TroutTrout
Solutions / OT Segmentation

OT Segmentation Without Rewiring or VLAN Redesign.

Trout Access Gate is an on-premise appliance to segment an OT network: it keeps each machine in its own zone and controls what talks to what, with no rewiring or VLAN redesign.

Last updated:

Trusted by leading companies

John CockerillOrange CyberdefenseElna MagneticsThales
OT NETWORK — ZERO-TRUST WITH ACCESS GATELIVEMPLS, APN, TUNNELSINTERNET / WANSITE BFIREWALL / ROUTERphysical wireLANZERO-TRUST OVERLAYVLANTagged & TrunkSECURITYAuth, Encryption, ACLOT SERVICESDNS, NTP, Protocol Gateway,Remote AccessACCESS GATEIT CLIENTIT SERVERZONE A OTZONE B OTDesktopDesktopDesktopDesktopIT SERVICESApps, SIEM, etcHMISensorDesktopPLCHMISensorPLCDesktop
Defense in Depth Limits

Why segmentation stalls on a live plant.

Most sites can describe the segmentation they want. The obstacle is that retrofitting it onto a running network means re-addressing equipment that cannot be taken offline. For the levels themselves and where the hierarchy stops matching real traffic, see <a href="/resources/purdue-model">the Purdue Model guide</a>.

The IT/OT boundary is the junction attackers aim for. It is also becoming more brittle with increased digitalization. Remote maintenance and cloud-bound data flows are prime examples of challenges to Purdue and segmentation efforts.

The result is that most sites stay flat or only partly segmented, not because operators do not know the model, but because retrofitting it onto a live network is too disruptive.

IEC alignment

IEC 62443 Zones and Conduits.

In IEC 62443: a zone is a grouping of assets that share the same security requirements and a common Security Level. The standard defines four, from SL1 (protection against casual or coincidental violation) to SL4 (protection against a state-level actor with extended resources). A conduit is the controlled communication path between two zones.

The hard part is implementing conduits on a network that is already running, which traditionally means a VLAN redesign: re-addressing equipment, reconfiguring switches, and taking production down for the cutover. For most operators, that downtime is the blocker that keeps a flat network flat for another year.

How the approaches compare

Flat, VLAN, firewall zones, or an overlay.

OT segmentation approach
Flat network
Enforcement point
None
Rewiring / downtime
None
Lateral movement
Unrestricted
Audit trail
None
OT segmentation approach
VLAN only
Enforcement point
Layer 2 isolation
Rewiring / downtime
Switch reconfig
Lateral movement
Inter-VLAN routing open
Audit trail
None
OT segmentation approach
Firewall zones / iDMZ
Enforcement point
Zone firewalls
Rewiring / downtime
Re-addressing, downtime
Lateral movement
Blocked at the zone edge
Audit trail
At the boundary
OT segmentation approach
Access Gate overlay
Enforcement point
Per-asset, identity-based
Rewiring / downtime
None (adjacent overlay)
Lateral movement
Blocked per asset
Audit trail
Every session recorded
How Access Gate deploys

OT Cybersecurity without a network redesign.

PHASE 1

Connect Access Gate to the Network

Access Gate deploys alongside the existing network in an aggregation or lollipop architecture. No VLAN changes. No agents on PLCs or OT endpoints.

PHASE 2

Zero Trust consolidation.

The overlay becomes the new Zero Trust fabric. Migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system site is done in a single day. IT admins and OT operators manage policy through role-based access in a shared UI.

Deployment

Access Gate adapts to your network

Pick your environment to see where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path, from full coverage to partial coverage.

Access Gate: deploy Zero-TrustSelect an option to highlight its path
See the full deployment guide
The second layer of value

Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.

OT runs through you, not around you.

Trusted by industrial and critical infrastructure operators.

Saint-Gervais Domaine Skiable
55

distributed sites protected across harsh operational environments, securing critical infrastructure without agents or downtime.

Read the case study

Trusted by leading companies

Thales
Orange Cyberdefense
Carahsoft
John Cockerill
NeverHack
Kyron
Eden Cluster
Airicom
Skynopy
Frequently asked questions

OT network security, answered.

6

Purdue, IEC 62443 zones, multi-site policy, and the two-phase Access Gate deployment

The Purdue Reference Model (part of ISA-95) is the standard architecture for industrial control systems. It defines six logical levels, from Level 0 (the physical process: sensors and actuators) up through Level 1 (basic control: PLCs and RTU), Level 2 (supervisory control: SCADA and HMIs), Level 3 (site operations and MES), to Levels 4 and 5 (enterprise IT). In OT security the model matters because it locates the IT/OT boundary at Level 3 and defines which systems should never talk directly to which. That is the basis for segmentation.

IEC 62443 formalises Purdue-style segmentation into two constructs. A zone is a grouping of assets that share the same security requirements and a common Security Level (SL1 to SL4). A conduit is the controlled communication path between zones. It sets and enforces exactly which traffic may cross a zone boundary, and under what conditions. Without conduits, a zone diagram is theoretical: any device can still reach any other.

Access Gate deploys in two phases. In Phase 1 it sits adjacent to the existing network at the Level 3 / DMZ boundary and creates a Zero Trust overlay across the Purdue zones. No VLAN reconfiguration, no agents on PLCs or OT endpoints, no production downtime. Visibility and identity-based access control are immediate. In Phase 2 that overlay becomes the new Zero Trust fabric as systems migrate behind the gate, with no forklift replacement of switches.

Phase 1, the adjacent overlay, is live in hours, not months. Phase 2 migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system OT environment is done in roughly a single working day. Compare that with the months a traditional VLAN redesign and consolidation project takes, most of which is change-control and validation, not the cutover itself.

NIS2 Article 21 does not name IEC 62443 explicitly, but its technical measures (network segmentation, access control, logging) map directly onto the zone-and-conduit model. National guidance for OT operators, including ANSSI guidance in France, treats IEC 62443 as the recognised technical implementation standard for those obligations, so building to IEC 62443 zones is the practical route to demonstrating Article 21 segmentation.

Access Gate provides central policy management across every site from a single role-based UI. Each site deploys independently in Phase 1, with no cross-site interdependency and no big-bang cutover. From day one of Phase 2, the sites roll up into one unified Zero Trust fabric. IT admins set enterprise-wide policy while OT operators keep site-level control, so a 50-site group runs a consistent IEC 62443 zone posture without sending a network team to every plant.

OT (operational technology) security protects the industrial systems that run physical processes: PLCs, HMIs, SCADA, and the legacy servers behind them. Unlike IT security it cannot rely on endpoint agents or frequent patching, so Access Gate enforces identity, segmentation, and monitoring at the network layer with a Zero Trust proxy in front of each asset, no agents and no downtime.

IT security defends data and user devices, where agents, patches, and reboots are routine. OT security defends availability and safety on equipment that often cannot be patched, agented, or taken offline. Access Gate adds Zero Trust access, microsegmentation, and audit at the network layer instead of on the device, so protection does not disrupt production.