Fortinet white logo
Fortinet white logo
7.6.0

Network Segmentation

Network Segmentation

Once the HMI’s and PLC’s have been classified and “registered” in FortiNAC, the next step is to configure Network Access Policies to place these devices into the appropriate Purdue Level VLAN.

Network Access Policies: Leveraging the device classification knowledge from the device profiling functionality.

Steps

  1. Go to Policy & Objects > Network Access > Policies.

  2. Create two network access policies. The picture below shows the Network Access Policies that will be created in this example.

    A screenshot of a computer

Description automatically generated

  3. Click Add

    Name your policy.

    User/Host Profile: Click Create. Make a User/Host profile.

    Network Access Configuration: Click Create. Create a Network Access Configuration. Create also a Logical Network.

    • PLC’s are assigned to a Purdue Level One VLAN

    • HMI’s are assigned to a Purdue Level Two VLAN

    • FortiCameras are assigned to an IoT VLAN

      A screenshot of a computer

Description automatically generated

      Settings for Add User/Host Profile

      Where (Location): Any

      Who/What by Group: Any

      Who/What by Attribute: Host [Device Type: PLC]

      When: Always

      A screenshot of a computer

Description automatically generated

  4. After creating a logical network, you need to go to Network > Inventory > Virtualized Devices. Then, right click root > Model Configuration.

    A screenshot of a computer

Description automatically generated

    We set the following settings under Model Configuration.

    a. Power & Utilities Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

    b. Oil & Gas Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

    c. Manufacturing Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

Network segmentation policies should be complete.

Network Segmentation

Network Segmentation

Once the HMI’s and PLC’s have been classified and “registered” in FortiNAC, the next step is to configure Network Access Policies to place these devices into the appropriate Purdue Level VLAN.

Network Access Policies: Leveraging the device classification knowledge from the device profiling functionality.

Steps

  1. Go to Policy & Objects > Network Access > Policies.

  2. Create two network access policies. The picture below shows the Network Access Policies that will be created in this example.

    A screenshot of a computer

Description automatically generated

  3. Click Add

    Name your policy.

    User/Host Profile: Click Create. Make a User/Host profile.

    Network Access Configuration: Click Create. Create a Network Access Configuration. Create also a Logical Network.

    • PLC’s are assigned to a Purdue Level One VLAN

    • HMI’s are assigned to a Purdue Level Two VLAN

    • FortiCameras are assigned to an IoT VLAN

      A screenshot of a computer

Description automatically generated

      Settings for Add User/Host Profile

      Where (Location): Any

      Who/What by Group: Any

      Who/What by Attribute: Host [Device Type: PLC]

      When: Always

      A screenshot of a computer

Description automatically generated

  4. After creating a logical network, you need to go to Network > Inventory > Virtualized Devices. Then, right click root > Model Configuration.

    A screenshot of a computer

Description automatically generated

    We set the following settings under Model Configuration.

    a. Power & Utilities Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

    b. Oil & Gas Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

    c. Manufacturing Logical Network to VLAN mapping

    A screenshot of a computer

Description automatically generated

Network segmentation policies should be complete.