How secure is a PDU connected to your data center's network?
A modern intelligent PDU does much more than just distribute power. The PDU measures energy consumption, monitors electrical values, communicates with management software, and can, depending on the configuration, even switch individual outlets remotely.
That provides a great deal of insight and control. But it also raises an important question:
How secure is a PDU once it is connected to your data center network? 🔐
Bee Schleifenbauer PDU 5.0 and EnerTree security is configured so that the solution can be integrated within the existing IT and OT security architecture of the data center.
Why is cybersecurity important for a PDU?
As soon as an intelligent PDU becomes part of the network, it must also be included in the data center's cybersecurity policy.
Depending on the configuration, a PDU can exchange measurement data, send alarm notifications, and offer capabilities for remote management.
Therefore, several questions are important regarding the security of intelligent PDUs:
- How many PDUs actually need a direct network connection?
- Who has access to the PDU infrastructure?
- Which communication protocols are used?
- Where is operational data processed?
- Can the PDU network be separated from other networks?
- Are activities and events logged?
- How are software and firmware updates managed?
With PDU 5.0 and EnerTree, Schleifenbauer offers functionalities that enable data center operators to incorporate these components into their existing IT and OT security policies.
Not every PDU needs its own Ethernet connection.
An important difference in Schleifenbauer's architecture is that not every intelligent PDU needs to be connected directly to the Ethernet network.
Within a Schleifenbauer Databus ring, one PDU with a Gateway or Controller module connection between the ring and the network.
Subsequently, up to 99 additional PDUs with Daisychain modules can communicate within the same ring, without each PDU requiring its own Ethernet connection or IP address.
In this way, a maximum of 100 PDUs can be accessed via a single IP address.
Why is that interesting from a cybersecurity perspective?
Every device directly connected to the network is an additional endpoint that must be configured, managed, and monitored.
By limiting the number of directly connected devices, the complexity of the network can also be reduced.
Instead of managing, for example, 100 separate PDUs, each with its own network connection and IP address, a complete Databus ring can be made accessible via a single network connection.
Fewer Ethernet connections. Lower network complexity. A smaller attack surface.
Keep operational PDU data within your own infrastructure.
For data centers, it is not only important which data is collected, but also where that data ends up.
EnerTree Lite and EnerTree Platform function within the customer's own network environment.
For normal use, no internet connection or cloud environment hosted by Schleifenbauer is required.
This means that organizations can keep their PDU monitoring and management within their own infrastructure and apply their existing security policies.
For data centers with strict requirements regarding security, compliance, or connectivity, such an on-premises approach also offers the ability to manage the PDU infrastructure without relying on an external cloud connection.
Decide for yourself who has access
Not every user needs to have the same rights.
EnerTree therefore supports Role-Based Access Control (RBAC). This allows organizations to grant users only the rights they need for their work.
For example, an administrator can be granted extensive configuration rights, while another user is only allowed to view measured values and status information.
With this, the principle of least privilege are applied: users are not granted more access rights than necessary.
Additionally, EnerTree can be integrated with LDAP and Microsoft Active Directory for central authentication and user management.
In this way, managing access to the PDU infrastructure can become part of the existing identity and access management processes within the organization.
Secure communication with HTTPS, TLS 1.3, LDAPS, SNMPv3 and SSH
Another important aspect of PDU security is the way systems communicate with each other.
EnerTree supports, among other things:
HTTPS, TLS 1.3, LDAPS, SNMPv3 and SSH.
This allows communication with EnerTree and the connected PDU infrastructure to be incorporated into an organization's existing security policy.
SNMPv3 can be used, for example, when authenticated and encrypted SNMP communication is required. HTTPS and TLS can be deployed to secure web-based communication.
The final configuration remains under the control of the customer.
Your network, your security architecture
From a cybersecurity perspective, a PDU never stands entirely on its own.
The network architecture surrounding the management system partly determines which users and systems have access to the PDU infrastructure.
With PDU 5.0 and EnerTree, the customer retains control over network access. Existing security measures can be applied, such as:
- Network segmentation
- VLANs
- Firewall rules
- Access policy
- Secure remote access
- The organization's own VPN solution
For example, a data center can make EnerTree accessible only from a specific management network, instead of allowing access from the entire corporate network.
In this way, the PDU infrastructure can be integrated into the security zones and network architecture already in use within the organization.
Logging and auditing
Good cybersecurity is not just about restricting access. You also want insight into what is happening within the environment.
EnerTree therefore has logging and auditing functionality.
This allows activities and events within the management environment to be captured. This can assist with both operational troubleshooting and internal security and audit processes.
In combination with Role-Based Access Control and central authentication, this gives organizations more insight into how the PDU infrastructure is used and managed.
Verified software and firmware updates
Updates are necessary to maintain infrastructure. Within a data center, you simultaneously want to maintain control over when and how such changes are implemented.
Updates for EnerTree software and Schleifenbauer PDU firmware can therefore be included in their own test, approval, and change management procedures of the customer.
Organizations can assess, test, and schedule updates in accordance with their own operational processes and security policy.
Cybersecurity is a shared responsibility
No connected infrastructure component is secure due to a single protocol, setting, or security function.
Good cybersecurity arises from the combination of product functionality, network architecture, configuration, and operational processes.
Schleifenbauer offers the functionalities to Integrating PDU 5.0 and EnerTree into a secure data center environment.
In doing so, the customer retains control over network segmentation, firewall configuration, user rights, authentication policy, and remote access, among other things.
Cybersecurity is therefore a shared responsibility: Schleifenbauer provides the capabilities to securely integrate the PDU infrastructure, while the organization determines how these capabilities are applied within its own security architecture.
How do you secure intelligent PDUs in a data center?
When securing intelligent PDUs, it is important to look at the entire architecture and not just at a single individual device.
Limiting unnecessary network connections, segmenting management infrastructure, using secure communication, implementing Role-Based Access Control, centrally managing authentication, and performing updates in a controlled manner can all contribute to a more secure environment.
Schleifenbauer's Databus architecture adds an interesting question to this:
Does every intelligent PDU actually need to be directly connected to the Ethernet network?
With the Schleifenbauer PDU 5.0, that is not necessary.
By making a maximum of 100 PDUs accessible via a single Databus ring and a single IP address, the number of PDUs with a direct Ethernet connection can be significantly reduced, while central monitoring and management via EnerTree remain possible.
Frequently asked questions about PDU security
Is an intelligent PDU a cybersecurity risk?
An intelligent PDU is part of a data center's connected infrastructure and must therefore be included in the cybersecurity policy. The actual risk depends on, among other things, the network architecture, configuration, access rights, communication protocols used, and available functionalities.
Does every Schleifenbauer PDU need its own IP address?
No. Within a Schleifenbauer Databus ring, one PDU with a Gateway or Controller module can provide the network connection. A maximum of 99 additional PDUs with Daisychain modules can communicate within the same ring without their own Ethernet connection or IP address. As a result, a maximum of 100 PDUs can be accessed via a single IP address.
Does EnerTree need a cloud connection?
No. EnerTree Lite and EnerTree Platform operate within the customer's own network environment. No Schleifenbauer-hosted cloud service or internet connection is required for normal use.
Does EnerTree support Role-Based Access Control?
Yes. EnerTree supports Role-Based Access Control, which allows organizations to assign different rights to different users. For example, it is possible to distinguish between users with administrative rights and users who are only allowed to view data.
Can EnerTree be linked to Microsoft Active Directory?
Yes. EnerTree can be integrated with LDAP and Microsoft Active Directory for central authentication and user management.
Which security protocols does EnerTree support?
EnerTree supports technologies and protocols including HTTPS, TLS 1.3, LDAPS, SNMPv3 and SSH. This allows the solution to be integrated into an organization's existing security policy.
Can Schleifenbauer PDUs be placed behind a firewall or in a separate VLAN?
Yes. The customer determines how the network environment is configured. Network segmentation, VLANs, firewall rules, and their own VPN or remote access solutions can be used to determine which systems and users gain access to EnerTree and the PDU infrastructure.
How do I report a potential vulnerability in a Schleifenbauer product?
Have you discovered a vulnerability in a Schleifenbauer PDU, EnerTree Lite or EnerTree Platform, or do you suspect that one of our products is being actively misused?
Then report this via:
Responsibly reporting potential vulnerabilities helps us investigate security issues and better protect our products and customers.
Secure PDU infrastructure starts with the architecture
As data centers become increasingly connected, cybersecurity must look beyond just traditional IT equipment.
Intelligent PDUs offer valuable capabilities for measuring, monitoring, and managing the power infrastructure. However, that connectivity also means that network access and security must be carefully considered.
Schleifenbauer PDU 5.0 and EnerTree are designed to function within an organization's existing IT and OT security architecture.
From less direct network connections and on-premises use to Role-Based Access Control, central authentication, secure communication, logging, and controlled updates.
And because a maximum of 100 PDUs can be accessible via a single IP address, Securing your PDU infrastructure can start with something fundamental: limiting the number of devices that need to be connected directly to your Ethernet network.
Want to learn more about the security architecture and security functionalities of PDU 5.0 and EnerTree? View the security capabilities of our intelligent PDU and energy management solutions or contact Schleifenbauer.
The post How secure is a PDU connected to your data center's network? appeared first on Schleifenbauer – PDUs.
Source: https://www.schleifenbauer.eu/nl/pdu-beveiliging-datacenter-cybersecurity/