Deep Dive: Protocol Intelligence
Looking for detailed risk analysis and hardening guides for NMEA, Modbus, and AIS?
Execution: To enforce Conduits (Step 03), you must map the “Language” of the assets to technical ports. This module provides the configuration data needed for firewall Access Control Lists (ACLs) as required by UR E26 §4.2.
1. Port & Service Mapping for Firewalls
2. Intelligence: Gateway Logic
Bridging the Serial Gap
Most maritime assets use serial RS-422/485. When using Serial-to-IP Gateways, they become network-visible. Ensure your Conduit (Firewall) only allows the specific IP and Port of the gateway.
ALLOW TCP [Bridge_Workstation] [NMEA_Gateway_IP] PORT 10110
Safe Scanning Checklist (OT-Grade)
Standard IT scanning tools can cause denial-of-service (DoS) conditions on legacy shipboard hardware. Follow these rules to avoid crashing systems:
Legacy engine controllers may lock up if they receive ICMP Echo requests while processing logic.
Serial-to-IP gateways have limited buffers. Rapid scanning will overwhelm them.
Never scan 65k ports. Only scan for the specific OT services identified in Section 1.
3. Maritime Discovery Commands
Use these specific Nmap strings to verify protocol presence across your Conduits.
Next Section
OT Traffic Baselining Procedures
OT Traffic Baselining Procedures Objective: Capture the "Normal" state of communication to create a blueprint for Firewa...
