Skip to Content

ABD6019-DPIFW

Enterprise-grade industrial security appliance with 10 physical network segments and Deep Packet Inspection. The Anybus Defender 6019 with DPI/FW license is built for large-scale OT environments — 1x WAN, 8x LAN Gigabit Ethernet and 1x SFP port for fiber optic or additional RJ45 connectivity, all with VLAN support for virtually unlimited logical segmentation.

Understands industrial protocols like Ethernet/IP CIP and Modbus at the application layer, with auto-learn capabilities that minimize manual rule creation. Integrated Snort and Suricata IPS enable virtual patching of legacy PLCs and HMIs. Built-in OT asset discovery identifies every connected device across all segments with make, type, firmware version and patch level.

Full VPN support (WireGuard, OpenSSL, IPsec) for secure plant-to-plant and OT-SDWAN connections, RADIUS/LDAP/AD authentication, DHCP server and policy scheduling. Configuration via web GUI with use-case wizards, RESTful API and CLI. Optional central management via the Anybus Cybersecurity Console.

Rugged fan-less IP50 metal enclosure with DIN rail mounting. Designed for multi-zone factory floors, large production facilities and OT-SDWAN deployments.

Price
3,480.00 € 3,480.00 € (Tax excluded)
3,480.00 € (Tax excluded)

Terms and Conditions

How it works


1
Install
Mount on DIN rail, connect WAN, up to 8 LAN segments and SFP uplink to your factory backbone or fiber infrastructure
2
Discover
Asset scanner maps every OT device across all 10 segments with firmware and patch level details
3
Auto-learn
DPI auto-learns industrial traffic patterns on every port and suggests firewall rules — minimizing manual configuration
4
Enforce
DPI rules and IPS signatures active on all segments — legacy devices virtually patched, VPN tunnels secured



Key use cases


10-segment OT security1x WAN + 8x Gigabit LAN + 1x SFP — protect an entire factory floor from a single appliance with DPI on every segment
Deep Packet InspectionInspect Ethernet/IP CIP and Modbus at the application layer across all 10 ports — auto-learn capable
Virtual patching at scaleProtect legacy devices across multiple zones — Snort and Suricata IPS with customizable signatures
OT-SDWAN & site-to-site VPNEncrypted plant-to-plant connections using WireGuard, OpenSSL or IPsec — purpose-built for OT-SDWAN
Fiber optic connectivitySFP port for fiber or additional RJ45 — connect to backbone switches, distant buildings or high-EMI environments
Enterprise asset discoveryIdentify every device across all 10 segments — make, type, firmware version, patch level and accuracy score

 

Technical Specs


License typeDPI/FW — Perpetual
Stateful firewallYes — deny by default
NATSimple NAT wizard, 1:1, 1:many
Bridge / transparent modeYes
VLAN supportYes — logical segmentation across all ports
Certificate managementYes
Deep Packet InspectionEthernet/IP CIP, Modbus — auto-learn capable
Intrusion Protection (IPS)Snort & Suricata — customizable signatures
Virtual patchingYes — protect unpatched legacy devices
VPNWireGuard, OpenSSL & IPsec
Remote client VPNYes
RADIUS / LDAP / AD authenticationYes
DHCP server & forwardingYes
Rules/policy schedulerYes — by date, time and duration
Asset discovery & inventoryYes — OT/ICS specific, with accuracy score
NotificationsEmail, syslog, Telegram Messenger, Pushover
Central managementOptional — Anybus Cybersecurity Console


WAN1x RJ45 Gigabit Ethernet
LAN8x RJ45 Gigabit Ethernet
SFP1x SFP port (RJ45 or fiber optic module)
Total physical segments10
VLANSupported — additional logical segments


Web GUIOn-board web interface with use-case wizards
Rule creationOne-click from firewall logs + floating rules
APIIntegrated RESTful API
CLISSH / Console access
DiagnosticsTraffic diagnostics, debug tools, ARP & bandwidth monitoring


Input voltage24V DC
Current consumption (max)1100 mA
Power consumption (max)26.4W


IP ratingIP50
Housing materialMetal — fan-less
MountingDIN rail (EN 50022)
Dimensions (L x W x H)140.4 x 69.6 x 179.7 mm
Weight1270 g
Operating temperature0°C to +60°C


CEYes
WEEEYes
Country of originUSA


 

Why 6019 over 6004? The Defender 6019 adds 5 more Gigabit LAN ports (8 vs 3) plus an SFP port for fiber optic connectivity — purpose-built for large factory floors with many OT zones, backbone fiber infrastructure and OT-SDWAN deployments. Same DPI/FW feature set. For smaller deployments, see the Defender 6004 (4 ports) or Defender 4002 (2 ports). For advanced routing, traffic shaping and HA, see the PRO/FW license.


Build the perfect configuration

Everything you need to complete your setup!

Your Dynamic Snippet will be displayed here... This message is displayed because you did not provide enough options to retrieve its content.