TroutTrout
Access Gate Architecture

Overlay Networking — Trout Access Gate

How Trout Access Gate creates an identity-enforced overlay network on top of the existing LAN without touching IP addressing, VLANs, or firewall rules. Non-inline deployment means zero production risk.

Zuletzt aktualisiert:

Overlay networking is how Trout Access Gate secures an existing industrial network without changing it. The Access Gate is a non-inline appliance that builds an identity-enforced overlay on top of the LAN you already run, so IP addressing, VLANs, and firewall rules stay exactly as they are. Because nothing sits in the production path, there is no re-IPing, no rewiring, and no downtime to turn it on.

Every device you enroll onto the overlay reaches other assets through the proxy, where access is bound to identity, scoped per asset and protocol, and recorded. Devices that are not enrolled keep communicating exactly as before, so you can adopt the overlay one machine at a time and roll any device back to the physical network without disrupting production.

What this video covers

  • Why an identity-enforced overlay sits on top of the existing LAN instead of replacing it
  • How non-inline deployment removes production risk: no inline choke point, no downtime
  • What stays untouched: IP addressing, VLANs, and existing firewall rules
  • How identity, per-asset scoping, and full session recording are enforced at the proxy
  • Carve-in and carve-out: enrolling assets and rolling them back without disruption

Protocol and vendor coverage

Because enforcement happens at the proxy rather than on the device, the overlay works with every industrial protocol, and therefore every vendor. Coverage includes Modbus and Modbus TCP, DNP3, OPC UA, EtherNet/IP, PROFINET, Siemens S7, IEC 61850, and MQTT, across 50+ OT and ICS vendors such as Siemens, Rockwell Automation (Allen-Bradley), Schneider Electric, Mitsubishi Electric, and Beckhoff. Legacy controllers that can never run an agent are protected the same way as modern ones.

Proven in production

Irish Manufacturing Research validated Access Gate as a reference implementation of overlay security for brownfield OT.

  • 5 protocols proven at the workflow level: Modbus TCP, OPC UA, MQTT, web, and RDP
  • 0 underlay changes: no agents on legacy devices, no re-IPing of production assets
  • One evidence base mapped to NIS2, IEC 62443, and ISO/IEC 27001
Read the case study

Questions and answers

What is overlay networking in OT?

Overlay networking runs a secure, identity-enforced network on top of the existing LAN. Trout Access Gate builds the overlay from a non-inline appliance, so IP addressing, VLANs, and firewall rules stay unchanged and there is no downtime to deploy it.

Does the overlay change my IP addressing or VLANs?

No. The overlay sits on top of the network you already run. Production IP addressing, VLANs, and firewall rules are untouched, which is why deployment carries no production risk.

Which protocols and vendors does it support?

All industrial protocols, and therefore all vendors. Coverage includes Modbus, DNP3, [OPC UA](/docs/detailed-use-cases/configure-opc-ua), EtherNet/IP, PROFINET, Siemens S7, IEC 61850, and [MQTT](/docs/detailed-use-cases/configure-mqtt) across 50+ OT and ICS vendors, because enforcement happens at the proxy rather than on the device.

Can I roll a device back off the overlay?

Yes. Assets are enrolled (carve-in) and removed (carve-out) individually, so you can adopt the overlay one machine at a time and roll any device back to the physical network without disrupting production.

Talk to an Engineer

See Access Gate in Your Environment.

The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.