Bridging the IT to OT Technology Gap Paul Didier, IoE Verticals Solution Architect Matt Tweedie, DP World PSOIOT-2005
Agenda Introduction & Objective IT and OT Natural Partners? IT and OT convergence @ DP World How to start the journey Conclusion
Introduction and Objectives
"If you went to bed last night as an industrial company, you're going to wake up today as a software and analytics company, Jeff Immelt CEO GE The impact of the IoT
The enablement of enterprises to more intelligently and responsively manage industrial operations globally Industrial Intelligence 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
IoT is Driving IT and OT Convergence
IT and OT Not natural partners
The Industrial Network: Conceptual View BDM/TDM CIO IT organization Enterprise Layer LAN/ WAN Plant Information Layer Plant Apps (MES, etc) Enterprise Apps (ERP, CRM, etc) General Plant Access Office to Plant Gateway Internet Customers Suppliers Partners Si Plant LAN, WLAN Vendors Networking IT Integrators Software Plant Mgr Advanced Mfg Controls Engineer Control Layers PAC Device Layer Historian HMI Robots Sensors Drives I/O Automation Software/Hardware Vendors Automation Integrators Original Equipment Manufacturers
IT and OT Differences
IT/OT @ DP World It can happen
What is London Gateway?
Blank Canvass Park land Park 560 acres (227 hectares) Port 435 acres (176 hectares) Port land Railway line
We ve gone from this
To This
Automation Manual Semi Automated ASC Stacks Fully Automated
How to start the Journey The Yellow Brick Road
Manufacturing and IT Convergence Creating Challenges and Opportunities
OT Basics: The Control Cycle Industrial Applications In Control Computations Out 20% 60% 20% Control Frame Input Output Jitter Network Latency Control Phase Delay Synchronization of inputs Sample Jitter Synchronization of outputs Sample Jitter Synchronization of control applications Control Frame Synchronization of network traffic and flows Sample Jitter, Control Frame Network Latency Overall Phase Delay Drives System Controllability/Stability
Not All Traffic Is Created Equal Control (e.g., CIP) Video Data (Best Effort) Voice Bandwidth Low to Moderate Moderate to High Moderate to High Low to Moderate Random Drop Sensitivity Latency Sensitivity High Low High Low High High Low High Jitter Sensitivity High High Low High Control Networks Must Prioritize Control Traffic over Other Traffic Types to Ensure Deterministic Data Flows with Low Latency and Low Jitter
IoT Cloud Challenges Oil Platform Manufacturing Robot Construction Crane Limited Bandwidth Latency Network Reliability
Logical Architecture Built on Industry Standards Enterprise Zone Enterprise Network Level 5 DMZ Manufacturing Zone Cell/Area Zone Site Business Planning and Logistics Network Demilitarized Zone Shared Access Site Manufacturing Operations and Control Area Control Level 4 Level 3 Level 2 Basic Control Level 1 Process Level 0
Common Architectures Wide Area Network (WAN) Physical or Virtualized Servers ERP, Email Active Directory (AD), AAA Radius Call Manager Enterprise External DMZ/ Firewall Internet Enterprise Zone Levels 4 and 5 Physical or Virtualized Servers Patch Management AV Server Application Mirror Remote Desktop Gateway Server Catalyst 2960 Link for Failover Detection Firewall (Active) Firewall (Standby) ASA 5500 Plant Firewalls Inter-zone traffic segmentation ACLs, IPS and IDS VPN Services Portal and Remote Desktop Services proxy Industrial Demilitarized Zone (IDMZ) Physical or Virtualized Servers FactoryTalk Application Servers on UCS Manufacturing Execution, Historian Network Services e.g. DNS, AD, DHCP, AAA Storage Array Site Operations Level 3 5500 Wireless LAN Controller (WLC) Active Standby RADIUS (AAA) Server UCS Remote Access Server Catalyst 6500/4500 Catalyst 3850 StackWise Switch Stack Catalyst 3750X StackWise Switch Stack Cell/Area Zone Levels 0-2 Cell/Area Zone Levels 0-2 Industrial Zone Levels 0-3 Stratix 5400 1Gi Access Links Stratix 5400 Routed Access Switch LWAP Stratix 5400 Routed Access Switch Stratix 5400 Routed Access Switch 1 Gi Access Links AP Camera WGB Phone LWAP SSID 5 GHz WGB LWAP SSID 2.4 GHz Drive Stratix 5400 1 Gi Inter-switch Links EtherChannel w/ REP EtherChannel w / MST Instrumentation HMI Soft Starter Safety Controller Safety I/O SSID 5 GHz WGB Controller Controller Controller I/O Servo Drive HMI Robot Safety I/O Cell/Area Zone - Levels 0-2 Redundant Star Topology - Flex Links Resiliency Unified Wireless LAN Cell/Area Zone - Levels 0-2 Ring Topology - Resilient Ethernet Protocol (REP) Unified Wireless LAN Cell/Area Zone - Levels 0-2 Linear/Bus/Star Topology Autonomous Wireless LAN
Training - Industrial IP Advantage A go-to resource for educational information about industrial network communication and using standard Internet Protocol (IP) for industrial applications Community of like-minded companies Cisco, Panduit, and Rockwell Automation Receive monthly e-newsletters with articles and videos on the latest trends Training Cell/Area Zone part 1: Breaking through the credibility threshold Bringing together IP & Automation vocabulary and objectives Cell/Area Zone part 2: Engineering for Integration Designing building block networks that can be combined into a plant-wide architecture Industrial Zone: Making convergence real in the plant Moving from multiple single purpose networks to a single converged architecture IT/OT Integration: Enabling business transformation Enabling collaboration and the cloud and moving towards Smart Manufacturing Rockwell Automation TechED 2015 @ROKTechED #ROKTechED Copyright 2015 Rockwell Automation, Inc. All rights reserved.
IoT Education Offerings Certifications Job Role Based Certification covering Domains, Tasks, Skills needed to perform Job Duties Cisco Industrial Networking Specialist CCNA Industrial Solutions Training Knowledge and understanding of complete solutions Vertical Specific Connected Health, Connected Safety, Connected Utilities Connected Mining, (future) Product Training Deep knowledge of IoT Products Ruggedized switches, routers, wireless and security products IE2K/3K Switch (Available) ISR 819 (Future) CSS, CGR, Wireless Basic/Skills Training Recommended or Mandatory Pre-Reqs IT for OT (elearning) OT for IT (elearning)
CCNA Industrial Addressing IT and OT Job Roles Career Certification Hands on Instructor Led Training + Exam CCNA Industrial Manufacturing (IMINS2) Specialist/Career Certification Hands on Instructor Led Training + Exam Cisco Industrial Networking Specialist Certification (IMINS) Basic Skills Training Networking Fundamentals Control Systems Fundamentals OT/Plant Engineer Network Engineer
OT Audience IT Audience Paths to get CCNA Industrial CCNA Exam (200-120) CCNA R&S IMINS2 (200-601) ICND1 (100-101) CCENT IMINS2 (200-601) CCNA Industrial IMINS (200-401) Cisco Industrial Networkin g Specialist IMINS2 (200-601)
Summary Words of Caution for IT
IoT Landscape Most Existing Players And Solutions Tend To Be Walled In Their Understanding Of The Smart Systems and IoT Market Little Understanding Of Adjacent Applications, Requirements And Technologies... Their Ability To Migrate Organically To Provide Customers With Broader Capabilities Has Historically Been Inhibited...
The Rise of the Machines Diversified Industrials and OEM s are not standing still They Have a Smart Services End-Game in Mind.
The New Look
Complete Your Online Session Evaluation Give us your feedback to be entered into a Daily Survey Drawing. A daily winner will receive a $750 Amazon gift card. Complete your session surveys though the Cisco Live mobile app or your computer on Cisco Live Connect. Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at CiscoLive.com/Online
Thank you
Internet of Things (IoT) Cisco Education Offerings Course Description Cisco Certification NEW! CCNA Industrial An associate level instructor led training course designed to prepare you for the CCNA Industrial certification CCNA Industrial Managing Industrial Networks with Cisco Networking Technologies (IMINS) Control Systems Fundamentals for Industrial Networking (ICINS) Networking Fundamentals for Industrial Control Systems (INICS) This curriculum addresses foundational skills needed to manage and administer networked industrial control systems. It provides plant administrators, control system engineers and traditional network engineers with an understanding of the networking technologies needed in today's connected plants and enterprises For IT and Network Engineers, covers basic concepts in Industrial Control systems including an introduction to automation industry verticals, automation environment and an overview of industrial control networks For Industrial Engineers and Control System Technicians, covers basic IP and networking concepts, and introductory overview of Automation industry Protocols. Cisco Industrial Networking Specialist For more details, please visit: http://learningnetwork.cisco.com Questions? Visit the Learning@Cisco Booth or contact ask-edu-pm-dcv@cisco.com