1-16
Cisco IE 2000 Switch Software Configuration Guide
OL-25866-01
Chapter 1 Configuration Overview
Network Configuration Examples
Demilitarized Zone
The demilitarized zone (DMZ) provides a buffer for sharing of data and services between the enterpri se
and manufacturing zones. The DMZ maintains availability, addresses security vulnerabilities, and
abiding by regulatory compliance mandates. The DMZ provides segmentation of organizational control,
for example, between the IT and production organizations. Different policies for each organiza tion can
be applied and contained. For example, the production organization might appl y security policies to the
manufacturing zone that are different than those applied to the IT organization.
Manufacturing Zone
The manufacturing zone comprises the cell networks and site-level activities. All the systems, devices,
and controllers that monitor the plant operations are in this zone. The cell zone is a functional area within
a production facility.
The cell zone is a set of devices, controllers, and so on, that provide the real-time control of a functional
aspect of the automation process. They are all in real-time communication with each other. This zone
requires clear isolation and protection from the other levels of plant or enterprise operations.