Access Gate — Carve In / Carve Out
How to selectively enroll devices onto the Access Gate overlay, and how to roll devices back to the physical network without disrupting production.
Zuletzt aktualisiert:
Carve-in and carve-out is how you adopt the Access Gate overlay at your own pace. You carve a device in to enroll it onto the identity-enforced overlay, and carve it out to return it to the physical network, one asset at a time, with production running throughout.
This makes rollout reversible and low-risk. You can start with a handful of assets, validate behavior, and expand, or pull a device back instantly if a maintenance window requires it. There is no big-bang cutover and no point where the plant has to stop.
What this video covers
- What carve-in (enroll) and carve-out (roll back) actually do
- Adopting the overlay one asset at a time, with production running
- Making rollout reversible and low-risk, with no big-bang cutover
- Pulling a device back to the physical network on demand
Millbrook Machine reached CMMC Level 1 in 4 days on-site with zero production disruption.
- 4 days from first site visit to a fully compliant environment
- 100% IT and OT coverage on a single policy, including foreign-sourced production machines
- 0 production disruption: deployed alongside the running MikroTik infrastructure
Questions and answers
What does carve-in and carve-out mean?
Carve-in enrolls a device onto the Access Gate overlay; carve-out returns it to the physical network. Both happen per asset, without disrupting production, so adoption and rollback are incremental.
Can I roll a device back if something goes wrong?
Yes. Carve-out returns a device to the underlay network immediately, so a maintenance window or an issue never requires unwinding the whole deployment.
Do I have to migrate everything at once?
No. You can carve in a few assets, validate, and expand. There is no big-bang cutover and no point where the plant has to stop.
See Access Gate in Your Environment.
The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.




