Ask AI
Network & access

Crane network topology

OT security

Cyber-security network segregation is being rolled out on all cranes: traffic is separated into VLANs on the managed e-house switch. Service engineers — check the VLAN plan and switch-port map below before plugging in. Switch credentials: Vault → lh/crane/switch.

Topology

Internet / MaxCloud AWS
outbound TLS only
eHawk jump host
remote support VPN
PERIMETER
Crane firewall / router
inter-VLAN routing + rules · 192.168.30.1
Managed switch (e-house)
802.1Q trunk · VLANs 10 / 30 / 40 / 99
VLAN 10 · MGMT
Proxmox host · switch mgmt
192.168.10.0/24
VLAN 30 · OT
Crane PLC · Maxedge VM · HMI
192.168.30.0/24
VLAN 40 · CUSTOMER
Datasharing OPC UA / Modbus
192.168.40.0/24
VLAN 99 · SERVICE
Service laptop access
192.168.99.0/24 · DHCP

VLAN plan

VLANPurposeSubnetDevicesAccess rules
10Management192.168.10.0/24Proxmox host mgmt, switch mgmt, firewall mgmtIT/engineering only; reachable from VLAN 99 with rule
30OT / Crane192.168.30.0/24Crane PLC, Maxedge VM (192.168.30.111), Proxmox host (192.168.30.110), HMINo inbound from customer network; outbound TLS to MaxCloud only
40Customer datasharing192.168.40.0/24OPC UA + Modbus TCP endpoints (Maxedge second NIC)Customer SCADA → Maxedge datasharing ports only (4840, 502)
99Service access192.168.99.0/24Service laptops (DHCP), port 12Time-limited; access to dashboards + SSH via firewall rules

Switch-port map — where to connect

Service laptops connect to port 12 (VLAN 99) only. Never plug into OT ports. Real cabinet photos go into the placeholders below.

Photo: switch front, ports labeled

E-house switch — front

Ports 1–4: PLC / OT (VLAN 30) · 5–6: Maxedge IPC trunk · 9–10: customer datasharing (VLAN 40) · 12: service access (VLAN 99)
Photo: service port 12, marked yellow

Service port 12 (VLAN 99)

Marked yellow in the cabinet. DHCP — laptop gets a 192.168.99.x address; firewall permits access to Maxedge dashboard and Proxmox UI.
Photo: e-house cabinet overview

Cabinet layout

Switch and Maxedge IPC location in the e-house cabinet. Firewall/router sits top-left of the network rail.
PortVLANConnected deviceWho may use it
1–430Crane PLC, HMINobody on site — OT only
5–6trunkMaxedge IPC (2 NICs: OT + customer)Fixed cabling
9–1040Customer SCADA uplinkCustomer IT, by agreement
1299— (yellow, free)Service engineers
24trunkFirewall / router uplinkFixed cabling

Segregation rules

Segregation rule: no device may bridge VLANs. Do not connect a laptop to OT ports (1–4), and never patch customer network directly into VLAN 30. Changes to VLAN config require approval from OT security (see Vault runbook lh/crane/network-change).
Internal use only · Lifting & Handling engineering · maintained by Product Engineering
Owner: OT Security · Updated 9 Sept 2026