Separate IT from OT. Your network stays as it is.
Trout Access Gate is an on-premise appliance that builds an industrial DMZ between your office network and the plant floor. Only approved traffic crosses the IT/OT boundary, so a hacked laptop cannot reach production machines.
Last updated:

Why flat OT networks fail at the IT/OT boundary.
Most plants still run a flat or lightly segmented network: the historian, the engineering workstation, the SCADA server, and the PLCs sit where a single compromised host can reach the control layer directly. That is what years of adding connectivity to a network built for reliability, not security, leaves behind.
An industrial DMZ is meant to sit between enterprise IT and OT at Level 3.5, brokering only the few flows that legitimately cross: the historian feed, patch distribution, remote access. In practice it accumulates services and exceptions until it becomes another trusted zone, and the boundary quietly erodes.
That is the risk surface attackers use. Most OT incidents start not on a PLC but on a phished workstation or an over-permissioned vendor connection, then move down into the control network. Closing the gap is less about another firewall than about controlling which zones may talk to which, with an identity behind every session.
IEC 62443 zones and conduits, applied to the iDMZ.
IEC 62443 makes the DMZ enforceable. A zone is a group of assets sharing a security level; a conduit is the controlled path between zones that defines exactly which traffic may cross. An industrial DMZ is the conduit between the enterprise and OT zones, and the standard is clear that naming the zones is the easy part.
The hard part is implementing the conduits on a network that is already running. Traditionally that means a VLAN redesign: re-addressing equipment, reconfiguring switches, and taking production down for the cutover. For most operators that downtime is the blocker that keeps a flat network flat, and the iDMZ stays a diagram rather than an enforced boundary.
An industrial DMZ without re-architecting the network.
Deploy beside the network, with no disruption.
Access Gate deploys alongside the existing network at the Level 3.5 boundary and creates a proxy-mediated DMZ overlay across the zones. No VLAN changes, no agents on PLCs or OT endpoints, no production downtime. Cross-zone traffic is brokered through authenticated proxies, and visibility and identity-based access control are live in a day.
Consolidate behind the gate.
The overlay becomes the enforcement layer. Systems migrate behind the gate through its proxy, with no forklift replacement of switches, and Access Gate becomes the iDMZ: deep packet inspection on industrial protocols, policy per user, device, and protocol, and a tamper-evident session log. It takes days. A traditional consolidation project takes months.
IEC 62443 and NIST SP 800-82, evidenced continuously.
The proxy-mediated DMZ maps directly onto the technical controls NIST SP 800-82 describes for OT: network segmentation (zones and conduits without rewiring), access control (identity-based, MFA enforced at the proxy, least privilege per asset and protocol), and logging (every cross-zone session recorded with user, timestamp, and protocol in a tamper-evident trail).
IEC 62443 zone-and-conduit architecture is the recognized technical implementation of those controls, and NIST SP 800-82 points to it as the model for demonstrating segmentation. Access Gate produces that evidence continuously, from the first session, instead of reconstructing it the week before an audit.
Where the iDMZ pattern fits.
A plant with no maintenance window.
A site that has postponed segmentation for years because it meant a firewall rewrite and production downtime. The overlay brings the IT/OT boundary under control in a day, with the physical network untouched, then consolidates behind the gate over the following days.
Learn moreMachines from many vendors.
A group running Siemens at one plant, Rockwell at the next, and Schneider at a third cannot standardise on any vendor's tooling. The DMZ overlay is vendor-agnostic: it enforces zones and conduits at the network layer above whatever PLCs and protocols each site runs, with central policy across all of them.
Learn moreSafe vendor access into OT.
Third-party access is the most common way the boundary is crossed. The iDMZ brokers every vendor session through an authenticated proxy, scoped to a single asset and protocol and fully recorded, so remote work never means a route into the flat network.
Learn moreA clear boundary between IT and OT.
Access Gate makes an industrial DMZ practical. No network redesign, no production impact, no specialist needed.
Your LAN stays as it is.
DMZ controls sit on top of the network you already have.
Every crossing goes through a proxy.
Traffic between zones passes an authenticated proxy. Machines stay hidden from unauthorized users.
It reads industrial traffic.
It inspects industrial protocols packet by packet.
Old machines are covered.
PLCs, HMIs, SCADA and DCS are protected with no change to the equipment.
Every flow is explicit.
Each path is defined, one-way where needed, and logged.
You decide who reaches what.
Set access per user, device and protocol, across every zone boundary.
Download the Access Gate Datasheet.
Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.
What's Inside
Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.
See It in Action
Request a live demo to see how the Access Gate deploys on your network without rewiring or downtime.
Questions about the industrial DMZ.
Network changes required. Access Gate draws the boundaries at the application layer, without touching VLANs, firewalls or cabling.
No. The Access Gate creates logical segmentation at the application layer, overlaying your existing network. There's no VLAN restructuring, no firewall reconfiguration, and no production impact. You can deploy and enforce zone boundaries without any downtime.
Traditional firewalls segment at the network layer and require topology changes. The Access Gate segments at the application layer, it can enforce per-user, per-device, per-protocol policies without changing your physical or logical network design. This makes it practical to deploy in brownfield environments.
Yes. The Access Gate protects devices without installing anything on them. PLCs, HMIs, SCADA systems, and DCS controllers are protected through proxy bastions that mediate all access, the legacy equipment doesn't need to support modern security protocols.
A proxy bastion is an authenticated gateway that mediates all traffic crossing a zone boundary. Users and devices must authenticate before traffic is forwarded. The bastion also performs deep packet inspection on industrial protocols and records full session logs for audit.
Yes. The Access Gate operates entirely on-premise with no cloud dependency. It's designed for air-gapped, hybrid, and classified environments where data cannot leave the network perimeter.
The proxy-mediated DMZ delivers the network segmentation, access control, and logging that NIST SP 800-82 recommends for OT, and it implements the IEC 62443 zone-and-conduit model directly. Every cross-zone session is brokered by identity and recorded in a tamper-evident log, so audit evidence is generated continuously rather than reconstructed before an inspection.