Deployment Choices¶
L2Proxy supports both identity-aware enforcement inside authenticated virtual access and standalone services for industrial boundaries, passive observation, and offline analysis. Different modes can operate together at the same site.
Selection guide¶
| Mode | Traffic impact | Primary purpose | Typical adoption stage |
|---|---|---|---|
| L2Proxy Connect | Active | User- and session-aware industrial enforcement inside the protected virtual access environment | Production remote access |
| Passive observation | None | Visibility, baselining, and policy tuning | Discovery and commissioning |
| Offline validation | None | Investigation, regression, and acceptance testing | Engineering and test |
| Transparent inline protection | Active | Enforcement without changing the existing addressing plan | Controlled rollout |
| Routed inline protection | Active | Enforcement at an established industrial zone boundary | Production operation |

Figure — Deployment topologies and product placement for Standalone L2Proxy and L2Proxy Connect.
Passive first¶
For an existing plant, begin with representative bidirectional traffic. Establish
normal masters, outstations, PLCs, functions, maintenance windows, retry behavior,
and expected startup sequences. Run enforcement candidates as log rules before
converting a result to Block.
L2Proxy Connect¶
Connect receives the industrial frame and authenticated session identity directly in the internal forwarding path. It does not require a separate bridge, routed inspection detour, or packet queue for that traffic. Use it when policies must distinguish users and sessions as well as equipment and operations.
See L2Proxy Connect for the complete identity-aware workflow.
Inline readiness checklist¶
- Both directions of the industrial exchange are available to the protection service.
- Normal startup, recovery, failover, maintenance, and emergency procedures were captured.
- Policies were tested with representative recorded traffic.
- Missing state, timeout, replay, duplicates, and out-of-order events have explicit behavior.
- The customer approved the safe response when inspection cannot make a normal decision.
- Service and event-storage capacity have been sized for the protected path.
- A rollback and bypass procedure exists for the change window.
Operational ownership¶
Rule changes affect process communication and should follow the customer's management of change. Recommended reviewers include control engineering, OT operations, network engineering, and OT cybersecurity. A rule should identify its owner, affected assets, deployment mode, enforcement status, test evidence, and rollback condition.
See Service Profiles for standalone profile management and Policy Assignment and Activation for the handoff from approved policy to a running service.