commissioning, managing & troubleshooting industrial networks

41
Tips for Commissioning, Managing, and Troubleshooting your Industrial Network Moxa Technology Webinar Series Richard Wood Networking Infrastructure Manager

Upload: creekside-marketing-group-llc

Post on 22-Jan-2018

123 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: Commissioning, Managing & Troubleshooting Industrial Networks

Tips for Commissioning,

Managing, and Troubleshooting

your Industrial Network

Moxa Technology Webinar Series

Richard Wood

Networking Infrastructure Manager

Page 2: Commissioning, Managing & Troubleshooting Industrial Networks

Agenda

Industrial Network Challenges

Network Configuration & Commissioning

Managing Industrial Networks

Troubleshooting to Minimize Downtime

Tips for Commissioning, Managing & Troubleshooting Your Industrial Network

Page 3: Commissioning, Managing & Troubleshooting Industrial Networks

Industrial Network Challenges

• Harsh operating

environments

• Network availability

requirements are much

higher than enterprise IT

• Cost of downtime is

extremely high

• Interoperability of industrial

devices/networks

• Limited networking

expertise

Typical challenges

Source:

http://www.strategiccompanies.com/pdfs/Assessing%20t

he%20Financial%20Impact%20of%20Downtime.pdf

Page 4: Commissioning, Managing & Troubleshooting Industrial Networks

Network Configuration &

CommissioningTips, Tricks & Tools

Page 5: Commissioning, Managing & Troubleshooting Industrial Networks

Network Configuration & Commisioning

Installation Configuration Troubleshooting Testing Commissioning

Typical steps

Page 6: Commissioning, Managing & Troubleshooting Industrial Networks

Unmanaged VS. Managed

HARDWARE

SOFTWARE

APPLICATIONSmall Scale Network

P2P Communication

Mid to Large Scale Network

Mission Critical Network with

Remote Monitoring

Packet Switching:

• Entry Level Switch ASIC

Packet Switching + Network

Management:

• Advanced Switch ASIC +

• CPU + Flash / RAM

Simple Data Switching Powerful Performance for

Network ManagementPOSITION

Plug and Play

No Configuration Required

Web / CLI Setting

• Network Security

• Network Redundancy

• Network Management

• Traffic Prioritization

Unmanaged

Switch

Managed

Switch

Page 7: Commissioning, Managing & Troubleshooting Industrial Networks

Network TopologyTypical Enterprise Star Topology

• Single point of failure

• Long, costly wire/fiber runs

Page 8: Commissioning, Managing & Troubleshooting Industrial Networks

Network ConfigurationSelecting the Right Topology for Your Needs

Redundant

Technology

Type Mesh STP RSTP Ring/Chain HSR/PRP

Feature

• Every node

connects to

each other

• IEEE

802.1D

• Loop-free

tree shape

topology

• IEEE 802.1w

• Loop-free

tree shape

topology

• Proprietary

technology

• Ring/Chain

Topology

• IEC 61850

• Dual Network (PRP)

• Dual Path (HSR)

Pros

• Highly

reliable

• Self-healing

• Open

Protocol

• Self-healing

• Open

Protocol

• Faster

recovery time:

~1 sec

• Low cost

• Self-healing

• Faster recovery

time (<20 ms)

• Open protocol

• Self-healing

• Zero recovery time

(0 ms)

Cons

• Too costly for

large network

deployment

• Recovery

time:

~15 sec

• Recovery

time not fast

enough

• Vendor specific

technology

• Prohibitively

expensive unless

absolutely needed

Backup Link

Root

Page 9: Commissioning, Managing & Troubleshooting Industrial Networks

Network TopologyTypical Industrial Ring Topology

• No single point of failure

• Reduced wiring costs

Page 10: Commissioning, Managing & Troubleshooting Industrial Networks

Industrial Protocols

• SCADA control / monitor PLC and field

devices via industrial protocols

Integration of SCADA & PLC Networks

Drive

I/O PLC

Ethernet

Switch

HMI

Page 11: Commissioning, Managing & Troubleshooting Industrial Networks

Network Configuration & Commissioning

• Two different methodologies for configuration of

network devices

• Many users from the industrial side prefer web

GUI

• Most users for commercial/enterprise side will

favor CLI

– Used by Cisco

Web Interface vs CLI

Page 12: Commissioning, Managing & Troubleshooting Industrial Networks

Device ConfigurationCommand Line Interface (CLI)

Page 13: Commissioning, Managing & Troubleshooting Industrial Networks

Device ConfigurationGraphical User Interface

• Visual confirmation of current settings

• Menu based configuration

• Standard web browser interface

Page 14: Commissioning, Managing & Troubleshooting Industrial Networks

Network Management Tools

Easy Configuration @ Installation Stage

Efficient Monitoring @ Operation Stage

Easy Backup/recovery @ Maintenance Stage

Quick Troubleshooting @ Diagnostics Stage

Page 15: Commissioning, Managing & Troubleshooting Industrial Networks

Mass Configuration Tools

Up to 10X Productivity Boost

One by One Setting by Web Batch Configuration by MXconfig

Multiple Devices Wiring

in Series

Broadcast Search

Group IP

Configuration

Group Redundancy

Configuration

Finish

400

sec

20

sec

200

sec

100

sec

Total

12 min

Single Power Supply

Single Device Wiring

IP Configuration

Redundancy Configuration

Repeat

100 times

Finish

10

sec

30

sec

35

sec

Total

125 min

Page 16: Commissioning, Managing & Troubleshooting Industrial Networks

Fast Group ConfigurationNetwork (IP address) Setting

Confidential

IP address setting for

mass devices

Page 17: Commissioning, Managing & Troubleshooting Industrial Networks

Fast Group Configuration802.1Q VLAN Setting

Confidential

Quick Add Panel

for cloning setting

*Mass 802.1Q VLAN Setting only for devices with the same model name

Page 18: Commissioning, Managing & Troubleshooting Industrial Networks

Fast Configuration DeploymentCopy Configuration

Confidential

Quick configuration copy

from one specific setting

to mass devices

Support mass IP

address setting

*Copy Configuration only for devices with the same model name

Page 19: Commissioning, Managing & Troubleshooting Industrial Networks

Configuration CheckStatus Overview

Confidential

Redundancy Setting

Overview802.1Q VLAN Setting

Overview

Page 20: Commissioning, Managing & Troubleshooting Industrial Networks

Startup Troubleshooting

Confidential21

Compare a Single Device with Whole Network

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=101, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

VLAN

1: Access, PVID=1, Forb=200

2: Access, PVID=2, Forb=300

3: Trunk, PVID=100, Tag=1,2

4: Trunk, PVID=100, Tag=1,2

Comparison

Sample

Benefit

Reduce Manual Setting Errors

Page 21: Commissioning, Managing & Troubleshooting Industrial Networks

DocumentationExport Configuration

Confidential

Export mass

configurations by

preference name

Page 22: Commissioning, Managing & Troubleshooting Industrial Networks

Network Management & Maintenance

Best Practices

Page 23: Commissioning, Managing & Troubleshooting Industrial Networks

Network Management & Maintenance

• Industrial NMS– Auto topology visualization

– Remote device management

– Real-time event management

– Comprehensive performance

reporting

Network Management Software

Confidential

Page 24: Commissioning, Managing & Troubleshooting Industrial Networks

Network Management & MaintenanceEfficient Visual Monitoring

Virtual Device Panel

Real-time Event

VLAN/IGMP

Visualization

Page 25: Commissioning, Managing & Troubleshooting Industrial Networks

CONFIGURATION CENTER

1-click for mass configuration backup and

firmware upgrade

Job scheduling for nightly configuration backup

Configuration change history

Network Management & MaintenanceSchedule Automatic Backups

Page 26: Commissioning, Managing & Troubleshooting Industrial Networks

• One-click Backup

– Only trigger ‘Reset’ button on switch to copy configuration and log

files to ABC-02-USB

• Files Import & Backup

– Configuration import & backup

– Firmware upgrade

– System log backup

Confidential

Rotate blinking under backup

Network Management & MaintenanceEasy Field Backup & Recovery

Page 27: Commissioning, Managing & Troubleshooting Industrial Networks

Potential Cyber Security Threats in Automation

• Operations disrupted by huge number of nuisance messages on network, slowing or blocking legitimate network traffic

Denial of service

• Causes computer to run attacker’s programStorage modification

• Replaces pieces of running program with attacker’s programMemory modification /Memory

Injection / SQL injection

• Attacker impersonates trusted computer, inserting itself as a middleman between trusted partner computers, modifying the messages between them to accomplish the attacker’s goals

Man-in-the-Middle

• Watches messages between computers to gain information about systemNetwork monitoring

• Gives attacker administrative privileges on systemEscalation of privilege

• Convincing users to unknowingly install malware by clicking on links, bypassing outward-directed firewallsPhishing attacks

• Attackers exploit trusting, helpful impulses of plant personnel to gain information used to bypass defenses and physical modification or sabotage of control equipment

Social engineering

Page 28: Commissioning, Managing & Troubleshooting Industrial Networks

Past Control

network security

• Physical perimeter security

• Air-gapping

• Security through obscurity

Maximize system

availability

• Remote access portals were added by plant engineering and vendor personnel

• Often without the acknowledge or approval by IT people

The security threat

environment has

substantially changed

• Nearly all systems are directly or indirectly connected to public networks

• Attackers are now aware of the possibilities of attacking control systems

Cyber Security Trend of Automation Network

Ref: Best practices in automation security by Murray McKay, Principal Application Engineer, Siemens Industry, Inc.

Page 29: Commissioning, Managing & Troubleshooting Industrial Networks

Create a Defense-in-Depth

Network Security Environment

Defense in Multiple Places

• Defend the Networks and Infrastructure (encryption and traffic flow security measures to resist passive monitoring)

• Defend the Enclave Boundaries (deploy Firewalls and Intrusion Detection to resist active network attacks)

• Defend the Computing Environment

Layered Defenses

• Each of these mechanisms must present unique obstacles to the adversary.

• Further, each should include both “protection” and “detection” measures

Confidential

The Best Countermeasure against Cyber Threats

Page 30: Commissioning, Managing & Troubleshooting Industrial Networks

Layered Cyber Security Solution for Automation

Security Site

• High-performance

• 500 Mbps

Security Zone

• Best Cost/Performance

• 300Mbps

Security Cell

• Best Integration

• 110 Mbps

Page 31: Commissioning, Managing & Troubleshooting Industrial Networks

Firmware updates

• FW updates are critical to ensuring your devices

are always up to date with the latest technology

– Includes both technology and security updates

• Many manufacturers offer free FW upgrades to

ensure their customers have longevity with the

products they have purhcased

Page 32: Commissioning, Managing & Troubleshooting Industrial Networks

Network Troubleshooting

Minimizing Downtime

Page 33: Commissioning, Managing & Troubleshooting Industrial Networks

Alerts on Unmanaged Switches

• While unmanaged switches

generally cannot communicate

status over the network, they

can be simply configured to

provide relay outputs for

alarms such as:

– Power Supply Failure

– Port Break Alarms

Monitoring System Changes

Page 34: Commissioning, Managing & Troubleshooting Industrial Networks

Alerts & Event Logs

Monitoring System Changes

Page 35: Commissioning, Managing & Troubleshooting Industrial Networks

Predictive Monitoring & AlertsComprehensive Fiber Status Monitoring and Warnings

Fiber Status Monitoring – Fiber

Temperature, Working Voltage,

Tx /Rx Powers

Auto Event Warning – SNMP

trap, Relay, Email, Event log

(DDM: Digital Diagnostics Monitoring)

SC ST SFP

All Fiber should be monitored

for fault prevention

Page 36: Commissioning, Managing & Troubleshooting Industrial Networks

Troubleshooting ToolsNetwork “Snapshot” Comparison Tools

• Quickly Collect Switch Info

(Take Network Snapshot)

• Quickly Compare Switch Info

(Compare Network Snapshots)

Page 37: Commissioning, Managing & Troubleshooting Industrial Networks

Troubleshooting ToolsEvent Playback

EVENT PLAYBACK

Record network status in 30 days

Network playback on any time/any event

Play at 1x, 2x, or 4x speed

Page 38: Commissioning, Managing & Troubleshooting Industrial Networks

Troubleshooting Tools

• Speed up on-site device finding to quickly diagnosis

Switch Finder

Confidential

Page 39: Commissioning, Managing & Troubleshooting Industrial Networks

Troubleshooting ToolsNetwork Protocol Analyzer

Page 40: Commissioning, Managing & Troubleshooting Industrial Networks

Q&A

Page 41: Commissioning, Managing & Troubleshooting Industrial Networks

Thank You