Security & Firewall

No business or industry is safe from attack. Whether intentional or accidental, threats can come at the hands of internal personnel, external hackers or even your physical environment. Either way, an unprotected network puts your enterprise at risk. To counter these risks, the best practices of Defense in Depth and zones and conduits are needed, while ensuring that your device can operate in the harshest of environments. Belden’s security devices deliver the functionality needed to implement these best practices and ensure the safety, resiliency and reliability of your network.

Hirschmann EAGLE40 Next-Generation Multiport Firewall

The Hirschmann EAGLE40 Next-Gen Firewall offers optimal cybersecurity for industrial and process automation systems by hardening networks at the factory-floor level. With multiport configuration, the versatile and ruggedized EAGLE40 is specifically designed to support maximum data throughput without compromising on performance or uptime. Combined with ongoing software enhancements, this firewall is an economically sound solution for reliable protection against the evolving cyber landscape.
Features & Benefits
Customizable Design: Many interface configuration options, including Fast Ethernet, Gigabit Ethernet and SHDSL
Easily Create New Rules: Firewall Learning Mode (FLM) offers an advanced graphical user interface
System Security: Experience the highest level of network security

EAGLE40-4F-SECURITY
EAGLE40-4F-SECURITY

Next-Generation, Field-Level Industrial Firewall with Enhanced Cybersecurity Including Deep Packet Inspection (DPI)
The Hirschmann EAGLE40-4F is a next-generation, field-level industrial firewall with four (4) Gigabit Ethernet ports, real-time traffic monitoring, and advanced cybersecurity capability. Includes deep packet inspection (DPI) modules.

Product description

Type: EAGLE40-4F-SECURITY
Name: EAGLE40-4F-Security

Port type and quantity
4 x GbE RJ45 ports

Displays
LEDs: LEDs (Power, Link Status, Data, Status), Signal Contact (24 V DC/1 A), Log File, Syslog, Configuration check RMON (Statistic), Trap for changes and configuration saves

More Interfaces
USB interface: 1 x USB 2.0 port
Serial Interface: 1 x RJ45 port (RS-232, RS-422, RS-485)

Power Supply
Power supply: 1 x plug-in terminal block, 10-pin

Power requirements
Operating Voltage: Dual 10 ~ 30 V DC
Power consumption: Minimum – 2.5W, Maximum – 12W

Security features
Multipoint VPN: IPSec, IKE v1/v2, 3DES, AES (-128, -192, -256), Pre-Shared Key (PSK), X.509v3 Certificates, MD5, SHA-1, NAT-T, Hub-and-Spoke
Stateful inspection firewall: Firewall rules (incoming/outgoing, management)
Unified Protection Suite (All Enforcers): Yes

Software
Redundancy: VRRP (Virtual Router Redundancy Protocol), Tracking Framework for VRRP
Management: SNMPv3, SSH2/SFTP/SCP, HTTPS, Serial CLI, SNMPv1/2, local and central User Management (RADIUS), HiDiscovery, Industrial HiVision, HiView, LLDP
Diagnostics: LEDs (Power, Link Status, Data, Status), Log File, Syslog, Configuration check, RMON (statistics), Trap for changes and configuration saves
Configuration: Command Line Interface (CLI), Web Interface, Auto-Configuration Adapter (ACA22), HiDiscovery, Industrial HiVision, HiView
Security: DoS prevention, IPSec VPN, Audit trail, Role-based Access Control, Remote Authentication via RADIUS, IEEE 1686 compliant configuration possible, Firewall Learning Mode, Routed Firewall Mode and Transparent Firewall Mode for Layer 3 and Layer 2 packet filtering rules, Management VLAN, Ingress storm protection, Authentication using LDAP, Deep Packet Inspection (DPI) Enforcer Modules: Modbus TCP, OPC, EtherNet/IP, IEC104, DNP3, and AMP
Miscellaneous: NTP Client and Server, DHCP L3 Relay
Routing: VLAN and port based routing, static routing, multinetting, IP masquerading, 1-to-1 NAT, port forwarding, Static and Dynamic ARP entries, OSPFv2, Static route tracking

Ambient conditions
MTBF (Telecordia SR-332 Issue 4) @ 25°C: 309,149 hours
Operating temperature: -40-+70 °C
Storage/transport temperature: -40-+85 °C
Dimensions (WxHxD): 48 x 137 x 105 mm
Weight: 613 g
Housing Material: Aluminum with DIN clip
Mounting: DIN Rail 35 mm
Protection Degree / IP Rating: IP30

Approvals
Basis Standard: CE, FCC
Safety of industrial control equipment: UL 61010
Hazardous locations: ISA-12.12.-01 Class 1 Div. 2 – Haz. Loc, ATEX-95 Category 3G (Zone 2)

Reliability
Guarantee: 60 months (please refer to the terms of guarantee for detailed information)
Warranty: 5 years

Further Instructions
Product Documentation: https://www.doc.hirschmann.com/index.html
Certificates: https://www.doc.hirschmann.com/certificates.html

History
Update and Revision: Revision Number: 0.66 Revision Date: 03-25-2025

Request for Quote
EAGLE40-6TX-EECC-HV-UN
EAGLE40-6TX-EECC-HV-UN

Next-Generation, Industrial Train Firewall with Enhanced Cybersecurity Including Support for Intrusion Detection Systems (IDS) and Deep Packet Inspection (DPI)

The Hirschmann EAGLE40-6M is a next-generation firewall designed for use on-board in railway rolling stock applications with six (6) 2.5-Gigabit Ethernet M12 X-coded ports, real-time traffic monitoring, advanced threat protection, and secure remote connectivity using IPSec VPN. Includes deep packet inspection (DPI) modules.

Product description

Port type and quantity: 6 x GbE X-coded M12 ports

Displays
LEDs: Power Supply Status LED, Device Status LED, HDD Activity LED, Port Status LEDs

More Interfaces
USB interface: 1 x USB 2.0/3.0, 5-pin A-coded M12
Serial Interface: 1 x Serial Console Port (4-pin, A-coded M12)
Power Supply: 1 x 5 pin K-coded M12

Power requirements
Operating Voltage: Dual 24 V DC – 110 V DC
Power consumption: 25 W

Security features
Multipoint VPN: IPSec, IKE v1/v2, 3DES, AES (-128, -192, -256), Pre-Shared Key (PSK), X.509v3 Certificates, MD5, SHA-1, NAT-T, Hub-and-Spoke
Stateful inspection firewall: Firewall rules (incoming/outgoing, management)

Software
Redundancy: VRRP (Virtual Router Redundancy Protocol), Tracking Framework for VRRP
Management: SNMPv3, SSH2/SFTP/SCP, HTTPS, Serial CLI, SNMPv1/2, local and central User Management (RADIUS), HiDiscovery, Industrial HiVision, HiView, LLDP
Diagnostics: LEDs (Power, Link Status, Data, Status), Log File, Syslog, Configuration check, RMON (statistics), Trap for changes and configuration saves
Configuration: Command Line Interface (CLI), Web Interface, Auto-Configuration Adapter (ACA22), HiDiscovery, Industrial HiVision, HiView
Security: DoS prevention, IPSec VPN, Audit trail, Role-based Access Control, Remote Authentication via RADIUS, IEEE 1686 compliant configuration possible, Firewall Learning Mode, Routed Firewall Mode and Transparent Firewall Mode for Layer 3 and Layer 2 packet filtering rules, Management VLAN, Ingress storm protection, Authentication using LDAP, Deep Packet Inspection (DPI) Enforcer Modules: Modbus TCP, OPC, EtherNet/IP, IEC104, DNP3, and AMP; Support for CylusOne IDS (Docker)
Miscellaneous: NTP Client and Server, DHCP L3 Relay
Routing: VLAN and port based routing, static routing, static multicast, IGMP query, multinetting, IP masquerading, 1-to-1 NAT, port forwarding, Static and Dynamic ARP entries, OSPFv2, Static route tracking

Ambient conditions
MTBF (Telecordia SR-332 Issue 4) @ 25°C: GB 25°C: 842,752 h / GB 75°C: 168,169 h
Operating temperature: -40 -+70 °C
Storage temperature (up to 3 months): -40 °C to +85 °C
Storage temperature (up to 1 year): -40°C to +70 °C
Storage temperature (up to 2 years): -40°C to +50 °C
Storage temperature (up to 10 years): 0°C to +30 °C
Protective paint on PCB: Yes (conformal coating)
Dimensions (WxHxD): 305 x 83 x 180 (mm)
Weight: 4.2 kg
Housing Material: Aluminum Extrusion Top cover, Others by using SGCC
Mounting: Wall mounting
Protection class: IP40

Approvals
Basis Standard: CE, FCC
Safety of industrial control equipment: UL 61010, EN 61131
Safety of information technology equipment: IEC 62368-2
Railway norm: EN 50155, EN 50121-4, EN 45545, EMV06

Reliability
Guarantee: 60 months (please refer to the terms of guarantee for detailed information)

Further Instructions
Product Documentation: https://www.doc.hirschmann.com/index.html
Certificates: https://www.doc.hirschmann.com/certificates.html

History
Update and Revision: Revision Number: 0.27 Revision Date: 03-25-2025

Request for Quote
EAGLE40-6TX-EECC-HV
EAGLE40-6TX-EECC-HV

Next-Generation, Industrial Train Firewall with Enhanced Cybersecurity Including Support for Intrusion Detection Systems (IDS)

The Hirschmann EAGLE40-6M is a next-generation firewall designed for use on-board in railway rolling stock applications with six (6) 2.5-Gigabit Ethernet M12 X-coded ports, real-time traffic monitoring, advanced threat protection, and secure remote connectivity using IPSec VPN.

Product description

Port type and quantity: 6 x GbE X-coded M12 ports

Displays
LEDs: Power Supply Status LED, Device Status LED, HDD Activity LED, Port Status LEDs

More Interfaces
USB interface: 1 x USB 2.0/3.0, 5-pin A-coded M12
Serial Interface: 1 x Serial Console Port (4-pin, A-coded M12)
Power Supply: 1 x 5 pin K-coded M12

Power requirements
Operating Voltage: Dual 24 V DC – 110 V DC
Power consumption: 25 W

Security features
Multipoint VPN: IPSec, IKE v1/v2, 3DES, AES (-128, -192, -256), Pre-Shared Key (PSK), X.509v3 Certificates, MD5, SHA-1, NAT-T, Hub-and-Spoke
Stateful inspection firewall: Firewall rules (incoming/outgoing, management)

Software
Redundancy: VRRP (Virtual Router Redundancy Protocol), Tracking Framework for VRRP
Management: SNMPv3, SSH2/SFTP/SCP, HTTPS, Serial CLI, SNMPv1/2, local and central User Management (RADIUS), HiDiscovery, Industrial HiVision, HiView, LLDP
Diagnostics: LEDs (Power, Link Status, Data, Status), Log File, Syslog, Configuration check, RMON (statistics), Trap for changes and configuration saves
Configuration: Command Line Interface (CLI), Web Interface, Auto-Configuration Adapter (ACA22), HiDiscovery, Industrial HiVision, HiView
Security: DoS prevention, IPSec VPN, Audit trail, Role-based Access Control, Remote Authentication via RADIUS, IEEE 1686 compliant configuration possible, Firewall Learning Mode, Routed Firewall Mode and Transparent Firewall Mode for Layer 3 and Layer 2 packet filtering rules, Management VLAN, Ingress storm protection, Authentication using LDAP, Support for CylusOne IDS (Docker)
Miscellaneous: NTP Client and Server, DHCP L3 Relay
Routing: VLAN and port based routing, static routing, static multicast, IGMP query, multinetting, IP masquerading, 1-to-1 NAT, port forwarding, Static and Dynamic ARP entries, OSPFv2, Static route tracking

Ambient conditions
MTBF (Telecordia SR-332 Issue 4) @ 25°C: GB 25°C: 842,752 h / GB 75°C: 168,169 h
Operating temperature: -40 -+70 °C
Storage temperature (up to 3 months): -40 °C to +85 °C
Storage temperature (up to 1 year): -40°C to +70 °C
Storage temperature (up to 2 years): -40°C to +50 °C
Storage temperature (up to 10 years): 0°C to +30 °C
Protective paint on PCB: Yes (conformal coating)
Dimensions (WxHxD): 305 x 83 x 180 (mm)
Weight: 4.2 kg
Housing Material: Aluminum Extrusion Top cover, Others by using SGCC
Mounting: Wall mounting
Protection class: IP40

Approvals
Basis Standard: CE, FCC
Safety of industrial control equipment: UL 61010, EN 61131
Safety of information technology equipment: IEC 62368-2
Railway norm: EN 50155, EN 50121-4, EN 45545, EMV06

Reliability
Guarantee: 60 months (please refer to the terms of guarantee for detailed information)

Further Instructions
Product Documentation: https://www.doc.hirschmann.com/index.html
Certificates: https://www.doc.hirschmann.com/certificates.html

History
Update and Revision: Revision Number: 0.27 Revision Date: 03-25-2025

Request for Quote
EAGLE40-6TX-EECC-HV
EAGLE40-6TX-EECC-HV

Next-Generation, Industrial Train Firewall with Enhanced Cybersecurity Including Support for Intrusion Detection Systems (IDS)

The Hirschmann EAGLE40-6M is a next-generation firewall designed for use on-board in railway rolling stock applications with six (6) 2.5-Gigabit Ethernet M12 X-coded ports, real-time traffic monitoring, advanced threat protection, and secure remote connectivity using IPSec VPN.

Product description

Port type and quantity: 6 x GbE X-coded M12 ports

Displays
LEDs: Power Supply Status LED, Device Status LED, HDD Activity LED, Port Status LEDs

More Interfaces
USB interface: 1 x USB 2.0/3.0, 5-pin A-coded M12
Serial Interface: 1 x Serial Console Port (4-pin, A-coded M12)
Power Supply: 1 x 5 pin K-coded M12

Power requirements
Operating Voltage: Dual 24 V DC – 110 V DC
Power consumption: 25 W

Security features
Multipoint VPN: IPSec, IKE v1/v2, 3DES, AES (-128, -192, -256), Pre-Shared Key (PSK), X.509v3 Certificates, MD5, SHA-1, NAT-T, Hub-and-Spoke
Stateful inspection firewall: Firewall rules (incoming/outgoing, management)

Software
Redundancy: VRRP (Virtual Router Redundancy Protocol), Tracking Framework for VRRP
Management: SNMPv3, SSH2/SFTP/SCP, HTTPS, Serial CLI, SNMPv1/2, local and central User Management (RADIUS), HiDiscovery, Industrial HiVision, HiView, LLDP
Diagnostics: LEDs (Power, Link Status, Data, Status), Log File, Syslog, Configuration check, RMON (statistics), Trap for changes and configuration saves
Configuration: Command Line Interface (CLI), Web Interface, Auto-Configuration Adapter (ACA22), HiDiscovery, Industrial HiVision, HiView
Security: DoS prevention, IPSec VPN, Audit trail, Role-based Access Control, Remote Authentication via RADIUS, IEEE 1686 compliant configuration possible, Firewall Learning Mode, Routed Firewall Mode and Transparent Firewall Mode for Layer 3 and Layer 2 packet filtering rules, Management VLAN, Ingress storm protection, Authentication using LDAP, Support for CylusOne IDS (Docker)
Miscellaneous: NTP Client and Server, DHCP L3 Relay
Routing: VLAN and port based routing, static routing, static multicast, IGMP query, multinetting, IP masquerading, 1-to-1 NAT, port forwarding, Static and Dynamic ARP entries, OSPFv2, Static route tracking

Ambient conditions
MTBF (Telecordia SR-332 Issue 4) @ 25°C:
GB 25°C: 842,752 h / GB 75°C: 168,169 h
Operating temperature: -40 to +70 °C
Storage temperature (up to 3 months): -40 °C to +85 °C
Storage temperature (up to 1 year): -40°C to +70 °C
Storage temperature (up to 2 years): -40°C to +50 °C
Storage temperature (up to 10 years): 0°C to +30 °C
Protective paint on PCB: Yes (conformal coating)

Dimensions (WxHxD): 305 x 83 x 180 mm
Weight: 4.2 kg
Housing Material: Aluminum Extrusion Top cover, Others by using SGCC
Mounting: Wall mounting
Protection class: IP40

Approvals
Basis Standard: CE, FCC
Safety of industrial control equipment: UL 61010, EN 61131
Safety of information technology equipment: IEC 62368-2
Railway norm: EN 50155, EN 50121-4, EN 45545, EMV06

Reliability
Guarantee: 60 months (please refer to the terms of guarantee for detailed information)

Further Instructions
Product Documentation: Hirschmann Documentation
Certificates: Certificates Page

History
Update and Revision
Revision Number: 0.27
Revision Date: 03-25-2025

Request for Quote
EAGLE40-4F-ROUTER
EAGLE40-4F-ROUTER

Next-Generation, Field-Level Industrial Firewall with Enhanced Cybersecurity

The Hirschmann EAGLE40-4F is a next-generation, field-level industrial firewall with four (4) Gigabit Ethernet ports, real-time traffic monitoring, and advanced cybersecurity capability.

Product description

Type: EAGLE40-4F-ROUTER
Name: EAGLE40-4F-Router

Port type and quantity: 4 x GbE RJ45 ports

Displays
LEDs: LEDs (Power, Link Status, Data, Status), Signal Contact (24 V DC/1 A), Log File, Syslog, Configuration check RMON (Statistic), Trap for changes and configuration saves

More Interfaces
USB interface: 1 x USB 2.0 port
Serial Interface: 1 x RJ45 port (RS-232, RS-422, RS-485)
Power Supply: 1 x plug-in terminal block, 10-pin

Power requirements
Operating Voltage: Dual 10 ~ 30 V DC
Power consumption: Minimum – 2.5W, Maximum – 12W

Security features
Multipoint VPN: IPSec, IKE v1/v2, 3DES, AES (-128, -192, -256), Pre-Shared Key (PSK), X.509v3 Certificates, MD5, SHA-1, NAT-T, Hub-and-Spoke
Stateful inspection firewall: Firewall rules (incoming/outgoing, management)

Software
Redundancy: VRRP (Virtual Router Redundancy Protocol), Tracking Framework for VRRP
Management: SNMPv3, SSH2/SFTP/SCP, HTTPS, Serial CLI, SNMPv1/2, local and central User Management (RADIUS), HiDiscovery, Industrial HiVision, HiView, LLDP
Diagnostics: LEDs (Power, Link Status, Data, Status), Log File, Syslog, Configuration check, RMON (statistics), Trap for changes and configuration saves
Configuration: Command Line Interface (CLI), Web Interface, Auto-Configuration Adapter (ACA22), HiDiscovery, Industrial HiVision, HiView
Security: DoS prevention, IPSec VPN, Audit trail, Role-based Access Control, Remote Authentication via RADIUS, IEEE 1686 compliant configuration possible, Firewall Learning Mode, Routed Firewall Mode and Transparent Firewall Mode for Layer 3 and Layer 2 packet filtering rules, Management VLAN, Ingress storm protection, Authentication using LDAP
Miscellaneous: NTP Client and Server, DHCP L3 Relay
Routing: VLAN and port based routing, static routing, multinetting, IP masquerading, 1-to-1 NAT, port forwarding, Static and Dynamic ARP entries, OSPFv2, Static route tracking

Ambient conditions
MTBF (Telecordia SR-332 Issue 4) @ 25°C: 309,149 hours
Operating temperature: -40 to +70 °C
Storage/transport temperature: -40 to +85 °C

Dimensions (WxHxD): 48 x 137 x 105 mm
Weight: 613 g
Housing Material: Aluminum with DIN clip
Mounting: DIN Rail 35 mm
Protection Degree / IP Rating: IP30

Approvals
Basis Standard: CE, FCC
Safety of industrial control equipment: UL 61010
Hazardous locations: ISA-12.12.-01 Class 1 Div. 2 – Haz. Loc, ATEX-95 Category 3G (Zone 2)

Reliability
Guarantee: 60 months (please refer to the terms of guarantee for detailed information)
Warranty: 5 years

Further Instructions
Product Documentation: Hirschmann Documentation
Certificates: Certificates Page

History
Update and Revision
Revision Number: 0.66
Revision Date: 03-25-2025

Request for Quote

Hirschmann EAGLE20/30 Multiport Industrial Firewall System

Paired with the advanced security functionality of Hirschmann Security OS software (HiSecOS), these multiport EAGLE20/30 Firewalls reliably secure entire industrial networks. Modular configuration options (up to eight ports) offer customization while eliminating multiple routers for significant cost savings and expedited installation. Features like Deep-Packet-Inspection (DPI) and Firewall Learning Mode (FLM) ensure packet data integrity, protect networks from malicious intents and make device configuration easy.

Features & Benefits
Customizable Design: Many interface configuration options, including Fast Ethernet, Gigabit Ethernet and SHDSL
Easily Create New Rules: Firewall Learning Mode (FLM) offers an advanced graphical user interface
System Security: Experience the highest level of network security

EAGLE30-04022O6TT999TCCY9HSE3FXX.X.XX
EAGLE30-04022O6TT999TCCY9HSE3FXX.X.XX

The advanced security functionality of the Hirschmann Security Operating System (HiSecOS), paired with these multiport industrial firewalls, creates a solution capable of securing and protecting an entire industrial network.

Data Sheet

EAGLE30-04022O6TT999TCCY9HSE3FXXXXX_techdata

Request for Quote

Tofino Xenon Industrial Security Appliance

The Tofino Xenon industrial security appliance provides comprehensive network protection. It is a versatile, extremely ruggedized device that ensures maximum data protection for production systems and is the ideal solution for segmenting a control network into security zones.

Tofino Xenon
Tofino Xenon
Request for Quote