Nine Steps to a Secure Control
System
16
Tofino Configurator
Release
V2.00
05/2014
Install the Tofino Configurator on your computer.
Create a project.
Define the Tofino SAs for your project.
This information will be used to configure the actual Tofino SAs that will
be installed on your network.
Define assets for your project.
These objects represent both real network entities (such as HMIs and
PLCs) and virtual entities (such as Broadcast Addresses) on your
network. They are used to simplify tasks like creating firewall rules.
Define firewall rules for your Tofino SAs.
These use the assets you created earlier, along with predefined protocols
and special rules that are supplied with the Tofino Configurator, to
determine what network traffic the Tofino SA will allow or block. The
various Deep Packet Inspection (DPI) Enforcer modules are accessed
through the Firewall selection.
Configure the Event Logger (optional).
Enter the details for your syslog server where you want Tofino SA alarms
and events sent. You can also configure the Tofino SA to save logs locally
on the Tofino SA for later offloading via a USB storage device.
Install your Tofino SA hardware.
The Tofino SA gets installed on the network between the device(s) to be
protected and the rest of the network.
Apply the configuration settings to the Tofino SAs in the field.
Depending on the options you have purchased, you can transfer the
configuration data from the Tofino Configurator to the Tofino SA(s) over
the network or using a USB storage device.
Verify the configuration.
Retrieves the configuration load reports sent over the network or from the
USB storage device that was used to load configurations onto one or
more Tofino SAs. This will allow you to record the configuration of Tofino
SAs in the field and save it in your project.
You have successfully installed the Tofino Industrial Security Solution and
significantly improved the security of your process network.
Note: The Tofino SA will pass network traffic freely during the initial
configuration or when its configuration is being updated. Firewall rules take
effect after completion of the initial configuration or update of the Tofino SA
so that network operations are not affected before the full rule set can be
loaded. A typical configuration load will finish in approximately 30 seconds.