StrideLinx Industrial VPN Router User Manual Appendix E Appxe
User Manual: Pdf Appendix E StrideLinx Series Industrial VPN Router - AutomationDirect
Open the PDF directly: View PDF
.
Page Count: 8
| Download | |
| Open PDF In Browser | View PDF |
StrideLinx Network Security In this Appendix... Appendix E Introduction: Intended Audience................................................................................E-2 Solution explained.......................................................................................................E-2 StrideLinx Router........................................................................................................E-2 StrideLinx Platform.....................................................................................................E-2 StrideLinx Client.........................................................................................................E-2 Overview....................................................................................................................E-2 Controls Network Security..........................................................................................E-4 Remote access............................................................................................................E-4 Local access................................................................................................................E-4 Company Network Security........................................................................................E-5 Connectivity...............................................................................................................E-5 Remote access............................................................................................................E-6 Local access................................................................................................................E-6 StrideLinx Platform Security.......................................................................................E-6 Servers.......................................................................................................................E-6 StrideLinx platform.....................................................................................................E-6 VPN Client Security.....................................................................................................E-7 Linx Appendix E: StrideLinx Network Security Introduction: Intended Audience The StrideLinx Remote Access Solution is designed to offer safe and secure remote access E to industrial equipment worldwide for efficient remote troubleshooting, programming and monitoring. As a result, it significantly reduces service costs and machine downtime. The 2 intended audience of this document is personnel responsible for the administration and security of the network environment in which the StrideLinx product will reside (i.e., IT dept., network admins, etc.). The router will generate outbound traffic to create an internet connection; 3 therefore, the network administrator of your network should be consulted. The StrideLinx platform and router provide a secure method to access your control devices 4 remotely, but it is important to note that it is just one part of an overall security strategy. It is important to evaluate and re-evaluate over time, the conditions of your particular 5 network. A list of helpful resources is available at http://support.automationdirect.com/docs/ securityconsiderations.pdf. 6 explained 7 Solution The StrideLinx Remote Access Solution comprises the StrideLinx router, web-based platform, and VPN client. 8 StrideLinx Router The StrideLinx router can easily be connected to the hardware on your machine, allowing you 9 to access your machine remotely for monitoring, troubleshooting and service purposes. ADC will offer the router in 3 variants: Ethernet wired, 4G LTE (America – AT&T) and WiFi 10 (802.11b/g/n). The 4G LTE & WiFi models can also be configured as wired by using the RJ45 WAN port. 11 StrideLinx Platform The StrideLinx platform is a secure web-based platform made up of a worldwide network of 12 scalable servers. It is focused on delivering and enhancing innovative secure remote access. The StrideLinx router connects your hardware to the StrideLinx platform via a secure VPN connection. 13 StrideLinx Client 14 The VPN client is a light-weight application that runs in the background on your laptop or PC. A VPN connection is established when you use the StrideLinx platform to remotely connect to your devices. A Overview B The remote access solution is made up of two connections – the client to platform (cloud servers) and the platform (cloud servers) to the router. This first connection is made when the local VPN router makes a VPN connection to the cloud server immediately upon startup. This C ensures that all traffic between the router and platform is securely encrypted through the VPN tunnel. Communication for this link is initiated by the local router to the cloud-based server via D an outbound connection through standard ports that are typically open, such as HTTPS. This usually requires no changes to the corporate IT firewall, thus satisfying IT security concerns. E-2 StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C Appendix E: StrideLinx Network Security Linx Linx HTTPS Connection Linx VPN Connection Outgoing Connection Linx Corporate Servers Linx Corporate Fire Wall Company Network Linx Company WiFi Internal Fire Wall VPN router PLC EtherNet/IP Devices Ethernet Plant/Controls Network HMI Plant WiFi Linx Hand-held Scanner VFD/Motor Application PLC Field I/O With the router and server connected, the remote user is given two options for the second connection between them and the cloud servers. The first option is to connect by HTTPS by simply connecting the mobile device or PC/laptop to the platform using a web browser (clientless access). No VPN client is required for this mode and allows the user flexibility in connecting to the platform from any mobile device or PC with a web browser. Capabilities in StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C E 2 3 4 5 6 7 8 9 10 11 12 13 14 A B C D E-3 Linx Appendix E: StrideLinx Network Security this mode include all standard platform functionality except VPN connection. The user has access to the router, but not to the LAN devices behind the router. So, programming software and other tools that require being on the local area network will not work in this mode. Two features that are supported in clientless access mode are VNC server & web server access by creating a shortcut on the Info tab of the router. This shortcut creates a secure port forward from the LAN port to the VPN tunnel. The shortcut allows users to access all of the features included on the LAN devices’ VNC or web servers in a secure manner. Clientless access mode is protected by TLS1.2, but does not pass through the VPN tunnel from the cloud server to the remote user. The second option for users to connect is by PC/laptop to the platform by VPN, allowing full local area network access. This method requires users log in to the platform through a web browser and have the VPN client installed on their PC. Upon a verified request from the remote user, the VPN client connects to the cloud server, providing a full VPN connection from remote user (PC) to the router. Once both connections have been made, all data passing through this VPN tunnel is secure. E 2 3 4 5 6 7 Controls Network Security Remote access 8 The StrideLinx router is equipped with a built-in firewall that completely separates the WAN port (company network) from the LAN ports (controls network). The firewall blocks all communication except for authorized and encrypted data verified by a valid certificate. This 9 means that only authorized users can access the controls network via our StrideLinx platform. 10 Local access Default settings allow for zero communication from the company network to the controls network (and vice versa). The StrideLinx router is configurable to allow communication from 11 the controls network to the company network, to the internet, or both. Authorization under this scenario is by means of the firewall section of the Configuration in the StrideLinx platform. 12 There are three types of port forwarding supported in the StrideLinx router: LAN→WAN, WAN→LAN, VPN→LAN. 13 • LAN→WAN options allow access from the LAN to the corporate network or the internet. This option is needed if you are accessing an FTP or mail server on the corporate network or cloud. This option maintains good security practice if the corporate router is in place 14 with strong security measures. • WAN→LAN options allow access by port forwarding to incoming traffic. A WARNING: This is usually not recommended as it opens specific ports to anyone on the B internet and could make the control network unsecure. • VPN→LAN port forwarding provides a secure port forward inside the encrypted VPN C tunnel so that StrideLinx users can access the HTTP server or VNC server of their control network devices by shortcut services in the StrideLinx platform. This feature allows the D clientless access mode for mobile & PC users as described in the “Solutions Explained” section above. E-4 StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C Appendix E: StrideLinx Network Security Company Network Security Connectivity The StrideLinx router uses an outgoing port to establish a secure connection to our StrideLinx platform. This means there is no need to open any incoming ports in your firewall. Via this outgoing port, the StrideLinx router connects to different servers: REST API, MQTT and OpenVPN servers. The IP addresses of these servers, as well as the number of servers, may change over time and are thus not pre-defined. What is pre-defined is the domain of these servers. This is why the StrideLinx router needs to be able to perform DNS requests; otherwise, the StrideLinx router can’t connect to our servers. Below is an overview of the outgoing ports and protocols that the StrideLinx router utilizes. Outgoing Ports and Protocols Port Protocol Application 443 TCP HTTPS, MQTT/TSL, OpenVPN 53 TCP & UDP DNS Port 443 is a port that is normally open and also used by other services to set up a secure connection (i.e. internet banking). If necessary, the local (plant) IT department can choose to allow internet access based on the MAC address or IP address of the StrideLinx router. The router WAN IP address can be set to a static IP address on the wired router configuration; the WiFi router is set to default. However, by default the WAN IP address is set to be obtained automatically via DHCP. To communicate with the StrideLinx platform, the StrideLinx router firmware uses the proven encryption standard SSL / TLS. The required TLS key exchange, crucial for security, is done in accordance with the industry standard 2048-bit RSA with SHA-256. During the RSA handshake the public server keys are shared and with built-in Certificate Authorities the server’s identity is verified. The StrideLinx agent does not use 3rd party Certificate Authorities which guarantees an up-to-date security for embedded devices. When setting up a VPN tunnel, the necessary security licenses are downloaded and the Blowfish/AES encrypted VPN tunnel is set up. Attacks like Man-in-the-middle, spoofing ARP and DNS hijacking will be detected immediately. The StrideLinx router remains permanently connected to the platform and sends out ‘keep-alive heartbeats’ on a regular interval. The remote connection between the StrideLinx router and StrideLinx platform can be managed by the local operator. A digital input allows the user to enable/disable the VPN connection at the flick of a switch, literally. For instance, this input can be used by plant personnel to manage access to the router by outside personnel on an as-needed basis. Alternatively, the connection can be terminated by powering off the StrideLinx router. Once it is powered again, the StrideLinx router automatically re-establishes the connection with the StrideLinx platform. StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C E 2 3 4 5 6 7 8 9 10 11 12 13 14 A B C D E-5 Linx Appendix E: StrideLinx Network Security If the local (plant) IT department does not allow any form of internet connection to third party hardware, the StrideLinx router with 4G LTE may be used to isolate the controls network from the corporate IT network. LTE 4G access requires a standard SIM card (standard size, 2FF) for cellular internet access. E 2 Remote access The StrideLinx router is equipped with a built-in firewall that completely separates the WAN port (company network) from the LAN ports (controls network). The firewall blocks all 3 communication except for authorized and encrypted data verified by a valid certificate. This means that only authorized users can access the controls network via our StrideLinx platform. 4 Local access Default settings allow for zero communication from the company network to the controls 5 network (and vice versa). The StrideLinx router is configurable to allow communication from the controls network to the company network, to the internet, or both. Authorization under 6 this scenario is by means of the firewall section of the Configuration in the StrideLinx platform. There are three types of port forwarding supported in the StrideLinx router: LAN→WAN, WAN→LAN, VPN→LAN. 7 • LAN→WAN options allow access from the LAN to the corporate network or the internet. This option is needed if you are accessing a FTP or mail server on the corporate network 8 or cloud. This option maintains good security practice if the corporate router is in place with strong security measures. 9 • WAN→LAN options allow access by port forwarding to incoming traffic. 10 WARNING: This is usually not recommended as it opens specific ports to anyone on the internet and could make the control network unsecure. 11 • VPN→LAN port forwarding provides a secure port forward inside the encrypted VPN tunnel so that StrideLinx users can access the HTTP server or VNC server of their controls 12 network devices by shortcut services in the StrideLinx platform. This feature allows the clientless access mode for mobile & PC users as described in the “Solution Explained” 13 section above. 14 StrideLinx Platform Security A Servers Our servers are hosted at one of the world’s largest cloud providers. All servers are certified by national and international safety standards. B StrideLinx platform C A crucial link within the complete StrideLinx solution is the StrideLinx platform, which acts as a secure proxy for the data between the StrideLinx router and StrideLinx client. The browser always checks for the valid SSL certificate on the StrideLinx platform. As a result, the StrideLinx D platform is protected against so called man-in-the-middle attacks. E-6 StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C Appendix E: StrideLinx Network Security Only authorized users can access the controls network via our StrideLinx platform. This requires you to have an account (login information) as well as having received an invite to the particular company and being granted access and permission to the registered StrideLinx router(s). The StrideLinx platform checks for login attempts forced by software to identify a username and password combination (so called Brute Force Attacks). Such attempts are detected and blocked by the StrideLinx platform. As an additional safety measure it is possible to set up 2-factor authentication for your account. All login sessions, connections with the StrideLinx router, changes made to the details or configuration and reboots of the StrideLinx router are being logged with a timestamp and designated user (if applicable). All these logs can be viewed on the StrideLinx platform under “Latest events”: when navigating to “Devices” and selecting a specific StrideLinx router, or when navigating to “Users” and selecting a specific user. The StrideLinx platform is the only component in the complete StrideLinx solution in which ports are exposed to the Internet. However, only VPN connections which carry a valid x.509 certificate receive access. The certificate is downloaded automatically once the user is successfully logged in and presses “connect” to connect to a specific StrideLinx router. VPN Client Security StrideLinx client is a light-weight application that runs in the background on your PC. It creates a virtual Ethernet port on your PC and handles all communication between your PC and the StrideLinx platform. The StrideLinx client uses the proven encryption standard SSL / TLS. The required TLS key exchange, crucial for security, is done in accordance with the industry standard 2048-bit RSA with SHA-256. During the RSA handshake the public server keys are shared, with built-in Certificate Authorities the server’s identity is verified. The StrideLinx client does not use 3rd party Certificate Authorities which guarantees an up-to-date security. When setting up a VPN tunnel, the necessary security licenses are downloaded and the Blowfish/AES encrypted VPN tunnel is set up. Attacks like man-in-the-middle, spoofing ARP and DNS hijacking will be detected immediately. StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C E 2 3 4 5 6 7 8 9 10 11 12 13 14 A B C D E-7 Linx Appendix E: StrideLinx Network Security E 2 3 4 5 6 7 8 9 10 11 12 13 14 A B C D E-8 StrideLinx™ Industrial VPN Routers User Manual 1st Edition, Rev. C
Source Exif Data:
File Type : PDF File Type Extension : pdf MIME Type : application/pdf PDF Version : 1.6 Linearized : No Author : AutomationDirect Create Date : 2018:05:02 14:40:05-04:00 Modify Date : 2018:05:02 15:01:24-04:00 Subject : StrideLinx Remote Access Solution Language : en-US Tagged PDF : Yes XMP Toolkit : Adobe XMP Core 5.6-c015 84.159810, 2016/09/10-02:41:30 Format : application/pdf Title : StrideLinx Industrial VPN Router User Manual Creator : AutomationDirect Description : StrideLinx Remote Access Solution Metadata Date : 2018:05:02 15:01:24-04:00 Creator Tool : Adobe InDesign CC 2017 (Windows) Instance ID : uuid:9e062d4b-37b4-4362-b161-2897067ba2e5 Original Document ID : xmp.did:AC8300A79C14E311B497E908AC6DEAF6 Document ID : xmp.id:0f516f84-5443-bb4c-b7d0-9483a9691dd0 Rendition Class : proof:pdf Derived From Instance ID : xmp.iid:7a701b20-22ef-a842-856a-e02d90699ef5 Derived From Document ID : xmp.did:45ef2e51-70bc-664a-a2d9-888d73a673ac Derived From Original Document ID: xmp.did:AC8300A79C14E311B497E908AC6DEAF6 Derived From Rendition Class : default History Action : converted History Parameters : from application/x-indesign to application/pdf History Software Agent : Adobe InDesign CC 2017 (Windows) History Changed : / History When : 2018:05:02 14:40:05-04:00 Producer : Adobe PDF Library 15.0 Trapped : False Page Layout : SinglePage Page Mode : UseOutlines Page Count : 8EXIF Metadata provided by EXIF.tools