Secure a plant with one gateway.
One Access Gate protects the IT and OT networks of a plant. Your router, firewall and switches stay in place. Run it in-line, so all machine traffic passes through it. Or connect it beside your edge gateway, which changes less.
How this design works.
This design covers a whole plant with one Access Gate. In-line, it carries your VLANs and trunks and acts as the machines' gateway. That gives the widest coverage, even without managed switches. Beside the edge gateway, it adds a secure overlay across all subnets. The router, firewall and switches stay as they are. The same appliance also runs remote access, protocol gateways, DNS and time, a historian and an update server.
Your current network stays.
Router, firewall and switches stay in place. No re-cabling and no IP changes.
In-line for the widest coverage.
Machine traffic passes through the Access Gate. It carries your VLANs and trunks and acts as the gateway. It works even without managed switches.
IT and OT in one deployment.
One deployment covers both IT and OT subnets. Subnets A and B are both protected.
A security layer on top.
Two-way NAT and routing create a virtual security layer. Nothing to install on machines.
How the gateway connects.
The Access Gate connects to the edge gateway. In the low-impact option, selected north-south and east-west traffic loops through it, with no VLAN changes. For fuller coverage, run it in-line so it carries the VLANs and trunks and acts as the gateway.
Connection to the edge gateway.
An Ethernet cable connects the Access Gate to the edge gateway.
A secure traffic loop.
This is the low-impact option. Traffic to sensitive machines loops through the Access Gate for inspection and control. No VLAN changes.
Routes on the edge gateway.
In the low-impact option, routes added at the edge gateway send critical traffic through the Access Gate. No VLAN changes needed.
Remote sessions pass a checkpoint.
North-south flows are inbound VPN sessions to IT or OT machines. The Access Gate stops each session, checks identity and permissions, and logs every action.
VPN to IT (north-south).
The VPN client connects to the Access Gate. The Access Gate then opens a second connection to the local IT machine. It acts as a bastion, with double NAT and session logging.
VPN to OT (north-south).
Remote OT access follows the same bastion path. Users authenticate before they reach any OT subnet.
Authentication and permissions.
MFA can be required. Access rules are scoped to specific resources, protocols and actions. Every action is logged.
Protocol analysis.
The Access Gate inspects each session at protocol level. It breaks the session for analysis before forwarding it.
Control traffic between machines.
East-west flows are lateral traffic between machines on the LAN. Routing them through the Access Gate applies Zero Trust inside the plant. You can limit it to critical machines.
IT to OT (east-west).
IT to OT traffic is routed through the Access Gate. A protocol break applies, and there is no direct layer 2 path between the domains.
OT to OT (east-west).
Lateral traffic between OT machines goes through the overlay. Each session between two machines is authenticated and logged.
Double NAT and session logs.
The Access Gate applies double NAT at both ends of each connection. Every session leaves a full audit trail.
Protocol break.
Sessions are broken and rebuilt through the Access Gate. This enables DPI, logging and control at the application layer.
Download the one gateway architecture.
Get all five diagrams in one pack: base topology, VPN flows and east-west flows.
Two gateway layers.
Need separate control zones for IT and OT? The two-layer design adds a second layer for critical OT networks.
Multi-site.
Running several plants? The multi-site design shows how enclaves extend between plants over secure tunnels.
One Gateway Architecture.
One Gateway Architecture: Video Walkthrough
See how a single Access Gate deploys on your network to enforce Zero Trust across IT and OT, without changing your existing infrastructure.
Request a DemoQuestions about the one gateway design.
Access Gate needed. This design uses one appliance connected to your edge gateway.
No. Your router, firewall and switches stay. In the low-impact option, one extra route creates the secure loop. Only selected traffic passes through the Access Gate for identity checks and inspection. Your existing policies do not change. For fuller coverage, run the Access Gate in-line so it carries your VLANs and trunks and acts as the gateway.
The secure loop is one routed path set on the edge gateway. It sends selected traffic through the Access Gate for authentication, checks and logging before it reaches its destination. It works as a checkpoint, so you do not redesign the network.
Yes. One Access Gate covers IT and OT subnets at the same time. You can also start with OT only and add IT later.
It keeps its current path, unchanged. You choose which flows the Access Gate controls, so you can move step by step without stopping production.