Stay updated on news, articles and information for the rail industry
12/4/2015
Phoenix Contact: FL mGuard security devices

With the increased threat of cyber attacks on infrastructure networks comes the need for highly effective security appliances. Phoenix Contact's FL mGuard family of security devices are designed to help protect transit rail, freight rail, and passenger rail networks from unauthorized access by people or malware.
The FL mGuard family of products is built around security. IT-friendly features such as an industrial firewall for traffic filtering, auditing and logging capabilities, anti-malware, and other security features aim to ensure network protection, company officials said. Additionally, the mGuard routing capabilities allow for connection to IT or enterprise networks.
The optional virtual private network (VPN) can create a secure remote connection over the Internet, which enables communication from a technician or control center to remote equipment and end-customer sites.
The RS2005 and RS4004 are the newest additions to the mGuard family. These new devices combine the mGuard's secure routing, VPN and firewall functions with network switch capabilities in one package. Thanks to the integrated switch, the updated mGuard devices can eliminate or reduce the need to buy and install a stand-alone switch. This results in lower hardware costs, a smaller installation footprint, and easier network set-up, according to the company.
The RS4004 integrates a four-port managed switch, enabling a flexible and cost-effective option for multiport security applications in Ethernet networks. The mGuard with a managed switch can provide port mirroring, multicast filtering, and querying and VLAN support.
The DMZ port in the RS4004 is a protected network located between two other networks. Both the secure LAN side and the unsecured WAN side of the network can access this port. However, the firewall that monitors and regulates all of the incoming and outgoing traffic at each transfer point can block access from the WAN side to the LAN or DMZ side and vice-versa.
The RS2005 integrates a five-port unmanaged Ethernet switch, with automatic detection of data transmission speed of 10 or 100 Mbps (RJ45) and auto-crossing function.
The mGuard can help achieve compliance with cybersecurity standards such as the American Public Transportation Association's "Securing Control and Communications Systems in Rail Transit Environments" Recommended Practice, along with NERC CIP, ISA99, and NRC RG 5.71.