Access Gate — One Gateway Architecture
The simplest Access Gate topology: a single non-inline appliance plugged into one switch port, creating an identity-enforced zero-trust overlay on the existing LAN without rewiring, downtime, or endpoint agents.
Zuletzt aktualisiert:
The one-gateway architecture is the simplest way to deploy Trout Access Gate. A single non-inline appliance plugs into one switch port and builds an identity-enforced zero-trust overlay across the existing LAN. Nothing is rewired, no endpoint agents are installed, and production keeps running while you turn it on.
From that one appliance you enroll assets onto the overlay, authenticate every user and device against your existing identity provider, and enforce least-privilege access per asset and protocol. It is the fastest path to Zero Trust on a flat OT network, and it grows into two-gateway and multi-site topologies later without redoing the work.
What this video covers
- Where the single appliance sits and why it is non-inline (no production choke point)
- How the overlay is built on the existing LAN with no rewiring and no agents
- Enrolling assets and enforcing identity-based, least-privilege access
- When to grow from one gateway to two-gateway or multi-site
Elna Magnetics secured 100% of its CUI data flows for CMMC Level 2 with a single appliance.
- 1 appliance on-site, connected to the existing Fortinet firewall
- 100% of CUI flows secured, including engineering workstations, file servers, and the production floor
- 0 production disruption: deployed without stopping a single machine
Questions and answers
What is the one-gateway Access Gate architecture?
It is the simplest deployment: a single non-inline appliance on one switch port that builds an identity-enforced overlay across the existing LAN, with no rewiring, no agents, and no downtime.
Does a single appliance mean a single point of failure?
The appliance is non-inline, so it is not in the production data path. If it is offline, unenrolled assets keep communicating on the physical network as before, and enrolled traffic follows your policy.
Can I start with one gateway and expand later?
Yes. The one-gateway topology grows into two-gateway (IT/OT boundary) and multi-site (federated, centrally managed) deployments without redoing the initial work.
See Access Gate in Your Environment.
The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.




