Glossary · OT cybersecurity
Firewall
Also known as: Industrial firewall, Network firewall
German: Firewall
In network security, a firewall is a device or software that controls traffic between network segments according to a rule set, allowing or blocking connections based on criteria such as addresses, ports, protocols and, for industrial firewalls, the content of industrial protocol messages.
- OT security
In one sentence
A firewall controls traffic between network segments with rules on addresses, ports, protocols and, in industrial firewalls, protocol content.
Example
The firewall of a machine cell allows the MES to read production counters over OPC UA but blocks all other traffic from the plant network to the cell's PLC.
How it applies
- Engineering: In the Zone and conduit model, firewalls are typical enforcement points of a Conduit. Industrial firewalls can inspect protocols such as Modbus TCP or OPC UA and, for example, allow read requests while blocking write requests.
- Commissioning: Rule sets should follow "deny by default" and allow only documented flows. Temporary rules for commissioning must be removed before handover.
- Maintenance: Rules need regular review; unused and overly broad rules accumulate. Firewall firmware needs patching like any other device.
- Documentation: Product documentation should list all ports, protocols and directions a component uses, so that integrators can write precise firewall rules. A clear port table in the manual saves commissioning time and prevents "allow any" rules.
Firewall vs. data diode
A firewall enforces rules on bidirectional traffic and can be misconfigured. A Data diode physically allows traffic in only one direction, which gives stronger assurance but fewer functions.