Protect IT and OT with two gateway layers.
This design has two variants. Protect IT and OT subnets separately, or focus control on OT alone. Every traffic path has its own diagram.
How this design works.
This design builds on the one gateway design with two coverage modes. In IT and OT mode, the Access Gate protects both domains. In OT-only mode, it focuses on the machines of the plant floor. In-line, it carries your VLANs and trunks, which is the fuller default. A secure loop stays available as the low-impact option. The same appliance also hosts remote access, protocol gateways, DNS and time, file sharing, a historian, dashboards and an update server.
IT and OT coverage.
One Access Gate applies policy across all subnets. IT and OT are protected at the same time.
OT-only coverage.
The Access Gate focuses on OT bus traffic. IT traffic keeps going through the existing firewall, unchanged.
Your current network stays.
Want the lightest change? Router, firewall and switches stay as they are, and the Access Gate works through a secure loop. In-line, it carries the VLANs and trunks directly.
You choose what passes through.
Non-critical traffic can bypass the Access Gate. Only sensitive flows need to pass through it.
Two ways to set the scope.
Two base topologies cover two scopes. Choose IT and OT coverage to control the whole perimeter. Choose OT only when existing tools already handle IT.
Connection to an existing gateway.
For fuller coverage, the Access Gate runs in-line and carries the local VLANs and trunks as the gateway. It can also connect beside the edge or OT gateway, with no changes to existing equipment.
Routes on the gateway.
In the low-impact option, routes added at the edge or OT gateway send traffic for sensitive machines through the Access Gate. No VLAN changes.
IT and OT mode.
Both IT and OT subnets are covered. All cross-domain and VPN traffic passes through the Access Gate.
OT-only mode.
Only OT traffic goes through the Access Gate. IT traffic is not affected.
Remote sessions pass a checkpoint.
North-south flows are inbound VPN sessions. The Access Gate intercepts VPN sessions to IT and to OT. It checks identity and analyses the protocol before it opens the second leg of the connection.
VPN to IT machines.
IT VPN traffic goes through the Access Gate with double NAT. Each session is logged and analysed before it reaches its destination.
VPN to OT machines.
OT VPN access goes through the Access Gate. MFA can be required. Each session reaches specific OT resources only.
A bastion with double NAT.
The Access Gate acts as a bastion host, with double NAT at both ends of the connection. Encryption and session recording are available.
Access limited to what is needed.
Inside the LAN, access is granted to specific machines or groups, protocols and actions.
Control traffic between machines.
Three diagrams cover lateral traffic: IT to OT, OT to OT across subnets, and OT to OT inside one VLAN. The Access Gate controls each one differently.
IT to OT (east-west).
Traffic from IT to OT goes through the Access Gate. The Access Gate acts as a proxy between the two machines.
OT to OT across subnets.
Lateral OT traffic between subnets goes through the Access Gate. Each session is authenticated and logged.
OT to OT inside one VLAN.
Traffic inside one VLAN is controlled with overlay addresses. The Access Gate can place a proxy even inside a single VLAN.
Non-critical traffic can bypass.
Traffic that is not sensitive can skip the Access Gate. Only critical and CUI flows need to pass through it.
Download the two gateway layers architecture.
Get all seven diagrams in one pack: base topologies, VPN flows and east-west flows.
One gateway.
Want a simpler start? One Access Gate covers IT and OT and connects to your existing network. Your perimeter does not change.
Multi-site.
Running several plants? The multi-site design shows how enclaves extend between plants over secure tunnels.
Multiple Gateway Architecture.
Multiple Gateway Architecture: Video Walkthrough
See how two Access Gates create layered defense-in-depth with separate enforcement zones for IT and OT networks.
Request a DemoQuestions about the two-layer design.
ways to deploy: IT and OT together, or OT only when IT is already covered.
In IT and OT mode, the Access Gate applies policy on all subnets. In OT-only mode, only OT bus traffic goes through it, and IT traffic keeps using the existing firewall. Teams often choose OT only when IT already has mature controls.
Yes. Routes on the core bus and OT bus decide which flows pass through the Access Gate. Non-critical traffic can stay on its current path. Only sensitive or CUI traffic needs to go through the overlay.
The Access Gate uses overlay addresses for machines that share a physical VLAN. Traffic routed through the overlay leaves the broadcast domain. The Access Gate can then apply a policy to each session.
No. One Access Gate handles both IT and OT. The two layers are two control zones, IT and OT, on the same appliance. That appliance also runs the plant's secure services.