Innominate mGuard
From SCADApedia
The Innominate mGuard is a line of security appliances designed for industrial and other non-office environments. The security appliance includes a firewall, VPN and anti-virus gateway. mGuard is sold by Innominate and by control system vendors that private label the products. In April 2008 Phoenix Contact purchased Innominate, and it is unclear what the impact to the mGuard product will be.
Contents |
Overview
The mGuard family of field security appliances runs on a Linux operating system in a variety of sizes and environmental performance parameters. All models have at least two 10/100 Base TX Ethernet ports. The base configuration of each model comes with a stateful inspection firewall, which is Innominate code rather than the open source iptables. Innominate has written IPSEC (ESP) VPN code for AES/DES/3DES algorithms that is available as a feature upgrade. A CLAM AntiVirus gateway capability is available for http, ftp, pop3 and smtp.
Models
- mGuard Smart is a small, lightweight (less than 1 pound) bump in the line device with a USB and RJ-45 Ethernet cable on one side and a RJ-45 Ethernet port on the other side.
- mGuard PCI is a PCI form factor that can be placed in a PC or other computer or appliance. List price for the PCI/266 with firewall only is 361 Euro.
- mGuard bladePack is a 19-inch rack mount device that can hold 1 to 12 mGuard blades. Each blade has the capability of a mGuard. The bladePack is appropriate for a control center or data center environment. A bladePack with 12 blades has a list price of about 10,000 Euro.
- EAGLE mGuard is a rail mounted device designed for a rugged, field environment. The EAGLE model meets environmental specifications more appropriate for a field environment such as IP20,IEC 60068 shock and vibration, and EN 61000 ESD, electromagnetic field, burst, surge and conducted emission. The EAGLE model is also sold under the Hirschmann brand.
- mGuard Delta is a small 4-port switch form factor. The Delta with the VPN feature has a list price of 538 Euro.
Management
A network of mGuard devices are deployed and managed with the Innominate Device Manager (IDM). The IDM server application runs on Windows 2000, XP or Linux. The IDM can push configuration settings to the device or an mGuard can pull configuration settings from the IDM. All IDM to mGuard communication takes place over a secure protocol, ssh or https.
"Stealth Mode" allows a mGuard to be placed inline at a field site without needing to change any IP addresses. A technician can install a mGuard without disrupting operations, except for the time it takes to connect cables. An IDM administrator would then remotely program the mGuard appliance. Templates can ease the deployment of multiple mGuard appliances with similar configurations.
Status
The first mGuard shipped in 2005 and approximately 10,000 have been sold to date. The deployed base includes both control system and other non-office environments.
Sales of mGuard are primarily in Europe, and the mGuard is not currently distributed by Innominate in the United States.
In April 2008 Phoenix Contact purchased Innominate.
