TroutTrout
Access Gate Architecture

Access Gate — Modern Industrial DMZ

Replace the firewall-based iDMZ with per-asset micro-DMZs enforced by Trout Access Gate proxies. Protocol-aware filtering, deny-by-default, identity-bound rules, deployed without rewiring the Purdue hierarchy.

Zuletzt aktualisiert:

The modern industrial DMZ replaces a single firewall-based iDMZ with per-asset micro-DMZs enforced by Trout Access Gate proxies. Instead of one broad zone between IT and OT, each asset gets its own deny-by-default boundary with protocol-aware filtering and identity-bound rules.

Because the proxies are non-inline and ride on the existing network, you get this without rewiring the Purdue hierarchy, re-IPing assets, or taking production down. Traffic to a controller is allowed only for the identities, protocols, and commands you specify, and everything else is denied and logged.

What this video covers

  • Why a single iDMZ is coarse and how per-asset micro-DMZs tighten it
  • Deny-by-default, protocol-aware, identity-bound rules at each asset
  • Getting there without rewiring the Purdue model or re-IPing assets
  • How every allowed and denied crossing is recorded for audit

Protocol and vendor coverage

Micro-DMZ rules are protocol-aware, so you can allow a protocol while constraining what it may do, down to the command and register. Access Gate covers every industrial protocol and therefore every vendor: Modbus and Modbus TCP, DNP3, OPC UA, EtherNet/IP, PROFINET, Siemens S7, IEC 61850, and MQTT, across 50+ OT and ICS vendors including Siemens, Rockwell Automation (Allen-Bradley), Schneider Electric, Mitsubishi Electric, and Beckhoff.

Proven in production

Irish Manufacturing Research validated Access Gate as a reference implementation of overlay security for brownfield OT.

  • 5 protocols proven at the workflow level: Modbus TCP, OPC UA, MQTT, web, and RDP
  • 0 underlay changes: no agents on legacy devices, no re-IPing of production assets
  • One evidence base mapped to NIS2, IEC 62443, and ISO/IEC 27001
Read the case study

Questions and answers

What is a modern industrial DMZ?

It replaces a single firewall-based iDMZ with per-asset micro-DMZs. Each asset gets its own deny-by-default, protocol-aware, identity-bound boundary enforced by a proxy, instead of relying on one broad zone.

Do I have to rewire the Purdue model?

No. The proxies are non-inline and run on the existing network, so per-asset micro-DMZs are added without rewiring Purdue levels or re-IPing assets, and without downtime.

Is filtering protocol-aware?

Yes. Rules are applied at the application layer, so you can allow a protocol such as Modbus or [OPC UA](/docs/detailed-use-cases/configure-opc-ua) while denying specific commands, rather than opening a port wholesale.

Talk to an Engineer

See Access Gate in Your Environment.

The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.