Cybersecurity Simplified: WALL IE. For Secure and Efficient Machine Networking

In a world where industrial systems face ever-growing cybersecurity threats, ensuring secure machine integration has become a necessity—not an option. At the latest with new specifications such as IEC 62443 and the European Machinery Regulation, corresponding cybersecurity measures will now be obligatory for all those who bring machinery into circulation. Helmholz addresses this critical need with the WALL IE, an industrial NAT gateway designed to streamline machine connectivity while safeguarding networks against potential risks.

Cybersecurity in Industrial Systems: A Key Priority

As Ethernet networking becomes integral to machinery and production systems, cybersecurity must take center stage. This necessity is reflected in current international norms and guidelines. For instance, the IEC 62443 series of standards focuses on securing Industrial Automation and Control Systems (IACS). It takes a holistic approach, addressing the needs of operators, integrators, and manufacturers. These standards define clear responsibilities for all stakeholders—mechanical engineers, suppliers, and end users—ensuring a unified approach to cybersecurity.

The European Union (EU) has also prioritized industrial cybersecurity through initiatives like the NIS-2 Directive (effective since 2023) and the Cyber Resilience Act (CRA). These measures underline the EU’s commitment to enhancing the digital security landscape.

Modernizing Machinery Regulations

In response to technological advancements—such as artificial intelligence, autonomy, and networked systems—the European Commission has revised the Machinery Directive 2006/42/EC, aligning it with the New Legislative Framework (NLF). These updates also address fundamental safety and health protection requirements for machinery.

The revised European Machinery Regulation 2023/1230 will come into effect on January 20, 2027, setting new standards for machinery placement in the market. This forward-looking regulation ensures that innovations in machinery technology are both safe and secure.

By aligning cybersecurity and machinery regulations with modern technological demands, industry leaders and regulators are safeguarding the future of industrial automation.

Securely Integrating Machinery Networks

Machine security has become a universal concern, underscoring the critical need to securely integrate machinery networks into overarching production systems. Achieving this requires robust strategies to safeguard Operational Technology (OT)—the hardware and software used to control, monitor, and secure industrial systems, devices, and processes.

The Role of “Secure OT”

The concept of “Secure OT” emphasizes protecting industrial control systems against growing threats in increasingly data-intensive environments. A key strategy here is network segmentation—dividing networks into separate zones to limit the spread of potential cyberattacks and enhance system integrity.

Zones and Conduits: A Proven Approach

Zones and conduits have emerged as a best practice for industrial network security. The IEC 62443 standard recommends this approach, recognizing that complex systems often face varied risks and threats. A security zone groups physical components with similar protection requirements, ensuring tailored defenses.

  • Security Zone Boundaries: Clearly define which components are inside or outside a zone.
  • Communication Conduits: Control and secure data flow between zones, with communication outside conduits explicitly restricted.

This layered approach enables a more precise response to risks, preventing a one-size-fits-all protection strategy from leaving critical vulnerabilities unaddressed.

By adopting these secure integration methods, manufacturers can better protect their production networks and enhance the resilience of industrial operations.

Secure Your Network Efficiently with WALL IE

When it comes to protecting networked machinery, the challenge lies in implementing a practical zones-and-conduits protection concept. While the market offers high-end solutions, these are often oversized for securing a single machine network—resulting in excessive complexity and costs. This leaves medium-sized mechanical engineering companies and their customers searching for a streamlined, reliable, and cost-efficient solution. That’s where the NAT Gateway WALL IE from Helmholz comes in: a compact, robust device that integrates seamlessly between the machine and the production network, combining bridge and firewall functionality in a user-friendly, efficient design.

Simple and Secure Network Protection

WALL IE secures your network by controlling which devices can exchange data, thanks to its packet filter functionality. This feature limits access between the production network and automation cells, creating a secure boundary. Additionally, the WALL IE simplifies network management by representing the machine network and production network as a single IP address.

This device operates in two modes for maximum flexibility:

  1. Bridge Mode: Acts as a switch while allowing packet filtering—unlike standard switches—enabling controlled access to specific areas without requiring separate networks.
  2. NAT Mode: Used by most users, this mode forwards traffic between different IPv4 networks (Layer 3) and uses packet filters for access control. NAT (Network Address Translation) functionality supports both basic NAT (1:1 NAT) and NAPT (1:N NAT or “Masquerading”), making it possible to integrate multiple automation cells with identical address ranges into the production network.

Expanded Options with Compact and Plus version

Since its launch in 2015, WALL IE has continuously evolved, responding to customer feedback to expand its capabilities. Since, new variants join the standard version (4 ports, 100 Mbps):

  • Compact Version: Designed with two ports—one for the company network (WAN) and one for the machine network (LAN)—this model is ideal for simpler setups.
  • Plus Version: Offers eight configurable ports for LAN or WAN, enabling smaller networks to be managed without additional switches.

Both Compact and Plus feature a faster processor with Ethernet speeds of up to 1 Gbit/s, opening up new application possibilities.

Easy Setup, Minimal Expertise Required

All WALL IE variants are designed for quick and straightforward installation. With no need to adjust LAN network configurations, integrating series machines with identical IP addresses is a breeze. This simplicity ensures that even users with basic network knowledge can deploy WALL IE effectively.

For secure, reliable, and cost-efficient network protection, WALL IE delivers a proven solution tailored to the needs of modern machinery networks.

Summary

In the connected industries of the future, machine and system security will be critical to ensuring stable, error-free operations. By segmenting networks and securing access to machine networks, processes can be optimized effortlessly. The WALL IE series from Helmholz provides an easy-to-configure solution with NAT Gateways and machine firewalls that deliver tailored protection for sensitive data. With minimal effort, these robust devices safeguard critical systems against cyber threats, making them an essential tool for secure and efficient operations.