Futureproof Your Industrial Network Security

With over 35 years of expertise in industrial automation, Moxa is proud to be one of the first companies globally to achieve both IEC 62443-4-1 certification for our secure development life-cycle (SDL) and IEC 62443-4-2 certification for a range of our networking products. These prestigious certifications underscore our commitment to delivering the highest level of security and reliability. We recognize your need for improved network uptime and reduced security risks. Trust our secure networking solutions—switches, routers, firewalls, and network management software—to help you build a resilient and secure industrial network while minimizing disruption to your operations.

At the Core of Our Secure Networking Solutions

Our secure networking solutions are designed to protect industrial devices and networks, embodying Moxa’s commitment to manufacture secure network devices. It equips industrial networks with security features that elevate authentication, authorization, and accounting (AAA), and diminish potential threats. Three foundational principles underpin our solutions' strategy for helping customers build secure industrial networks.



How Moxa Delivers Secure Devices

Built on a Foundation of Trust


Our commitment to supplying reliable industrial network solutions spans over three decades. We understand that the rise in cyberattacks poses a significant threat to operational efficiency and reliability. Therefore, we implement a secure development life-cycle (SDL) process to build a secure foundation for our network devices. Additionally, our network devices come with secure default factory settings, strengthening system integrity and shrinking the attack surface.


Our Security Commitment
  • Implement our SDL and vulnerability management processes to secure our devices throughout their life cycle.
  • Enhance system integrity to reduce security incidents when deploying and updating firmware.
  • Maximize security and limit attack surfaces using a secure-by-design approach, such as only enabling HTTPS.

How Moxa’s Solutions Enhance Authentication, Authorization, and Accounting

Empowering Users With Greater Control and Visibility


During daily operations, your network devices can be accessed by users in different roles. Without an efficient and secure approach to control access and monitor event logs, it is a challenge to ensure device security and respond swiftly to abnormal activities. With our secure networking solutions, access and actions are limited to authorized users. This access and activity can also be monitored and traced for periodic audits and swift incident responses.


Our Security Commitment
  • Allow controlled user access and limit their activities to a permitted scope.
  • Record security-related events for audits and support quick responses to incidents.

How Moxa’s Solutions Reduce Potential Threats for OT Networks

Strengthening Network Resilience With Enhanced Security and Availability


Growing cybersecurity risks and stricter industry regulations are increasing the need for businesses to strengthen network resilience. Our secure networking solutions provide robust network security features, starting with building a secure communication protocol and including diverse data flow restriction methods to meet various network protection needs. In the event of potential threats, our fail-safe mechanisms facilitate quick network recovery, maximizing your network operations.


Our Security Commitment
  • Establish secure communications protecting credentials and configurations over the network.
  • Restrict data flow with multiple mechanisms, including port-based access control, built-in firewalls and ACLs, and network segmentation such as VLAN, NAT, and routing functions.
  • Maximize network operations with fail-safe mechanisms such as redundancy support.

Discover the Right Secure Networking Solutions for Your Industrial Networks

Moxa combines industrial networking and cybersecurity expertise to provide layered protection for your industrial networks. Explore how these solutions work.

Moxa’s Secure Networking Solutions

Secure Routers, Firewalls, and NATs
Secure Managed Switches

Do Your Switches Provide Sufficient OT Security?

For an effective defense-in-depth strategy, OT operators need security controls at the switching layer. Using switches without management and security capabilities leaves the network edge exposed to poor visibility, unauthorized access, and lateral threat movement.

Our secure managed industrial switches help strengthen OT cybersecurity by providing network visibility, device access control, device monitoring, and resilient network performance. The following questions explain why managed switches are a foundational part of any secure and reliable industrial network.

Why are managed switches the critical first step for enhancing OT cybersecurity?

You can’t protect your devices if you don’t have visibility of their status. Managed switches are often the first step in improving OT cybersecurity because they provide the device-level visibility and control needed to manage industrial networks securely.

Our secure managed switches help operators see network status, identify connected devices, monitor port traffic, and apply built-in security features. This gives OT teams better awareness of their environment, creates the foundation for stronger device access control, and provides more information for incident response.

If a plant already uses industrial firewalls, why are security features on managed switches still necessary?

Industrial firewalls and secure managed switches serve different but complementary roles in an OT security architecture. Firewalls protect boundaries between zones, while managed switches enforce device access control within the network itself. Switches with VLAN and Access Control List (ACL) support let administrators limit access to only the systems, users, and traffic flows required for specific roles or operations. This prevents unauthorized access and helps restrict lateral threat movement across the plant network.

How do secure managed switches help prevent network downtime and ensure continuous production?

By combining high bandwidth up to 10GbE and advanced redundancy mechanisms for millisecond-level network recovery, our secure managed switches minimize disruptions and help maximize operational uptime. These capabilities help reduce communication interruptions, maintain stable connections between controllers and devices, and support high availability for critical industrial applications.

How can small OT teams efficiently monitor and troubleshoot hundreds of managed switches?

Centralized network management software gives small OT teams a clear view of the entire industrial network without requiring manual inspection of each switch. Moxa’s MXview One automatically discovers managed switches and generates a real-time visual topology map. It also supports at-a-glance network health monitoring, centralized configuration backup, and event log review. These functions help teams detect issues faster, troubleshoot root causes more efficiently, and maintain reliable network operations at scale.

Secure Managed Switches
Ports
Security Features
Redundancy Protocols
Compatible Management Software
Industrial Certifications
MDS-G4000 Family
MDS-G4000
RKS-G4028-PL
RKS-G4028
RKS-G4028
RKS-G4028
EDS-4000/G4000
EDS-G4000
EDS-500E Family
EDS-500E
Up to 4 10GbE + 24 GbE Up to 12 10GbE + 16 GbE Up to 28 GbE Up to 6 2.5GbE + 8 GbE Up to 4 GbE + 24 FE
VLAN, HTTPS, SSL/SSH, ACL, IEEE 802.1X, Port Security, DHCP Snooping, Secure Boot1 VLAN, HTTPS, SSL/SSH, ACL, IEEE 802.1X, Port Security, DHCP Snooping, Secure Boot VLAN, HTTPS, SSL/SSH, ACL2, IEEE 802.1X
Turbo Ring, Turbo Chain, RSTP/STP, MRP, VRRP (L3 Model) Turbo Ring, Turbo Chain, RSTP/STP, MRP
MXview One
IEC 61850-3, IEEE 1613, EN 50121-4, NEMA TS2, ATEX3, CID23 IEC 62443-4-2 SL2, IEC 61850-3, IEEE 1613, EN 50121-4, NEMA TS2 IEC 62443-4-2 SL2, IEC 61850-3, IEEE 1613 (Class 1), DNV4, ABS4, NK4, LR4, EN 50121-4, NEMA TS2, ATEX5, CID25, IECEx5 IEC 61850-3, IEEE 1613, DNV6, ABS6, NK6, LR6, EN 50121-46, NEMA TS26, ATEX6, CID26
  • 1. Only available for -4XGS models.
  • 2. Only available for 18 and 28 port models.
  • 3. Only available for the non-4XGS models.
  • 4. Only available for -LV and PoE models.
  • 5. Only available for -LV models.
  • 6. Only available for 10 and 18 port models.

How Do You Choose the Right Boundary Protection for Your OT Network?

Securing the boundary of an OT network poses many challenges, from overlapping IP addressing to protecting unpatchable legacy systems. When implementing security measures to address these issues, the ideal solution improves cybersecurity without disrupting control loops, changing machine configurations, or introducing new operational risks.

Our secure routers, industrial firewalls, and NAT devices are designed to meet OT security requirements. They help manufacturers resolve IP conflicts, segment industrial networks, protect legacy assets, and maintain reliable operations at the network edge. The following questions highlight key use cases to help you select the right industrial security appliance.

How can we integrate identical OEM machines into the plant network without rewriting PLC code?

Use devices that support Network Address Translation (NAT). Our secure routers and dedicated NAT devices allow multiple OEM machines with the same internal IP address to be connected to the same plant network without changing PLC logic or modifying the original machine configuration. With 1:1 NAT, each machine’s internal IP address is mapped to a unique external plant-network address. This speeds up the deployment of identical machines and hides internal addresses from external exposure.

How do industrial firewalls protect unpatchable legacy systems without changing existing IP subnets?

Industrial firewalls that support Layer 2 Transparent Bridge mode, such as our EDF-G1002-BP Series, can be inserted directly in front of a vulnerable legacy device without changing the existing IP subnet, routing design, or overall network topology. Using deep packet inspection (DPI) and virtual patching, these firewalls establish a transparent security perimeter that protects legacy systems from malicious traffic.

How can we prevent an industrial firewall from becoming a single point of failure that halts production?

Choose an industrial firewall with hardware-level bypass technology. Our EDF-G1002-BP and EDR-G9004 Series include Gen3 LAN Bypass, which helps maintain network communications if the device loses power or experiences a system failure.

In such an event, internal relays automatically bridge the connection so critical traffic can continue to pass between PLCs, remote I/O, and other control devices.

Will our OT network stop forwarding traffic if a security subscription expires?

No. Moxa’s OT-focused security solutions are designed to ensure that essential functions such as routing and stateful firewall filtering continue operating even if an advanced security subscription expires.

If an IPS subscription lapses, the firewall will stop receiving new intrusion prevention signature updates but will continue running with the last downloaded signature database. Core traffic forwarding functions remain active to help prevent unexpected production impact and maintain baseline protection.

  • Secure Routers and Firewalls
  • NATs
Secure Routers and Firewalls
Ports
NAT
Firewalls
IPS/IDS
DPI
VPN
Routing Throughput (based on RFC 2544)
Redundancy Protocols
Compatible Management Software
Industrial Certifications
EDF-G1002-BP
EDF-G1002-BP
EDR-G9010
EDR-G9010
EDR-G9004
EDR-G9004
EDR-8010
EDR-8010
2 GbE (Gen3 LAN Bypass) 2 2.5GbE + 8 GbE1 Up to 2 2.5GbE + 2 GbE (1/2 DMZ/WAN ports) 2 GbE + 8 FE1
- 1-to-1, N-to-1, NAT loopback, Port forwarding
DDoS, Ethernet protocols, ICMP, IP address, MAC address, Ports
Enabled by default. IPS pattern update functionality requires an additional license. Requires an additional license
DNP3, EtherNet/IP, IEC 60870-5-104, IEC 61850 MMS, Modbus TCP, Modbus UDP, Omron FINS,Siemens S7 Comm., Siemens S7 Comm. Plus, OPC UA, MELSEC communication protocol
- Up to 250 IPsec VPN tunnels Up to 50 IPsec VPN tunnels
- Max. 350K packets per second / 2 Gbps Max. 50K packets per second / 500 Mbps
- VRRP, Turbo Ring, Turbo Chain, RSTP/STP VRRP VRRP, Turbo Ring, Turbo Chain, RSTP/STP
MXview One, MXview Security3, MXsecurity
NEMA TS2, EN 50121-4, CID2, ATEX, IECEx, DNV IEC 62443-4-2 SL2, IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX2, CID22, EN 50121-42, NEMA TS22, DNV2, DNV IEC 61162-460 Edition 3.02, DNV security profile 22, IACS UR E27 Rev.12, IEC 609452 IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX, CID2, IECEx, EN 50121-4, NEMA TS2, DNV IEEE 1613, IEC 61850-3 Ed. 2.0, ATEX, CID2, IECEx, EN 50121-4, NEMA TS2, DNV, DNV IEC 61162-460 Edition 3.0, DNV security profile 2, IACS UR E27 Rev.1, IEC 60945
  • 1. Supports user-configurable DMZ/WAN ports.
  • 2. Only available for -LV models.
  • 3. An active MXview One license is required in order to activate the MXview Security add-on license.
NATs
Ports
NAT
Firewalls
Routing Throughput (based on RFC 2544)
Compatible Management Software
Industrial Certifications
NAT-G102
NAT-G102
NAT-102
NAT-102
NAT-108
NAT-108
2 GbE 2 FE 8 FE
1-to-1, N-to-1, NAT loopback, Port forwarding, IP Twins Mapping1
IP address, MAC address (Device Lockdown), Ports
Max. 80K packets per second /1000 Mbps Max. 15K packets per second /100 Mbps
MXview One
- EN 50121-4, NEMA TS2, ATEX, CID2 -
  • 1. NAT-108 Series only.

Make Secure Network Infrastructure Easier to Deploy and Maintain

You can easily manage and maintain our secure routers, firewalls, and managed switches using one platform. Our MXview One Series simplifies device security management, allowing you to easily adjust security levels and receive alerts when abnormal activity occurs. Additionally, our software includes a network security add-on that enables centralized firewall policy management and provides a dashboard for at-a-glance network security monitoring.