What is an industrial proxy?
A security proxy built for OT: it brokers every session in front of the PLC, understands industrial protocols, needs no agent on the device, and is engineered to minimize impact on uptime, with failover and a break-glass path.
An industrial proxy sits in the access path in front of an OT asset, terminates each session, authenticates the user, authorizes the specific command, and records it, before anything reaches the PLC, HMI, or SCADA server. It differs from a generic forward or reverse proxy in three ways that matter for OT: it is protocol-aware (Modbus, DNP3, and more), agentless on the asset, and built for resilience. Trout Software's Access Gate is an industrial proxy.
It sits in the remote and vendor access path, not in the live control loop. The local HMI-to-PLC polling never traverses it, so it adds no latency or jitter to the running process, and on-site operation continues if the gateway is offline.
What makes a proxy industrial?
A web proxy relays HTTP for browsers. An industrial proxy mediates access to controllers that were never meant to be reached, and cannot defend themselves. Four properties separate the two.
Protocol-aware
It parses OT protocols such as Modbus and DNP3 and enforces at the command and register level, not just the port.
Agentless on the asset
The PLC, HMI, or SCADA server installs nothing and never changes. All enforcement happens at the proxy.
Built for resilience
Because OT prioritizes uptime, it runs with failover and a break-glass path so it does not become a single point of failure for the running process.
Identity-bound and recorded
Every session is tied to an authenticated identity, restricted to what that identity may do, and recorded end to end for audit.
You cannot modernize every controller. You can put a modern proxy in front of it.
Most OT protocols have no native authentication or encryption, and most controllers cannot be patched to add it. Replacing them is a multi-decade program. An industrial proxy inserts modern identity, authorization, encryption, and audit in front of the existing asset, with no change to the controller and no downtime. It is the practical way to bring Zero Trust to a plant that cannot be rebuilt.
The industrial proxy, answered
An industrial proxy is a security proxy purpose-built for operational technology. It sits in the access path in front of a PLC, HMI, or SCADA server, terminates each session, authenticates the user, authorizes the specific command against policy, records it, and forwards only what is allowed. Unlike a generic web proxy, it understands OT protocols such as Modbus and DNP3, and it is built for resilience, with failover and a break-glass path, to minimize impact on uptime. Trout Software's Access Gate is an industrial proxy.
A forward proxy sits in front of clients and mediates their outbound requests; a reverse proxy sits in front of servers and mediates inbound requests to them. An industrial proxy is a mediating proxy in the access path: it terminates the session on both sides, so it acts as a bastion between the person or system requesting access and the OT asset. The difference that matters is not forward vs reverse, it is that the industrial proxy is protocol-aware for OT, agentless on the asset, and engineered for availability.
A forward proxy relays a client's requests to a destination on the client's behalf, commonly to filter or log outbound web traffic. OT does not need a generic forward web proxy. It needs a mediating industrial proxy that brokers access to specific assets, binds each session to an identity, restricts it to the exact protocol and command allowed, and records it, without installing anything on the controller.
No. A firewall, even an application-aware one, inspects and filters traffic between zones; it does not authenticate a person, bind the session to their identity, and record what they did. An industrial proxy decides whether this specific user, in this specific session, may send this specific command to this specific asset, right now, and keeps the full record. A firewall filters; a proxy mediates and attributes.
The PLC installs nothing. The industrial proxy stands in front of it: the operator or vendor connects to the proxy, which authenticates them, checks the specific Modbus or DNP3 request against policy, records the session, and forwards only authorized traffic to the controller. A twenty-year-old PLC that cannot run an agent gets identity-bound access, authorization, and audit it could never host itself.
Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.
OT runs through you, not around you.