Architectural overview

At this point, our ICS network architecture should look something along these lines:

All switch-to-switch connections are dual link EtherChannels.

This architecture design segments the ICS network into an Enterprise Zone, an Industrial Zone, and an Industrial Demilitarized Zone. Redundancy at the cores is implemented by a VSS pair of layer 3 switches (for example, a pair of Cisco 4500-X catalysts) and firewall redundancy is achieved with an active-standby pair of any flavor of firewalls.

For extra resiliency, the core switch and firewall pairs should be installed in separate server rooms on opposite sides of the facility, ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.