Networks
Rev 5058-CO900D
Session Description
Agenda
Selecting Infrastructure
Information Integration
Best Practices and Example Architectures
Where
to learn more
Reference
Architectures
Solutions
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
33
Integration of data
SQL or other servers for data collection and monitoring
Supply chain integration
Remote Access
Troubleshooting, monitoring, program changes
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
44
Agenda
Selecting Infrastructure
55
Switch Considerations
Advantages
Managed
Switches
Unmanaged
Switches
Inexpensive
Simple to set up
Embedded
Switches
Diagnostic information
Prioritization services (QoS)
Time Sync Services (1588 Transparent
Clock)
Network resiliency
Loop prevention
Disadvantages
More expensive
Requires some level of support and
configuration to start up
No management capabilities
No security
No diagnostic information
Difficult to troubleshoot
No resiliency support
No loop prevention
Technology Segmentation
Safety System
ControlLogix chassis
EtherNet/IP
SERCOS
DeviceNet
PV+ EOI
Stratix 8000
PowerFlex 755
POINT I/O
Kinetix
6000
ArmorBlock I/O
EtherNet/IP
PV+ EOI
Sercos
EtherNet/IP
ArmorBlock I/O
POINT I/O
Kinetix
6000
PowerFlex 755
Control VLAN
Control Vlan
ControlLogix chassis
EtherNet/IP
PV+ EOI
PowerFlex 755
Stratix 8300
Kinetix
6000
POINT I/O
Safety System
ArmorBlock I/O
Control VLAN
Control VLAN
Safety VLAN
Video VLAN
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
Network
Enterprise
DMZ
Industrial
Zone
1
SYST
RPS
MASTR
STAT
DUPLX
SPEED
STACK
MODE
9 10
11 12
13 14
15 16
17 18
19 20
21 22
23 24
1X
11X
13X
23X
2X
12X
14X
24X
1
SYST
RPS
MASTR
STAT
DUPLX
SPEED
STACK
MODE
9 10
11 12
13 14
15 16
17 18
19 20
21 22
23 24
1X
11X
13X
23X
2X
12X
14X
24X
Lightweight AP
(LWAP)
Mobile User
AP as Workgroup
Bridge (WGB)
Cell/Area Zone #1
Cell/Area Zone #2
Cell/Area Zone #3
Cell/Area Zone #4
Security Considerations
Physical Access Security
Disable unused switch ports
Lock a port to only allow specific devices to be
connected
Change passwords from default settings
Access Control Lists and Firewall Features
Limit access to secure areas of the network.
Limit access to secure services on the
network
Block remote access to secured devices
VLANs
Simplify security enforcement by creating
function groups
Control Access by function, by user, by
location, etc.
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
Infrastructure Performance
Bandwidth
1 at 4ms RPI
3 at 10ms RPI
4ms updates
10ms RPI
13
Infrastructure Performance
Jitter
1 at 4ms RPI
3 at 10ms RPI
4ms updates
10ms RPI
14
0000
HP-GPS
EN2T
CNB/E
OB16IS
L63
0000
0000
GM
15
Copy
Agenda
Information Integration
16
16
Information Network
Control
and
Information
Network
Control Network
Benefits
Clear network ownership demarcation line
Challenges
Limited visibility to control network devices
for asset management
Limited future-ready capability
Benefits
Plantwide information sharing for data
collection and asset management
Future-ready
Challenges
Blurred network ownership demarcation line
IP address management
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
17
Machine 2 NAT
10.104.x.x :
192.168.1.x
Machine 1 NAT
10.104.x.x :
192.168.1.x
192.168.1.100
192.168.1.100
192.168.1.104
Within a Machine
192.168.1.104
PV+ or PV+
Compact
10.10.10.10
192.168.1.2
CompactLogix L4
PowerFlex
4/40 AC
Drive
PowerFlex
4/40 AC
Drive
Dual NIC
Pros:
Cons:
Plant
10.10.10.10 192.168.1.2
CompactLogix 5370 L3
NAT
Pros:
Cons:
19
PowerFlex
4/40 AC
Drive
Plant
10.10.10.10
PV+ or PV+
Compact
PowerFlex
4/40 AC
Drive
Machine
VLAN
IP Routing
Pros:
No machine level switch configuration needed if the
machine is a single VLAN
Removes single point of failure for NAT device
Designed to allow network services (SNMP, VPN,
DNS, DHCP)
Cons:
IP addressing must be unique at the machine level
10.10.10.10 192.168.1.2
CompactLogix 5370 L3
NAT
Pros:
Cons:
20
For pre-commissioning at
equipment manufacturer
Equipment manufacturer
requires a planned
address list (-)
Duplication of equipment
IP addressing in programs
may differ (-)
Centralized management
of the entire address
space needed (-)
Additional maintenance
effort for the required 1:1
NAT address mappings
(private public)
required (-)
Failure probability
Availabilty of network
services (ie. DHCP, DNS,
Remote access)
difficult (-)
Operate and
Maintain
NAT router
Design and
Install
Criterion
Inside-Out
Remote
Desktop
Conference
Technology
Outside-In
VPN
Dial-Up
Modems
22
Enterprise
Data Center
Internet
Enterprise Zone
Levels 4 and 5
Enterprise Edge
Firewall
S SL V P N
I P S EC VPN
Remote Engineer
or Partner
Enterprise
Connected
Engineer
Enterprise
WAN
HTTPS
Enterprise Zone
Levels 4 and 5
Patch Management
Terminal Services
Application Mirror
AV Server
Cisco
ASA 5500
Firewall
(Standby)
Firewall
(Active)
Remote Desktop
Protocol (RDP)
Demilitarized Zone (DMZ)
View
Historian
AssetCentre
Transaction Manager
FactoryTalk Services
Platform
Directory
Security/Audit
Data Servers
Catalyst
6500/4500
RSLogix 5000
FactoryTalk View Studio
Catalyst 3750
StackWise
Switch Stack
EtherNet/IP
Manufacturing Zone
Site Manufacturing
Operations and Control
Level 3
Cell/Area Zones
Levels 02
23
Agenda
24
24
PanelView Plus
HMI
Ethernet Switch
EtherNet/IP
Vision
I/O
GuardLogix
Controller
EtherNet/IP
PowerFlex
Drives
Copyright 2010 Rockwell Automation, Inc. All rights reserved.
Kinetix 6500
Servo Drives
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
25
836
Pressure
Sensor
CompactLogix
Plant Network
Connectivity
Point I/O
PowerFlex40 VFDs
PanelviewPlusCE
837E
Temperature
Transmitters
836E
Pressure
Transmitters
839E Flow
Transmitters
O
R
873P
Ultrasonic
Level
Sensors
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
26
27
Agenda
Where
to learn more
Reference
Architectures
Solutions
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
28
28
Additional Material
Rockwell Automation
29
Additional Material
Cisco and Rockwell Automation Alliance
Website
http://www.ab.com/networks/architectures.html
Design Guides
CPwE DIG 2.0
Education Series
Whitepapers
Securing Manufacturing Computer and
Controller Assets
Production Software within Manufacturing
Reference Architectures
Achieving Secure Remote Access to Plant Floor
Applications and Data
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
30
Additional Material
Cisco and Rockwell Automation Alliance
What every Plant Floor Controls Engineer should know about working with IT
Available Online
http://www.ab.com/networks/architectures.html
Copyright 2013 Rockwell Automation, Inc. All Rights Reserved.
31
Questions?
Rev 5058-CO900D
Rev 5058-CO900D