{"id":61360,"date":"2025-09-26T11:19:29","date_gmt":"2025-09-26T11:19:29","guid":{"rendered":"https:\/\/becolve.com\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/"},"modified":"2025-09-26T11:19:29","modified_gmt":"2025-09-26T11:19:29","slug":"5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii","status":"publish","type":"blog","link":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/","title":{"rendered":"5 Recommendations for the Deployment of Secure OT Networks (Part II)"},"content":{"rendered":"<p>As a continuation of this <a href=\"http:\/\/www.ciberseguridadlogitek.com\/5-recomendaciones-para-el-despliegue-de-redes-ot-seguras\/\" target=\"_blank\" rel=\"noopener\">entry<\/a>, we propose the last two recommendations:<\/p>\n<h4>4. Create a DMZ (demilitarized zone) if the SCADA WEB server needs to be accessed by users from the Internet and\/or the OT network.<\/h4>\n<p>A demilitarized zone or DMZ is an intermediate network that is created between two other networks <strong>through two firewalls<\/strong>. The purpose of this intermediate network is that the information\/application that wants to be shared by the users of the main networks is located in said intermediate network, allowing said access on the one hand, but <strong>avoiding traffic and direct access<\/strong> between the two main networks. <\/p>\n<p>The figure shows how an intermediate network, the <strong>DMZ<\/strong>, with its own IP address range (202.168.1.Y), has been created between network A or IT (192.168.1.X) and network B or OT (193.167.1.X). This intermediate network houses the applications and\/or information that needs to be shared by users of the IT and OT networks (<strong>MES solutions or a Historian-Replicated<\/strong> so that process data is accessible from IT) or the servers that must be accessible from outside (SCADA Web Server). <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg\" alt=\"  Create a DMZ (demilitarized zone)\" width=\"401\" height=\"275\"><\/p>\n<p>&nbsp;<\/p>\n<h4>5. Incorporate <a href=\"http:\/\/www.ciberseguridadlogitek.com\/wp-content\/uploads\/Firewalls-industriales_Hirschmann_Tofino_DPI.pdf\" target=\"_blank\" rel=\"noopener\">industrial DPI (Deep Packet Inspection) firewalls<\/a> between the SCADA servers and the PLCs to guarantee the security of the process against possible threats and malicious actions.<\/h4>\n<p>The industrial <strong>DPI<\/strong> firewalls are located between the <strong>SCADA systems and the PLCs<\/strong>, guaranteeing their security, and therefore that of the process. The fact that they perform DPI implies that they block malware built on typically IT protocols. That is, most malware is not built on industrial protocols. By being able to define specific segmentation rules by industrial protocol (<strong>Modbus, Profinet, OPC, Ethernet\/IP, DNP3<\/strong>) this traffic would not be allowed.   <\/p>\n<p>In addition, it allows segmentation of traffic that does not conform to the \u201cstandard\u201d of the selected industrial protocol and even define segmentation rules by <strong>Function Codes specific to protocols such as Modbus or Ethernet IP<\/strong>. For example, if the protocol used is Modbus TCP\/IP, it is possible to define a rule that does not allow a master to execute the \u201cfunction codes\u201d 05 \u201cwrite cole\u201d and 06 \u201cwrite register\u201d on a slave. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image0031.jpg\" alt=\"  industrial DPI (Deep Packet Inspection) firewalls\" width=\"401\" height=\"275\"><\/p>\n<p>&nbsp;<\/p>\n<p>We hope that these recommendations for the <strong>deployment of secure OT Networks<\/strong> have been useful to you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a continuation of this entry, we propose the last two recommendations: 4. Create a DMZ (demilitarized zone) if the SCADA WEB server needs to be accessed by users from the Internet and\/or the OT network. A demilitarized zone or DMZ is an intermediate network that is created between two other networks through two firewalls. [&hellip;]<\/p>\n","protected":false},"author":31,"featured_media":61361,"menu_order":0,"template":"","categories":[1371],"tags":[],"arquitectura":[1839],"area":[],"sector":[],"experto":[1396],"weborigen":[157],"productos-tax":[],"soluciones-tax":[],"marcas-tax":[],"coauthors":[],"class_list":["post-61360","blog","type-blog","status-publish","has-post-thumbnail","hentry","category-cybersecurity","arquitectura-industrial-cybersecurity","experto-industrial-cybersecurity-total-availability","weborigen-ciberseguridadlogitek-com"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital\" \/>\n<meta property=\"og:description\" content=\"As a continuation of this entry, we propose the last two recommendations: 4. Create a DMZ (demilitarized zone) if the SCADA WEB server needs to be accessed by users from the Internet and\/or the OT network. A demilitarized zone or DMZ is an intermediate network that is created between two other networks through two firewalls. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/\" \/>\n<meta property=\"og:site_name\" content=\"Becolve Digital\" \/>\n<meta property=\"og:image\" content=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"401\" \/>\n\t<meta property=\"og:image:height\" content=\"275\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Logitek_es\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Becolve Digital\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/\",\"name\":\"5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/image003.jpg\",\"datePublished\":\"2025-09-26T11:19:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/#primaryimage\",\"url\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/image003.jpg\",\"contentUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/image003.jpg\",\"width\":401,\"height\":275},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/becolve.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog Items\",\"item\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"5 Recommendations for the Deployment of Secure OT Networks (Part II)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/\",\"name\":\"Becolve Digital\",\"description\":\"Transformaci\u00f3n digital en industria e infraestructuras\",\"publisher\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/becolve.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#organization\",\"name\":\"Becolve Digital\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/becolve-logo-h-black_200.png\",\"contentUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/becolve-logo-h-black_200.png\",\"width\":200,\"height\":64,\"caption\":\"Becolve Digital\"},\"image\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Logitek_es\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/becolve-digital\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/","og_locale":"en_US","og_type":"article","og_title":"5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital","og_description":"As a continuation of this entry, we propose the last two recommendations: 4. Create a DMZ (demilitarized zone) if the SCADA WEB server needs to be accessed by users from the Internet and\/or the OT network. A demilitarized zone or DMZ is an intermediate network that is created between two other networks through two firewalls. [&hellip;]","og_url":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/","og_site_name":"Becolve Digital","og_image":[{"width":401,"height":275,"url":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@Logitek_es","twitter_misc":{"Est. reading time":"2 minutes","Written by":"Becolve Digital"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/","url":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/","name":"5 Recommendations for the Deployment of Secure OT Networks (Part II) | Becolve Digital","isPartOf":{"@id":"https:\/\/becolve.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/#primaryimage"},"image":{"@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/#primaryimage"},"thumbnailUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg","datePublished":"2025-09-26T11:19:29+00:00","breadcrumb":{"@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/#primaryimage","url":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg","contentUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/image003.jpg","width":401,"height":275},{"@type":"BreadcrumbList","@id":"https:\/\/becolve.com\/en\/blog\/5-recommendations-for-the-deployment-of-secure-ot-networks-part-ii\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/becolve.com\/en\/"},{"@type":"ListItem","position":2,"name":"Blog Items","item":"https:\/\/becolve.com\/en\/blog\/"},{"@type":"ListItem","position":3,"name":"5 Recommendations for the Deployment of Secure OT Networks (Part II)"}]},{"@type":"WebSite","@id":"https:\/\/becolve.com\/en\/#website","url":"https:\/\/becolve.com\/en\/","name":"Becolve Digital","description":"Transformaci\u00f3n digital en industria e infraestructuras","publisher":{"@id":"https:\/\/becolve.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/becolve.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/becolve.com\/en\/#organization","name":"Becolve Digital","url":"https:\/\/becolve.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/becolve.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/becolve-logo-h-black_200.png","contentUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/becolve-logo-h-black_200.png","width":200,"height":64,"caption":"Becolve Digital"},"image":{"@id":"https:\/\/becolve.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Logitek_es","https:\/\/www.linkedin.com\/company\/becolve-digital\/"]}]}},"_links":{"self":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog\/61360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/users\/31"}],"version-history":[{"count":0,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog\/61360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/media\/61361"}],"wp:attachment":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/media?parent=61360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/categories?post=61360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/tags?post=61360"},{"taxonomy":"arquitectura","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/arquitectura?post=61360"},{"taxonomy":"area","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/area?post=61360"},{"taxonomy":"sector","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/sector?post=61360"},{"taxonomy":"experto","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/experto?post=61360"},{"taxonomy":"weborigen","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/weborigen?post=61360"},{"taxonomy":"productos-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/productos-tax?post=61360"},{"taxonomy":"soluciones-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/soluciones-tax?post=61360"},{"taxonomy":"marcas-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/marcas-tax?post=61360"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/coauthors?post=61360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}