The firewall that knows what a PLC stop is.
RagerSec is an OT-native firewall for Siemens plants. It reads S7comm, S7CommPlus and OPC UA down to the function level and only lets through the access your process actually needs.
| 10:42:17 | S7comm | PLC Stop (0x29) | HMI-02 → CPU 315 | BLOCKED |
| 10:42:19 | S7comm | Read Var DB12 | HMI-02 → CPU 315 | ALLOWED |
| 10:42:21 | S7CommPlus | SetVariable | ENG-WS → CPU 1516 | BLOCKED |
| 10:42:24 | OPC UA | Read · ns=3 | SCADA → CPU 1516 | ALLOWED |
| 10:42:30 | S7comm | Download Block | unknown → CPU 315 | BLOCKED |
Port 102 open means everything is open.
With Siemens controllers, conventional firewalls only see TCP port 102. Whether an HMI is reading a value or someone is stopping the CPU stays invisible.
IT firewall
- Rules based on IP and port only
- Read, write, stop and program download look the same
- No visibility into data blocks or OPC UA nodes
RagerSec
- Rules per protocol function, e.g. “read only on DB12”
- CPU stop and block download blocked by default
- Time-limited approvals for maintenance windows
Built for plants, not office networks.
Deep packet inspection
Decodes S7comm, S7CommPlus and OPC UA down to the individual function and address.
Learning mode
Records normal traffic and proposes a rule set for you to review and approve.
Transparent deployment
Runs as a layer 2 bridge. No new IP addresses, no changes to the PLC configuration.
Maintenance windows
Program changes only after approval and only for a defined period.
Traceable
Every decision is logged and can be forwarded to your SIEM or OT monitoring.
Zones and conduits
Technically enforces the zone boundary according to IEC 62443-3-3.
Between supervisory level and cell.
RagerSec sits at the boundary between two zones and checks every access to the controllers.
Looking for pilot sites
We are looking for operators and system integrators running S7-300/400 or S7-1200/1500 plants to test RagerSec in our early access program.