Session Operations and Evidence¶
L2Proxy Connect links remote-access operations with industrial activity. An operator can inspect a live session, understand who owns it, review its operating context, and relate that session to L2Proxy dissections and rule decisions.
Live session visibility¶
The management workspace provides a consolidated session view including information such as:
- session identity and authenticated user;
- virtual access domain;
- connection status and start time;
- client identity and connection context;
- transferred traffic and activity indicators;
- effective access policy;
- current and historical session records.
This establishes the user and connection context before the industrial activity is examined.
Industrial activity inside the session¶
L2Proxy Connect adds the same user and session identity to:

Figure — Session activity becomes normalized industrial evidence with asset and policy context.
- decoded industrial messages;
- rule-match events;
- Accept and Drop decisions;
- dynamic rule metadata;
- central archive records.
An investigation can therefore move through one continuous chain:
VPN User
→ Live Session
→ Industrial Message
→ Equipment and Operation
→ Matching Rule
→ Accept or Drop
Questions the evidence can answer¶
- Which user established the session?
- Which session introduced the industrial message?
- Which equipment and point were addressed?
- Was the activity observation or control?
- Which value, command, or protocol function was used?
- Which rule matched?
- Was the operation accepted or blocked?
- Which safety condition or sequence influenced the decision?
- What else occurred during the same session?
Controlled session containment¶
Authorized operators can inspect the impact of a session action and disconnect a selected session. User management can also disable access when the business need ends or a security condition requires containment.
This provides two levels of response:
| Response | Appropriate use |
|---|---|
| Block one industrial operation | The session remains valid, but the specific operation violates industrial policy |
| Disconnect the session | The complete session is no longer trusted or authorized to continue |
The two actions complement each other. A protocol violation does not always require terminating legitimate work, while suspected credential misuse may require immediate session containment.
Live, historical, and exported evidence¶
Session operations support:
- live session monitoring;
- observed connection and disconnection history;
- searchable security and operational logs;
- filtering by user and session;
- reporting and controlled export;
- correlation with raw L2Proxy events in the central archive;
- normalized industrial descriptions for plant-oriented review.
Example event narrative¶
The authenticated protection engineer, through the identified live session, requested a Close operation on the F12 feeder breaker. L2Proxy Connect blocked the operation because lockout 86 was active and retained the user, session, breaker, command, rule, and decision as investigation evidence.
The original protocol record remains available when a control engineer requires deeper analysis.