Secure Your Network Efficiently with WALL IE

When it comes to protecting networked machinery, the challenge lies in implementing a practical zones-and-conduits protection concept. While the market offers high-end solutions, these are often oversized for securing a single machine network—resulting in excessive complexity and costs. This leaves medium-sized mechanical engineering companies and their customers searching for a streamlined, reliable, and cost-efficient solution. That’s where the NAT Gateway WALL IE from Helmholz comes in: a compact, robust device that integrates seamlessly between the machine and the production network, combining bridge and firewall functionality in a user-friendly, efficient design.

Simple and Secure Network Protection

WALL IE secures your network by controlling which devices can exchange data, thanks to its packet filter functionality. This feature limits access between the production network and automation cells, creating a secure boundary. Additionally, the WALL IE simplifies network management by representing the machine network and production network as a single IP address.

Key Features

  • NAT and Packet Filtering: Efficiently manage data traffic between different IPv4 networks with advanced NAT capabilities and packet filtering.
  • Bridge Mode: Operate as a layer 2 switch with packet filtering to restrict access without needing separate networks.
  • Easy Configuration: User-friendly web interface for quick setup and management.
  • Security Compliance: Meets IEC 62443 standards for industrial cybersecurity, ensuring comprehensive protection for your network.

Basic NAT

NAT functionality

The WALL IE series uses Network Address Translation (NAT) to integrate multiple automation cells with identical ip address ranges into a production network, preventing IP address conflicts.

It supports various NAT types, including Basic NAT (1:1 NAT), NAPT (1:N NAT), and SNAT (Source NAT), each offering different levels of address translation and port forwarding capabilities.

The configuration is straightforward, involving setting the operating mode, configuring LAN and WAN interfaces, and defining NAT rules to map internal IP addresses to external ones. This makes the WALL IE an effective solution for network integration and security.

Bridge functionality

In bridge mode, the WALL IE acts as a network bridge within an IPv4 subnetwork, functioning similarly to a layer 2 switch. Unlike typical switches, the WALL IE allows for packet filtering, enabling you to restrict access to specific areas of your network without needing separate networks.

This mode is particularly useful for managing traffic and enhancing security within a single network segment by filtering packets based on criteria such as IP addresses, protocols, and MAC addresses.

WALL IE Firewall

Product overview

WALL IE Standard

WALL IE Firewall / Bridge / NAT small

Features

  • 4 ports for 100 Mbps
  • Integration of series machines with identical IP addresses
  • NAT (Basic NAT, NAPT and port forwarding)
  • SNAT: No adjustment of the network configuration necessary in the machine network
  • Access restriction through packet filters: IPv4 addresses Protocol (TCP/UDP/ ICMP), ports, MAC addresses
  • Simple integration of identical IP subnets through port forwarding (NAPT)

WALL IE Compact

Features

  • All features of the WALL IE standard
  • 2 ports for 100/1000 Mbps
  • Integration of series machines with identical IP addresses
  • Quick and easy configuration via a responsive web interface
  • Reduced to the relevant functional scope

WALL IE Plus

Features

  • All features of the WALL IE standard
  • 8 ports for 100/1000 Mbps
  • Integration of series
  • machines with identical IP addresses
  • Firewall and user administration integrated
  • Ethernet ports for LAN or WAN. Freely configurable
  • Reduction of the network load through broadcast filtering

Zones and Conduits: A Proven Approach

Zones and conduits have emerged as a best practice for industrial network security. The IEC 62443 standard recommends this approach, recognizing that complex systems often face varied risks and threats. A security zone groups physical components with similar protection requirements, ensuring tailored defenses.

  • Security Zone Boundaries: Clearly define which components are inside or outside a zone.
  • Communication Conduits: Control and secure data flow between zones, with communication outside conduits explicitly restricted.

This layered approach enables a more precise response to risks, preventing a one-size-fits-all protection strategy from leaving critical vulnerabilities unaddressed.

By adopting these secure integration methods, manufacturers can better protect their production networks and enhance the resilience of industrial operations.

Secure Your Network Efficiently with WALL IE

When it comes to protecting networked machinery, the challenge lies in implementing a practical zones-and-conduits protection concept. While the market offers high-end solutions, these are often oversized for securing a single machine network—resulting in excessive complexity and costs. This leaves medium-sized mechanical engineering companies and their customers searching for a streamlined, reliable, and cost-efficient solution. That’s where the NAT Gateway WALL IE from Helmholz comes in: a compact, robust device that integrates seamlessly between the machine and the production network, combining bridge and firewall functionality in a user-friendly, efficient design.