Segmentation / Structure
Convergence-ready Solutions
Additional Information
What is real-time?
Application dependent ….. only you can define what this means for your
application.
Information
Integration, Time-critical
Function Slower Process Discrete Automation
Motion Control
Automation
Communication .Net, DCOM, TCP/IP Industrial Protocols - CIP
Hardware and Software
Technology solutions, e.g. CIP Motion, PTP
Period 10 ms to 1000 ms 1 ms to 100 ms 100 µs to 10 ms
Auto, food & beverage,
Oil & gas, chemicals,
Industries energy, water
semiconductor, Subset of discrete automation
metals, pharmaceutical
Pumps, compressors, Material handling, filling, Printing presses, wire drawing,
Applications mixers, instrumentation labeling, palletizing, packaging web making, pick & place
Source: ARC Advisory Group
Avoiding
Enabling OEM
– Communication patterns, topology and resiliency requirements
– Types of traffic – information, control, safety, time synchronization,
drive control, voice, video
• Develop a logical framework (roadmap)
Convergence-Ready
Because Network
– Migrate from flat networks to structured and hardened networks
DevelopNetwork toSprawl!!
– Define zones and segmentation, place applications and devices
Solutions
in the logical framework based on requirements
•
Infrastructure Matters
a physical framework align
with and support the logical framework
• Deploy a Holistic Defense-in-Depth Security Model ASSESS
deployment:
– Use information technology (IT) standards AUDIT DESIGN/PLAN
– Follow industrial automation technology (IAT) standards IMPLEMENT
– Utilize reference models and reference architectures
Logical Model
Industrial Automation and Control System (IACS)
Converged Multi-discipline Industrial Network
HMI
Rockwell Automation Safety Safety
Stratix 5700/8000 I/O Controller
Phone Layer 2 Access Switch
Controller
Layer 2 Layer 2 Layer 2
Building Block
Camera Building Block Building Block
MCC I/O Soft
Instrumentation Starter
Servo Level 0
Media & Level 1 Drive
Connectors Drive
Cell/Area Zone #1 Cell/Area Zone #2 Controller
Redundant Star Topology Ring Topology Cell/Area Zone #3
Flex Links Resiliency Resilient Ethernet Protocol (REP) Bus/Star Topology
Enterprise-wide
Business Systems Levels 4 & 5 – Data Center
Enterprise Zone
Industrial Zone
Physical or Virtualized Servers
Plant-wide • FactoryTalk Application Servers & Services Platform
• Network Services – e.g. DNS, AD, DHCP, AAA
Site-wide • Remote Access Server (RAS)
Operation Systems •
•
Call Manager
Storage Array Level 3 - Site Operations
• Plant LAN – VLAN17 - Layer 2 Domain
• Plant IP - Subnet 10.17.10.0/24
Cell/Area Zones
Line/Area Levels 0-2
Controller
Cell/Area Zone #3
Subnet 192.168.1.0/24
Enterprise-wide
Business Systems Levels 4 & 5 – Data Center
Enterprise Zone
Industrial Zone
Physical or Virtualized Servers
Plant-wide • FactoryTalk Application Servers & Services Platform
• Network Services – e.g. DNS, AD, DHCP, AAA
Site-wide • Remote Access Server (RAS)
Operation Systems •
•
Call Manager
Storage Array Level 3 - Site Operations
• Plant LAN – VLAN17 - Layer 2 Domain
• Plant IP - Subnet 10.17.10.0/24
Cell/Area Zones
Levels 0-2
Cell/Area Zone #3
Subnet 192.168.1.0/24
Industrial Zone
Physical or Virtualized Servers
Plant-wide • FactoryTalk Application Servers & Services Platform
• Network Services – e.g. DNS, AD, DHCP, AAA
Site-wide • Remote Access Server (RAS)
Operation Systems •
•
Call Manager
Storage Array Level 3 - Site Operations
• Plant LAN – VLAN17 - Layer 2 Domain
• Plant IP - Subnet 10.17.10.0/24
Cell/Area Zones
Levels 0-2
Cell/Area Zone #3
Subnet 192.168.1.0/24
Enterprise-wide
Business Systems Levels 4 & 5 – Data Center
Enterprise Zone
Industrial Zone
Physical or Virtualized Servers
Plant-wide • FactoryTalk Application Servers & Services Platform
• Network Services – e.g. DNS, AD, DHCP, AAA
Site-wide • Remote Access Server (RAS)
Operation Systems •
•
Call Manager
Storage Array Level 3 - Site Operations
• Plant LAN – VLAN17 - Layer 2 Domain
• Plant IP - Subnet 10.17.10.0/24, every
Cell/Area Zone #3 Cell/Area Zones
device requires a unique IP address Levels 0-2
VLAN30
Subnet 10.10.30.0/24
Enterprise-wide
Business Systems Levels 4 & 5 – Data Center
Enterprise Zone
Industrial Zone
Physical or Virtualized Servers
Plant-wide • FactoryTalk Application Servers & Services Platform
• Network Services – e.g. DNS, AD, DHCP, AAA
Site-wide • Remote Access Server (RAS)
Operation Systems •
•
Call Manager
Storage Array Level 3 - Site Operations
• Plant LAN – VLAN17 - Layer 2 Domain
• Plant IP - Subnet 10.17.10.0/24
Cell/Area Zones
Levels 0-2
Random Drop
High Low High Low
Sensitivity
Latency
High High Low High
Sensitivity
Jitter Sensitivity High High Low High
Video Output
Output Bulk Data Critical Data
Queue 2
Queue 4
Scavenger Bulk Data
Best Effort
Scavenger
Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.
Prioritization - Quality of Service (QoS)
Design and Implementation Considerations
• QoS trust boundary moving from switch
access ports to QoS-capable CIP devices
– Stratix 5700/8000/8300 Smartport enables
Trusted Markings
• For existing CIP devices, marking at the
switch access port is based on port
number Device w/out
QoS marking
Cisco
Catalyst 2955
HMI HMI
Controller
Controllers
HMI Controllers
HMI
Controllers,
Drives, and Distributed I/O
Cell/Area Zone Controllers, Drives, and Distributed I/O Controllers, Drives, and Distributed I/O
Cell/Area Zone Cell/Area Zone Cell/Area Zone
Device-level Topologies
Switch-level and
Device-level Topologies
Stratix
8300
I/O
I/O I/O
VFD
Drive
VFD
Drive
HMI
Controller
Servo
Drive HMI
Controllers, VFD
Drives, and Distributed I/O Drive I/O
Controller
Cell/Area Zone Instrumentation
Forwarding
Blocking
Link Failure
Blocking
Forwarding
Blocking
Advantages Disadvantages
Loop prevention
Security services More expensive
Diagnostic information Requires some level of support and
Managed configuration to start up
Segmentation services (VLANs)
Switches
Prioritization services (QoS)
Network resiliency
Multicast management services
No loop prevention
Inexpensive No security services
Simple to set up No diagnostic information
Unmanaged
No segmentation or prioritization
Switches
services
Difficult to troubleshoot
No network resiliency support
Cable simplification with reduced cost
Ring loop prevention & Network resiliency Limited management capabilities
ODVA Embedded Prioritization services (QoS)
May require minimal configuration
Time Sync Services (IEEE 1588 PTP Transparent
Switch Technology Clock)
Diagnostic information
Multicast management services
RSTP (802.1w) X X X X X
MSTP (802.1s) X X X X X
rPVST+ X X X X
REP X X X
EtherChannel
X X X X
(LACP 802.3ad)
Flex Links X X X
DLR
X X X X
(IEC & ODVA)
StackWise X X X X X
HSRP X X X X
GLBP X X X X
VRRP
X X X X X
(IETF RFC 3768)
ArmorPoint I/O
PowerFlex
POINT I/O POINT I/O
Device-level Ring Topology with Device Level Ring Protocol
• Supervisor blocks traffic on one port
• Sends Beacon frames on both ports to detect break in the ring
• Once ring is restored, supervisor hears beacon on both ports,
and transitions to normal ring mode, blocking one port
Industrial
Zone
HMI I/O
VFD
IES Drive
CIP Class 3
IES IES
CIP
Class 1
IES
Class 3 Controller I/O
Redundant REP
IES
Controllers
IES DLR
DLR CIP Sync
VFD
HMI Drive
CIP Class 1 Controller CIP Motion
VFD
Drive Safety I/O
Safety I/O Servo
I/O Controller Drive
CIP Safety
Instrumentation
Partner
Solution(s) Plant-wide
e.g. Machine Industrial
Automation Systems
Partner
Solution(s) e.g. Plant-wide / Site-wide
Process Skid Industrial
Automation Systems
Enterprise-wide
Business Systems Levels 4 & 5 – Data Center
Enterprise Zone
Industrial Zone
Plant-wide Physical or Virtualized Servers
• FactoryTalk Application Servers & Services Platform
Operation Systems • Network Services – e.g. DNS, AD, DHCP, AAA
• Remote Access Server (RAS)
• Call Manager
• Storage Array Level 3 - Site Operations
Cell/Area Zones
Levels 0-2
Integrated
Services
VLANs
Router
NAT w/ NAT
Appliance
Machine/Skid #1 Machine/Skid #2
Machine/Skid #3
• Websites
– Reference Architectures
• Design Guides
– Converged Plant-wide Ethernet (CPwE)
– CPwE Resilient Ethernet Protocol (REP)
• Application Guides
– Fiber Optic Infrastructure Application Guide
– Wireless Design Considerations for Industrial Applications
• Whitepapers
– Top 10 Recommendations for Plant-wide EtherNet/IP
Deployments
– Securing Manufacturing Computer and Controller Assets
– Production Software within Manufacturing Reference
Architectures
– Achieving Secure Remote Access to plant-floor Applications
and Data
– Design Considerations for Securing Industrial Automation
and Control System Networks
Stratix 8000/8300
Layer 2, Layer 3
Stratix 5700
Layer 2
Stratix 6000
Stratix 5900 Layer 2
Layer 2/3 - UTM
• Sessions
• NI11 – IT and Plant Floor – Breaking Down the
Barriers
• NI13 – The Connected Enterprise
• NI03 - Testing the Physical Layer for Ethernet/IP
• NI04 - When is a good time to have MICE on your
plant floor? Structured Cabling Best Practices
(Industrial Ethernet)
• NI18 – Remote Access
• Tradeshow
• Solution Area 3 – Process & Connected Enterprise
• Werner DataComm Booths