Industrial Ethernet · PROFIBUS PI

PROFINET RT/IRT Security

PROFINET (Process Field Network) is the Industrial Ethernet successor to PROFIBUS, standardised by PROFIBUS & PROFINET International (PI). It runs over standard IEEE 802.3 Ethernet and uses standard IP for engineering and configuration traffic, while using optimised Layer 2 Ethernet frames for real-time I/O data. PROFINET is the dominant industrial protocol in German automotive manufacturing and is growing rapidly across European process industries.

PROFINET Classes

ClassCycle TimeTransportTypical Use
PROFINET NRT>100msTCP/IP (port 34964)Engineering, parameterisation, SNMP
PROFINET RT1–10msLayer 2 Ethernet (EtherType 0x8892)Standard I/O — drives, sensors, actuators
PROFINET IRT31.25µs–1msLayer 2 with synchronised hardwareMotion control, precision manufacturing

RT and IRT frames bypass the IP stack entirely, operating at EtherType 0x8892 with no TCP/IP overhead. This makes firewall-based filtering at Layer 3 ineffective — RT/IRT traffic can only be filtered at Layer 2 by managed switches.

Security Vulnerabilities

PROFINET Security Measures

PROFINET does not have a native security extension equivalent to OPC UA's TLS or DNP3's SA. Security relies on compensating controls:

Defences

ControlSREffect
802.1X port authenticationSR 1.2Authenticate devices at switch port level
Disable DCP write servicesSR 7.7Prevent device renaming and factory reset via network
PROFINET VLAN isolationSR 5.1RT traffic isolated from NRT and IT network
Switch port MAC bindingSR 5.2Only registered device MACs can communicate on RT VLAN
⚡ Explore PROFINET in ICSora Labs

Examine PROFINET frame structure, DCP vulnerability, and Layer 2 isolation techniques in the interactive protocol lab.

Open PROFINET Protocol Lab →