Hello,
I have a customer who is considering implementing an Emerson Smart Firewall, but they are split on the decision and are asking me to provide them with a justification or list of pros and cons based on their current architecture. I need some help considering a reply. Their network architecture is laid out as follows (using page 17 of the DeltaV Security Manual as a reference):
The L2.5 network will be implemented and a DeltaV Continuous Historian will be connected to it. They are going to add a firewall between the L3 and the L2.5 network and restrict the traffic. In the DMZ they plan to place a PI Data Collector server which will connect to the DeltaV Continuous Historian on the L2.5 network.
The debate is whether or not the Emerson Smart Firewall is necessary, useful, and/or desired. Currently, there are a few points/questions be debated:
Your thoughts and expertise is appreciated!
Thanks,Dave
Andre Dicaire
In reply to Andre Dicaire:
In reply to dave_marshall:
In reply to gamella:
The firewall that the corporate IT group has chosen has the ability to create a separate DMZ network on its own. In this separate DMZ that they can create (separate from the DeltaV Process DMZ in the security manual) they plan to place the PI Data collector. See the image below for reference as to what this would look like with the Emerson firewall.
If they place the PI Data Collector server in the DMZ off of the Corp firewall, does this make the Emerson firewall un-necessary as Andre suggests?