Passive Asset Discovery User Guide
Total Page:16
File Type:pdf, Size:1020Kb
ICS SHIELD R 510.2 Asset Passive Discovery (Asset PD) User Guide CS-ICSE777en-510B September 2019 DISCLAIMER This document contains Honeywell proprietary information. Information contained herein is to be used solely for the purpose submitted, and no part of this document or its contents shall be reproduced, published, or disclosed to a third party without the express permission of Honeywell International Sàrl. While this information is presented in good faith and believed to be accurate, Honeywell disclaims the implied warranties of merchantability and fitness for a purpose and makes no express warranties except as may be stated in its written agreement with and for its customer. In no event is Honeywell liable to anyone for any direct, special, or consequential damages. The information and specifications in this document are subject to change without notice. Copyright 2019 – Honeywell International Sàrl DocID CS-ICSE777en-510B 2 Notices Trademarks Experion®, PlantScape®, SafeBrowse®, TotalPlant®, and TDC 3000® are registered trademarks of Honeywell International, Inc. ControlEdge™ is a trademark of Honeywell International, Inc. OneWireless™ is a trademark of Honeywell International, Inc. Matrikon® and MatrikonOPC™ are trademarks of Matrikon International. Matrikon International is a business unit of Honeywell International, Inc. Movilizer® is a registered trademark of Movilizer GmbH. Movilizer GmbH is a business unit of Honeywell International, Inc. Other trademarks Trademarks that appear in this document are used only to the benefit of the trademark owner, with no intention of trademark infringement. Third-party licenses This product may contain or be derived from materials, including software, of third parties. The third party materials may be subject to licenses, notices, restrictions and obligations imposed by the licensor. The licenses, notices, restrictions and obligations, if any, may be found in the materials accompanying the product, in the documents or files accompanying such third party materials, in a file named third_party_ licenses on the media containing the product, or at http://www.honeywell.com/ps/thirdpartylicenses. Legal Notices • "Ethernet/IP" • "COTP" • "TPKT • "Link-Local Multicast Name Resolution" • "Server Message Block" • "Tabular Data Stream" • "Transparent Network Substrate" • "DNP3" DocID CS-ICSE777en-510B 3 • "EtherCAT" • "IEC 60870 5" • "Generic Substation Events" • "BACnet" • "Manufacturing Message Specification" • "ICCP Protocol" • "DCERPC" • "OPC Data Access" • "PROFINET" • "Profibus" • "Routing Information Protocol" • "Interior Gateway Routing Protocol" • "Open Shortest Path First" • "Cisco Discovery Protocol" • "Link Layer Discovery Protocol" • "Simple Network Management Protocol" These articles are released under the Creative Commons Attribution-Share-Alike License 3.0. Documentation feedback You can find the most up-to-date documents on the Honeywell Process Solutions support website at: http://www.honeywellprocess.com/support If you have comments about Honeywell Process Solutions documentation, send your feedback to: [email protected] Use this email address to provide feedback, or to report errors and omissions in the documentation. For immediate help with a technical problem, contact your local Honeywell Process Solutions Customer Contact Center (CCC) or Honeywell Technical Assistance Center (TAC). DocID CS-ICSE777en-510B 4 How to report a security vulnerability For the purpose of submission, a security vulnerability is defined as a software defect or weakness that can be exploited to reduce the operational or security capabilities of the software. Honeywell investigates all reports of security vulnerabilities affecting Honeywell products and services. To report a potential security vulnerability against any Honeywell product, please follow the instructions at: https://honeywell.com/pages/vulnerabilityreporting.aspx Submit the requested information to Honeywell using one of the following methods: Send an email to [email protected]. or Contact your local Honeywell Process Solutions Customer Contact Center (CCC) or Honeywell Technical Assistance Center (TAC) listed in the “Support” section of this document. Support For support, contact your local Honeywell Process Solutions Customer Contact Center (CCC). To find your local CCC visit the website, https://www.honeywellprocess.com/en- US/contact-us/customer-support-contacts/Pages/default.aspx. Training classes Honeywell holds technical training classes that are taught by process control systems experts. For more information about these classes, contact your Honeywell representative, or see http://www.automationcollege.com. DocID CS-ICSE777en-510B 5 About this Guide This guide describes how to configure and use the Asset Passive Discovery (Asset PD) , the solution that enables the VSE to collect information about the network assets that the VSE can access. Scope This guide provides step-by-step instructions for configuring, distributing, and using Asset Passive Discovery (Asset PD) . at all levels, from the initial settings up to the deployment in the Security Center and the VSEs. Intended audience This guide is for people who are responsible for the configuration and operation of Asset Passive Discovery (Asset PD) on the Security Center and VSEs: • Initial Settings - Professional Services, Support, or IT personnel • Security Center – Administrators and operators • VSE – Administrators and operators Prerequisite skills This guide assumes basic knowledge of the ICS Shield R 510.2 modules relevant to the Security Center, the VSE, or both, depending on your specific role. Related documents The following list identifies publications that contain information relevant to the information in this document. Document Name Document Number ICS Shield R510.1 - Security Center Getting Started CS-ICSE400en-510A Guide ICS Shield R510.1 - Virtual Security Engine – User CS-ICSE601en-510A Guide DocID CS-ICSE777en-510B 6 Revision history Revision Supported Date Description Release A Release 510.1 August 2019 This software is an upgrade-only release from Release 501.1 A Release 500.1 June 2019 First release of product to Honeywell Enterprise customers DocID CS-ICSE777en-510B 7 Contents 1. SECURITY CONSIDERATIONS ........................................................................................ 11 1.1 Physical security ...................................................................................................................................... 11 1.2 Secured zone ............................................................................................................................................. 11 1.3 Limiting access ........................................................................................................................................ 11 1.3.1 At the VSE level ...................................................................................................................... 11 1.3.2 At the directory or file level ............................................................................................... 12 1.4 Authorization measures ...................................................................................................................... 12 2. TERMS AND DEFINITIONS .............................................................................................. 13 3. INTRODUCTION ................................................................................................................... 15 3.1 Understanding the AssetPD solution ........................................................................................... 15 3.2 The Definition of Asset ......................................................................................................................... 16 3.3 Exploring the AssetPD architecture .............................................................................................. 17 4. INSTALLATION ..................................................................................................................... 19 4.1 Installation prerequisites .................................................................................................................... 19 4.1.1 Configuring the mirror port ............................................................................................. 19 4.2 Installation procedure .......................................................................................................................... 20 5. CONFIGURATION ................................................................................................................ 22 5.1 Configuring AssetPD............................................................................................................................. 22 5.1.1 Configuring the connection to remote VSE ............................................................ 22 5.1.2 Configuration of sources .................................................................................................. 23 5.2 Configuring network interfaces ....................................................................................................... 23 5.3 Configuring offline sources ............................................................................................................... 24 6. RUNNING ASSETPD ........................................................................................................... 26 6.1 Getting AssetPD Results ....................................................................................................................