Access Gate — Modern Industrial DMZ
Replace the firewall-based iDMZ with per-asset micro-DMZs enforced by Trout Access Gate proxies. Protocol-aware filtering, deny-by-default, identity-bound rules, deployed without rewiring the Purdue hierarchy.
Zuletzt aktualisiert:
The modern industrial DMZ replaces a single firewall-based iDMZ with per-asset micro-DMZs enforced by Trout Access Gate proxies. Instead of one broad zone between IT and OT, each asset gets its own deny-by-default boundary with protocol-aware filtering and identity-bound rules.
Because the proxies are non-inline and ride on the existing network, you get this without rewiring the Purdue hierarchy, re-IPing assets, or taking production down. Traffic to a controller is allowed only for the identities, protocols, and commands you specify, and everything else is denied and logged.
What this video covers
- Why a single iDMZ is coarse and how per-asset micro-DMZs tighten it
- Deny-by-default, protocol-aware, identity-bound rules at each asset
- Getting there without rewiring the Purdue model or re-IPing assets
- How every allowed and denied crossing is recorded for audit
Protocol and vendor coverage
Micro-DMZ rules are protocol-aware, so you can allow a protocol while constraining what it may do, down to the command and register. Access Gate covers every industrial protocol and therefore every vendor: Modbus and Modbus TCP, DNP3, OPC UA, EtherNet/IP, PROFINET, Siemens S7, IEC 61850, and MQTT, across 50+ OT and ICS vendors including Siemens, Rockwell Automation (Allen-Bradley), Schneider Electric, Mitsubishi Electric, and Beckhoff.
Irish Manufacturing Research validated Access Gate as a reference implementation of overlay security for brownfield OT.
- 5 protocols proven at the workflow level: Modbus TCP, OPC UA, MQTT, web, and RDP
- 0 underlay changes: no agents on legacy devices, no re-IPing of production assets
- One evidence base mapped to NIS2, IEC 62443, and ISO/IEC 27001
Questions and answers
What is a modern industrial DMZ?
It replaces a single firewall-based iDMZ with per-asset micro-DMZs. Each asset gets its own deny-by-default, protocol-aware, identity-bound boundary enforced by a proxy, instead of relying on one broad zone.
Do I have to rewire the Purdue model?
No. The proxies are non-inline and run on the existing network, so per-asset micro-DMZs are added without rewiring Purdue levels or re-IPing assets, and without downtime.
Is filtering protocol-aware?
Yes. Rules are applied at the application layer, so you can allow a protocol such as Modbus or [OPC UA](/docs/detailed-use-cases/configure-opc-ua) while denying specific commands, rather than opening a port wholesale.
See Access Gate in Your Environment.
The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.




