The OT firewall. As hardware or virtual.
RagerShield checks every access to your controllers down to the function level. You choose where it runs: as rugged hardware in the control cabinet or as a virtual machine in the control room and data centre.
One firewall, two form factors
RagerShield Hardware
- Fanless and passively cooled, no moving parts
- DIN-rail mounting
- Hardware bypass: if the device fails, the process keeps running
- Transparent layer 2 bridge, no changes to the configuration
RagerShield Virtual
- VMware ESXi
- Microsoft Hyper-V
- Proxmox / KVM
- Delivered as a ready-made VM image with the same features as the hardware
Technical data and datasheet on request.
Included in both editions
- Deep packet inspection for industrial protocols
- Learning mode and allowlist rule set
- Time-limited maintenance windows
- Logging via syslog to SIEM and OT monitoring
- Central management with RagerVision
What a rule looks like
Rules are readable and can be versioned. In this example the HMI may only read one register range, only the control centre may send commands to the telecontrol station, and the engineering station may only write during the maintenance window.
| Source | Target | Protocol | Function | Range | Action |
|---|---|---|---|---|---|
| HMI-02 | M580 | Modbus/TCP | Read (FC 3) | 40001–40100 | Allow |
| ENG-WS | CPU 1516 | S7CommPlus | Write, download | all | Maintenance window only |
| SCADA | RTU-07 | IEC 60870-5-104 | Commands C_SC, C_DC | IOA 1000–1099 | Allow |
| any | all controllers | all | Stop, reset, download | – | Block |
| any | any | all | other | – | Block + alert |
Observe first, then protect
Passive listening on a mirror port. No interference with traffic, ideal for the initial assessment.
RagerSec records connections and functions and derives a proposed rule set.
Rules are active, violations are reported but not yet blocked.
Everything not allowed is dropped. Critical functions are always blocked except during an approved maintenance window.
From pilot to production
Assessment
Monitor mode on a mirror port. Together we see who talks to which CPU.
Rule set
Learning mode produces a proposal that your maintenance team reviews.
Inline test
Installed as a bridge during a shutdown, initially in alert mode.
Protection on
Switch to blocking. Maintenance windows are opened through an approval.
Fail-safe: a hardware bypass is planned for inline operation so that a device failure does not stop the process.
Looking for pilot sites
We are looking for operators and system integrators in manufacturing, energy and building automation to test RagerSec in our early access program.