Skip to content

In-Session Industrial Enforcement

L2Proxy Connect is placed directly in the forwarding lifecycle of the protected virtual access domain. Every eligible frame is inspected before it is forwarded to another session or toward the industrial environment.

Operating path

In-session industrial enforcement inside L2Proxy Connect

Figure — In-session industrial enforcement on the L2Proxy Connect operating path.

The industrial decision is therefore made where authenticated session identity is already known. No address-to-user reconstruction is required.

Context delivered with every frame

Context Industrial use
Authenticated user Apply policy to a named vendor, engineer, or operator
Session identity Correlate all activity belonging to one live connection
Virtual access domain Separate policies for different customer or plant access domains
Session type Distinguish user traffic from infrastructure-originated traffic
Industrial message Evaluate protocol, equipment, point, command, value, and sequence

Same L2Proxy protection capabilities

Connect reuses the established L2Proxy capabilities:

  • native L2Proxy Dissector inspection;
  • stateless and multi-state rules;
  • equipment and point helpers;
  • Select-Before-Operate and other sequence controls;
  • dynamic event metadata;
  • ordered rule evaluation;
  • Record, Accept, and Drop outcomes;
  • raw dissection and rule-match evidence;
  • optional central PostgreSQL event archive;
  • industrial event normalization downstream.

The industrial dissectors do not need special VPN logic. Session identity is supplied as additional decision context, keeping protocol inspection reusable.

Operational resilience controls

The Connect path includes bounded processing and explicit behavior for abnormal service conditions:

  • bounded evaluation queue;
  • evaluation timeout;
  • customer-selectable fail-open or fail-closed posture;
  • service enable and disable control;
  • rule validation before activation;
  • supervised runtime restart;
  • local and central evidence options.

These are deployment safeguards. The customer's availability, safety, and change-control requirements determine the approved posture.

When to use Connect

Use L2Proxy Connect when:

  • authenticated VPN sessions are the source of industrial access;
  • user and session identity must be part of the industrial rule;
  • the customer wants to inspect traffic inside the protected virtual access domain;
  • a separate bridge or routed inspection detour is unnecessary or undesirable;
  • session operations and industrial evidence should be correlated directly.

Use a standalone L2Proxy service for general industrial boundaries, independent passive observation, offline analysis, or traffic that does not originate from the protected VPN environment.

Next: Session Operations and Evidence.