TroutTrout

Compare Access Gate and VLANs.

VLANs need switch reconfiguration, recabling and downtime. Overlay networking deploys on top of your existing network in a day. You get the same segmentation with a fraction of the effort.

The problem

You can segment without rewiring.

Standards and regulations such as IEC 62443, NERC CIP and CMMC require network segmentation in OT. The traditional approach is VLAN-based segmentation. It means weeks of planning, switch reconfiguration, physical recabling and production downtime. For a large plant, a VLAN migration can mean long downtime windows and lost production.

Trout Access Gate

Overlay networking defines segments in software.

Trout overlay networking creates logical segments on top of your existing physical network. No switch reconfiguration, no cable changes, no downtime. Segments are defined by identity and policy rather than physical port assignments. Deploy across an entire facility in a day and manage all sites from a single console.

VLANs

VLANs need physical and logical reconfiguration.

VLANs segment networks by configuring switches and routers to isolate traffic into separate broadcast domains. This means planning the VLAN topology, reconfiguring every switch, recabling devices to the right ports and testing. Production is interrupted during cutover windows.

Feature comparison
FeatureAccess GateVLANs
Network segmentation
Deployment time
A day
Weeks to months
Requires recabling
Production downtime
During cutover
Identity-based access
Port-based only
OT protocol awareness
Scales across sites
Centralized policy
Complex per-site config
Change management overhead
Low
High, network-wide impact
Works on flat networks
Requires network redesign
Audit trail
Full session logging
Limited to ACL logs
Key differences

Deployment needs no downtime.

Overlay networking deploys on top of your existing network without any physical changes. There is no cutover window, no production stoppage, and no risk of miscabled connections.

Segments follow the device.

VLANs tie segmentation to physical switch ports. Move a device and you break its network assignment. Overlay segments are defined by device identity and policy, so segmentation follows the device regardless of where it connects on the physical network.

The same rules at every site.

Managing VLANs across multiple sites means duplicating configuration on every switch at every location. Overlay networking applies consistent segmentation policies across all sites from a single management console, reducing configuration drift and administrative overhead.

Questions

Questions about Access Gate and VLANs.

Not necessarily. Overlay networking can work alongside existing VLANs. If you already have some VLAN segmentation in place, the overlay adds finer-grained micro-segmentation and identity-based policies on top. For greenfield deployments or flat networks, the overlay can provide all segmentation without any VLAN configuration.

Yes. The overlay operates at a logical layer above your physical network. Existing VLANs continue to function normally. The overlay adds additional segmentation and access control without interfering with your current VLAN topology or switch configuration.

Yes. Overlay networking provides network segmentation that meets the requirements of IEC 62443 zones and conduits and NERC CIP network isolation standards. It meets the same compliance bar as VLANs, with identity-based enforcement and full audit trails on top.

Access Gate is installed in a day, and a typical facility is segmented within days, depending on size and complexity. This compares to weeks or months for VLAN-based approaches. Because there is no recabling or switch reconfiguration, the deployment does not require maintenance windows or production shutdowns.

Keep comparing

Also looking at cloud security tools?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.