İçereği Atla
AIMdefense | Next Generation Firewall
  • 0
  • 0
    • Ana Sayfa
    • Funktionen
    • NGFW-Package
    • Bereitstellung
    • Doku & Downloads
    • Über AIMdefense
    • Solutions
    • Success Stories
    • Kontakt
  • Bizi takip et
  • English (UK) Deutsch Türkçe
AIMdefense | Next Generation Firewall
  • 0
  • 0
    • Ana Sayfa
    • Funktionen
    • NGFW-Package
    • Bereitstellung
    • Doku & Downloads
    • Über AIMdefense
    • Solutions
    • Success Stories
    • Kontakt
  • Bizi takip et
  • English (UK) Deutsch Türkçe

The service engineer needs access to the machine, not to your network

How manufacturers enable remote maintenance by machine suppliers without accepting a permanently open door into the plant network.

The typical starting position

Modern production plant comes with remote maintenance. The manufacturer connects in, reads out fault memories, installs updates and helps with troubleshooting. Without this option, repairs take considerably longer, and a day of travel often sits between the fault and the fix.

In practice, the access route usually came about in whatever way was quickest during commissioning. A router next to the machine with its own mobile or DSL line, a remote maintenance box brought along by the manufacturer, or a permanently configured VPN connection with far-reaching rights.

Why this is a problem

Every one of these variants shares the same core issue. There is a route from outside into production that the company does not fully control.

A manufacturer's own router creates a second internet connection that bypasses the company firewall. The company does not know who connects in and when, and in case of doubt does not even see that the line exists. With permanent VPN access, the connection is available at all times, including during the months in which there is no service case at all.

There is more: the access rarely belongs to one person. It is shared within the manufacturer's service team, and credentials outlive staff changes. And whoever connects in can, in many cases, reach not only that one machine but everything in the same network segment.

The supply chain thus becomes an attack path. This now occupies auditors as well, because NIS2 explicitly addresses supply chain security, and customers pass their requirements down to their suppliers.

The approach

The aim is not to prevent remote maintenance. It should take place, but on the terms of the operating company rather than those of the manufacturer.

With AIMdefense as a controlled transition, this means:

  • One entrance instead of many. Manufacturer-owned mobile routers are replaced. External access runs through the company's central firewall, and only there.
  • Access to the machine, not to the network. The service engineer reaches precisely the controller they are responsible for, through precisely the services required. The rest of production stays out of reach.
  • Access on request. The route is opened for the service case and closed again afterwards, by the company and not by the manufacturer. Between two assignments there is no open connection.
  • Traceability. Every session is logged: when, by whom, to which system. If a fault occurs after a service visit, this can be reconstructed.
  • Separate access per manufacturer. Companies with several plant suppliers give each of them their own, clearly bounded route instead of one shared connection for all.

Technically this is the same mechanism as network separation. Remote access is simply another transition between two zones, except that one of the zones lies outside the plant. It is therefore treated in the same way: named, governed by rules and logged.

Getting there

The first step is taking stock, and it regularly brings to light access routes that nobody in the company remembered. Machines from earlier investments, lines that were supplied at commissioning, credentials belonging to engineers who left long ago.

Next comes the conversation with the plant suppliers. Some service contracts assume particular forms of access. That is negotiable, but it has to be settled before an existing route is switched off. Experience shows that most manufacturers accept controlled access, because what mainly changes for them is that they announce themselves instead of dialling in at any time.

Only then is the changeover made, machine by machine. No standstill is required for this. The new route is set up and tested before the old one is removed.

What changes afterwards

Remote maintenance continues to work, with the same response time and often faster, because the route is defined rather than improvised. What disappears are the unknown doors.

For the company this above all means being able to give answers. Anyone who asks which external access to production exists receives a reply. In front of auditors, customers and insurers, that is the difference between evidence and an assumption.

At a glance

Field of applicationManufacturing with remotely maintained plant
Initial problemUncontrolled manufacturer access, permanently open connections
AIM productsAIMdefense, AIM
Role of AIMdefenseSingle entrance from outside, access granted on request
Core principleAccess to the machine instead of to the network, on request instead of permanent
Side effectComplete overview of existing remote access routes
Reference frameworkSupply chain security in the sense of NIS2

More about AIMdefense

For where AIMdefense sits as the central transition, and which size classes and deployment options are available for it, please see the Deployment page.

For an example of how a single rule set is maintained centrally across many environments, see the success story Managed service provider with more than 170 tax advisory environments.

Request a demoBecome a partner
AIMdefense

Next Generation Firewall, Software-first.

Secure 2 Fiber GmbH · Am Brambusch 24 · 44536 Lünen

+49 231 999 85 400 · info@secure2fiber.com

AIM-Familie

AIM
AIMdefense
AIMSTRONG
AIMcompute
AIMroute
AIMnetworks
AIMsoc (in Vorbereitung)
AIMdesk

Rechtliches

Impressum
Datenschutz
AGB
Unternehmensseite
Partner werden

© Secure 2 Fiber GmbH · Die Marken AIM, AIMSTRONG und AIMdefense unterliegen den Markenrechten der Secure 2 Fiber GmbH.

Telif Hakları; Secure 2 Fiber GmbH

Bu web sitesinde size daha iyi bir kullanıcı deneyimi sunmak için çerezleri kullanıyoruz. Çerez Politikası

Sadece temel bilgiler Kabul Ediyorum