Skip to content

Commit 94b2c0a

Browse files
authored
Merge pull request #264124 from tarTech23/otProtocols
Ot new protocols
2 parents 19cf8b5 + 72d8ae8 commit 94b2c0a

File tree

3 files changed

+25
-9
lines changed

3 files changed

+25
-9
lines changed

articles/defender-for-iot/organizations/concept-supported-protocols.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,13 +16,16 @@ OT network sensors can detect the following protocols when identifying assets an
1616

1717
|Brand / Vendor |Protocols |
1818
|---------|---------|
19-
|**ABB** | ABB 800xA DCS (IEC61850 MMS including ABB extension)<br> CNCP<br> RNRP<br> ABB IAC<br> ABB Totalflow |
19+
|**ABB** | ABB 800xA DCS (IEC61850 MMS including ABB extension)<br> CNCP<br> RNRP<br> ABB IAC<br> ABB Totalflow <br> ABB NetConfig |
2020
|**ASHRAE** | BACnet<br> BACnet BACapp<br> BACnet BVLC |
2121
|**Beckhoff** | AMS (ADS)<br> Twincat |
2222
|**Cisco** | CAPWAP Control<br> CAPWAP Data<br> CDP<br> LWAPP |
23+
|**DICOM** | Dicom |
2324
|**DNP. org** | DNP3 |
2425
|**Emerson** | DeltaV<br> DeltaV - Discovery<br> Emerson OpenBSI/BSAP<br> Ovation DCS ADMD<br>Ovation DCS DPUSTAT<br> Ovation DCS SSRPC |
2526
|**Emerson Fischer** | ROC |
27+
|**FANUC** | FANUC FOCUS |
28+
|**FieldComm Group**| HART-IP |
2629
|**GE** | ADL (MarkVIe) <br>Bentley Nevada (System 1 / BN3500)<br>ClassicSDI (MarkVle) <br> EGD<br> GSM (GE MarkVI and MarkVIe)<br> InterSite<br> SDI (MarkVle) <br> SRTP (GE)<br> GE_CMP |
2730
|**Generic Applications** | Active Directory<br> RDP<br> Teamviewer<br> VNC<br> |
2831
|**Honeywell** | ENAP<br> Experion DCS CDA<br> Experion DCS FDA<br> Honeywell EUCN <br> Honeywell Discovery |
@@ -36,9 +39,9 @@ OT network sensors can detect the following protocols when identifying assets an
3639
|**Omron** | FINS <br>HTTP |
3740
|**OPC** | AE <br>Common <br> DA <br>HDA <br> UA |
3841
|**Oracle** | TDS<br> TNS |
39-
|**Rockwell Automation** | CSP2<br> ENIP<br> EtherNet/IP CIP (including Rockwell extension)<br> EtherNet/IP CIP FW version 27 and above |
42+
|**Rockwell Automation** | CSP2<br> ENIP<br> EtherNet/IP CIP (including Rockwell extension)<br> EtherNet/IP CIP FW version 27 and above <br>Rockwell AADvance Discover <br> Rockwell AADvance SNCP/IXL |
4043
|**Samsung** | Samsung TV |
41-
|**Schneider Electric** | Modbus/TCP<br> Modbus TCP–Schneider Unity Extensions<br> OASYS (Schneider Electric Telvant)<br> Schneider TSAA |
44+
|**Schneider Electric** | Modbus/TCP<br> Modbus TCP–Schneider Unity Extensions<br> OASYS (Schneider Electric Telvant)<br> Schneider TSAA <br> Schneider NetManage |
4245
|**Schneider Electric / Invensys** | Foxboro Evo<br> Foxboro I/A<br> Trident<br> TriGP<br> TriStation |
4346
|**Schneider Electric / Modicon** | Modbus RTU |
4447
|**Schneider Electric / Wonderware** | Wonderware Suitelink |

articles/defender-for-iot/organizations/release-notes.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,9 +112,10 @@ To understand whether a feature is supported in your sensor version, check the r
112112
This version includes the following updates and enhancements:
113113

114114
- [Alert suppression rules from the Azure portal](how-to-accelerate-alert-incident-response.md#suppress-irrelevant-alerts)
115-
- [Focused alerts in OT/IT environments](alerts.md#focused-alerts-in-otit-environments)
115+
- [Focused alerts in OT/IT environments](alerts.md#focused-alerts-in-otit-environments)
116116
- [Alert ID (Id field) is now aligned on the Azure portal and sensor console](how-to-manage-cloud-alerts.md#view-alerts-on-the-azure-portal)
117117
- [New setting to focus local networks in the device inventory](configure-sensor-settings-portal.md#configure-subnets-in-the-azure-portal)
118+
- [Newly supported protocols](concept-supported-protocols.md)
118119

119120
## Versions 23.2.x
120121

articles/defender-for-iot/organizations/whats-new.md

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Features released earlier than nine months ago are described in the [What's new
2020

2121
|Service area |Updates |
2222
|---------|---------|
23-
| **OT networks** | - [Alert suppression rules from the Azure portal (Public preview)](#alert-suppression-rules-from-the-azure-portal-public-preview)<br>- [Focused alerts in OT/IT environments](#focused-alerts-in-otit-environments)<br>- [Alert ID now aligned on the Azure portal and sensor console](#alert-id-now-aligned-on-the-azure-portal-and-sensor-console)<br>- [New setting to focus local networks in the device inventory](#new-setting-to-focus-local-networks-in-the-device-inventory) |
23+
| **OT networks** | - [Alert suppression rules from the Azure portal (Public preview)](#alert-suppression-rules-from-the-azure-portal-public-preview)<br>- [Focused alerts in OT/IT environments](#focused-alerts-in-otit-environments)<br>- [Alert ID now aligned on the Azure portal and sensor console](#alert-id-now-aligned-on-the-azure-portal-and-sensor-console)<br>- [New setting to focus local networks in the device inventory](#new-setting-to-focus-local-networks-in-the-device-inventory)<br>- [Newly supported protocols](#newly-supported-protocols)|
2424

2525
### Alert suppression rules from the Azure portal (Public preview)
2626

@@ -54,6 +54,20 @@ To better focus the Azure device inventory on devices that are in your OT scope,
5454

5555
:::image type="content" source="media/whats-new/ics-toggle.png" alt-text="Screenshot of the ICS Subnet toggle in the Azure portal Sensor settings." border="true":::
5656

57+
### Newly supported protocols
58+
59+
We now support these protocols:
60+
61+
- HART-IP
62+
- FANUC FOCAS
63+
- Dicom
64+
- ABB NetConfig
65+
- Rockwell AADvance Discover
66+
- Rockwell AADvance SNCP/IXL
67+
- Schneider NetManage
68+
69+
[See the updated protocol list](concept-supported-protocols.md).
70+
5771
## January 2024
5872

5973
|Service area |Updates |
@@ -83,7 +97,7 @@ Sensor versions 23.2.0 run on a Debian 11 operating system instead of Ubuntu. De
8397

8498
Using Debian as the base for our sensor software helps reduce the number of packages installed on the sensors, increasing efficiency and security of your systems.
8599

86-
Due to the operating system switch, the software update from your legacy version to version 23.2.0 may be longer and heavier than usual.
100+
Due to the operating system switch, the software update from your legacy version to version 23.2.0 might be longer and heavier than usual.
87101

88102
For more information, see [Back up and restore OT network sensors from the sensor console](back-up-restore-sensor.md) and [Update Defender for IoT OT monitoring software](update-ot-software.md).
89103

@@ -106,7 +120,6 @@ For example, use the privileged *admin* user in the following scenarios:
106120
107121
For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md).
108122

109-
110123
### New architecture for hybrid and air-gapped support
111124

112125
Hybrid and air-gapped networks are common in many industries, such as government, financial services, or industrial manufacturing. Air-gapped networks are physically separated from other, unsecured external networks like enterprise networks or the internet, and are less vulnerable to cyber-attacks. However, air-gapped networks are still not completely secure, can still be breached, and must be secured and monitored carefully.
@@ -140,7 +153,7 @@ For more information, see:
140153

141154
### Live statuses for cloud-based sensor updates
142155

143-
When running a sensor update from the Azure portal, a new progress bar appears in the **Sensor version** column during the update process. As the update progresses the bar shows the percentage of the update completed, showing you that the process is ongoing, is not stuck or has failed. For example:
156+
When running a sensor update from the Azure portal, a new progress bar appears in the **Sensor version** column during the update process. As the update progresses the bar shows the percentage of the update completed, showing you that the process is ongoing, isn't stuck or has failed. For example:
144157

145158
:::image type="content" source="media/whats-new/sensor-version-update-bar.png" alt-text="Screenshot of the update bar in the Sensor version column." lightbox="media/whats-new/sensor-version-update-bar.png":::
146159

@@ -216,7 +229,6 @@ From your sensor, do one of the following to open the **Cloud connectivity troub
216229
- On the **Overview** page, select the **Troubleshoot** link at the top of the page
217230
- Select **System settings > Sensor management > Health and troubleshooting > Cloud connectivity troubleshooting**
218231

219-
220232
For more information, see [Check sensor - cloud connectivity issues](how-to-troubleshoot-sensor.md#check-sensor---cloud-connectivity-issues).
221233

222234
### Event timeline access for OT sensor Read Only users

0 commit comments

Comments
 (0)