Details about the industrial environment – lab setup
Let's look at the industrial environment part of the lab architecture:
Here, we can see that the network is split into two enclaves, separated by the Operational Technology (OT) firewall. The controls and automation devices are a mix of physical hardware and VMs. All the VMs will be running on the Dell ESXi server for the industrial environment, including the Security Onion and SilentDefense appliances (see the Packet capturing and passive security tools section for details). We will use a single vSwitch with multiple virtual port groups (VLANs) to create a separation between the Level 3 Site Operations enclave and the process network. The OT firewall (pfSense) is configured with three virtual NIC cards to connect to the Level 3 Site Operations VLAN, the process network VLAN, and the Cisco 3750 enterprise switch. Finally, we...