Professional Documents
Culture Documents
Cisco IoT Solutions For Energy Utilities v2
Cisco IoT Solutions For Energy Utilities v2
Cisco IoT Solutions For Energy Utilities v2
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
Cisco Utility Solutions – Best of Both Worlds
Best of IT Best of OT
IED
RTU IED
Gain visibility on your OT to build and enforce the right security policies
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
LTE
Public, Private, FirstNet, 5G Fiber
Wi-SUN
Ethernet
Mesh IR510 LoRaWAN or Serial
IE3200
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
SCADA Serial-to-IP Migration
Cisco Industrial Routers w/ Raw Sockets and DNP Translation
IR1101
• One RS-232 Connection
SCADA FEP
Utility
WAN
• 9 Serial Connections
• 5 Serial Connections
Ethernet Ethernet
Cisco IR
Cisco IR Cisco IR
using Raw
using DNP using Raw Sockets
Sockets
Translation & DNP Translation
Translation
Serial Serial
Control Center
IND Cyber ISE Stealth Splunk CUCM Directory WLC
EMS, DMS, OMS, etc. Vision Watch Service
WAN
IPSec
Cellular
IPSec
IPSec
Secure Substation DMZ
Electronic Security Perimeter (ESP) ISA 3000 Multi-service Zone Corporate Zone
IR8340
IE 5000 IE 5000
IE 5000 IE 5000
Parallel
Redundancy
Station LAN A Protocol (PRP) IE 4000 IE 4000 IE 4000
IE9310 / IE4010 LAN B IE9310 / IE4010
Bus
CGR 2010
(for AMI or DA)
Bay controllers, protection
relays, PDC, wide area IE 4000
IE 4000
control
Highly Available Seamless
Ring(HSR) Physical Security
Process Bus
DANH DANH SANH
IR8340
4 copper • 4 combo • 4 SFP • 2 combo WAN ports
4 expansion slots
5G • SD-WAN
Redundant power supplies
1G IPSec WAN Connection
• Single integrated platform for routing, • DNA-Center and SD-WAN • Security and visibility with Cyber Vision
switching and security • 8 core processor for dispersed workloads • Hardware based MACSec LAN and WAN
• Easier to manage: One control plane for • PoE, PoE+ and UPoE • IPSEC - DMVPN, FlexVPN, IKEv1, IKEv2
Layer 2 and Layer 3 • Backwards compatible with Serial • URL filtering, Cisco AMP, Snort (IPS/IDS)
• Full MPLS Layer 3 support • Only Cisco router that converts GNSS time to • Group based policy (TrustSec)
NTP, PTP, SyncE • Policy edge node support (DNA Center)
• Zone based firewall
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
* Encrypted throughput vs. previous generation
Introducing the Cisco Catalyst
IE3200, 3300, 3400 Rugged Switches
Gigabit modular system
Feature-packed modern
Fixed
software for scalable IoT deployments
system • Flexible, resilient, secure Cisco® IOS XE
operating system
• Simplified management, automation, and
visibility IND, Cisco DNA Center, Prime®, WebUI
• Rich IE features – PRP*, HSR*, MRP*, PTP, MACSEC*,
TSN*, CIP, Profinet*
• Flexible licensing options:
Expandable - Network Essentials comes as PIK-PAK
modular system - Cisco DNA Essentials*
- Network Advantage, and Cisco DNA Advantage (post-FCS)*
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential ‘*’ – Post FCS 13
IE3x00 platforms at a glance
IE3200 IE3300 IE3400
fixed basic modular basic modular advanced
IE 3000 transition
Low port count, low power, High port count, Cisco DNA Advanced features, high port count
Positioning
Network Essentials features Essentials, or Cisco DNA High port count
Advantage features
• Layer 2 • Layer 2
• Layer 2
FCS • Fixed: 10 x 1GE ports • Modular – 26 x1GE ports
• Modular –26 x 1GE ports
features • PTP, REP, • PTP, REP
• PTP, REP
• PoE/PoE+ • PoE/PoE+
• Layer 3
• Layer 3
• Netflow
• Netflow
• Profinet, MRP, HSR, PRP, L2NAT
• Profinet, MRP • Profinet, MRP
Post-FCS • Macsec, SGT, SGACL
• Macsec • Macsec
features • Cisco DNA Essentials, Cisco DNA Advantage
• Cisco DNA Essentials • Cisco DNA Essentials, Cisco
• SDA Extended Node, SDA Fabric Edge
DNA Advantage
• TSN
• SDA Extended Node
• Cisco® IOx
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
Catalyst IE3x00 Rugged Series Switches & modules
Highly flexible architecture with a wide array of module choices
Advanced
1 Copper fixed 1 Copper basic modular system 1 8p copper 5 6p copper 6 16p copper 8 14p copper + 2p 9 8p fiber 10
8p fiber
+ 2p fiber fiber mixed
8p PoE+ mixed
2 POE+ fixed 2 PoE+ basic modular system 2 7 16p PoE+
Advanced
3 8p copper
3 Copper Advanced modular system
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
Cisco IE 4000 Series
GE Uplinks and Downlinks
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Cisco IE 5000 Front Panel
Front or Rear Mount Capability Advanced Time Sync Console
§Redundant LED placements at front and • Analog and Digital IRIG §Console over USB
rear of router • GPS Receiver §Console over RS232
§System, Alarm and Port Status LEDs
Conductive Cooling
12 Copper Gigabit Ethernet Ports § No fans or moving parts
§10/100/1000M Fixed Copper POE+ § Increased Operating Temp
Swap Drive 12 SFP Gigabit Ethernet Ports Field Replaceable Power Supplies
4 Uplink SFP or SFP+ Ports
§SD Flash §100/1000M SFP §High Voltage PS: 85–265 VAC 88-300 VDC
§1G/10G (IE-5000-12S12P-10GE)
§1G(IE-5000-16S12P) §Low Voltage PS: 18-75 VDC
Substation Hardened All Ports IEEE 1588 v2/PTP Alarm Contacts
§Substation Compliant
§Power Profile c37.238, Default Profile §FOUR Alarm Inputs
IEC61850-3 and IEEE1613
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
§ONE Alarm Output 17
cisco.com/go/cus
Cisco
Validated
Design
Tested Implemented Proven
A holistic security solution for utility industry Cisco Security Feature
Application
Sensor Flow Threat Detection
Sensor
IR 1101 Router
Sensor
IR8140
IR 8340 Router Router
Sensor Sensor
New
SENSOR New Cyber Vision Center Cisco Stealthwatch
Network Flow Analysis
SENSOR Operational Insights Threat Detection
XT
TE
N
CO
IC 3000 Switch
Cisco ISE
CISCO Industrial OT Portfolio Access Control
ICS
Purdue level 3 Sensor Network Sensor
Application-Flow
Massive Lightweight
increase in Sensor
IC3000 Metadata
traffic due to
SPAN
Purdue level 2
ICS
Sensor
Non-Cisco IE3400
Network Switches
Out-of-Band
SPAN collection
network
Purdue
level 0-1 Network-Sensors eliminate the need for SPAN
• The application-flow is streamed through existing network enabling lowest TCO
Expensive
SPAN • Hardware-sensor to support brownfield only requires one-hop SPAN
cabling
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
Cyber Vision Global Center
Gerencia Central / HQ SOC
Cyber Vision Global Center
Gerencia Regional
Cyber Vision Center
Cyber Vision Center Gerencia Regional
SE 1 SE 2 SE 3 SE 4 SE 5
SUDESTE SUL
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
UNILIN : https://www.cisco.com/c/en/us/solutions/collateral/internet-of-things/unilin-group-case-study.html
Albuquerque Water Authority : https://www.cisco.com/c/en/us/about/case-studies-customer-success-
stories/albuquerque-water-authority.html
Danone Group : 8 plants are deployed already around the world. +15 before the end of the year. One of the plant
deployed is one of largest plant for bottling water (20 000 OT devices) in Europe.
PMI (Philips Morris International ) : 25 plants around the world. 15 plants already running.
TESLA : 3 plants already running and new expansions/sites to come soon.
Airbus Helicopter : Cybervision Deployed in part of their main factory for asset discovery and network segmentation
support.
CELEC : Currently under National Deployment in Ecuador
DEWA (Dubai Electric Water Agency) : Under advanced process of deployment
Medtronic : Cybervision Deployed on their largest plant
PARCERIA CISCO + SENAI : Under operation in the IND4.0 plant of São Caetano do Sul. Expansion for other SENAI
units to come soon. Cisco Cybervision solution chosen for training Graduation and Post Graduation students on
IND4.0 courses of OT security.
CMPC : Project under final deployment faze on their Factory on south of Brazil
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23
Suporte a protocolos OT
Smart Fleet Management Solution Overview
Audio and (OCR) License
Video Analytics Plate Recognition GPS
Telemetry
3G / 4G Backhaul
( Dual Chip )
Satelite Link
Printer for Back Up
Secured WiFi – 50
to 100m ratio
People and Asset Wireless IP
Management Phones
Spark and
Jabber
collaboration
Bar Code tools
Reader
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Tablets 24
Main Architecture
GPS
3G/4G
Satelite Moden
Cisco Explorer Threme
IP Camera Dual WiFi Radio Bgan 326
Telemetry
IR829 with
Integrated
PoE+ LTE/AP/Firewall/L2TP/NAT
EN50155
B+B
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Cisco Catalyst IR1800 Rugged Series Routers
The router for everywhere you go, and everything you connect
Edge
IOS-XE Wi-Fi 6 SD-WAN FirstNet*
Compute
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential * FirstNet certification pending 26
Definir una arquitectura de rede convergente y estandarizada
WAN Connectivity and Backhaul Approaches
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
Catalyst
IE9300 Cisco’s IOS-XE
Catalyst
IR1800
Industrial Routers &
IE Switches
Catalyst
IR1101 Supports same operating system
and architectural models as Cisco
Enterprise Switches and Routers
Catalyst
IR8140 Network Automation
Catalyst IR8300 Zero Trust Capabilities
Utility-Focused Features
Catalyst
IE3400
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
Modular LTE Modems for Operational Simplicity
5G NOW
Private LTE, FirstNet, Multi-Carrier for Cisco Industrial Routers
Cat-18 w/ Multicarrier, Private LTE,
& Public Safety with FirstNet B14
P-5GS6-GL
Cat 4 w/ Public Safety
FirstNet Band 14
P-LTEAP18-GL
IR1101
Cat 6 LTE w/Multicarrier
P-LTE-MNA
and Private LTE
IR1800
P-LTEA-EA
P-LTEA-LA
Cat 4 LTE w/
Single Carrier
IR8140
IR8340
P-LTE-GB
P-LTE-US
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30
P-LTE-VZ
Private LTE Distribution SCADA
Utility Broadband Alliance (UBBA) Plugfest, October 2021
Control Center
Distribution SCADA Edge Private LTE Networks Applications
ADMS
Anterix
NOC
Public LTE Networks
MNO Network
Applications
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential FirstNet, ATT, US Cellular 31
Cisco DistribuTech DA Wall Display
Catalyst IR1101
Rugged Series Router
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
IR8140H – LTE, pLTE, FirstNet, and 900MHz WiSUN
The only IoT Heavy Duty Outdoor Router
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
Lower TCO Multi-service/Multi-Access Extended product life-time
IR8140H IP67 LTE MODULE(s)
N-Connector
(Main Antenna)
IRMH-LTEAP18-GL IRMH-LTE-MNA
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
Cisco Ultrareliable Wireless Backhaul
Utility Field Area Network Connectivity
Ethernet
Substation and
SCADA Assets
Up to 10’s of miles
1 – 500 Mbps Ethernet AMI
Aggregator
WAN
Ethernet WiSun
Mesh
Ethernet
eNodeB pLTE RAN
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
FM Volo