Skip to Content

ABD4002-NATFW

Industrial security appliance for essential OT network protection. The Anybus Defender 4002 with NAT/FW license provides the foundation for securing your operational technology environment — stateful firewalling with deny-by-default policy, versatile NAT configuration, transparent bridging and VLAN support for logical network segmentation.

Built-in OT asset discovery automatically identifies connected devices on your network with make, type, software version and patch level — giving you full visibility into your OT environment. Configuration via an intuitive web GUI with use-case wizards and one-click rule creation directly from firewall logs. RESTful API and CLI SSH access for integration and maintenance. Optional central management via the Anybus Cybersecurity Console.

Rugged fan-less metal enclosure with DIN rail mounting. 2x 1 Gbit RJ45 Ethernet (1x WAN, 1x LAN) with VLAN support.

Price
1,812.00 € 1,812.00 € (Tax excluded)
1,812.00 € (Tax excluded)

Terms and Conditions

How it works


1
Install
Mount on DIN rail, connect WAN and LAN between your IT/OT boundary or in front of a machine cell
2
Discover
The built-in asset scanner identifies all connected OT devices with firmware versions and patch levels
3
Configure
Use the web GUI with use-case wizards to set up NAT, firewall rules and whitelists — one-click rule creation from logs
4
Protect
Switch to enforcement — only whitelisted traffic gets through. Your OT network is segmented and secured



Key use cases


OT/IT network segmentationDeny-by-default stateful firewall with VLAN support — isolate production from corporate IT
IP conflict avoidanceVersatile NAT (1:1, 1:many) to connect identical machines on one network without address conflicts
Machine-level protectionPlace a Defender in front of each machine or cell — only whitelisted traffic gets through
IEC 62443 complianceImplement security zones and conduits according to industry standards for machine isolation
OT asset discoveryAutomatically identify every device on your network — make, type, firmware version and patch level
Transparent bridgingDrop into an existing network at Layer 2 without changing any IP addresses — invisible to connected devices

 

Technical Specs


License typeNAT/FW — Perpetual
Stateful firewallYes — deny by default
NATSimple NAT wizard, 1:1, 1:many
Bridge / transparent modeYes
VLAN supportYes — logical segmentation
Certificate managementYes
Asset discovery & inventoryYes — OT/ICS specific, with accuracy score
NotificationsEmail, syslog, Telegram Messenger, Pushover
Central managementOptional — Anybus Cybersecurity Console


WAN1x RJ45 Gigabit Ethernet
LAN1x RJ45 Gigabit Ethernet
VLANSupported — additional logical segments


Web GUIOn-board web interface with use-case wizards
Rule creationOne-click from firewall logs + floating rules
APIIntegrated RESTful API
CLISSH / Console access
DiagnosticsTraffic diagnostics, debug tools, ARP & bandwidth monitoring


Input voltage24V DC
Current consumption (max)840 mA
Power consumption (max)20W


IP ratingIP20
Housing materialMetal — fan-less
MountingDIN rail (EN 50022)
Dimensions (L x W x H)114.6 x 118.2 x 64.5 mm
Weight680 g
Operating temperature0°C to +50°C
Humidity0–85% non-condensing


CEYes
RoHSYes (2011/65/EU)
WEEEYes
Country of originUSA


 

Need more? The NAT/FW license covers essential firewalling, NAT, bridging and asset discovery. For Deep Packet Inspection on industrial protocols (Ethernet/IP, Modbus), virtual patching via IPS, VPN, DHCP server and policy scheduling — upgrade to the DPI/FW license. For advanced routing, traffic shaping, load balancing and high availability — see the PRO/FW license.


Build the perfect configuration

Everything you need to complete your setup!

Your Dynamic Snippet will be displayed here... This message is displayed because you did not provide enough options to retrieve its content.