Developed according to IEC 62443-4-1
Security by Design and Default
- Certified to IEC 62443-4-1 Security Level 3: MB Connect Line is targeting IEC 62443-4-2 Security Level 3 certification in Q4 2026 to meet the requirements of the Cyber Resilience Act (CRA).
- The PLUS in security: An integrated key switch provides physical control over remote access.
- Optimised data throughput: 4 × 1 Gbit/s LAN ports and 1 × 1 Gbit/s WAN port, with an optional 1 Gbit/s DMZ port.
- Additional DMZ port: Maximum control and clear network separation. The router provides secure, separate data paths to the external network and the production network.
- Full IT compatibility – seamless integration into modern IT and OT infrastructures:
- SNMPv3, MQTT API, MQTT Bridge and REST API for secure remote monitoring and router management.
- Two-factor authentication (TOTP, passkeys) for secure access to the GUI.
- Network segmentation using port-based VLANs.
- 802.1X client and server authentication for controlled network access.
- The device therefore meets key requirements for security, transparency and professional network segmentation.
- Integrated failover: Ensures uninterrupted connectivity and maximum availability.
- SIMPLY.connect: Intuitive integration of new devices into the mbCONNECT24 Remote Service Portal via smartphone – making device onboarding easier than ever.
Additional highlights
- Data acquisition
- Optional serial or MPI/PROFIBUS connectivity
- Supports mbWEB2go
- Digital inputs and outputs
- IIoT-ready
- Nano-SIM slot (LTE version only)
- Flexible connectivity via LAN, Wi-Fi or LTE
With its integrated key switch, this industrial remote access router combines key OT security requirements as recommended by the BSI and international cybersecurity authorities. Discover how simple secure remote access can be.
Key-controlled remote access
- Three switch positions determine when access to the router is permitted and when the connected machines and systems are enabled for remote access.
- Physical authorisation provides clear responsibilities, greater transparency and better control over remote access.
Warning signal during an active remote session
- A digital output can be used to activate a local acoustic or visual warning signal.
- This ensures that operating personnel are always aware when a remote access session is active.
Unique device password
- Each device is delivered with its own unique factory-set password.
- No default credentials, no shared secrets – enhanced protection from the very first start-up.
Secure Boot
- The boot process is protected: the router starts exclusively with signed and verified firmware.
- Manipulated or unauthorised firmware images are prevented from being loaded.