Network Segmentation
Once the HMI’s and PLC’s have been classified and “registered” in FortiNAC, the next step is to configure Network Access Policies to place these devices into the appropriate Purdue Level VLAN.
Network Access Policies: Leveraging the device classification knowledge from the device profiling functionality.
Steps
-
Go to Policy & Objects > Network Access > Policies.
-
Create two network access policies. The picture below shows the Network Access Policies that will be created in this example.
-
Click Add
Name your policy.
User/Host Profile: Click Create. Make a User/Host profile.
Network Access Configuration: Click Create. Create a Network Access Configuration. Create also a Logical Network.
-
PLC’s are assigned to a Purdue Level One VLAN
-
HMI’s are assigned to a Purdue Level Two VLAN
-
FortiCameras are assigned to an IoT VLAN
Settings for Add User/Host Profile
Where (Location): Any
Who/What by Group: Any
Who/What by Attribute: Host [Device Type: PLC]
When: Always
-
-
After creating a logical network, you need to go to Network > Inventory > Virtualized Devices. Then, right click root > Model Configuration.
We set the following settings under Model Configuration.
a. Power & Utilities Logical Network to VLAN mapping
b. Oil & Gas Logical Network to VLAN mapping
c. Manufacturing Logical Network to VLAN mapping
Network segmentation policies should be complete.