Industrial Firewall with DPI: 5 Essential Rules for Safe OT

Share:
Cybersecurity
Industrial Firewall with DPI: 5 Essential Rules for Safe OT

Industrial protocols were built for trusted networks, so any device that reaches a PLC can usually command it. Filtering traffic by what each message actually does, not just by address and port, closes that dangerous gap.

Deep Packet Inspection Modbus TCP Function Codes Industrial Firewall

A normal IT firewall sees only addresses and ports, so it cannot tell a harmless read from a dangerous write. Protocol aware filtering looks inside each Modbus message and allows only what the process truly needs.

Hello everyone, today we are going to learn how an industrial firewall uses deep packet inspection to filter Modbus TCP traffic, why it beats plain stateful rules and how to build a safe read only policy.
industrial firewall

What Is an Industrial Firewall?

An industrial firewall is a rugged, protocol aware security device placed between control network zones that filters traffic by address, port and the content of industrial messages. It enforces the conduits described in IEC 62443 zones and conduits.

Moxa points out that Modbus TCP has no built in security, so any host that reaches a PLC on port 502 can read or write it. The protocol itself is explained in Modbus protocol explained.

Deep packet inspection filtering industrial traffic
Image credit: Moxa

An industrial firewall is usually DIN rail mounted, fanless and rated for wide temperatures. Many also support transparent bridge mode so they can be added without readdressing the network.

Stateful Inspection vs Deep Packet Inspection

FeatureStateful InspectionDeep Packet Inspection
Checks addresses and portsYesYes
Tracks sessionsYesYes
Reads Modbus unit IDNoYes
Filters by function codeNoYes
Allows reads, blocks writesNoYes
Checks register rangesNoOften yes

Moxa explains that DPI filters on the Modbus unit ID and function codes, so it can allow reads and block writes, something stateful inspection cannot do. A SCADA historian can then read data without any ability to change setpoints.

The Tofino Modbus TCP enforcer from MTL applies the same idea, with a default deny policy for anything not listed. Similar filtering exists for other protocols compared in DNP3 and IEC 60870 5 104.

Where to Place an Industrial Firewall

EnterpriseBusiness network, level 4
DMZHistorian mirror and jump hosts
SupervisorySCADA and HMI servers, level 2
Cell FirewallDPI in front of PLC zones
ControllersPLCs and RTUs, level 1

The layers follow the Purdue model for ICS security. Placing a small DPI device right in front of critical controllers adds protection even inside the control zone.

Switches alone do not filter by function, see network switches for SCADA and DCS. Segmentation choices are compared in air gapped vs segmented ICS networks.

5 Essential Industrial Firewall Rules

1
Default Deny
Block everything not explicitly allowed.
2
Allow by Host Pair
Permit only known masters to known slaves.
3
Filter Function Codes
Allow reads, restrict writes to engineering hosts.
4
Limit Unit IDs
Accept only the unit IDs actually used.
5
Log and Alert
Send blocked attempts to the security team.

Start a new industrial firewall in a test or monitor mode to learn real traffic before enforcing. A rule that blocks a legitimate write can stop production just like an attack.

Modbus Function Code Classes

Read codes: 1, 2, 3, 4 and 24, allow for monitoring hosts
Write codes: 5, 6, 15, 16, 21, 22 and 23, allow only for approved masters

Example:
Historian sends function code 16, Write Multiple Registers
Policy for the historian is read only
Result: class write, action block

Function code 23 reads and writes in one message, so treat it as a write. Diagnostic codes such as 8 should also be restricted, since some sub functions can force a device into listen only mode.

Function Code Checker

Modbus Function Code Allow List Checker
Result
Function code 16, Write Multiple Registers, class write, action block under a read only policy

Codes above 127 are exception responses from the slave, not requests. Any unusual code seen on the network is worth investigating.

Advantages
  • Blocks unauthorised writes to PLCs.
  • Works with legacy devices unchanged.
  • Rugged hardware for panels.
  • Clear logs of blocked commands.
Limitations
  • Rules need protocol knowledge.
  • Encrypted traffic cannot be inspected.
  • Wrong rules can stop production.
  • Adds a device that must be maintained.

Firewalls are one layer in a wider program aligned with PLC cybersecurity standards. Combine them with the practices in SCADA network security and a zero trust approach for OT.

Understanding common threats helps you write better rules, see types of cyber attacks. Review the rule set after every plant modification.

Tofino Modbus DPI Data Sheet PDF

PDF
Tofino Modbus TCP Deep Packet Inspection LSM Data Sheet
MTL Tofino module for Modbus content filtering

Modbus Deep Packet Inspection Video

Industrial Firewall FAQ

What is an industrial firewall?
It is a rugged, protocol aware firewall placed between control network zones. It filters traffic by address, port and the content of industrial protocol messages.
Why is Modbus TCP risky?
Modbus TCP has no authentication or encryption built in. Any device that reaches port 502 can normally read and write PLC coils and registers without any check.
What does deep packet inspection add?
It reads inside each message to check the unit ID, function code and often the register range. That allows reads while blocking writes from the same host.
Can a stateful firewall block Modbus writes?
No, a stateful firewall only sees addresses, ports and sessions. It cannot tell a read request from a write request on port 502, because both use the same connection.
Which function codes are writes?
Common write codes are 5, 6, 15, 16, 21, 22 and 23. Codes 1 to 4 are the most common read codes used by HMI and historian systems.
Where should the firewall sit?
Place firewalls between Purdue levels and also in front of critical PLC zones. This follows the zones and conduits approach of IEC 62443 and limits how far an attacker can move.
Should I start in blocking mode?
It is safer to begin in a test or monitor mode to learn real traffic. Enforce rules only after confirming that every legitimate message is allowed.

Related Articles

External References

What We Learn Today

  • An industrial firewall with DPI filters Modbus by unit ID and function code.
  • It can allow reads and block writes, which stateful rules cannot.
  • Start with default deny, test in monitor mode, then enforce.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *