Layered Industrial Controls¶
L2Proxy Connect combines secure remote-access controls with L2Proxy industrial policy. The two layers have different responsibilities and become stronger when used together.

Figure — Layered controls on the Connect path: authentication, authorization, session brokerage, and industrial enforcement.
Layer 1: connection and session control¶
The access layer manages capabilities such as:
- VPN user lifecycle;
- authentication and credential control;
- user groups and inherited access settings;
- effective user policy;
- virtual access-domain separation;
- session limits and client restrictions;
- ordered access rules;
- live sessions and session history;
- controlled disconnect;
- security logs, audit, reports, and alerts.
These controls determine who may establish and maintain access.
Layer 2: industrial operation control¶
The L2Proxy layer evaluates:
- industrial protocol and function;
- equipment, endpoint, point, and object;
- read, control, configuration, and maintenance operations;
- command code and requested value;
- permitted ranges and states;
- Select-Before-Operate and other sequences;
- prior authorization and session continuity;
- command feedback and timeouts;
- Record, Accept, and Drop outcomes.
These controls determine what the authenticated session may do to the industrial process.
Why both layers matter¶
| Access-only decision | Combined L2Proxy Connect decision |
|---|---|
| Vendor may connect to the site | Vendor may connect and perform diagnostic reads only on the assigned package unit |
| Engineer belongs to the protection group | Engineer may read relay state and use only approved reset operations |
| User may reach the transformer controller | User may request only valid tap positions through the approved sequence |
| DER specialist has an active session | Intertie Close is allowed only under approved voltage and synchronization conditions |
Connection policy cannot normally interpret the industrial meaning of a DNP3, Modbus, IEC 104, or S7comm operation. Protocol policy alone does not inherently know the authenticated VPN user. L2Proxy Connect brings the two contexts into one decision path.
Separation of policy ownership¶
The layers remain independently governable:
| Policy area | Typical owner |
|---|---|
| User, group, authentication, and session controls | Remote-access or OT infrastructure owner |
| Equipment, point, command, value, and sequence policy | Operations, protection/control engineering, and OT security |
| Combined activation and review | Customer change authority |
This prevents industrial rules from becoming hidden inside general VPN configuration and prevents session administration from being mixed into protocol expressions.
Customer-facing positioning¶
L2Proxy Connect delivers identity-aware industrial least privilege:
Approved identity
AND approved equipment
AND approved operation
AND approved process condition
→ permitted industrial activity
It supports a ZTNA-style outcome for industrial remote access without claiming to replace every enterprise identity, endpoint posture, or access-broker product.