Understand industrial networks, topologies, Industrial Ethernet, switches, protocols, SCADA integration, security, redundancy and commissioning.
Check it out!
Industrial networks are communication infrastructures designed to interconnect sensors, instruments, controllers, IEDs, machines, switches, gateways, servers and supervisory systems in automation environments. Unlike a conventional corporate network, they must support operational functions with defined requirements for availability, latency, determinism, synchronization, diagnostics, security and continuity.
An industrial network is not characterized only by the use of rugged equipment or by operating inside a factory. What differentiates it is the direct relationship between communications and the physical process. Packet loss, a delayed message, a failed link or a configuration change can affect control, protection, production, functional safety or supervision.
In practice, the design must combine the physical layer, topology, industrial switches, protocols, segmentation, SCADA integration, synchronization, monitoring and cybersecurity. Technology choices should start from the operational function, not from a manufacturer preference or a generic feature list.
What are industrial networks?
Industrial networks are communication systems used in automation, control, supervision and data acquisition. They connect field devices to control, operations and management levels, transporting measurements, commands, states, alarms, events, parameters and diagnostic information.
The term covers serial networks, fieldbuses, Industrial Ethernet, optical networks, industrial wireless systems and hybrid architectures. An installation may use RS-485 at field level, Ethernet in the backbone, OPC UA for application integration and specific protocols for telecontrol or electrical automation.
The objective is not to transport the largest possible volume of data. The network must deliver the right information, within the required time, with known quality and predictable behavior during failures. A high-throughput architecture may be inadequate if it lacks segmentation, redundancy, diagnostics or change control.
Industrial network vs. corporate network: what are the differences?
Corporate networks prioritize services such as web access, collaboration, files, business applications and user access. In industrial networks, traffic is associated with machines, processes and assets with long life cycles.
Availability has a different meaning. A few minutes of interruption in an administrative service may be tolerable; the same interruption in a control network may stop a line, prevent supervision or compromise an operational function. Maintenance and upgrades therefore need to consider maintenance windows, redundancy, validation and rollback capability.
Life cycles also differ. Controllers, relays and supervisory systems may remain in operation for many years. The network must coexist with legacy equipment, older firmware and protocols with limited security features.
This does not mean IT practices should be rejected. Addressing, routing, identity, logs, configuration management and observability are essential. Their application, however, must respect operational constraints, as discussed in the guide to IEC 62443 applied to substations and OT environments.
Layered architecture
An industrial network can be understood in functional layers. The model does not need to be identical in every installation, but it helps separate responsibilities and flows.
The field layer includes sensors, actuators, instruments, drives, meters and auxiliary devices. The control layer includes PLCs, controllers, RTUs and IEDs. The supervisory layer contains HMIs, SCADA servers, historians and engineering workstations. Above it there may be maintenance, analytics, MES, asset-management and corporate-integration applications.
Vertical communication occurs between these levels. Horizontal communication occurs between cells, controllers, machines or subsystems at the same level. Both need to be made explicit in diagrams and flow matrices.
The architecture must identify concentration points. A gateway, central switch, server or firewall can become a common point of failure. Duplicated equipment does not guarantee independence when both units share the same power supply, cabinet, fiber route or configuration.
Requirements that define the design
The design begins with functional and performance requirements. For every flow, the engineer must know the source, destination, protocol, direction, frequency, message size, criticality, maximum latency, loss tolerance and behavior during failures.
Availability must be treated as a measurable requirement. Stating “high availability” is not enough. The design must define recovery time, covered failures, auxiliary-system autonomy, degraded-operation capability and restoration criteria.
Determinism is the ability to maintain predictable temporal behavior. It is not synonymous with speed. A network can have high bandwidth and still present jitter that is unacceptable for a particular control function.
Scalability also needs to be planned. Spare ports, addresses, fibers, uplink capacity, processing capacity and licenses should consider foreseeable expansions. Uncontrolled growth can turn a segmented architecture into a flat network that is difficult to troubleshoot.
Modernizing an industrial network starts by understanding the real condition of the environment.
An inventory of assets, protocols, versions, dependencies, physical paths, recurring failures and process constraints creates the baseline needed to decide what to retain, upgrade or replace.
Latency, jitter, loss and cycle time
Latency is the time between sending and receiving information; jitter is the variation in that time; loss represents messages that do not reach their destination or are discarded. In industrial networks, the impact of each parameter depends on the operational function. Reporting data may tolerate seconds, while motion control, protection or interlocks may require much tighter temporal behavior.
Cycle time does not depend only on the nominal link speed. It includes acquisition, controller processing, transmission, queues, gateways, firewalls, servers and device response. Measuring only the delay through one switch therefore does not prove end-to-end performance.
Tests should reproduce load and contingency conditions. A network that works under nominal conditions may degrade during reconvergence, an event storm, server recovery, backups or file transfers. Acceptance criteria should record expected values, measurement methods and test conditions.
Industrial network topologies
Physical topology describes how links are arranged; logical topology describes how traffic moves through the network. Bus, star, ring, line and tree topologies remain common in industrial environments, but each creates different failure domains and maintenance requirements.
Buses are common in serial networks and fieldbuses and require attention to termination, stubs and length. Stars simplify isolation and troubleshooting but concentrate criticality in the central element. Rings provide an alternate path only when an appropriate redundancy mechanism is configured; physically closing an Ethernet ring without loop control can take the entire cell offline.
The choice should consider not only availability, but also expansion, panel locations, maintenance access, independent physical routes and behavior when an intermediate node fails.
Industrial Ethernet
Industrial Ethernet uses technologies from the IEEE 802.3 family in automation and control, combined with equipment, protocols and mechanisms suited to operational constraints. It is not a single protocol and does not automatically turn a corporate network into an OT network.
The Ethernet foundation supports VLANs, QoS, multicast, SNMP, synchronization and IP integration, but protocols such as PROFINET, EtherNet/IP, Modbus TCP and IEC 61850 use distinct communication models. Some use TCP or UDP; others use Ethernet frames directly and employ their own real-time mechanisms.
The design must size cyclic and acyclic traffic, alarms, engineering traffic, synchronization and maintenance. Video, backups, discovery traffic and corporate access should not compete with critical functions without predefined segmentation, capacity and prioritization.
How to choose an industrial switch
An industrial switch should be selected according to the environment, traffic and function it will perform. Port count and rated temperature are only part of the specification. Vibration, humidity, EMC, power, mounting, connectors, enclosure rating and immunity requirements may be decisive.
Switching capacity, forwarding rate, table size, buffers, queues, multicast and uplinks must be compatible with aggregate flows. Applications with GOOSE, Sampled Values or heavy multicast traffic require specific analysis of prioritization and traffic replication.
In critical networks, management capability is an engineering requirement. VLANs, QoS, redundancy, SNMPv3, syslog, LLDP, port mirroring, access control, configuration backup and power-supply alarms improve the ability to troubleshoot and operate the system.
Managed or unmanaged switch
Unmanaged switches may serve simple, isolated cells, but provide little operational evidence. In networks with SCADA, multiple protocols, redundancy, security or troubleshooting requirements, managed switches are generally more appropriate because they expose counters, events, neighbors, topology and interface status.
Management also requires governance: templates, version control, backups and change approval. Feature-rich equipment configured inconsistently can increase risk instead of reducing it.
Physical media: copper, fiber and wireless
Metallic cables are common inside panels and over short runs. Category, shielding, connectors, flexibility, bend radius, environment and electromagnetic compatibility need to be considered. Shielding does not replace equipotential bonding and does not correct a poor route.
Fiber optics provides galvanic isolation, electromagnetic immunity and longer distances, making it especially useful between buildings, panels at different electrical potentials and areas subject to interference. Fiber type, optical budget, connectors, splices, slack, ODFs and routes need to be documented and tested.
Wireless can support mobility, sensors and difficult-to-reach points. Coverage, interference, roaming, latency, security and spectrum availability must be designed. Moving a critical function to radio without analyzing risk and failure behavior is not equivalent to replacing a cable.
Fieldbus and Industrial Ethernet
Fieldbuses replaced large amounts of point-to-point wiring with shared digital communication and remain present in many plants. PROFIBUS, DeviceNet and serial networks can coexist with Ethernet backbones for years.
Migration does not need to be total or immediate. Gateways can integrate stable legacy networks while the backbone, segmentation and supervisory systems are modernized. The decision should consider life cycle, spare parts, support, staff knowledge, security and outage risk.
Main industrial protocols
Industrial protocols define how devices structure, address and exchange information. Selection should start from the operational function and required interoperability, not from a list of protocols available in a switch or controller.
Modbus
Modbus RTU and Modbus TCP are found in meters, drives, UPS systems, controllers and auxiliary equipment. The design needs to document addresses, register maps, data types, scaling, endianness, polling, timeouts and behavior when communications are lost.
PROFINET
PROFINET combines cyclic communication, parameterization, alarms and diagnostics over Industrial Ethernet. Cycle times, topology, device names, LLDP, synchronization, conformance classes and redundancy mechanisms need to be consistent with the process.
EtherNet/IP
EtherNet/IP uses the Common Industrial Protocol over Ethernet, TCP, UDP and IP, with explicit and implicit messaging. Requested Packet Interval, connection count, multicast or unicast operation and controller capacity directly affect sizing.
OPC UA
OPC UA is used for interoperability among applications, gateways, SCADA systems and historians. In addition to values, it can carry quality, timestamps, events, methods and information models. It does not automatically replace the field protocol; a gateway often collects data using another protocol and publishes it through OPC UA.
MQTT
Industrial MQTT uses broker-based publish/subscribe and is useful for IIoT, analytics and distributing data to multiple consumers. Topics, payloads, QoS, retention, sessions, authentication and broker availability need to be designed; the protocol alone does not provide industrial semantics.
IEC 61850, DNP3 and IEC 60870-5-104
In the power sector, IEC 61850 structures models and services for power-system automation. DNP3 and IEC 60870-5-104 are used for telecontrol and integration with control centers. Each family has its own mechanisms, events, commands and requirements.
How to choose an industrial protocol
The decision starts with the function: cyclic control, telemetry, parameterization, protection, integration, supervision or analytics. Interoperability must be demonstrated by the profiles and features actually implemented; a simple statement of “support” in a datasheet does not guarantee compatibility between two devices.
Performance, device count, update rate, security, tools, diagnostics, support and life cycle should also be evaluated. A technically suitable protocol may be a poor choice if the ecosystem is not sustainable for operations.
Integration with SCADA systems
A SCADA system receives measurements, states, alarms and events from controllers, RTUs, IEDs and gateways and may send authorized commands. Integration is not complete merely because a tag appears on a screen.
Type, scaling, unit, quality, timestamp and source should be preserved. A frozen value must not continue to be displayed as valid after communication is lost. The point list acts as a contract between field and application and should record address, name, description, type, scale, unit, quality, frequency, permissions and destination.
Alarms need severity, delay, hysteresis, acknowledgment, return-to-normal behavior and treatment of repetitive events. A network that delivers thousands of alarms without prioritization may be technically connected but operationally inadequate.
Industrial integration must be validated end to end, not only by equipment connectivity.
Protocols, gateways, point lists, quality, timestamps, alarms, commands and behavior during communication loss must be verified between field, control and supervision.
Gateways and protocol converters
Gateways integrate different networks and protocols and can convert serial to Ethernet, Modbus to OPC UA, or OT data to MQTT. Scaling, endianness, quality, timestamps, caching and failure behavior must be explicitly defined.
Because they concentrate functions, gateways can become single points of failure. Capacity, redundancy, backups, firmware, licenses, monitoring and spare units need to be part of the design. When the last value is retained in cache, its age and quality must remain visible to the consumer.
Addressing, VLANs and routing
The addressing plan should avoid overlap, allow expansion and identify site, zone or function. Static addresses are common for critical assets, but they require centralized management, documented reservations and traceability.
VLANs separate broadcast domains, but do not by themselves constitute a security barrier. Communication between zones should pass through routing and controls consistent with the flow matrix. NAT can solve temporary conflicts, but increases complexity and should be documented as an exception.
QoS, multicast and prioritization
QoS classifies, marks and prioritizes traffic; it does not create bandwidth. A policy only delivers results when it is coherent end to end and tested under congestion. Under nominal conditions, different classes may appear equivalent.
Multicast is used by several industrial protocols. IGMP Snooping and, where applicable, a querier and multicast routing control its distribution. Incorrect configuration can cause flooding, subscriber loss or intermittent behavior that is difficult to troubleshoot.
Redundancy and high availability
Redundancy can exist in links, switches, controllers, servers, power supplies and physical paths, and each mechanism covers specific failures. Two devices powered by the same circuit or two fibers installed in the same duct remain exposed to a common-mode failure.
RSTP and ring protocols reconverge after a failure. MRP and DLR are used in specific industrial ecosystems. PRP and HSR use parallel paths and serve applications in which the recovery strategy requires different treatment.
Recovery time must be compatible with the operational function and measured in tests. Link loss, switch loss, power-supply failure, controller failure, server failure and WAN-path loss should be simulated in a controlled manner while checking reconvergence, duplication, lost commands and return to normal conditions.
Time synchronization
Logs, alarms, events, sequences and forensic analyses depend on coherent clocks. NTP serves many applications; PTP, IRIG-B and other mechanisms are used when greater precision is required. The design must define sources, hierarchy, redundancy, accuracy, holdover and monitoring.
NTP synchronization in networks and substations also affects certificates, authentication and SIEM correlation. Time differences can hide the real sequence of a failure or incident.
Industrial network cybersecurity
Security should be based on risk, zones, conduits and least privilege. IEC 62443 provides a framework for industrial automation and control systems. Segmentation should separate cells, supervision, engineering access, remote access and corporate services according to the flows that are actually required.
A DMZ between IT and OT networks reduces direct connections and hosts intermediary services. Legacy protocols without authentication or encryption require compensating controls such as source restrictions, firewalls, monitoring and segmentation.
OT architecture must integrate communications, security and operations from the design stage.
VLANs, zones, firewalls, flow matrices, remote access, synchronization, redundancy and SCADA interfaces should be documented as engineering requirements rather than added only after implementation.
Identity and network access
RADIUS and 802.1X can authenticate users and devices where supported. Legacy equipment requires controlled alternative policies. Remote access should use MFA, VPN and an intermediary access point with session recording, especially for vendors.
PAM, jump servers and bastion hosts help individualize access, control credentials and reduce shared accounts. When a common account cannot be eliminated on the final asset, access must be individualized before reaching it and remain auditable.
Monitoring and observability
Ping does not demonstrate network health. Interfaces can accumulate errors, drops, saturation, power-supply failures or optical degradation while equipment continues to respond. SNMP and SNMPv3, syslog, telemetry and flows provide complementary evidence.
Port mirroring and controlled packet captures allow protocol and timing analysis. Monitoring platforms should record availability, capacity, power supplies, temperature, redundancy and alarms. Security events can be forwarded to a SIEM without turning the monitoring network into a hidden operational dependency.
Server and workstation security
SCADA servers, historians and engineering workstations need policies compatible with operations. Antimalware, EDR, patches and hardening must be validated so they do not interrupt applications or communications. Unsupported systems should be isolated and protected with compensating controls.
OT and IT integration
OT/IT convergence enables analytics, asset management and maintenance, but it should not create unrestricted connectivity. Historians, brokers, APIs and OPC UA servers in intermediary zones can publish data without allowing corporate applications to initiate sessions directly with controllers.
Flow direction must be explicit. Dependencies on DNS, identity, certificates, cloud services and the internet should be known, and critical functions must remain available when corporate services fail.
Electrical infrastructure, EMC and environment
Switches, gateways and servers depend on power, grounding, surge protection and environmental conditions. Redundant power supplies need sufficiently independent circuits; UPS systems and battery banks should consider the real autonomy and consumption of the assets.
Electromagnetic compatibility influences the choice between copper and fiber, shielding, routing and equipotential bonding. In harsh areas, temperature, dust, vibration, corrosion and surge exposure need to appear in the specification and acceptance criteria.
Design documentation and governance
Documentation should include logical and physical diagrams, topology, inventory, addressing, VLANs, routes, flow matrices, protocols, ports, synchronization, redundancy, power and security criteria. Diagrams need to show fibers, transceivers, ports and relevant physical paths.
Configurations should have templates, backups and version control. The point list integrates automation and SCADA; the communication matrix integrates networking and security. Responsibilities for switches, firewalls, controllers, servers, certificates and changes need to be defined so the solution does not degrade after handover.
Industrial network design process
The process begins with a survey of assets, functions and requirements. Architecture, segmentation, topology, protocols, performance, availability, synchronization and security are then defined. Equipment selection should come afterward, using functional and environmental requirements that allow technical comparison.
The detailed design generates lists, diagrams, configuration criteria and test procedures. Multidisciplinary reviews should involve automation, telecommunications, electrical engineering, cybersecurity and operations, especially at interfaces among panels, networks, servers and supervisory systems.
Modernizing legacy networks
Modernization should start with an inventory of protocols, addresses, versions, dependencies, cables, spare parts and single points of failure. Migration can occur in phases: gateways maintain serial networks or fieldbuses while the backbone, segmentation and servers are renewed.
Coexistence periods require testing and documentation of exceptions. Protocol translations, NAT and temporary firewall rules should have an owner and a removal plan. Migration windows should have verifiable go/no-go and rollback criteria.
OT modernization requires technical governance over scope, interfaces, migration and acceptance.
In brownfield environments, an independent perspective helps control equivalencies, exceptions, coexistence risks, field changes, testing and documentation through final handover.
FAT, SAT and commissioning
FAT validates equipment, versions, configurations and integrations before field deployment. SAT verifies the actual installation, cabling, power, communications, interfaces and environmental conditions. Commissioning consolidates the evidence that the system meets functional and performance requirements.
- topology, addressing, VLANs, routes and versions;
- copper and fiber testing, identification and optical budget;
- communication among controllers, gateways, SCADA and historians;
- latency, jitter, loss and cycle time where applicable;
- failure of links, switches, power supplies, servers, controllers and time references;
- firewall rules, authentication, remote access, logs and alarms;
- backup, restoration, reconnection and return after contingencies.
Acceptance must demonstrate the network under nominal and contingency conditions.
Physical media, protocols, SCADA, redundancy, synchronization, security, alarms, backup and recovery need to be tested against measurable criteria with traceable evidence.
Fault diagnosis
Troubleshooting should proceed by layers. First verify power, physical media, signal and link. Then check VLANs, addressing, routes, firewalls, protocols and applications.
Interface errors may indicate a cable, connector, transceiver or interference problem. Drops may indicate congestion or buffer limitations. Flapping may point to physical instability or negotiation issues.
When only one protocol fails, IP connectivity does not prove operation. Ports, multicast, sessions, parameters and device capacity need to be evaluated.
Traffic captures should be performed at controlled points. Equipment and capture-tool timestamps need to be synchronized for correlation.
Common mistakes
A recurring mistake is building a flat network because “all devices need to communicate.” The flow matrix usually shows that only certain pairs actually require connectivity.
Another problem is selecting switches only by port count and temperature without evaluating multicast, buffers, redundancy, management or protocol certification.
It is also inadequate to apply QoS without measuring congestion, create VLANs without firewalls, duplicate equipment on a common power supply or assume that an open protocol guarantees interoperability.
Incomplete documentation turns small changes into risk. Addresses, ports and passwords maintained only in personal spreadsheets prevent sustainable operations.
Finally, testing only ping and one tag reading does not prove the network. Contingencies, load, alarms, quality, timestamps and recovery need to be tested.
Conclusion
Industrial networks connect the physical process to control, supervision and management systems. Their design combines performance, availability, protocols, switches, physical media, SCADA integration, security and operations.
A reliable architecture begins with functional requirements and distributes responsibilities across field, control, supervision and integration. Protocols are selected according to function; redundancy is validated through real failure scenarios; security is based on zones and flows; monitoring provides operational evidence.
When documentation, governance and commissioning are part of the solution, the network ceases to be merely a collection of equipment and becomes an engineering infrastructure capable of supporting automation throughout its life cycle.
Technical references
[1] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security. Gaithersburg, 2023. Available at: https://csrc.nist.gov/pubs/sp/800/82/r3/final.
[2] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 62443 series — Security for industrial automation and control systems. Available at: https://www.iec.ch/cyber-security/industrial-cyber-security.
[3] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 61158-1:2023 — Industrial communication networks — Fieldbus specifications — Part 1: Overview and guidance. Available at: https://webstore.iec.ch/en/publication/66931.
[4] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 61784 series — Industrial communication networks — Profiles.
[5] IEEE. IEEE 802.1Q-2022 — Bridges and Bridged Networks. Available at: https://standards.ieee.org/ieee/802.1Q/10323/.
[6] IEEE 802.1 WORKING GROUP. Time-Sensitive Networking Task Group. Available at: https://1.ieee802.org/tsn/.
[7] OPC FOUNDATION. OPC Unified Architecture. Available at: https://opcfoundation.org/about/opc-technologies/opc-ua/.
[8] MODBUS ORGANIZATION. Modbus Application Protocol Specification. Available at: https://modbus.org/specs.php.
[9] PROFIBUS & PROFINET INTERNATIONAL. PROFINET Technology. Available at: https://www.profibus.com/technology/profinet/.
[10] ODVA. EtherNet/IP. Available at: https://www.odva.org/technology-standards/key-technologies/ethernet-ip/.
[11] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 61850 series — Communication networks and systems for power utility automation. Available at: https://webstore.iec.ch/en/publication/6028.
[12] IEEE. IEEE 1815-2012 — Standard for Electric Power Systems Communications — Distributed Network Protocol (DNP3). Available at: https://standards.ieee.org/ieee/1815/5414/.
Frequently asked questions
They are communication infrastructures used to integrate sensors, controllers, machines, IEDs, gateways and SCADA systems in automation and control environments.
An industrial network is directly linked to the physical process and must meet requirements for availability, latency, determinism, life cycle and operational security.
It is the use of Ethernet technologies in industrial environments, combined with equipment, protocols and capabilities suited to automation, diagnostics, real-time operation and redundancy.
Evaluate the environment, ports, capacity, buffers, multicast, VLANs, QoS, redundancy, management, power, EMC and compatibility with the protocols used.
Common protocols include Modbus, PROFIBUS, PROFINET, EtherNet/IP, OPC UA and MQTT. In the power sector, IEC 61850, DNP3 and IEC 104 are also relevant.
There is no universally best protocol. The choice depends on function, performance, interoperability, security, life cycle and equipment support.
Controllers, RTUs, IEDs or gateways provide measurements, states, alarms and commands to SCADA through compatible protocols and a documented point list.
A VLAN separates broadcast domains, but does not replace firewalls, flow controls, identity and monitoring between zones.
Combine redundancy of links, equipment, power supplies and servers, and test recovery times and common-mode failures.
Use indicators for interfaces, errors, utilization, power supplies, temperature, redundancy, logs, protocols and synchronization through SNMP, syslog and observability platforms.
Physical and logical diagrams, addressing, VLANs, routes, protocols, flow matrices, redundancy, synchronization, power, security, configurations and test criteria.
Commissioning should validate physical media, configurations, protocols, SCADA, performance, contingencies, security, logs, backups and recovery with evidence.
Complementary technical materials
Related solutions
- Industrial Networks
- SCADA Systems
- Digital Supervision and Control Systems
- Zabbix — Infrastructure Monitoring
Related services
Protocols, architecture and integration
- Modbus: RTU, TCP and industrial security
- OPC UA: security and SCADA integration
- Industrial MQTT: broker, QoS and security
- RS-485: topology, termination and troubleshooting
- SCADA in the power sector
- Digital substations and IEC 61850
- PRP and HSR in high-availability networks
Security, monitoring and operations