guides on uninstalling an old SFR module and reinstalling it via the command line.

Install SFR 5.4.1.2 Update

Instructions for installing the SFR 5.4.1.2 update, recommended if not updating to 6.4.

Install SFR 5.4.1.4/5.4.1.6 Updates

Instructions for installing specific SFR patch updates (5.4.1.4 and 5.4.1.6).

Final Reset

Steps to perform a final reset on the system using the ASA CLI.

Glossary

Index