TroutTrout

Industrial DMZ Design Patterns.

From flat networks to proxy-based segmentation, architectures that protect legacy OT without replacing equipment.

Zuletzt aktualisiert:

Industrial Networks Were Built for Reliability, Not Security

Early automation networks were closed, purpose-built ecosystems. When Ethernet and TCP/IP entered plants, they were overlaid onto environments that retained their original assumptions, stability and availability above all.

The Traditional DMZ Became a Shared Services Zone

Originally designed for a narrow problem, the Level-3.5 DMZ accumulated responsibilities it was never built to carry, historians, patch servers, remote access tools, gradually forming another trusted environment with its own complexity.

Security Depended on Configuration Discipline

As industrial connectivity expanded, the centralized DMZ became a convergence point for unrelated workflows. Architectural clarity gave way to operational convenience. Security became a matter of configuration hygiene.

Der vertrauenswürdige Pfad ist der exponierte Pfad

Ein großer Teil der tatsächlichen OT-Exposition verläuft über autorisierte Engineering- und Dienstleisterpfade, die vertrauenswürdige Wartungsverbindung, die Remote-Support-Sitzung, den Jump-Host, und nicht über einen unbefugten Netzwerkeinbruch. Genau diesen Pfad lässt eine gemeinsame DMZ durch.

From Boundaries to Interaction Control

Industrial Security Risk Is Defined by Interactions, Not Asset Location.

A controller sharing telemetry carries fundamentally different risk than that same controller accepting configuration changes, even if both occur over the same network segment.

Operational Context Matters

Die Absicht zu verstehen ist wichtiger, als die Topologie abzubilden. Ein Modbus-FC3-Lesevorgang von Holding-Registern über TCP 502 und ein Logik-Download über dieselbe S7comm-Sitzung auf TCP 102 nehmen denselben Pfad, tragen aber ein gegensätzliches Risiko. Sicherheit muss bewerten, was eine Verbindung auf der Ebene des Funktionscodes tut, nicht nur, wohin sie geht.

Segmentation Alone Is Insufficient

Network boundaries reduce exposure but cannot distinguish acceptable from unsafe connectivity. Effective security requires mediation, explicit, constrained, purpose-aligned exchanges.

Infrastructure Evolves Toward Controlled Movement

Transportation networks rely on signaling and checkpoints to regulate behavior without redesigning the roads. Industrial cybersecurity follows the same principle: supervise interactions, don't attempt to separate systems entirely.

The Architecture

A Distributed Mediation Layer.

Security Introduced at the Moment of Interaction.

Die Industrial DMZ muss sich zu einer verteilten Kontrollschicht entwickeln, die Interaktionen zwischen Systemen vermittelt und diese Systeme dabei grundlegend unverändert lässt. Sicherheit wird durch sorgfältig platzierte Durchsetzungspunkte eingeführt, die den betrieblichen Charakter industrieller Infrastruktur respektieren. Der zyklische Verkehr zwischen Controller und I/O bleibt im Underlay; nur routbare Sitzungen aus Leitwarte, Engineering und von Dienstleistern werden vermittelt, sodass die deterministische Regelschleife nie im Durchsetzungspfad liegt.

DISTRIBUTED MEDIATION — EACH INTERACTION GOVERNEDINLINE MEDIATIONPLC-1ENFORCEACTIVEINLINE MEDIATIONHMI-2ENFORCEACTIVEINLINE MEDIATIONRTU-3ENFORCEACTIVEINLINE MEDIATIONSCADAENFORCEACTIVEINLINE MEDIATIONHISTENFORCEACTIVEINLINE MEDIATIONSIS-4ENFORCEACTIVEXXXXXXXMEDIATION LAYER STATUS6 ASSETS GOVERNEDNETWORK TOPOLOGY: UNCHANGED
Design Patterns

Four Patterns for Securing OT Without Redesign.

Inline Mediation

Same path, different risk: inline mediation conceptual diagram
Whitepaper

Download the Full Design Patterns Guide.

Get the complete guide: the limits of the traditional DMZ, four design patterns for proxy-based segmentation, and how to apply Zero Trust principles without altering plant networks.

Fertig

What You'll Learn

How industrial networks came to look the way they do. Why the centralized DMZ concept fails at scale. Four design patterns, inline mediation, functional segmentation, overlay connectivity, and operational observability, that introduce control without operational disruption.

9 pages

Apply It With Access Gate

Access Gate setzt alle vier Entwurfsmuster aus einer einzigen Appliance um. Die Platzierung ist eine bewusste, standortspezifische Entscheidung: standardmäßig als Overlay neben dem Netzwerk oder inline, wo eine stärkere, nicht umgehbare Durchsetzung erforderlich ist. Kein Netzwerk-Redesign, keine Agenteninstallation, keine Änderungen an bestehenden OT-Assets.

Request a Demo
FAQ

Common Questions About Industrial DMZ Design.

4

design patterns for securing OT environments. Each addresses a distinct architectural challenge: deployment, segmentation, overlay, and observability.

Inline-Vermittlung platziert einen transparenten Durchsetzungspunkt auf dem Pfad zwischen zwei kommunizierenden Systemen, ohne eines von beiden neu zu konfigurieren. Es ist eine von zwei Platzierungen: Das benachbarte Overlay ist der Standard, und inline wird dort gewählt, wo die Durchsetzung unmöglich zu umgehen sein muss. In OT-Umgebungen, in denen Ausfallzeiten inakzeptabel sind und Anlagenlebenszyklen sich über Jahrzehnte erstrecken, ist das wichtig, weil Sicherheit in bestehende Signalpfade eingeführt werden kann, genau so, wie Industrieanlagen bereits Instrumentierung und Sicherheitsverriegelungen hinzufügen, ohne den Prozess zu stören.

VLAN-based segmentation divides address spaces. Functional segmentation defines policy based on operational intent. A maintenance session, a telemetry feed, and a configuration update may traverse the same physical cable, but they carry fundamentally different risk. Functional segmentation allows policy to describe which operational actions are permitted under which circumstances, not just which subnet may speak to another.

An overlay adds an additional logical layer that governs trust relationships without altering physical infrastructure. Switching, routing, IP addressing, and VLANs remain completely unchanged. Access Gate establishes authenticated, encrypted communication paths as an overlay, leaving the existing network exactly as it is while adding identity and policy enforcement above it.

Yes. The four design patterns described in this whitepaper support compliance through mediation rather than migration. Inline enforcement provides the access control and audit trail required by NIS2 and CMMC. Functional segmentation supports IEC 62443 zone and conduit models. All without requiring infrastructure redesign or equipment replacement.

Correct. The inline mediation pattern requires no modification to endpoints, legacy PLCs, HMIs, RTUs, and SCADA systems that cannot run modern security software are protected through the proxy layer. The OT asset communicates exactly as it always has; enforcement happens at the Access Gate, not on the device itself.