TroutTrout

Industrial DMZ design patterns. Protect legacy OT without a redesign.

Four architectures, from flat networks to proxy-based segmentation. Each one protects legacy OT without replacing equipment.

Last updated:

Industrial networks were built for reliability first.

Early automation networks were closed, purpose-built ecosystems. When Ethernet and TCP/IP entered plants, they were overlaid onto environments that retained their original assumptions, stability and availability above all.

The traditional DMZ became a shared services zone.

The Level-3.5 DMZ was designed for a narrow problem. It then took on jobs it was never built to carry: historians, patch servers and remote access tools. It slowly became another trusted environment with its own complexity.

Security came to depend on configuration discipline.

As industrial connectivity expanded, the centralized DMZ became a convergence point for unrelated workflows. Architectural clarity gave way to operational convenience. Security became a matter of configuration hygiene.

Most exposure runs through trusted access paths.

Much of the real OT exposure runs through authorized engineering and vendor paths. Think of the trusted maintenance connection, the remote support session and the jump host. Unauthorized network intrusion is a smaller part of it. A shared DMZ waves these trusted paths straight through.

From boundaries to interaction control

Risk depends on what a connection does.

A controller sharing telemetry carries fundamentally different risk than that same controller accepting configuration changes, even if both occur over the same network segment.

Operational context matters.

Understanding intent matters more than mapping topology. A Modbus FC3 read of holding registers over TCP 502 and a logic download over the same S7comm session on TCP 102 travel the identical path but carry opposite risk. Security must evaluate what a connection does at the function-code level, not just where it goes.

Segmentation alone is not enough.

Network boundaries reduce exposure. They cannot tell acceptable connectivity from unsafe connectivity. Effective security needs mediation: explicit, constrained exchanges with a clear purpose.

Supervise interactions instead of separating systems.

Transport networks use signals and checkpoints to regulate traffic without redesigning the roads. Industrial cybersecurity follows the same principle. Supervise interactions instead of trying to separate systems entirely.

The architecture

A distributed mediation layer.

Security applies at the moment of interaction.

The industrial DMZ must become a distributed control layer. It mediates interactions between systems and leaves those systems unchanged. Enforcement points are placed with care, so they respect how industrial infrastructure runs. Cyclic controller-to-I/O traffic stays on the underlay. Only routable supervisory, engineering and vendor sessions are mediated. The deterministic control loop is never in the enforcement path.

DISTRIBUTED MEDIATION · EACH INTERACTION GOVERNEDINLINE MEDIATIONPLC-1ENFORCEACTIVEINLINE MEDIATIONHMI-2ENFORCEACTIVEINLINE MEDIATIONRTU-3ENFORCEACTIVEINLINE MEDIATIONSCADAENFORCEACTIVEINLINE MEDIATIONHISTENFORCEACTIVEINLINE MEDIATIONSIS-4ENFORCEACTIVEXXXXXXXMEDIATION LAYER STATUS6 ASSETS GOVERNEDNETWORK TOPOLOGY: UNCHANGED
Design patterns

Four patterns to secure OT without a redesign.

Session mediation

Same path, different risk: session mediation conceptual diagram
Whitepaper

Download the full design patterns guide.

Get the complete guide: the limits of the traditional DMZ, four design patterns for proxy-based segmentation, and how to apply Zero Trust principles without altering plant networks.

Done

What you'll learn

How industrial networks came to look the way they do. Why the centralized DMZ fails at scale. Four design patterns that add control without disrupting operations: session mediation, functional segmentation, overlay connectivity and operational observability.

9 pages

Apply it with Access Gate.

Access Gate implements all four design patterns from one appliance. It connects to your existing network, and you steer through it the flows you want protected, one site at a time. No network redesign, nothing to install on machines, no changes to existing OT assets.

Request a demo
FAQ

Common questions about industrial DMZ design.

4

design patterns for securing OT environments. Each addresses a distinct architectural challenge: deployment, segmentation, overlay, and observability.

Session mediation places a transparent enforcement point on the path between two systems, without reconfiguring either one. Access Gate connects to your existing network, and only the flows you steer through it are mediated. In OT, downtime is unacceptable and equipment lasts decades. Mediation adds security to existing signal paths without disrupting the process. Plants already add instrumentation and safety interlocks the same way.

VLAN-based segmentation divides address spaces. Functional segmentation defines policy based on operational intent. A maintenance session, a telemetry feed, and a configuration update may traverse the same physical cable, but they carry fundamentally different risk. Functional segmentation allows policy to describe which operational actions are permitted under which circumstances, not just which subnet may speak to another.

An overlay adds an additional logical layer that governs trust relationships without altering physical infrastructure. Switching, routing, IP addressing, and VLANs remain completely unchanged. Access Gate establishes authenticated, encrypted communication paths as an overlay, leaving the existing network exactly as it is while adding identity and policy enforcement above it.

Yes. The four design patterns in this whitepaper support compliance through mediation rather than migration. Session mediation provides the access control and audit trail that CMMC and NERC CIP require. Functional segmentation supports the IEC 62443 zone and conduit model. Neither requires an infrastructure redesign or equipment replacement.

Yes. The session mediation pattern requires no change to endpoints. Legacy PLCs, HMIs, RTUs and SCADA systems that cannot run modern security software are protected through the proxy layer. The OT asset communicates exactly as it always has. Enforcement happens at Access Gate, not on the device itself.