TXOne Networks
ヒーロー背景

生産を止めないインラインOT保護

全セグメントにGen3ハードウェアバイパスを搭載。2ポートから96ポートまで対応。

500マイクロ秒未満のレイテンシを実現するトランスペアレントなインライン侵入防御です。IPアドレス変更やネットワーク再設計なしに展開できます。ハードウェアバイパスがあらゆる状況でも運用継続を保証します。

EdgeIPS Proは全セグメントにGen3ハードウェアバイパスを備えたトランスペアレントなインライン保護を提供します。運用チームは継続稼働を確保し、セキュリティチームは防御能力を手に入れます。

運用チームがインラインセキュリティに抵抗するのは、単一障害点になり得るからです。セキュリティチームがインライン保護を必要とするのは、パッシブモニタリングでは攻撃を止められないからです。EdgeIPS Proはこの対立を解消します。全ポートペアのGen3ハードウェアバイパスがあらゆるシナリオでの生産継続を保証し、トランスペアレント展開によりIPアドレス変更やネットワーク再設計が不要です。2ポートのコンパクトモデルから96ポートのプラットフォームまで、EdgeIPS Proは500マイクロ秒未満のレイテンシでスケールします。

セキュリティと運用の対立を終わらせる

セキュリティチームはインライン保護を求め、運用チームは生産リスクゼロを求めています。EdgeIPS Proはその両方を実現します。トランスペアレント展開によりIPアドレス変更、ネットワーク再設計、ダウンタイムはすべて不要です。全セグメントのGen3ハードウェアバイパスがあらゆる障害シナリオでも生産継続を保証します。個別資産を保護する2ポートのコンパクト機器から施設全体を守る96ポートのモジュール式プラットフォームまで、EdgeIPS Proは運用規模に合わせてスケールします。

トランスペアレント展開

ネットワーク変更ゼロ。IPの再設定もトポロジーの再設計もダウンタイムも不要です。

セグメントごとのハードウェアバイパス

全ポートペアのGen3ハードウェアバイパスが、あらゆる障害時でも生産継続を保証します。

スケーラブルなアーキテクチャ

2ポートのコンパクトDINレールユニットから96ポートのモジュール式ラックマウントプラットフォームまで対応。

ハイブリッドプロトコルフィルタリング

ファームウェアアップグレード不要で詳細なOTプロトコルインスペクションを実現。新しいプロトコルは動的に追加されます。

Gbps 最大スループット
ポリシー適用ルール数
あらゆる環境に対応するモデル数
<
マイクロ秒 平均レイテンシ

インラインアセット保護

重要な個々のアセットを保護するコンパクトな1対1 IPSアプライアンス

EdgeIPS 102 Gen2

EdgeIPS 102 Gen2

DINレールマウント

Compact protection for a single critical device.

200Mbps
Threat prevention speed
1
Protected segment
30K
Simultaneous connections
-40 to 75°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
Standard copper ports
Two RJ-45 ports connect with the cables you already use.
Rugged and fanless
Mounts directly on a DIN rail. Rugged design with no fans or moving parts.
Power: 12/24/48 VDC via terminal block, or 12V DC via barrel jack
EdgeIPS 103

EdgeIPS 103

DINレールマウント

Fast, compact protection for a single critical device.

850Mbps
Threat prevention speed
1
Protected segment
30K
Simultaneous connections
-40 to 75°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
Standard copper ports
Two RJ-45 ports connect with the cables you already use.
Rugged and fanless
Mounts directly on a DIN rail. Rugged design with no fans or moving parts.
Power: 12/24/48 VDC via terminal block, or 12V DC via barrel jack
EdgeIPS 103F

EdgeIPS 103F

DINレールマウント

Fiber connections for a single critical link.

850Mbps
Threat prevention speed
1
Protected segment
30K
Simultaneous connections
0 to 40°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
Gigabit fiber ports
Two fiber ports. Choose a multi-mode model for short runs or a single-mode model for long distances.
Rugged and fanless
Mounts directly on a DIN rail. Rugged design with no fans or moving parts.
Power: 12/24/48 VDC via terminal block, or 12V DC via barrel jack
EdgeIPS LE 102

EdgeIPS LE 102

DINレールマウント

Compact next-gen IPS for cost-sensitive environments

100Mbps
Throughput (IMIX)
1
Hardware Segment
512
Policy Rules
30K
Concurrent Connections
2 GbE Ports
Auto-sensing 10/100/1000 Mbps copper connectivity
Hardware Bypass
Fail-open for uninterrupted production
Ultra-Compact
110 x 109 x 26 mm DIN-rail mount
Cost-Effective
Purpose-built for high-volume deployments
12–48 VDC•Dual-type input (3-pin terminal block + DC-IN 12V)

マルチセグメント保護

1台のデバイスから複数のネットワークセグメントを保護するマルチポートアプライアンス

EdgeIPS Pro 212F

EdgeIPS Pro 212F

DINレールマウント

Multi-segment protection for copper and fiber links.

1.8Gbps+
Threat prevention speed
6
Protected segments
200K
Simultaneous connections
-40 to 75°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity, including during uplink disconnection.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
Copper and fiber together
Two copper segments and four multi-mode fiber segments in one device.
Flexible mounting
Mounts on a DIN rail, in a rack, or on a wall.
Power: 12/24/48 VDC via terminal block, plus 12V DC via barrel jack (dual redundant inputs)
EdgeIPS Pro 216

EdgeIPS Pro 216

DINレールマウント

Eight-segment protection in two versions: Commercial for temperature-controlled sites, or Rugged for harsh environments.

1.8Gbps+
Threat prevention speed
8
Protected segments
200K
Simultaneous connections
-40 to 75°C
Operating temperature (Rugged) Commercial: 0 to 40°C
Hardware bypass
Fail-safe bypass ensures network continuity, including during uplink disconnection.
16 GbE Ports
High-density copper connectivity for production floors
16 copper ports
16 RJ-45 ports protect up to 8 network links.
Flexible mounting
Mounts on a DIN rail, in a rack, or on a wall.
Power: 12/24/48 VDC via terminal block, plus 12V DC via barrel jack (dual redundant inputs)

プロダクション&データセンタースケール

大規模OTネットワーク保護のための高性能ラックマウントアプライアンス

EdgeIPS Pro 732

EdgeIPS Pro 732

1Uラックマウント

High-capacity protection for large production sites.

7.2Gbps
Threat prevention speed
16
Protected segments
2M
Simultaneous connections
0 to 40°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity, including during uplink disconnection.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
32 copper ports
32 RJ-45 ports protect up to 16 network links.
Standard 1U rack size
Fits a 1U rack. Rack ears and sliding rails are supported.
Power: 90 to 264 VAC via two C14 inlets (redundant 800W hot-swappable power supplies)
EdgeIPS Pro 1048 Gen2

EdgeIPS Pro 1048 Gen2

1Uラックマウント

Modular 48-port IPS for large-scale network segmentation

10Gbps
Throughput (IMIX)
48
Max Ports
24
Bypass Segments
2M
Concurrent Connections
Up to 48 Ports
Modular card-based expansion for flexible deployment
24 Segment Bypass
Gen3 hardware bypass for copper and fiber modules
Hot-Swap PSU
Redundant 800W active-active power supplies
2M Connections
Enterprise-scale concurrent session handling
90–264 VAC•Redundant 800W PSU (1+1 AC, active-active, hot-swappable)
EdgeIPS Pro 2096 Gen2

EdgeIPS Pro 2096 Gen2

2Uラックマウント

Maximum port density for the largest networks.

20Gbps
Threat prevention speed
Up to 48
Protected segments
4M
Simultaneous connections
0 to 40 °C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity, including during uplink disconnection.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
Add ports as you grow
Add copper or fiber cards to reach up to 96 ports.
Very low delay
Adds under half a millisecond of delay on average, so production timing is not affected.
Power: 90 to 264 VAC via two C14 inlets (redundant 800W hot-swappable power supplies)
EdgeIPS Pro 4016F

EdgeIPS Pro 4016F

1Uラックマウント

The fastest EdgeIPS, built for high-speed fiber networks.

40Gbps
Threat prevention speed
8
Protected segments
4M
Simultaneous connections
0 to 40°C
Operating temperature
Hardware bypass
Fail-safe bypass ensures network continuity, including during uplink disconnection.
Inline or offline deployment
Sits directly in the network path, or connects to a SPAN (mirror) port to watch traffic offline.
16 fiber ports, 10 gigabit
Order multi-mode for short runs or single-mode for long distances.
Fastest in the EdgeIPS family
40 Gbps is the highest threat prevention speed of any EdgeIPS.
Power: 90 to 264 VAC via two C14 inlets (redundant 800W hot-swappable power supplies)
課題

OTセキュリティの課題

EdgeIPSが解決するために設計された重要な課題

従来の展開には6〜12ヶ月を要するのに対し、トランスペアレントアーキテクチャでは数日で完了

ネットワーク再設計が必要

ITセキュリティアプライアンスはIPアドレスの変更やネットワークアーキテクチャの変更を必要とします。生産環境ではこれはダウンタイム、広範なテスト、運用リスクを伴い、保護の開始が数ヶ月単位で遅延します。

主な機能

主な機能

EdgeIPSがOT環境をどのように保護するかをご覧ください

生産優先のハードウェアバイパス

アップリンク切断に対応するUniversal Bypassを備え、全セグメントにGen3ハードウェアバイパスを搭載。自動切り替えと復旧機能により、メンテナンス、アップデート、あらゆる障害シナリオでも運用を中断させません。ネットワークセキュリティのために生産を止める必要はありません。

主要な機能

自動フェイルオーバーと復旧
メンテナンス時間中も継続した保護
単一障害点なし
アップリンク保護のためのUniversal Bypass
ユースケース

実際の適用事例

組織がEdgeIPSを本番環境でどのように展開しているかをご覧ください

生産セルの保護

EdgeIPS Pro 212F または 216 - 制御ネットワーク境界において各セルに1台を配置し、半導体ファブや製造セルにセグメント分離、プロトコルフィルタリング、レガシーHMI保護を提供します。

運用チームの方へ

IPアドレスに一切手を加えることなくインラインネットワークセキュリティを展開できます。EdgeIPS Proのトランスペアレントアーキテクチャと自動ハードウェアバイパスにより、メンテナンス中や障害発生時も生産を止めません。

  • ネットワーク変更ゼロ
  • 全セグメントにハードウェアバイパスを搭載
  • 自動フェイルオーバーと復旧

テクノロジー

EdgeIPSを支えるテクノロジー

CPSDRネットワーキング技術

産業ネットワークに向けた予測的脅威検知

EdgeIPS ProはCPSDRを活用し、異常なネットワーク挙動を最初期段階で特定・予測します。OTプロトコルへの深い理解と組み合わせることで、産業用制御システムを標的とした高度な脅威に対してプロアクティブな防御を実現します。

  • ネットワークセグメント全体にわたる予測的異常検知
  • 生産への影響が生じる前にプロアクティブに脅威をブロック
  • 資産を考慮した行動分析
  • 継続的なネットワークポスチャ評価

インライン展開でも生産を中断させない設計

二者択一のジレンマ:保護か生産性か

セキュリティチームはインライン保護がスタンダードであることを知っています。一方、運用チームはインラインデバイスが単一障害点になり得ることも知っています。誤検知や機器障害が1件起きるだけで、1時間あたり数百万ドルの価値を持つ生産ラインが止まりかねません。

展開方式

IT中心のアプローチ

IPアドレス変更とネットワークアーキテクチャの変更が必要で、数ヶ月のダウンタイムとリスクを伴います。

TXOneソリューション

IPアドレス変更なしのトランスペアレント展開で、導入中も生産が継続します。

フェイルオーバー保護

IT中心のアプローチ

ハードウェアバイパスなし。デバイス障害が発生すると生産が停止します。

TXOneソリューション

全セグメントにGen3ハードウェアバイパスを搭載し、サブマイクロ秒での切り替えを実現。

プロトコルサポート

IT中心のアプローチ

Modbus、SECS/GEM、S7Commを検査できないため、産業用プロトコルへの攻撃が見えません。

TXOneソリューション

CPSDR予測検知による180以上の産業用プロトコルへのディープインスペクション。

EdgeIPS Proは、その困難な二者択一を解消します。セキュリティチームはインライン防御を手に入れ、運用チームはハードウェアバイパスの保証を得られます。

EdgeIPSを4ステップで導入

運用を中断することなく、OT環境向けに設計された効率的な導入プロセス。

01

第1週:展開の優先順位を特定するテクニカルアセスメント

02

第2〜3週:トランスペアレントインストールによるパイロット展開

03

第1〜2ヶ月:Asset-Centric Auto Learningでカバレッジを拡大

04

継続:EdgeOne統合による一元的な可視性の確保

運用中&保護済み

技術仕様

侵入防御あり(CPSDR-Networking)
シグネチャベースのウイルス対策あり
ポリシールール数100,000
ICSプロトコルプロファイル数256
ハードウェアバイパス全セグメントにGen3搭載
Universal Bypassあり

EdgeIPSとのシームレスな統合

運用を中断することなく、既存のOTインフラストラクチャに統合するよう設計されています。

既存のネットワークアーキテクチャを維持したトランスペアレント展開
あらゆるイベント発生時も生産継続を保証するハードウェアバイパス
マルチデバイス展開向けのEdgeOne集中管理
SenninによるStellarエンドポイント保護とのCPSDR連携
ネットワーク層でレガシーシステム保護を拡張する仮想パッチ適用

お客様の成功事例

Ansaldo

“Within this context, TXOne Networks emerged as the ideal technology partner, capable of responding precisely to Ansaldo Energia’s requirements.”

Diego Lusso
Cyber Security OT Manager, Ansaldo
Carlsberg Group

“Thanks to OT security solution Stellar, TXOne Networks helps us mitigate risks that we couldn't address yesterday without making significant financial investments.”

Chris Thompson
Director of Brewery OT Security, Carlsberg Group

生産リスクのないインライン保護をご検討ですか?

Gen3ハードウェアバイパスとトランスペアレント展開を実際にご確認ください。お客様のネットワーク環境に合わせたテクニカルアセスメントをご依頼いただけます。