Product Architecture¶
L2Proxy connects equipment knowledge, policy engineering, identity-aware access, industrial segmentation, independent enforcement services, protocol-aware detection, and operational evidence.

Figure — Product architecture: equipment knowledge, policy engineering, access and segmentation, enforcement paths, and evidence.
Managed product layers¶
| Layer | Customer responsibility answered | L2Proxy capability |
|---|---|---|
| Equipment knowledge | What assets, points, states, limits, and commands exist? | Industrial Equipment and Protection Management |
| Policy intent | Who may do what, to which equipment, under which conditions? | Industrial Policy Management |
| Identity-aware access | Which authenticated user and live session introduced the industrial operation? | L2Proxy Connect |
| Segmentation | Which domains may communicate, and which equipment and operations are permitted across the path? | Industrial Segmentation and Microsegmentation |
| Service operation | Where and how will the approved protection run? | Standalone Deployment and Operations |
| Detection and enforcement | Is this operation permitted and consistent with current process state? | Rule Engine and Stateful Protection |
| Evidence | What occurred, what decision was made, and what does it mean to the plant? | Normalization, Event Archive, and Event Explorer |
Each layer has a distinct owner and lifecycle. This prevents an equipment-library edit from silently becoming a production policy change, or a policy revision from becoming an unapproved service activation.
Two enforcement paths¶
An individual rule captures one precise test. An Access Policy combines rule logic with the user, industrial scope, order, and decision. A Policy Profile assembles the complete approved policy set. The customer can then use either enforcement path.

Figure — Enforcement path placement: Standalone L2Proxy on the network path and L2Proxy Connect on the authenticated session path.
┌→ L2Proxy Connect → authenticated session path
Rule → Access Policy → Policy Profile ┤
└→ Service Profile → standalone L2Proxy instance
The result is traceable from an industrial requirement to the service and evidence that demonstrate its application.
L2Proxy Connect¶
Connect evaluates traffic directly inside the protected virtual access environment. The authenticated user, live session, access domain, and session type are supplied to the Rule Engine with each industrial frame. No separate bridge, routed detour, or address-to- user reconstruction is required for this path.
Standalone L2Proxy Service¶
A managed Service Profile runs an independent L2Proxy instance for a transparent or routed industrial boundary, passive observation point, or offline validation task. It is appropriate when traffic is not already inside the Connect access environment or when a separate service lifecycle is required.
Deployment postures¶
The platform supports four controlled postures:
| Posture | Industrial purpose |
|---|---|
| Passive observation | Establish normal behavior and tune policy without affecting production traffic |
| Inline enforcement | Allow approved operations and block violations on the protected path |
| Offline analysis | Validate policy, investigate incidents, and perform regression testing using recorded traffic |
| In-session identity-aware enforcement | Evaluate authenticated user and session context directly in the protected virtual access path |
Connect and standalone Service Profiles can operate together at the same site.
Evidence architecture¶
L2Proxy preserves several levels of evidence:
- decoded protocol facts from the industrial traffic;
- rule decisions and customer-selected event metadata;
- state transitions and timeout events where sequence matters;
- normalized descriptions, equipment context, severity, category, and tags;
- queryable archive records for investigation and reporting;
- local service logs for operational troubleshooting.
This allows a control-room operator to read the industrial meaning while an engineer or investigator can still reach the detailed protocol evidence.
Industrial safety boundary¶
L2Proxy provides an independent network-level inspection and decision point. It does not replace relay protection, process interlocks, safety instrumented functions, switching procedures, or operator authority. Its role is to keep observed network activity aligned with the industrial access and operations explicitly approved by the customer.