RagerShield
The firewall for your control networks, as fanless DIN-rail hardware or as a virtual machine.
- Passively cooled, built for the control cabinet
- Hardware bypass on failure
- As a VM for VMware ESXi, Hyper-V and Proxmox/KVM
RagerSec is an OT-native firewall for industrial networks. It understands protocols such as S7, Modbus, OPC UA, IEC 104 and DNP3 down to the function level and only lets through the access your process actually needs.
| 10:42:17 | S7comm | PLC Stop (0x29) | HMI-02 → CPU 315 | BLOCKED |
| 10:42:19 | Modbus/TCP | Read Holding Reg. (FC 3) | HMI-02 → M580 | ALLOWED |
| 10:42:21 | IEC 104 | Single command C_SC_NA_1 | unknown → RTU-07 | BLOCKED |
| 10:42:24 | OPC UA | Read · ns=3 | SCADA → CPU 1516 | ALLOWED |
| 10:42:30 | Modbus/TCP | Write Mult. Reg. (FC 16) | ENG-WS → M580 | BLOCKED |
With controllers, conventional firewalls only see ports such as 102, 502 or 2404. Whether an HMI is reading a value or someone is stopping a controller stays invisible.
Decodes industrial protocols such as S7, Modbus, OPC UA, IEC 104 and DNP3 down to the individual function and address.
Records normal traffic and proposes a rule set for you to review and approve.
Runs as a layer 2 bridge. No new IP addresses, no changes to the controller configuration.
Program changes only after approval and only for a defined period.
Every decision is logged and can be forwarded to your SIEM or OT monitoring.
Technically enforces the zone boundary according to IEC 62443-3-3.
RagerShield protects the plant on site. RagerVision manages all RagerShields centrally.
The firewall for your control networks, as fanless DIN-rail hardware or as a virtual machine.
The management tool for all RagerShields: rules, devices, vulnerabilities and alerts in one place.
RagerSec sits at the boundary between two zones and checks every access to the controllers.
We are looking for operators and system integrators in manufacturing, energy and building automation to test RagerSec in our early access program.