Protocols About 2 min read

IP transport and segmentation

List the endpoints, transports and connection direction your integration requires. Use that list to define routing, segmentation and firewall rules.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Design baseline, not a site addressing plan, firewall rule set, or performance validation.

Verification and testing

Overview#

Ethernet and IP provide reachability, not application interoperability or trust. IEEE 802.3 defines Ethernet layers; IEEE 802.1Q covers bridges and VLANs. IPv6 is standardised in RFC 8200, TCP in RFC 9293, and UDP in RFC 768.1234

Layer contract#

Layer Record explicitly Common false inference
Ethernet link speed/duplex, VLAN, MTU, PoE, redundancy, multicast treatment same VLAN means trusted
IP v4/v6 addresses, prefix, routes, gateways, fragmentation policy, NAT IP address is device identity
Transport TCP/UDP, local/remote ports, connection direction, keepalive, timeout TCP ACK means application completed
Application protocol edition/profile, framing, correlation, authorisation TLS alone makes commands safe

TCP is a byte stream: parsers must handle partial and coalesced messages, bound lengths, and implement application correlation. UDP preserves datagram boundaries but not delivery, ordering, uniqueness, or path MTU success; application retry and duplicate rules are essential. Neither transport authenticates a peer.

IPv4 and IPv6#

Maintain policy parity. An IPv4 only firewall rule doesn't constrain IPv6, and link local IPv6 may remain active even when no global address was planned. Inventory all addresses, extension header policy, multicast dependencies, neighbour discovery exposure, DNS records, default routes, and management binding. Don't disable IPv6 casually when the product or secure protocol uses it; constrain and monitor it deliberately.

NAT isn't an authorisation control. It can break protocols that advertise embedded addresses, use multicast/broadcast, accept inbound callbacks, or bind security identity to an endpoint name. Prefer routed, policy controlled zones and protocol aware configuration over undocumented address translation.

Segmentation pattern#

Create zones from consequence and administration, not vendor alone: endpoints, controllers/servers, management, monitoring, identity/time, operator clients, and third party/remote service. Define conduits as exact source, destination, direction, protocol, port, initiating role, rate, and maintenance window. Default deny unused east west and management access; log policy changes and denials at a sustainable rate.

VLANs provide logical separation inside a bridge domain but require routed enforcement to become a security boundary. QoS, multicast snooping/queriers, redundancy, and security inspection must preserve alarm latency, media bandwidth, and industrial real time requirements. Validate failover and congestion on an isolated representative design.

Failure and observation#

Instrument link transitions, address/route change, duplicate address, neighbour/ARP churn, connection failure, RTT/loss, retransmission, UDP sequence gaps, MTU/fragmentation failure, multicast membership, firewall deny, and application health separately. A ping response is neither application health nor identity proof.

Validate segmentation, failover, congestion, MTU, multicast, and packet filter behaviour against the authorised target network and recovery plan.

Primary sources#

Section overview · Wiki home

  1. IEEE Standards Association, IEEE 802.3-2022 ↩

  2. RFC Editor, RFC 8200, IPv6 ↩

  3. RFC Editor, RFC 9293, TCP ↩

  4. RFC Editor, RFC 768, UDP ↩