References

The high level of customer confidence speaks for itself. We enable the reliable transport of energy and data.

Use cases from the energy industry

Communication technology connection
of a transformer stationintelligent local network stations

Measurement data is transferred to the cloud by setting up advanced network architectures based on IPv6, Dual APN, OSPF and RIP. The zero-trust principle is used to ensure a supply chain free of sensitive secrets, both in startup and running configuration mode. An automatic certificate exchange (EST) and the separation of the control channel and data channel contribute to security. The cryptographic procedures comply with BSI TR-02102 standards and high availability is ensured by connection redundancy over various channels such as DSL, fibre and LTE, including LTE450 MHz communication for critical infrastructure.

Arrange a consultation now!

Communication connection of a gas pressure regulator station

Measurement data is transmitted to control and cloud systems using secure communication via public or private networks, utilising both OpenVPN and IPsec. Fault messages and alarms are transmitted effectively via SMS, email and MQTT. The icom Connectivity Suite also enables remote maintenance and remote access to network devices. The flexible connection technology includes LTE, LTE450, fibre optics and DSL. To ensure high availability, this technology relies on redundancy, both in the area of fibre optics and LTE as well as between different LTE connections (LTE1 & LTE2).

LTE 450 MHz mobile communications for KRITIS

MRX3 LTE450

MRX5 LTE450

MRcard PL450

LTE450 Antennas

LTE450 Wall Antenna 5G/4G/3G/2G IP67 IK10 5m SMA

Remote access, Remote maintenance
und 24/7 Scada Monitoring

Simple commissioning
and secure operation in KRITIS environments

Highlights

  • null
    Complete network coverage
  • null
    Highest availability
  • null
    Best IT security

Membership of the 450 MHz Alliance

German provider for our LTE450 solution

Arrange a consultation now!

IT security features for critical infrastructure

  • KRITIS compliant; provider with the most installations in critical infrastructure
  • MRX3-LTE router certified according to BSI BSZ for critical infrastructures
  • Firmware update signed and encrypted
  • Encrypted support packages
  • Cryptographic procedures compliant with BSI TR-02102-2
  • Hardened firmware
  • Regular penetration tests
  • UpdatePolicy

  • 8-week update cycle for router firmware
  • White-list industrial firewall with IP packet and MAC filter
  • No default passwords
  • User/PW, RADIUS or certificate-based authentication
  • X.509 certificates and use of own PKI

Rollout and operation of large router fleets with icom Router Management

  • Monitor router fleet

  • Keep your router up to date & secure

  • Firmware, certificate and software updates

  • Carry out mass rollouts

  • Start/run configuration

Arrange a consultation now!

icom Connectivity Suite – The VPN service from INSYS icom.

Ideal for accessing distributed stations and system technology.

The advantages of the icom Connectivity Suite

  • Remote access to the controller, IPC or HMI.
  • Simple commissioning of router and remote maintenance PC.

  • Standardised solution: also open for third-party devices with OpenVPN Client.

  • Rights management: Access for technology or external service providers only to selected systems/groups.

  • SIM solution for mobile routers integrated in the portal, enables simple onward billing to end customers.

From the field: Utonomy develops cloud-based gas pressure control

“The INSYS icom products are perfectly adapted to our application for smart gas grids and operate on-site with a high level of reliability. We are delighted to be working with the highly experienced team of INSYS icom.”

Adam Kingdon
Managing Director
Utonomy Ltd., Southampton (UK)

 

Added value of the INSYS solution

Extensive routing, VPN and firewall functions

OSPF, RIP, GRE, IPsec, OpenVPN, DMVPN, parallele Tunnel,
EST, SCEP, zustandsabhängige Firewall, IP/MAC, Port-Filter

null

Analysis & debugging tools

Tools for analysing the network: ping/icmp, tcpdump, traceroute, …

null

Multi VPN

Several parallel VPN tunnels can be set up (IPsec, OpenVPN). Client and server available.

null

Web proxy function

Access to web interface e.g. of video cameras without VPN client from smartphone, tablet and browser.

null

Own software container

LXC container technology for installing your own applications on the router. Dedicated IP endpoint for full firewall control.

Die Applikationssoftware icom Data Suite ermöglicht dem Betreiber, Daten direkt auf dem Router zu erfassen und zu verarbeiten (Edge Computing).

quality

Durable products you can rely on.

null

Standard-compliant

Compatible with all common network products and protocols, e.g. Cisco, Fortinet, Juniper.

null

Interfaces

In addition to Ethernet, analogue and digital IOs as well as serial interfaces (e.g. Modbus) are available.

Durch die flexiblen MRcards schafft der modulare Router MRX mit bis zu 17 Ethernet-Ports, seriellen Schnittstellen oder digitalen und analogen I/Os viele verschiedene Anwendungs-Schnittstellen.

Alle Produkte und Dienste werden zudem regelmäßig von unabhängiger Stelle getestet. You can find out more here.

Communication technology for energy and gas grids – Frequently asked questions

What is the difference between an industrial router and a home router?

Service life, availability, IT security
Home routers are developed for a service life of 2-3 years and the electrical components are selected accordingly. In harsher environmental conditions, e.g. temperature fluctuations in control cabinets or increased EMC/vibration, this service life is significantly reduced. Industrial routers have a service life of 10+ years. The use in industry and infrastructure does not allow frequent changes.

Availability
Industrial applications rely on high communication availability. The router system has been developed for uninterrupted 24/7 operation.

Security – Interesting facts about the IT security of industrial routers
Infrastructure and industrial plants are attractive targets for cyber criminals. The router operating system is specially developed and hardened for these applications and offers functions for secure operation in critical infrastructure.

Is INSYS certified for critical infrastructure?

INSYS has received a security certificate for critical infrastructure from the German Federal Office for Information Security for the MRX3-LTE. Further information on the IT security. For all products, regular Penetration tests carried out by an independent body.

Is it possible to operate several VPN tunnels in parallel?

Both OpenVPN and IPsec tunnels to different remote stations can exist in parallel. The networks are completely isolated from each other and can therefore also be used for external participants.

Can I access surveillance cameras remotely?

With a router installed on site and the web proxy function of the icom Connectivity Suite, surveillance cameras can be accessed directly in the browser. This does not require a VPN client on the end device.

How and where are industrial routers installed?

Industrial routers are clicked onto a top-hat rail (DIN rail) in the electrical enclosure or screwed directly to the housing or a bracket.
With mobile routers, the external mobile phone antenna is routed out of the control cabinet and mounted on the outside wall of the building.

Which SIM cards are suitable for the water industry?

Most faults in mobile routers can be traced back to SIM cards. For this reason, we offer licensed multi-roaming industrial SIM cards at favourable conditions. We have the most experience and test coverage with these SIM cards. AAll the advantages at a glance.

Any questions? We will be happy to advise you!

Menu