Free Masterclass: Firewall and Zoning in OT
OT protocols carry no user identity, which makes the firewall rule the authentication. On 23 August we stop drawing zones and start writing rules on a live substation.
OT protocols carry no user identity.
Modbus, S7, IEC 104, DNP3 — nobody has to prove who they are.
So whoever can reach the controller can command it. Your firewall rule is your authentication.
The Session
Sunday 23 August, 20:00 Berlin / 14:00 New York. Free.
We build the boundary on Electroshock, the 6 kV substation running inside Labshock — two RTUs, six feeders, two incomers, a sectioned bus, and SCADA above them.
What We Do
- Split the estate into three zones
- Build a default-deny rule table
- Open exactly one path
- Test the denies from both sides
- Read the log and prove the deny actually fired
The last step is the one that turns the exercise into evidence.
A rule you did not test is not a rule. It is an intention.
Why This Is Not A Diagram Exercise
IEC 62443 gives you zones and conduits. Purdue gives you levels.
Neither one tells you whether traffic actually stops at the boundary. Only a test tells you that, and the test has two halves — the path you opened works, and the paths you did not open fail, observably, in a log you can point at.
Six weeks ago we wrote about where the firewall sits in OT — level 1, level 2, or a DMZ between. That post is at labshocksecurity.com/news/ot-firewall-placement-dmz
This session stops drawing it and starts writing rules.
Everything we build lives in Firegate, the substation zone we launched in July: labshocksecurity.com/news/firegate-substation-lab-dnp3-iec104
OT security must be testable.
Not documented.
Try It Yourself
- Join the session and ask questions live: discord.gg/bpmaQFfW76
- Start free first so you can follow along in your own copy: github.com/zakharb/labshock
- Bring one rule from your own estate that you have never tested from both sides. That is the one worth rebuilding here.
- Everything built in the session stays in Firegate at labshocksecurity.com
More on event
