RAGERSEC
Protocols

One rule set for every industrial protocol.

RagerSec understands the protocols of manufacturing, energy and building automation down to the function level. Version 1 starts with Siemens S7, OPC UA and Modbus/TCP, with more protocols following step by step.

Overview

Supported protocols

ProtocolUseTransportStatus
Manufacturing
S7commSiemens S7-300/400TCP 102Version 1
S7CommPlusSiemens S7-1200/1500TCP 102Version 1
OPC UAmulti-vendorTCP 4840Version 1
Modbus/TCPmulti-vendorTCP 502Version 1
EtherNet/IP (CIP)Rockwell, Omron and othersTCP 44818 · UDP 2222In development
PROFINETfield devicesEthernet 0x8892Planned
Energy & utilities
IEC 60870-5-104telecontrolTCP 2404In development
DNP3telecontrol, waterTCP 20000In development
IEC 61850 MMSsubstationsTCP 102Planned
IEC 61850 GOOSEsubstationsEthernet 0x88B8Planned
Buildings & IIoT
BACnet/IPbuilding automationUDP 47808Planned
MQTTIIoT, telemetryTCP 1883 · 8883Planned
Functions

What is blocked by default

For every protocol, RagerSec distinguishes between read access and functions that change the process. Critical functions stay blocked until you explicitly allow them, for example for a maintenance window.

ProtocolBlocked by defaultAllowed per rule
S7comm / S7CommPlusPLC stop, block download, start and reset commandsReading and writing variables in approved areas
Modbus/TCPWrite (FC 5, 6, 15, 16), diagnostics (FC 8), vendor-specific programming functionsRead (FC 1–4) in approved register ranges
OPC UAWrite and Call outside approved nodes, connections with SecurityMode “None”Browse, Read, subscriptions
EtherNet/IP (CIP)Tag writes, reset, program downloadTag reads
IEC 60870-5-104Commands (C_SC, C_DC, C_SE) and reset process (C_RP) from unknown stationsMonitoring (M_*), interrogation (C_IC) and clock sync (C_CS) from the control centre
DNP3Select/Operate, Direct Operate, cold/warm restart, stop applicationRead, unsolicited responses
IEC 61850Control commands (Operate), file transfer, unknown GOOSE publishersReading data objects, known GOOSE streams
BACnet/IPWriteProperty on critical objects, ReinitializeDevice, DeviceCommunicationControlReadProperty, Who-Is/I-Am
MQTTPublish to control topics by unknown clientsTelemetry topics, subscribe
Encryption

Encrypted connections

Many protocols can be secured today, for example OPC UA with SignAndEncrypt, S7 with TLS or MQTT over TLS. For OPC UA, RagerSec can enforce a minimum security mode.

When content is encrypted, RagerSec enforces rules at the connection and endpoint level and logs every session. Inspecting individual functions is not possible in that case.

Looking for pilot sites

We are looking for operators and system integrators in manufacturing, energy and building automation to test RagerSec in our early access program.