Glossary · Industrial communication
Industrial firewall
Also known as: OT firewall, Industrial security appliance
German: Industriefirewall
In OT security, an industrial firewall is a network device that filters traffic between network zones of an industrial plant according to rules, built for industrial environments and often able to inspect industrial protocols such as Modbus, S7 or OPC UA.
- Industrial communication
- OT security
In one sentence
An industrial firewall filters traffic between OT network zones and often inspects industrial protocols such as Modbus or OPC UA.
Example
An industrial firewall between the cell network and the plant network only allows OPC UA connections from the MES server to the line controller.
How it applies
- Engineering: Firewalls implement the Conduit between Security zones. Rules are derived from the Communication matrix: only listed connections are allowed, everything else is denied by default.
- Commissioning: Rules are tested against real traffic. A temporary "allow all" rule during commissioning must be removed before handover; this is a common finding in audits.
- Operation: Firmware updates, rule reviews and log monitoring are part of Patch management and security operations. Deep packet inspection of industrial protocols can, for example, block write commands while allowing reads.
- Documentation: The documentation team documents the firewall's location in the zone model, the rule set with justification, and who may change it. A firewall alone doesn't make a plant secure; it is one measure in a defense-in-depth concept.
Industrial firewall vs. industrial router
An Industrial router forwards traffic between IP networks; many routers include basic packet filtering. A firewall's primary job is enforcing a security policy, often with stateful and protocol-aware inspection. Many devices combine both functions.