10
Network and IT Guidance Technical Guide
www.eaton.com/lightingsystems
Eaton's view on cybersecurity
Eaton views security as a cornerstone of a safe, dependable and reliable electrical system. Accordingly, the all Eaton connected lighting
systems employ current industry best practices to reduce, identify, contain and manage security risks. These systems have been designed
and engineered with wireless security as a key requirement with flexibility to accommodate improvements if new security attack surfaces
are identified. The Eaton Product Cybersecurity Center of Excellence (PCCoE) provided guidance throughout the development of each system
and offers Eaton customers an Internet accessible portal to identify emerging threats, find ways to secure products against them and help
customers deploy and maintain Eaton product solutions in a secure environment. More information on the Eaton PCCoE can be found at
www.eaton.com/cybersecurity
Network topology options
The LumaWatt Pro network provides the following topology options:
1. Gateways on Separate Secure Network, on premise - IT does not want the system on the corporate LAN
2. Cloud Connected Secure Connections, (multiple sites) - Provides secure access to multiple locations - Provides secure access to
multiple locations
3. Corporate LAN Deployment with L2 VLAN - Lighting network exists on a Layer 2 VLAN - Lighting network exists on a Layer 2 VLAN
4. Corporate LAN Deployment with BMS Connection – Mode 1
5. Corporate LAN Deployment with BMS Connection – Mode 2
6. Enterprise Energy Manager Deployment with BMS Connection
Each topology is explained in detail in the following sections.
Sensor Network PoE Switch
Gateway
HTTPS
- Separate (Isolated from IT) Network
- Web Access only if connected to the
Sensor Network PoE Switch
Ethernet
Ethernet
Ethernet
LumaWatt Pro
Energy Manager
Ethernet
Interface 2
SSL
SSL, SCP
Intelligent
fixtures
Wireless Network Gateway
Gateway
Floor sub-panel
Option 1: Gateways on Separate Secure Network, on premise
Physically Isolated LAN, Secure Shell, SSL
Wireless
- 2.4 Ghz spectrum
- AES-128 bit encryption
- Hardened LINUX
- No “root” access
- Only (HTTPS SSH)
ports open
(120/277VAC mains power)