102 Rockwell Automation Publication 1783-UM010C-EN-P - June 2019
Chapter 8 Firewall Modes
Cell/Area Zone Monitoring
The cell/area zone monitor mode use case is used to monitor traffic of interest
without placing the IFW directly inline of a controller, skid, machine, or cell/
area zone of interest. The IFR is connected to a switch that has visibility to the
traffic that is required to be monitored. A span session or port mirror is created
to send the traffic of interest to the IFW.
Figure 29
illustrates this use case.
Figure 29 - Industrial Firewall Placement for Cell/Area Zone Monitoring
Considerations
Before implementing the IFW as a monitor, it is recommended that the
designer understand and document:
• Ingress and egress traffic volume