Firewalls are generally used to restrict electronic access to
the network, and Virtual Private Networks (VPNs) may be
used to establish remote connections. Firewalls are available
with a variety of capabilities, ranging from simple devices,
which block communication based on source or destination
addresses to powerful devices, which are able to inspect the
contents of communication and dynamically decide whether
information should be passed on or blocked. At the minimum,
a firewall should be placed between the industrial network
and any external network to which it connects. However, a
18
single firewall may often be inadequate, depending on the level
of access that is required. For example, high level devices
such as plant historians often pose a challenge to single
firewall installations. If the historian is located on the industrial
network many client devices on the business network must be
given access to the industrial network to communicate with
the historian. Alternatively, the historian could be placed on
the business network and be granted access to all the devices
on the industrial network from which it gathers data. In either
scenario, the firewall must be configured to be very open, with
a high level of interaction allowed between the business and
industrial networks.