OPNsense on SEL Hardware
Firewall
Secure operational technology (OT) networks and enhance the resilience of network communications between substations and the control center. OPNsense on rugged SEL hardware provides stateful firewall tracking, deep-packet inspection, adaptive routing, and hardware failover. OPNsense on SEL hardware is configured to your exacting specifications by the SEL Cybersecurity Services team. The system is purpose-built for industrial environments, contains no moving parts, and operates over a wide temperature range, from –40° to +75°C (–40° to +167°F).
Protect the OT Network From Malware and Unauthorized Access
Apply a stateful firewall with OPNsense on SEL hardware. The firewall tracks the state of network connections (such as TCP streams and UDP communication) to increase filtering while reducing configuration needs. The firewall protects OT networks, such as substation LANs, against ransomware, trojans, viruses, and other malware and uses deep-packet inspection to detect malicious code in incoming packets from WANs. OPNsense on SEL hardware supports multiple network address translation (NAT) options, such as one to one, port forwarding, and outbound NAT, and supports multiple public interfaces.Rely on Hardware Designed Specifically for OT Environments
The system uses SEL rugged automation controllers, which are tested to protective relay standards. These automation controllers have no moving parts and are designed to withstand vibration, electrical surges, fast transients, and extreme temperatures.Enhance Resiliency With Dynamic Routing Between Substations and the Control Center
Deploy the system as a dynamic edge router for the substation. The firewall supports adaptive routing protocols, such as Open Shortest Path First (OSPF), the Border Gateway Protocol (BGP), and the Route Information Protocol (RIP), to improve fault tolerance and reduce configuration needs. It also supports VPNs and is a VPN concentrator that allows multiple VPN tunnels to use a single network.Improve Reliability With Automatic and Seamless Failover
Configure multiple firewalls for high availability using the Common Address Redundancy Protocol (CARP) for hardware failover. If the primary firewall fails, then the secondary firewall becomes active.Make High-Priority OT Traffic More Deterministic
Apply traffic shaping in the firewall to limit bandwidth for various IT and OT applications and to prioritize network traffic. Bandwidth limitations can be configured based on the interface, IP source and destination, direction of traffic, and port numbers.OPNsense on SEL Hardware Features
Front
Rear
Operational Status LEDs
A green “ENABLED” LED indicates normal operation. The “ALARM” LED illuminates red when a nonoptimal system condition exists.Ethernet Status Indicators
“LNK” (link) indicates that the port is connected, and “ACT” (activity) indicates when data are being transmitted and received.
1
2