VCL-2140 is a low data rate serial and ethernet data encryption equipment with integrated firewall capabilities that may be installed to secure and protect ethernet and RTU data (Remote Terminal Data) in critical infrastructure such as Sub-Stations, Smart Grid Distribution Systems, Oil and Gas Infrastructure and Railway Signalling Networks. The VCL-2140 may be used to secure RTU data and protect it from being compromised or accessed by hostile elements.

The VCL-2140 Data Encryption Equipment may be installed in point-to-point applications and used to provide to secure communications between the RTU Terminals and their corresponding IEC -101, -104, DNP, MODBUS protocol central server(s) located in Load Dispatch Centre(s) / SCADA Management Centre(s) and Rail Traffic Control Room(s).

  • IEC 60870-5-104
  • Firewall
  • DNP
Download Brochure


Protocols supported:

  • IEC 60870-5-101 (IEC 101): RS-232 and RS-485 ports
  • IEC 60870-5-104 (IEC 104): 10/100BaseT Ethernet Port
  • DNP (Distributed Network Protocol):
    • RS-232 and RS-485 ports
    • 10/100BaseT Ethernet Port
    • RS-232 and RS-485 ports
    • 10/100BaseT Ethernet Port

Versions and Technology Deployment:

  • VCL-2140 Data Encryption Equipment:
    • High-Security Data Encryption Equipment
    • Point-to-Point -101, -104, DNP, MODBUS Protocol RTU Data Encryption equipment. The VCL-2140 is designed to be used only in point-to-point applications.
    • Encrypting RTU data between two Terminals


  • Utilities: Electric generation, transmission, and distribution
  • Smart Grid Distribution Systems
  • Oil & Gas production, pipelines
  • Remote nodes in SCADA networks
  • Railway Signalling Infrastructure: Rail Traffic Control Room(s)
  • All distributed data networks consisting of a central server and multiple edge locations.

Interfaces – Terminal:

  • Total Number of Ethernet Interfaces: 3
    • One, 10/100 RJ45 equipment interface for the local (trusted) LAN side
    • One, RS-232 interface
    • One, RS-485 interface
    • One 10/100 RJ45 network interface to the WAN (untrusted) network side
  • Auto MDI/X (straight or crossover Ethernet cable correction)
  • USB serial port for local access and configuration.

Data Encryption Protocols:

  • IPSec. OpenVPN

Data Encryption Algorithms:

  • AES128, AES192, AES256

Encrypted Data Throughput:

  • Compact, DIN-Rail Remote Data Encryption Terminal, Maximum Encrypted Data Rate, ≤ 12Mbps with AES256 Encryption Algorithm.

Network Support:

  • IPv4 and IPv6 Routing
  • Ethernet
  • VLAN tag preservation
  • MPLS tag preservation
  • IPv4

Monitoring and Access Control:

  • Password Strength Monitor
  • Device Management and Alarm Monitoring
  • Command Line Interface – Telnet, SSH
  • SNMPv2; SNMPv3 Alarm Monitoring
  • Alarm condition detection and reporting (traps and SNMP alarm table)
  • Syslog
  • Audit Log

Firewall – Features and Capabilities:

  • Deep Packet Inspection
  • Per-frame/packet authentication
  • Firewall
    • Port (Soft) – based
    • MAC – based
    • IP Address – based
    • IP Domain – based
  • White List and Black-List options
    • White-List Exception allowed and blocks all other traffic by default (system default mode)
    • Black-List Exception blocked and allows all other traffic by default
    • Seamless scalability
  • Infrastructure neutral
  • Transparent to network and applications
  • Easy installation and management


  • Power: 1+0 or 1+1 Power Supply Options
  • 12V DC to 60V DC
  • 85V DC to 250V DC
  • 100~240V AC, 50/60Hz
  • Power Consumption: 15W at maximum load