Skip to content

19.1 EAGLE One Firewall

Rack mount switches handle the backbone. Protecting the boundary between network zones requires purpose-built industrial firewalls. The EAGLE One is Hirschmann’s entry-level industrial firewall for cell protection and simple IT/OT boundaries.

A PLC cell communicates with the SCADA server over a small set of well-defined connections. Allowing unrestricted access from the plant network to the cell exposes the PLC to broadcast storms, port scans, and unauthorized configuration changes. The EAGLE One sits at the cell boundary and permits only the traffic the application requires.

SpecificationValue
Ports2 FE (internal + external)
SoftwareClassic Firewall Software
Firewall typeStateful L2 and L3
Temperature-40 C to +70 C (variant dependent)
HousingDIN rail, IP20/IP30
Power12-48 V DC, 24 V AC

The EAGLE One includes a Firewall Learning Mode that monitors traffic flowing through the device and automatically generates firewall rules based on observed connections. The workflow:

  1. Install the EAGLE One in the network path with the firewall in learning mode.
  2. Run the application through its normal operating cycle.
  3. The EAGLE One records every source/destination IP, port, and protocol combination.
  4. Review the generated rules, remove any unwanted entries, and activate the firewall.

This approach eliminates the need to manually document every connection before writing rules. It is especially valuable for legacy systems where protocol documentation is incomplete.

CertificationScope
ATEX Zone 2Hazardous locations (EU)
IEC 61850-3 / IEEE 1613Substation environments
EN 50121-4Railway trackside EMC
DNVGLMarine applications

Cell protection: An EAGLE One between the plant network and a robot cell permits only Modbus TCP (port 502) from the SCADA server and blocks everything else. The robot PLC is invisible to the rest of the network.

Simple IT/OT boundary: An EAGLE One at the DMZ boundary permits HTTPS from the historian server to the corporate network and blocks all inbound connections from IT to OT.

Learning Mode accelerates deployment

Let the EAGLE One observe normal traffic, then review and activate the generated rules. No manual rule writing required.

Certified for substations and rail

IEC 61850-3, IEEE 1613, EN 50121-4, ATEX Zone 2, DNVGL. Deploy in regulated environments without additional enclosures.

The EAGLE One handles simple cell protection. The next section covers the EAGLE40 Next-Generation Firewall with Deep Packet Inspection, IPSec VPN, and industrial protocol enforcement.

  • Belden/Hirschmann. (2024). EAGLE One Data Sheet. Belden Inc.