Portada » Moxa at SPS 2025: Products for secure, reliable, and future-proof OT networks

Moxa at SPS 2025: Products for secure, reliable, and future-proof OT networks

by admin
579 views

Under the motto “Connected Manufacturing. Securely. Since 1987,” Moxa presents its wide range of switches, next-generation firewalls, intrusion prevention systems, and serial-to-Ethernet gateways that comply with IEC 62443-4-2. This facilitates the practical implementation of industrial cybersecurity requirements such as NIS-2 and the Cyber ​​Resilience Act (CRA). The Moxa product range stands for interoperability, scalability, and flexibility, thanks to its support for multiple protocols such as PROFINET, MRP, EtherCAT, and OPC UA FX. With a wide range of serial-to-Ethernet gateways, Moxa offers the possibility of integrating existing installations into modern OT networks during modernization projects. Moxa responds to the growing demand for real-time performance with gateways and junction boxes for EtherCAT.

OT Cybersecurity in Focus

With the NAT-102/108 series NAT (address translation and access control) devices, Moxa resolves IP conflicts in production. Even if multiple machines have the same IP address, they can be integrated into the OT network securely and with little effort. The series accelerates machine onboarding and supports role-based access control. The hardened design, compliant with IEC 62443-4-2 Security Level 2 (SL2), includes, for example, secure boot, signed firmware updates, traffic logging, and MAC/IP/port filtering, and meets the key requirements of Annex I, Part I of the CRA.

The EDF-G1002-BP-Series industrial IPS (intrusion prevention system) combines deep packet inspection (DPI) and virtual patching with up to 500 Mbps and 45,000 packets/s to provide real-time protection on machine or plant networks. It strengthens network security through enhanced access control, defense against known threats, and comprehensive logging for complete traceability, helping machine builders implement key CRA requirements. In both passive detection and active prevention modes, the firewall increases threat visibility.

The device operates in transparent mode, allowing it to be integrated directly into the network topology without changing existing IP addresses. The management interface can be operated on a separate VLAN, allowing access and monitoring to be segmented without impacting production. The EDF-G1002-BP series is IEC 62443-4-2 SL2, EN 50121-4, NEMA TS2, and IECEx certified, and is also suitable for use in railway, traffic, and explosive environments.

CRA Alignment Throughout the Product Lifecycle

In addition to secure devices that comply with Annex I, Part I of the CRA by default, Moxa also supports Annex I, Part II of the CRA with a Secure Development Lifecycle (SDL) aligned with the IEC 62443-4-1 standard. This includes systematic threat modeling across the entire portfolio, secure coding, and continuous testing. Moxa’s Product Security Incident Response Team (PSIRT) coordinates responsible vulnerability reporting in accordance with international standards. As the official CVE Numbering Authority (CNA), Moxa assigns CVE identifiers to its products and systematically publishes entries to ensure high traceability. Security advisories and SBOMs (Software Bills of Materials) ensure transparency. Additionally, Moxa meets the CRA’s documentation requirements for third-party components and the implementation of secure OT networks according to the IEC 62443 and NIS-2 frameworks, with solutions for network zoning and segmentation, access control, auditability, and long-term resilience.

Network Transparency: MXview One Live Demonstration

Visitors will experience real-time monitoring and diagnostics on industrial networks through a live demonstration of the MXview One network management platform. The software automatically detects and displays network and SNMP/IP devices in subnets. Management and configuration are performed centrally via a web browser. A dynamic topology view shows connection and redundancy status at a glance: comprehensive reports and event notifications, detailed device information, full visibility into redundant LAN connections, and many other features ensure comprehensive transparency at all times.

Related News