RAGERSEC
In development · Early access from 2027

The firewall that knows what a PLC stop is.

RagerSec is an OT-native firewall for industrial networks. It understands protocols such as S7, Modbus, OPC UA, IEC 104 and DNP3 down to the function level and only lets through the access your process actually needs.

rule-log · conduit supervisory ↔ cell-3Sample data
10:42:17S7commPLC Stop (0x29)HMI-02 → CPU 315BLOCKED
10:42:19Modbus/TCPRead Holding Reg. (FC 3)HMI-02 → M580ALLOWED
10:42:21IEC 104Single command C_SC_NA_1unknown → RTU-07BLOCKED
10:42:24OPC UARead · ns=3SCADA → CPU 1516ALLOWED
10:42:30Modbus/TCPWrite Mult. Reg. (FC 16)ENG-WS → M580BLOCKED
Write access from the engineering station is only allowed during an approved maintenance window.
The problem

An open port means everything is open.

With controllers, conventional firewalls only see ports such as 102, 502 or 2404. Whether an HMI is reading a value or someone is stopping a controller stays invisible.

IT firewall

  • Rules based on IP and port only
  • Read, write, stop and program download look the same
  • No visibility into data blocks, registers or telecontrol commands

RagerSec

  • Rules per protocol function, e.g. “read only on DB12”
  • Stop, write and download commands blocked by default
  • Time-limited approvals for maintenance windows
Features

Built for plants, not office networks.

DPI

Deep packet inspection

Decodes industrial protocols such as S7, Modbus, OPC UA, IEC 104 and DNP3 down to the individual function and address.

Allowlist

Learning mode

Records normal traffic and proposes a rule set for you to review and approve.

Bridge

Transparent deployment

Runs as a layer 2 bridge. No new IP addresses, no changes to the controller configuration.

Maintenance

Maintenance windows

Program changes only after approval and only for a defined period.

Syslog

Traceable

Every decision is logged and can be forwarded to your SIEM or OT monitoring.

62443

Zones and conduits

Technically enforces the zone boundary according to IEC 62443-3-3.

Products

Two products, one system.

RagerShield protects the plant on site. RagerVision manages all RagerShields centrally.

OT firewall

RagerShield

The firewall for your control networks, as fanless DIN-rail hardware or as a virtual machine.

  • Passively cooled, built for the control cabinet
  • Hardware bypass on failure
  • As a VM for VMware ESXi, Hyper-V and Proxmox/KVM
Learn more
Management

RagerVision

The management tool for all RagerShields: rules, devices, vulnerabilities and alerts in one place.

  • Central management and updates
  • Asset inventory and vulnerabilities
  • On-premises or as a cloud service
Learn more
Deployment

Between supervisory level and cell.

RagerSec sits at the boundary between two zones and checks every access to the controllers.

Looking for pilot sites

We are looking for operators and system integrators in manufacturing, energy and building automation to test RagerSec in our early access program.