Secure every plant with one policy.
One Access Gate per plant, linked by secure tunnels. Protected zones extend from one plant to another. You get one policy, one view and one audit trail for every plant.
How this design works.
Each plant gets its own Access Gate. Plants connect over WAN links or site-to-site tunnels. Secure tunnels between Access Gates let enclaves cross plant boundaries. People and machines reach resources at other plants under the same rules, with no central cloud controller.
One Access Gate per plant.
Site A and Site B each run their own Access Gate. Local traffic is controlled locally, so cross-site routing adds no latency.
Tunnels between plants.
Access Gates build secure tunnels to each other over WAN or VPN. Enclaves then extend between plants.
No cloud dependency.
All policy, data and management stay on-premises. Plants run on their own and connect when needed.
A local bastion at each plant.
Each Access Gate acts as the local bastion. It hides and protects local devices when plants connect to each other.
Two plants joined by a secure link.
The base topology shows Site A and Site B connected over a WAN. Each site has its own router, WAN link and gateway. Each Access Gate connects locally and builds a secure tunnel to the other site.
A local deployment at each site.
Each site gets one Access Gate, in-line to carry local VLANs or beside the local gateway. It also runs local services such as DNS and time, a historian and an update server. Site A and Site B run on their own.
A WAN link between sites.
Sites connect over the WAN. The Access Gates build secure tunnels to each other over this link.
Enclaves span sites.
Enclaves defined at Site A extend to Site B through the tunnel. Machines at both sites can join the same enclave.
Each site fits its own network.
Site A may connect at the edge gateway while Site B connects at the OT gateway. Each site is set up for its local network.
Reach a machine at another plant.
This diagram shows a user at Site B reaching a resource at Site A through the tunnel. The two Access Gates set up the session. Both ends check identity and apply the rules.
Access across sites.
A user or machine at Site B can reach a protected resource at Site A. The shared enclave carries the overlay traffic between Access Gates.
Secure tunnel setup.
Access Gates negotiate a secure tunnel between sites. Each site's settings decide whether it connects at the edge or the OT gateway.
Enclaves are not tied to one site.
A CUI enclave or OT protection zone defined at one site can include machines from other sites.
The same rules everywhere.
Access rules follow the enclave, not the building. The same authentication and permissions apply at every site.
Download the multi-site architecture.
Get both diagrams in one pack for your team: base topology and enclave connection.
One gateway.
Start with one plant. Connect one Access Gate to your existing network and add more plants later.
Two gateway layers.
Need separate control for IT and OT before you add plants? One appliance covers both domains.
Multi-Site Architecture.
Multi-Site Architecture: Video Walkthrough
See how Access Gates create encrypted overlay networks across distributed sites (substations, factories, and remote facilities) with centralized policy management.
Request a DemoHow many sites do you run?
Count your plants and small sites. See the Access Gates you need, the price and the ROI against a network project.
Questions about the multi-site design.
sites supported. Each new site adds one Access Gate, with no central controller.
No. Each site runs on its own Access Gate. If the WAN link drops, local control continues. Access between sites pauses during the outage and resumes on its own when the link returns.
The design scales to many sites. Each site adds one Access Gate. Enclaves can span any mix of connected sites, with no central hub or cloud controller.
Any standard IP link works: MPLS, internet VPN or dedicated WAN lines. The Access Gate builds encrypted tunnels whatever the WAN technology underneath.
Yes. Each site sets up its Access Gate on its own. Site A might connect at the core bus while Site B connects at the OT bus. The tunnel between them handles the difference.