Map IP Reuse Domains in Operational Technology Environments

Networks in plant/production, building automation, and other Operational Technology environments often contain duplicate sites and network structures. IP addresses repeat, or overlap, across the network.

To support these networks, the eyeSight and the eyeInspect solution use IP Reuse Domains to distinguish several instances of an overlapping IP address. You define a unique IP Reuse Domain for each repeated segment or network branch. IP addresses are unique in each IP Reuse Domain.

  • In the eyeSight, IP Reuse Domains are assigned to Appliances. Identical segments are distinguished from each other by the IP Reuse Domain of the Appliance that manages each segment.
  • In eyeInspect, IP Reuse Domains are defined in the Command Center Console and assigned to selected Sensors.

The IP Reuse Domains you define in the eyeSight must correlate to the IP Reuse Domains defined in your eyeInspect deployment.

The Operational Technology plugin integrates the eyeSight with your eyeInspect deployment. Use this plugin to:

  • Define the eyeSight connection to Command Center.
  • Define the mapping between IP Reuse Domains, as described below.

For more information about Operational Technology support in the eyeSight, refer to the Operational Technology Plugin Configuration Guide.

Before you begin, review the IP Reuse Domains defined in Command Center, as described in the eyeInspect Installation and Configuration Guide.

Use this procedure to map the IP Reuse Domains defined in the eyeSight to the IP Reuse Domains defined in eyeInspect. Repeat this procedure when you change IP Reuse Domain definitions in either platform.

To map IP Reuse Domains to a Command Center:

  1. To review IP Reuse Domains defined in the eyeSight, select Tools > Options > CounterACT Devices > Overlapping IPs Management. The table shows segments in each IP Reuse Domain. Select Export to export IP Reuse Domain information.
  2. Go to Options > Operational Technology and select the Overlapping IP Addresses tab.
  3. To define mapping between an IP Reuse Domain defined in the eyeSight Internal Network and IP Reuse Domains defined in the eyeInspect Command Center:
    1. Select Add or select an existing rule and select Edit.
    2. In the Internal Network IP Reuse Domain drop-down, select an IP Reuse Domain.
    3. In the Command Center IP Reuse Domains drop-down, select an IP Reuse Domain. Domains are shown for all connected Command Centers.
    4. Select OK.
  4. Repeat steps 1-3 for all mappings you wish to establish. All non-mapped Command Center IP Reuse Domains will default to the Global IP Reuse Domain of Counteract.
  5. Select Apply to save the definitions.