Skip to content

L2Proxy Connect

L2Proxy Connect combines authenticated remote-access identity, live session management, and protocol-aware industrial enforcement in one operating path. Every industrial frame inside the protected virtual access environment can be evaluated with the identity of the user and session that introduced it.

L2Proxy Connect identity-aware industrial access architecture

Figure — L2Proxy Connect architecture for identity-aware industrial access.

Customer outcome: know who is connected, understand what industrial operation that person is attempting, apply equipment- and process-aware policy, and retain the user, session, rule, and decision as one traceable event.

Purpose and expected outcome

This section explains identity-aware industrial access. After reading it, the customer should understand how an authenticated user and live session become part of an equipment- and operation-aware decision, when Connect is appropriate, what can be recorded or enforced, and which evidence remains available.

Identity-aware industrial enforcement

Authenticated VPN User
Live user session
L2Proxy Connect inside the protected access environment
Industrial protocol and equipment inspection
User + Session + Operation + Process Context
Record · Accept · Block

L2Proxy Connect does not infer user identity from an address. The remote-access platform supplies the authenticated user, session, virtual access domain, and session type with the industrial frame. L2Proxy evaluates that trusted context together with the decoded protocol operation.

One decision across two control layers

Control layer Customer question
Secure access control Who may connect, under which account, group, access policy, and session restrictions?
Industrial protocol control Which equipment, point, function, command, value, sequence, or process state may that session use?

The combined decision can distinguish “the user is allowed to connect” from “the user is allowed to issue this specific command to this specific equipment now.”

No external inspection detour

L2Proxy Connect evaluates traffic directly in the internal forwarding path of the protected virtual access environment. It does not require a separate Linux bridge, routed detour, or packet-queue handoff to inspect that traffic.

This provides a distinct deployment model from standalone L2Proxy services:

Model Best suited to
L2Proxy Connect Identity-aware inspection and enforcement for authenticated VPN sessions inside the protected access environment
Standalone L2Proxy Service Independent protection of bridges, routed boundaries, passive observation points, and offline traffic

Both models use the same industrial parser, Rule Engine, policy concepts, metadata, and event evidence.

Delivered capabilities

  • User-specific industrial rules
  • Session-specific industrial rules
  • Virtual access-domain-aware policy
  • Protocol-aware Record, Allow, and Block decisions inside the session path
  • Rule-match evidence containing user and session identity
  • Protocol dissections containing the same session context
  • Live session inventory and detail
  • Session history and connection activity
  • User and group management
  • Effective access-policy visibility
  • Controlled session disconnection
  • Access-rule management and analysis
  • Searchable security and operational logs
  • Central archive of industrial dissections and policy decisions

Industrial value

  • Least privilege beyond login: connection approval does not imply unrestricted industrial control.
  • Direct accountability: every relevant event can identify the authenticated user and live session responsible for the activity.
  • Immediate containment: an operator can disconnect the affected session while preserving its evidence.
  • Equipment-aware access: authority can be limited to a device, point, operation, value range, or approved sequence.
  • Layered protection: remote-access controls and industrial Rule Engine decisions work together rather than competing as separate policy systems.
  • Simpler protected path: Connect does not require a separate bridge or routed inspection path for traffic already inside the virtual access environment.

L2Proxy Connect provides identity-aware industrial access enforcement and supports a ZTNA-style least-privilege outcome for OT remote sessions. It is presented in terms of its delivered industrial controls rather than as a claim to implement every function of a general enterprise ZTNA platform.

Foundation for industrial microsegmentation

L2Proxy Connect is the identity-aware enforcement path for industrial microsegmentation. Protected access domains reduce broad reachability; user, group, session, network, and access policies constrain communication; and the L2Proxy Rule Engine determines which industrial equipment, points, operations, values, and sequences are permitted within that path.

Standalone L2Proxy services extend the same industrial policy model to physical or routed OT boundaries. Together they support North-South and East-West control wherever traffic crosses a managed enforcement point.

See Industrial Segmentation and Microsegmentation.

Continue with Industrial Use Cases.