Sd03029sen 0122-00
Sd03029sen 0122-00
Special Documentation
Security Manual
FieldEdge SGC500
Industrial edge device for connecting field devices to the
Netilion Cloud
Security Manual FieldEdge SGC500
Serial number
2. www.endress.com/deviceviewer Endress+Hauser
Operations App
3.
A0023555
2 Endress+Hauser
Security Manual FieldEdge SGC500 Table of contents
Table of contents
Endress+Hauser 3
Reporting security gaps and advisories Security Manual FieldEdge SGC500
4 Endress+Hauser
Security Manual FieldEdge SGC500 About this document
Reference to documentation
Reference to graphic
Result of a step
1, 2, 3, ...
Item numbers
A, B, C, ...
Views
Endress+Hauser 5
About this document Security Manual FieldEdge SGC500
2.3 Documentation
6 Endress+Hauser
Security Manual FieldEdge SGC500 System design
3 System design
Endress+Hauser 7
System design Security Manual FieldEdge SGC500
1
2
3
Netilion 4
IT
3
16
5
6
OT 7
10
15
11
14
12
13
A0048899
1 Connection of FieldEdge SGC500 via separate interfaces for Internet and fieldbus network (blue marking
shows the system boundaries for this manual)
IT Information Technology, here: company network for information processing and with Internet connection
OT Operational Technology, here: network for process automation
1 Netilion Cloud
2 Netilion Connect: Application Programming Interface (API)
3 https Internet connection
4 User system with user application
5 Netilion Services: browser-based Netilion Service app
6 System firewall
7 WAN Internet connection – https, plant-side connection
8 FieldEdge SGC500 reads field device data and transmits it securely to the Netilion Cloud
9 Fieldbus network
10 Ethernet communication
11 Supported fieldbus gateways for conversion from a fieldbus protocol to an IP protocol
12 Fieldbus communication
13 System components such as Endress+Hauser field devices and third-party field devices
14 EtherNet/IP-enabled field devices
15 Industrial Ethernet
16 Firewall of company network
8 Endress+Hauser
Security Manual FieldEdge SGC500 System design
The graphic shows the FieldEdge SGC500 and all the components that are involved in the
information flow and are required to capture the device status information and forward
this to the Endress+Hauser Netilion Cloud.
The FieldEdge SGC500 is an edge device. Communication between the FieldEdge SGC500
and the system components is based on Industrial Ethernet protocols, such as HART/IP, or
also proprietary protocols. The FieldEdge SGC500 only forwards dedicated information
from the subordinate system components, which has been requested by the FieldEdge, to
the Netilion Cloud via the Web address netilion.endress.com.
General forwarding of data from the fieldbus network (OT) to the company network (IT)
does not take place. The operator must provide a firewall.
Netilion
IT
OT OT
4 1
3 2
A0048892
2 Recommended segmentation in the event of multiple fieldbus networks with several FieldEdge SGC500
units (blue marking shows the system boundaries for this manual)
1 FieldEdge SGC500 for fieldbus network 1
2 Fieldbus network 1
3 Fieldbus network 2
4 FieldEdge SGC500 for fieldbus network 2
The graphic shows the recommended segmentation of a fieldbus network when two
FieldEdge SGC500 units are used. In this version, two subordinate fieldbus networks are
connected to the Netilion Cloud. Each fieldbus network (OT) is connected to the higher-
level company network (IT) via a FieldEdge SGC500. This wiring ensures that the two
fieldbus network segments are separated.
Endress+Hauser 9
System design Security Manual FieldEdge SGC500
Netilion 1
2
IT
3
4
OT
A0050292
3 Connection of FieldEdge SGC500 via just one interface for Internet and fieldbus network (blue marking
shows the system boundaries for this manual)
1 Netilion Cloud
2 https Internet connection
3 Firewall of company network
4 Internet and fieldbus network only connected to one interface of the SGC500
5 FieldEdge SGC500
6 Fieldbus network
The graphic shows the connection of the FieldEdge SGC500 via a single interface. In this
example, the data traffic of the field network and the data traffic to the Netilion Cloud run
via one network interface on the FieldEdge SGC500.
This version is not recommended due to the limited separation of the data flows. This
layout does not work with EtherNet/IP.
10 Endress+Hauser
Security Manual FieldEdge SGC500 System design
Endress+Hauser 11
System design Security Manual FieldEdge SGC500
In addition to the risk assessment, the planning process should also include specifications
on how the product is to be configured during commissioning. This includes, for example,
switching off interfaces and/or services that are not required or changing default
passwords etc. These measures are explained in the following sections.
12 Endress+Hauser
Security Manual FieldEdge SGC500 System design
IIoT ecosystem. This can be accomplished by securely storing the access data and
certificates.
During commissioning it may be necessary to configure the FieldEdge locally. The
FieldEdge is protected via a login. The local configuration must be made temporarily via a
directly connected Ethernet cable in the access-controlled control room.
For more information on "Login (manual connection)", see the Operating Instructions
→ 6
Endress+Hauser 13
Commissioning (installation and configuration) Security Manual FieldEdge SGC500
4.3 Installation
Install and connect the product in accordance with the relevant Brief Operating
Instructions/Operating Instructions.
4.4 Configuration
14 Endress+Hauser
Security Manual FieldEdge SGC500 Commissioning (installation and configuration)
Endress+Hauser 15
Commissioning (installation and configuration) Security Manual FieldEdge SGC500
16 Endress+Hauser
Security Manual FieldEdge SGC500 Operation
5 Operation
Endress+Hauser 17
Operation Security Manual FieldEdge SGC500
You can determine the software version of the FieldEdge as follows: the software version
currently loaded in the FieldEdge is shown in the Netilion Account under the SGC500
details for the SGC500 in question.
Troubleshooting
FieldEdge is defective
Endress+Hauser Service found that the FieldEdge is defective and needs to be replaced.
Endress+Hauser Service will send you a preconfigured replacement device.
Furthermore, you are requested to return the defective FieldEdge to Endress+Hauser or to
destroy and dispose of the defective FieldEdge.
18 Endress+Hauser
Security Manual FieldEdge SGC500 Operation
4. Connect, configure and commission the new FieldEdge as specified in the Operating
Instructions.
We recommend you delete your access data / user data from the FieldEdge if you
have to take the FieldEdge out of service due to a defect. By deleting your data, you
are preventing any improper use of your data.
5.8.2 Disposal
Proceed as follows if you have to dispose of the FieldEdge:
1. After being instructed by Endress+Hauser Service, delete the access data from the
FieldEdge to the Netilion Cloud from the defective FieldEdge.
2. In Netilion, delete or reset the data on the following pages: "Network Interface
Details", "Field Gateways" and / or "EtherNet/IP Activation Status"
3. Destroy the defective FieldEdge and dispose of it. Observe the following instructions.
• We recommend you delete your access data / user data from the FieldEdge if you
have to dispose of the FieldEdge. By deleting your data, you are preventing any
improper use of your data.
• Before you dispose of, or scrap, the FieldEdge, we recommend that you proceed in
accordance with the following guideline: NIST Special Publication 800-88,
Revision 1: Guidelines for Media Sanitization
Endress+Hauser 19
Decommissioning Security Manual FieldEdge SGC500
6 Decommissioning
The product has a fault that you are unable to Contact Endress+Hauser Service and follow the instructions of
rectify. Endress+Hauser Service→ 18.
20 Endress+Hauser
Security Manual FieldEdge SGC500 Appendix
7 Appendix
DNS 53/853 It must be possible to reach a TCP-DNS server with the current
address resolution.
UDP DHCP (IPv4) 67 Bootstrap Protocol (BOOTP) server, also used by DHCP
Endress+Hauser 21
Appendix Security Manual FieldEdge SGC500
SSH 22 SSH This service is only used for forensic analysis in the event of a
defective FieldEdge. SSH is secured by a private key. The private
key is only available on Endress+Hauser development PCs.
Endress+Hauser does not provide for access via SSH during
operation. We recommend you block this service in the company
firewall.
https 443 The updates of the FieldEdge SGC500 are transmitted to the
FieldEdge in a response to a request via https (port 443).
22 Endress+Hauser
Security Manual FieldEdge SGC500 Appendix
Endress+Hauser 23
*71587739*
71587739
www.addresses.endress.com