What problem does it solve?
Flat OT networks without segmentation allow threats to move freely between enterprise IT and industrial control systems. This Skill designs a Purdue Model-based segmentation architecture from real traffic baselines, generates firewall rules and VLAN configurations, and validates that zone isolation works without disrupting operations.
Core Features & Use Cases
- Segmentation Design from Traffic Baselines: Parses passive monitoring baseline JSON to generate VLAN assignments per Purdue level, firewall allow rules from observed flows, DPI profiles for Modbus/EtherNet-IP/OPC UA/S7/DNP3, and a four-phase migration plan with rollback steps.
- Industrial Switch Hardening: Provides Cisco IE switch configuration for VLANs, port security with MAC binding, storm control, trunk setup, and unused-port quarantine.
- Post-Deployment Validation: Runs TCP connectivity tests to confirm enterprise-to-PLC traffic is blocked, operations read polls succeed, and SIS is unreachable from the BPCS.
- Use Case: After an IEC 62443-3-2 risk assessment reveals a flat network, use this Skill to produce a zone/conduit design, configure OT-aware firewalls in monitor-then-enforce mode, and verify segmentation during a maintenance window.
Quick Start
Use this skill to design a Purdue Model segmentation plan from my traffic baseline file baseline.json and generate the VLAN, firewall rule, and validation test outputs.