Skip to content

12.2 HiOS Operating System

The previous section introduced the Hirschmann product families. Every managed Hirschmann switch runs one of three operating systems: HiOS (Hirschmann Industrial Operating System), HiEOS (Hirschmann Entry Operating System), or HiSecOS (Hirschmann Security Operating System). The operating system determines the available features.

A network with 50 switches from three product families (BOBCAT, MSP, RSPE) uses the same CLI commands, the same web interface layout, and the same SNMP MIBs, as long as all run HiOS. The software level (L2S, L2A, L3S, L3A) controls which protocols and features are available. Upgrading the software level on existing hardware adds features without replacing the switch.

The base managed feature set. Includes MRP (client and manager), RSTP (802.1D-2004), VLAN (802.1Q), LACP, SNMP v1/v2c/v3, SSH, HTTPS, LLDP, port mirroring, RMON, syslog, and basic QoS (802.1p priority queuing). Available on RSP, RSPE, GREYHOUND 1020/1030, and RED switches.

Adds IGMP snooping/querier (v1/v2/v3), GVRP, MVRP, MMRP, port-based access control (802.1X) with RADIUS, MAC authentication bypass, guest VLAN, DHCP snooping, IP source guard, dynamic ARP inspection, DoS prevention, ingress/egress ACLs (MAC-based, IPv4-based, VLAN-based), time-based ACLs, advanced QoS with egress shaping and ingress storm protection, and RSPAN. Available on BOBCAT, MSP, RSPE, GREYHOUND 100/103/105/106/1040, and DRAGON MACH4x00.

Adds static unicast routing, OSPFv2, RIPv1/v2, VRRP, VLAN-based router interfaces, loopback interfaces, ICMP filtering, and proxy ARP. Available on RSP and RSPE.

Adds multicast routing: IGMP proxy, DVMRP, PIM-DM (RFC 3973), PIM-SM/SSM (RFC 4601). Adds Equal-Cost Multi-Path (ECMP) routing, ICMP Router Discovery (IRDP), and static route tracking. Available on MSP40, GREYHOUND 1040, and DRAGON MACH4x00.

FeatureL2SL2AL3SL3A
MRP, RSTP, VLAN, LACPYesYesYesYes
SNMP v3, SSH, HTTPSYesYesYesYes
802.1X, RADIUS, ACLsNoYesYesYes
DHCP snooping, ARP inspectionNoYesYesYes
IGMP snooping (advanced)NoYesYesYes
Static routingNoNoYesYes
OSPF, RIP, VRRPNoNoYesYes
Multicast routing (PIM)NoNoNoYes
ECMPNoNoNoYes

HiEOS runs on LEMUR lite managed switches. It provides essential Layer 2 switching with a simplified, intuitive web GUI designed for users without specialized IT knowledge. HiEOS includes MRP client, RSTP, ERPS (G.8032), VLAN (802.1Q), IGMP snooping, QoS, SNMP v1/v2/v3, SSH, HTTPS, port mirroring, syslog, and MAC address limit per port.

HiEOS does not include 802.1X, RADIUS, ACLs, DHCP snooping, Layer 3 routing, or the full HiOS CLI command set. It trades feature depth for simplicity and lower cost.

CapabilityHiEOS (LEMUR)HiOS L2S
Web GUISimplified, responsiveFull HiOS interface
CLILimitedFull Cisco-like CLI
MRPClient onlyClient + Manager
RSTPYesYes
ERPS (G.8032)YesNo (L2A adds it)
802.1X / RADIUSNoNo (L2A adds it)
ACLsNoNo (L2A adds it)
Price pointLowerHigher

HiSecOS (Hirschmann Security Operating System)

Section titled “HiSecOS (Hirschmann Security Operating System)”

HiSecOS runs on the EAGLE40 Next-Generation Firewall. It combines routing and switching with stateful firewall, Deep Packet Inspection (DPI), IPSec VPN, OSPF, and VRRP. Designed to meet IEEE 1686 requirements: audit trail logging, user management with password policies, and role-based access control.

DPI protection suites inspect industrial protocol payloads:

  • Industrial Automation Protection Suite: EtherNet/IP enforcer + Modbus enforcer + OPC enforcer
  • Substation Protection Suite: IEC 104 enforcer + DNP3 enforcer + GOOSE enforcer + Modbus enforcer
  • Unified Protection Suite: combines both suites
MethodProtocolDefault StateRecommended
Web GUIHTTP / HTTPSHTTP enabledHTTPS only
CLITelnet / SSHTelnet enabledSSH only
SNMPv1/v2c/v3v1/v2c enabledSNMPv3 only
Serial consoleRS-232 / V.24AvailablePhysical access

The default management IP is 192.168.1.1/24. Default credentials are admin / private (older firmware) or a device-specific password printed on the label (newer firmware). Change the password immediately on first access.

Access the CLI via SSH. HiOS CLI uses Cisco-like syntax:

enable # Enter privileged mode
configure # Enter configuration mode
show interfaces # Show port status
show vlan # Show VLAN table
show mrp # Show MRP status
show log # Show event log
copy running-config startup-config # Save configuration

HiOS supports SNMP for integration with network management systems. Key MIBs include RFC1213-MIB (standard interface statistics), HIRSCHMANN-MRP-MIB (ring status), and IF-MIB (interface counters). SNMP traps fire for link up/down events, MRP topology changes, authentication failures, and temperature alarms.

Upload firmware via the web interface at Basic Settings → Load/Save → Software. Test updates on a non-production switch first. Back up the configuration at Basic Settings → Load/Save → Configuration → Download. The configuration file is XML. Store it in version control for history, comparison, and rapid recovery. HiOS supports dual software images: upload the new firmware to the inactive image slot, verify, then switch the active image.

Choose the software level at order time

L2S for basic switching and redundancy. L2A for security features (ACLs, 802.1X). L3S for routing. L3A for multicast routing and ECMP. Upgrade in the field with a license key.

HiEOS trades depth for simplicity

LEMUR switches with HiEOS cost less and configure faster. They lack 802.1X, ACLs, and Layer 3 routing. Use them where those features are unnecessary.

HiSecOS is for firewalls only

EAGLE40 runs HiSecOS with DPI, VPN, and audit trail. It is a separate operating system from HiOS with different CLI syntax.

HiOS manages individual switches. Managing an entire network of switches requires a network management system. The next section covers HiVision, Hirschmann’s network management software for topology discovery, monitoring, and event management.

  • Belden/Hirschmann. (2024). Hirschmann Essentials Product Catalog. Belden Inc.
  • Hirschmann. (2024). HiOS Reference Manual. Belden/Hirschmann.
  • Hirschmann. (2024). HiSecOS Reference Manual. Belden/Hirschmann.