Product Short Description
Product Overview
Layer 3 industrial security router dedicated to factory automation network isolation, equipped with dual Gigabit Ethernet LAN ports, hardware encryption VPN chip, integrated SPI stateful firewall, realize interconnection between production control subnet and office IT network with complete data security isolation, support industrial field bus serial conversion and multi-layer network routing scheduling
Description
Core Technical Specifications
- Network Interfaces
- 2 × 10/100/1000BASE-T Gigabit RJ45 galvanically isolated Ethernet ports
- 1 × DB9 male serial port, configurable RS232/422/485 galvanic isolation, baud rate 110~460800bps
- 4 × Digital I/O signal terminals for VPN status trigger and link cut-off control
- Routing & Security Parameters
- Routing Protocol: Static route, RIPv2, OSPF IPv4 Layer 3 routing
- VPN Encryption: Hardware-accelerated IPsec (max 64 simultaneous tunnels), OpenVPN; AES-128/192/256, 3DES, DES encryption algorithms
- Firewall: SPI stateful packet inspection, MAC/IP address access control list, port filtering
- NAT Function: 1:1 static NAT, masquerading NAT subnet address translation
- Electrical & Environmental
- Power Input: 7 ~ 36 VDC industrial wide voltage, NEC Class 2 certified
- Operating Temperature: -25°C ~ +70°C
- Storage Temperature: -40°C ~ +85°C
- Humidity: 5% ~ 90% non-condensing
- Protection Rating: IP30
- Physical Data
- Mounting: 35mm DIN rail mounting
- Enclosure Material: Die-cast aluminum alloy
- Weight: 0.72kg
- Dimensions: 125mm × 110mm × 45mm
- Management Modes: HTTPS web management, SNMP v3, Windows dedicated configuration tool, serial console
Function & Performance Features
- Hardware encryption chip offloads VPN computing, no network bandwidth loss under multi-tunnel concurrent operation
- Galvanic isolation between Ethernet, serial and power circuits, eliminate ground loop interference between different network subnets
- Four digital signal I/O terminals: VPN active status output, WAN link forced cut-off trigger, packet filter rule trigger
- Industrial network isolation core function: Separate production control network and office ERP network to prevent virus spread from IT network to automation equipment
- Serial port transparent transmission: Convert Modbus RTU serial signal to TCP/IP Ethernet data for remote field bus device access
- Real-time network traffic monitoring, built-in system log record access, alarm, VPN connection events
- Support X.509 digital certificate and PSK dual authentication for VPN tunnel connection
- RoHS, cULus, CE industrial safety certification, long-term stable operation in cabinet harsh environment
Working Principle
When data packets pass between LAN1 and LAN2 ports, the router first executes SPI firewall rule filtering, then completes NAT address translation according to configured subnet rules. Cross-site remote data transmission is encrypted via hardware IPsec tunnel before forwarding to public network. The isolated RS485 serial port collects Modbus field device data, encapsulates serial frames into TCP packets and routes to upper monitoring system. Digital I/O terminals detect VPN tunnel online status, output switch signal to PLC for network fault interlock control.
Material & Structural Characteristics
- Housing: Die-cast aluminum alloy shell, anodized anti-corrosion treatment, excellent heat dissipation for encryption chip
- Circuit Board: Conformal coated PCB, all signal ports with isolation transformer
- DIN Rail Clip: Integrated plastic metal composite buckle, easy disassembly with flat screwdriver
- Terminal Blocks: Screw-type gold-plated terminals for power and digital I/O wiring
Installation Requirements
- Install on standard 35mm DIN rail inside industrial cabinet, reserve 15mm heat dissipation space around the router
- Power supply wiring uses 24VDC industrial power supply, cable cross-section ≥0.75mm²
- Separate control network and office network cables to two different Gigabit ports, do not cross wiring
- Serial RS485 wiring uses twisted pair shielded cable, single-end grounding of shielding layer
- Digital I/O wiring connects to 24VDC PLC digital module for network fault signal collection
- Do not install near high-power frequency converters to avoid serial communication interference
Application Scenarios
- Factory production network and enterprise office IT network security isolation gateway
- Cross-regional factory remote equipment VPN encrypted monitoring
- Modbus RTU serial field bus to Ethernet protocol conversion gateway
- Energy management system multi-subnet interconnection routing equipment
- Intelligent logistics remote AGV fleet encrypted data transmission
- Water treatment plant remote PLC secure access control
Operation & Maintenance Precautions
- Modify default web management login account and password after first power-on to prevent unauthorized access
- Regularly back up full router configuration via web interface, save encryption certificate files separately
- Do not short-circuit digital I/O signal terminals, which will damage internal optocoupler isolation circuits
- Avoid condensation environment without cabinet heating strip, moisture will cause circuit board corrosion
- When IPsec tunnel disconnection occurs, check public network port mapping and firewall ACL rules first






Reviews
There are no reviews yet.