GE Digital OpShield-300-2 Firewall

  • Available with fiber optic support, network modules and SFP ports, and high availability features like hot-swappable dual power supplies
  • OT network baselining to establish and review “normal”
  • Intelligent policy creation uses machine learning to suggest policy based on baseline
  • OT protocol inspection engine reads OT packets to the command and parameter levels
  • Vulnerability signatures protect against root causes, not just one-off threats
  • Drag-and-drop virtual network segmentation limits misconfiguration and attacker impact
  • Security alerts can be delivered to the management console and SIEM tools
  • Simplifies security administration with easy to use graphical interfaces—no CLI required
  • Can deploy with minimal or no production disruption


The traditional industry is becoming a digital industry. The embedded devices connected via critical infrastructure SCADA systems are increasingly closing the air gap that operators have relied on to keep industrial assets safe from cyber incidents. It’s important to use the right tools to protect these connected industrial assets. The stakes are high, with cyber mistakes and attacks potentially impacting safety, availability and asset health, as well as reputation and intellectual property. OpShield from GE Digital was created specifically to protect critical infrastructure, drawing on over ten years of embedded device testing and assessments of hundreds of industrial facilities. To protect it, you need to see it. OpShield provides increased visibility within operational technology (OT) networks because it understands what IT firewalls can’t—OT commands and parameters in the context of a defined control process. Knowing something’s wrong is useful, but having the ability to prevent it is better. That’s why OpShield’s enforcement policies not only alert but can also be configured to block traffic that is not on a whitelist of allowable commands in the context of a particular data flow. OpShield supplements its whitelist capability with unique vulnerability signatures. These heavily researched signatures help protect a device’s root vulnerabilities vs. spotting is known exploits one by one. The result is increased effectiveness and signature life. In addition to the ongoing inspection and enforcement OpShield provides, it also helps protect OT networks structurally via virtual segmentation. Segmentation creates zones that reduce the mobility and damage of a misconfiguration or attacker. From segmentation to protocol inspection and command blocking, OpShield provides several layers of the defense-in-depth approach necessary to help protect the people, assets, and operations that run critical infrastructure.

Gigabit Ethernet RJ45 2 with bypass + 1 mgmt port
Console Serial over DB9
Power Requirement
Power Supply (DC Power) 12 ~ 36 VDC
Power Consumption (Avg/ Max) (DC Power) 13.8 W / 15.7 W
Redundant Power (DC Power) Dual DC Connectors
Physical Characteristics
Weight 1.0 kg / 2.2 lbs
Operating temperature -40º ~ 70º C
Storage temperature -40º ~ 85º C
Humidity 5% ~ 95% (non-condensing)
Standards and Certifications Safety: RoHS, IP30 (Ingress Protection), ATEX C1D2 (300 only) , UL: UL 60950-1, Information Technology Equipment Safety Part 1: General Requirements, CSA C22.2 No. 60950-1-07, Information Technology Equipment Safety Part 1: General Requirements, FCC: FCC Part 15, Subpart B: 2012 Class A, ICES-003 Issue 5: 2012 Class A, CE: IEC 60068-2-64 Vibration, IEC 60068-2-27 Mechanical Shock, EN 55022: 2010 + AC: 2011 Class A , EN 61000-3-2: 2006 +A1: 2009 + A2: 2009 Class A, EN 61000-3-3: 2008, EN55024: 2010, IEC 61000-4-2: 2008, IEC 61000-4-3: 2006 + A1: 2007 + A2: 2010, IEC 61000-4-4: 2012, IEC 61000-4-5: 2005, IEC 61000-4-6: 2008, IEC 61000-4-8: 2009, IEC 61000-4-11: 2004, VCCI
Height 146 mm / 5.75 inches
Mounting DIN (or optional Wall-Mount)
Width 65 mm / 2.56 inches
Depth 127 mm / 5.00 inches
Cooling Passive (Fanless)