TroutTrout
AI OT security · Firewall rule automation

Automate OT firewall rules from your LLM.

Access Gate Performance lets your LLM automate OT firewall rules: iterate in plain words, dry-run the config file, and a person pushes it to every plant at once. Every change is recorded and reversible.

Last updated:

Trusted by leading companies

John CockerillOrange CyberdefenseElna MagneticsThales
Change request · 6 plantsPerformance
Your request

Give the packaging line vendor SSH to every packaging PLC and HMI in all six plants, sign-in first, encrypted, until Friday.

230machines
6plants
1change to review

By hand: 230 rules, typed into 6 firewall consoles.

  1. 01Iterate with your LLMDone
  2. 02Dry-run the config file230 rules prepared
  3. 03Push the migrationWaiting for you
  4. 04LiveAll 6 plants

Why OT access rules fall behind

Every plant keeps its own firewall policy, written rule by rule in a firewall UI or CLI. Across many plants, one change takes weeks, and drift between plants sets in. So OT security ships late, and nobody is sure what is allowed.

From chat to the wire in four steps

How does LLM firewall rule automation work?

Your LLM works through admin access to the appliance. Nothing goes live until a person pushes it.

Diagram: four steps. Iterate with your LLM in plain words, dry-run the config file to see every rule first, push the migration once a person approves it, and the change is live on the wire. If the dry run is not right, go back and iterate. Every change lands in the enclave change history and can be rolled back.
  1. 01

    Iterate with your LLM.

    Describe the change in plain words, for example vendor access to 230 machines in six plants, and refine it until it says what you mean.

  2. 02

    Dry-run the config file.

    Your LLM prepares the configuration. The dry run shows every rule it would create before any of them exists. Not right? Go back to step one.

  3. 03

    Push the migration.

    A person approves the change and pushes it. Every plant gets it at once.

  4. 04

    Live.

    Access Gate enforces it on the wire. The change lands in the enclave change history, and you can roll it back.

What every rule carries

Is it safe to let AI change OT firewall rules?

Yes. Nothing goes live until a person pushes it.

01 · Checked first

A dry run before anything changes.

Your LLM prepares the change. A person reads the dry run and pushes it.

02 · Scoped

It never touches your machines.

Your LLM changes the Access Gate configuration through a scoped account, nothing else. Run it locally and nothing leaves the site. Your PLCs and HMIs stay as they are.

03 · Recorded

Every change in the history.

Prepared by your LLM, pushed by a named person, with the time. Roll back any time.

Change history
04 · The right tool

Your LLM for big moves, the interface for fine work.

Provision a plant or 230 machines with your LLM. Make precise edits and upkeep in the interface.

OT firewall management: UI, CLI or your LLM

How does it compare with managing firewall policy in a UI or CLI?

How each method of firewall policy management holds up when the same rule base must run in many plants.

CriterionFirewall UIFirewall CLI / scriptsYour LLM driving Access GateAccess Gate Performance
Time per change at scaleSlowOne screen per rule, on each plant's firewall.MediumFaster once someone writes and maintains the scripts.Plain wordsDescribe the change once. Your LLM prepares it.
Risk of driftHighEach plant is edited by hand, so copies diverge.MediumScripts help until they fall out of date.LowRules live in one place. Each change is reviewed before it applies and recorded.
Review before applyVariesDepends on the team's own process.PartialPossible when scripts go through peer review.Dry runDry run first, then a person applies the change.
Audit trailPer deviceChange logs sit on each firewall.PartialScript history, when someone keeps it.Every changeEach change lands in the enclave change history.
RollbackManualUndo by hand or restore a backup.PartialRerun an older script, if it was kept.SupportedRoll back any change you do not want.
Per-user sign-inAdd-onPossible with a directory agent; OT rules often still match addresses.Add-onPossible with a directory agent; OT rules often still match addresses.Per userAn access screen asks each user to sign in.
Up in a day

Enforcing in a day, managed in plain words.

Access Gate connects to your existing network. Nothing is installed on your machines.

4 hours

From installation to enforcement, for each Thales deployment.

Read the Thales story
1 day

To put an Access Gate in a plant, connected beside your existing network.

Deployment options
Performance

LLM management is available today on Access Gate Performance only. Essential does not include it.

Access Gate Performance
FAQ

Questions about firewall rule automation with your LLM.

0

Agents installed on your machines. Your LLM changes the Access Gate configuration, and Access Gate enforces it on the wire.

Generating and applying access rules for many OT machines from one described intent, instead of typing them rule by rule into each plant's firewall. With Access Gate Performance, your LLM prepares the change, a dry run shows it, and a person pushes it.

Yes. Any LLM agent tool that can use admin access to the appliance works, Claude Code and ChatGPT being two examples. Access Gate does not depend on one model. Your team keeps the tool it already uses.

No. LLM management is available today on Access Gate Performance only. Essential does not include it.

The Access Gate configuration: who reaches which machine, the access screen, encryption and the access control lists. It works through admin access to the appliance and its database. It does not touch your machines.

Yes, for the fine work. Use your LLM for provisioning and large changes, such as a new plant or a vendor across hundreds of machines. Use the interface for precise edits to one rule, user or machine, and for upkeep over time.

Run it as a dry run. You see what would change, and nothing is applied. A person then reviews the change and applies it.

In the enclave change history, with who made the change and when. A change shows that your LLM prepared it and which person pushed it. Users cannot edit or delete that history.

Not if you choose so. You can run a local, self-hosted LLM, so the configuration never leaves your site. Give it a scoped or read-only account and it can only do what that account allows.

Each plant has its own Access Gate, and all of them are managed from one shared control plane. Your LLM prepares the change there, and a person pushes it once for every plant.

Yes. You can roll back any change that does not do what you expected.

No. The LLM changes the Access Gate configuration only. Nothing is installed on your machines, and Access Gate enforces the rules on the wire.

Each Thales deployment took 4 hours from installation to enforcement. Read the Thales story.

No. Your LLM works through admin access to the appliance and its configuration database. Any agent tool that can use that access can manage Access Gate.

See it on your network

Watch one change go from request to rule.

In a demo, we describe a change in plain words, dry-run it, apply it and roll it back.