RAGERSEC
RagerShield

The OT firewall. As hardware or virtual.

RagerShield checks every access to your controllers down to the function level. You choose where it runs: as rugged hardware in the control cabinet or as a virtual machine in the control room and data centre.

Editions

One firewall, two form factors

For control cabinets and field level

RagerShield Hardware

  • Fanless and passively cooled, no moving parts
  • DIN-rail mounting
  • Hardware bypass: if the device fails, the process keeps running
  • Transparent layer 2 bridge, no changes to the configuration
For control rooms, data centres and virtual networks

RagerShield Virtual

  • VMware ESXi
  • Microsoft Hyper-V
  • Proxmox / KVM
  • Delivered as a ready-made VM image with the same features as the hardware

Technical data and datasheet on request.

Features

Included in both editions

  • Deep packet inspection for industrial protocols
  • Learning mode and allowlist rule set
  • Time-limited maintenance windows
  • Logging via syslog to SIEM and OT monitoring
  • Central management with RagerVision
Rules

What a rule looks like

Rules are readable and can be versioned. In this example the HMI may only read one register range, only the control centre may send commands to the telecontrol station, and the engineering station may only write during the maintenance window.

SourceTargetProtocolFunctionRangeAction
HMI-02M580Modbus/TCPRead (FC 3)40001–40100Allow
ENG-WSCPU 1516S7CommPlusWrite, downloadallMaintenance window only
SCADARTU-07IEC 60870-5-104Commands C_SC, C_DCIOA 1000–1099Allow
anyall controllersallStop, reset, download–Block
anyanyallother–Block + alert
Operating modes

Observe first, then protect

Monitor

Passive listening on a mirror port. No interference with traffic, ideal for the initial assessment.

Learn

RagerSec records connections and functions and derives a proposed rule set.

Alert

Rules are active, violations are reported but not yet blocked.

Protect

Everything not allowed is dropped. Critical functions are always blocked except during an approved maintenance window.

Rollout

From pilot to production

  1. Assessment

    Monitor mode on a mirror port. Together we see who talks to which CPU.

  2. Rule set

    Learning mode produces a proposal that your maintenance team reviews.

  3. Inline test

    Installed as a bridge during a shutdown, initially in alert mode.

  4. Protection on

    Switch to blocking. Maintenance windows are opened through an approval.

Fail-safe: a hardware bypass is planned for inline operation so that a device failure does not stop the process.

Looking for pilot sites

We are looking for operators and system integrators in manufacturing, energy and building automation to test RagerSec in our early access program.