background image

10

 

 

Network and IT Guidance Technical Guide

www.eaton.com/lightingsystems

Eaton's view on cybersecurity

Eaton views security as a cornerstone of a safe, dependable and reliable electrical system. Accordingly, the all Eaton connected lighting 

systems employ current industry best practices to reduce, identify, contain and manage security risks. These systems have been designed 

and engineered with wireless security as a key requirement with flexibility to accommodate improvements if new security attack surfaces 

are identified. The Eaton Product Cybersecurity Center of Excellence (PCCoE) provided guidance throughout the development of each system 

and offers Eaton customers an Internet accessible portal to identify emerging threats, find ways to secure products against them and help 

customers deploy and maintain Eaton product solutions in a secure environment. More information on the Eaton PCCoE can be found at 

www.eaton.com/cybersecurity

Network topology options

The LumaWatt Pro network provides the following topology options:

1. Gateways on Separate Secure Network, on premise - IT does not want the system on the corporate LAN

2. Cloud Connected Secure Connections, (multiple sites) - Provides secure access to multiple locations -  Provides secure access to  

    multiple locations

3. Corporate LAN Deployment with L2 VLAN - Lighting network exists on a Layer 2 VLAN - Lighting network exists on a Layer 2 VLAN

4. Corporate LAN Deployment with BMS Connection – Mode 1

5. Corporate LAN Deployment with BMS Connection – Mode 2

6. Enterprise Energy Manager Deployment with BMS Connection

Each topology is explained in detail in the following sections.

Sensor Network PoE Switch

Gateway

HTTPS

- Separate (Isolated from IT) Network
- Web Access only if connected to the 
   Sensor Network PoE Switch

Ethernet

Ethernet

Ethernet

LumaWatt Pro 
Energy Manager

Ethernet
Interface 2

SSL

SSL, SCP

Intelligent 
fixtures

Wireless Network Gateway

Gateway

Floor sub-panel

Option 1: Gateways on Separate Secure Network, on premise

Physically Isolated LAN, Secure Shell, SSL

Wireless
- 2.4 Ghz spectrum
- AES-128 bit encryption 

- Hardened LINUX
- No “root” access
- Only (HTTPS SSH) 
   ports open

(120/277VAC mains power)

Summary of Contents for LumaWatt Pro

Page 1: ...rtant Engage appropriate network security professionals to ensure all lighting control system hardware and servers are secure for access Network security is an important issue Typically the IT organiz...

Page 2: ...7 Potential causes for signal disruption 7 Administration and Maintenance 7 Configuration and Management tools 7 Internal web pages 7 Certificates 8 User management roles and access 8 Backup and Resto...

Page 3: ...gh the LumaWatt Pro Gateway using the IEEE 802 15 4 wireless communication protocol that includes AES encryption to ensure secure links The LumaWatt Pro Energy Manager is typically mounted in a wiring...

Page 4: ...Energy Manager System Overview The LumaWatt Pro Wireless Network is based on the IEEE 802 15 4 standard and operates in the 2 4 GHz ISM spectrum The chief concern with deploying IEEE 802 15 4 network...

Page 5: ...2 TCP 52725 Energy Manager SSL secured CAPI web services Always Open Network LAN and WAN LumaWatt Pro was designed so only Gateways and Energy Manager devices with the interface directly with the LAN...

Page 6: ...ices communicating on the same channel can cause interference the devices need to be set on channels that do not overlap If we overlay the most frequently used channels used by IEEE 802 15 4 LumaWatt...

Page 7: ...ignals can have trouble communicating through these solid objects reducing the wireless range b Transmitter and end device placement planning during the design phase is critical to ensure proper cover...

Page 8: ...stomer s network system administrator and any required 4G modem installation VPN access port opening and or credentials are revoked upon completion of the required support service Special service prog...

Page 9: ...etwork can communicate with sensors on the LumaWatt Pro Wireless network In addition to isolation from IT networks the LumaWatt Pro Wireless Network provides security against tampering through the wir...

Page 10: ...Watt Pro network provides the following topology options 1 Gateways on Separate Secure Network on premise IT does not want the system on the corporate LAN 2 Cloud Connected Secure Connections multiple...

Page 11: ...ed Secure Connections Multiple Sites LumaWatt Pro sensor 4G Gateway CR DSL Internet SSL Ethernet Interface 1 120 277VAC mains power Gateway Option 1 Energy Manager Acts as DHCP server and services add...

Page 12: ...1 LumaWatt Pro Energy Manager Lighting L2 VLAN Corporate LAN BMS Network Gateway Ethernet Interface 2 Gateway Option 5 Corporate LAN Deployment with BMS Connection Mode 2 Ethernet Interface 1 LumaWat...

Page 13: ...ctive owners Gateway Ethernet Interface 2 Gateway Option 6 Enterprise Energy Manager Development with BMS Connection Ethernet Interface 3 Lighting L2 VLAN Corporate LAN BMS Network Building 1 BACNET I...

Reviews: