TroutTrout
Access Gate Architecture

Access Gate — Two Gateway Architecture

Deploy Trout Access Gate as two appliances to enforce a boundary between IT and OT networks. Identity, encryption, and audit apply to every session traversing the boundary.

Zuletzt aktualisiert:

The two-gateway architecture places a Trout Access Gate on each side of the IT and OT boundary so that every session crossing between the two networks is brokered, not routed. Identity, encryption, and a full audit record apply to each connection, and neither network gets a flat route into the other.

This is how you enforce the IT/OT split without re-architecting either side. The gateways sit non-inline, enforce least-privilege access per asset and protocol, and record every crossing, so a compromise on the IT side has no path onto the plant floor and every OT-bound action is attributable.

What this video covers

  • Why a boundary needs brokering, not just a firewall rule
  • How the two gateways enforce identity, encryption, and audit on every crossing
  • Keeping IT and OT split without re-architecting either network
  • What an attacker on the IT side can and cannot reach

Protocol and vendor coverage

Every session that crosses the boundary is inspected at the application layer, so the gateways understand the industrial protocols in use rather than passing opaque traffic. That spans Modbus and Modbus TCP, DNP3, OPC UA, EtherNet/IP, PROFINET, Siemens S7, IEC 61850, and MQTT, across 50+ OT and ICS vendors, from Siemens and Rockwell Automation to Schneider Electric, Mitsubishi Electric, and Beckhoff.

Proven in production

Thales deployed Access Gate Enterprise to enforce Zero Trust boundaries in restricted environments.

  • 4 hours to deploy per environment, from installation to full Zero Trust enforcement
  • 2 years in stable production across multiple homologated environments
  • 0 cloud dependencies: fully sovereign, all data stays on-premise
Read the case study

Questions and answers

What is the two-gateway Access Gate architecture?

It deploys one appliance on each side of the IT/OT boundary so every session crossing between them is brokered by identity, encrypted, and recorded, with no flat route between the networks.

How is this different from an IT/OT firewall?

A firewall filters addresses and ports. The two-gateway model brokers each session at the application layer, binds it to a verified identity, scopes it to one asset and protocol, and records it, so crossings are controlled and attributable rather than merely permitted.

Do the gateways sit in the production path?

No. They are non-inline, so they broker boundary sessions without becoming an inline choke point on either network.

Talk to an Engineer

See Access Gate in Your Environment.

The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.