Skip to content

L2Proxy Connect Industrial Use Cases

The following cases show how user identity, live session management, and industrial protocol policy combine in common OT remote-access scenarios.

Authenticated industrial session path used across Connect use cases

Figure — Session path reused across L2Proxy Connect industrial use cases.

OEM support for one packaged unit

Need: an OEM specialist must diagnose a compressor, skid, or packaged process unit.

Connect policy: the named user may establish a session and perform approved diagnostic reads only on the assigned unit. Writes, control commands, and access to adjacent equipment are blocked and recorded.

Operational response: operations can observe the live session, review its activity, and disconnect it when support ends or behavior becomes unexpected.

Protection engineer investigation

Need: a specialist must investigate feeder trip and lockout behavior.

Connect policy: the assigned user may read F12 trip, pickup, target, lockout, and breaker state. Only approved reset or acknowledge operations are available; broader switching authority is not implied.

Evidence: relay events, user, session, attempted control, matching rule, and verdict remain correlated.

Controlled feeder switching

Need: an authorized engineer must operate a feeder breaker remotely.

Connect policy: Open or Close is permitted only for the named user, on the assigned breaker, in Remote mode, without active lockout, and through the approved command sequence.

Outcome: a valid operation is accepted and recorded. A Close attempted during lockout is blocked and attributed to the exact session.

Transformer condition monitoring

Need: an asset specialist needs loading, temperature, and tap visibility but no control authority.

Connect policy: reads for the TR1 measurements and actual tap position are accepted; OLTC requests are blocked.

Value: access to information does not silently become authority to change the process.

Time-bounded OLTC maintenance

Need: a transformer vendor requires approved tap-control authority during a maintenance activity.

Connect policy: the named user may request only positions inside the engineering range and only through the approved sequence. Request and feedback are retained with the session identity.

Closure: the session is disconnected and user access revised when the work is complete.

DER intertie operation

Need: a DER specialist must inspect generation and operate the intertie.

Connect policy: only the assigned user may request approved intertie operations. Close requires acceptable bus voltage and synchronization or dead-bus readiness.

Value: authentication, electrical prerequisites, and protocol operation become one enforced decision.

Suspicious authenticated activity

Need: a valid account begins issuing operations outside its normal industrial role.

Connect response: individual violations are blocked and logged with user and session identity. The operator can inspect related activity, disconnect the live session, and disable the account where approved.

Value: a valid login is not treated as unlimited trust.

Session-based incident reconstruction

Need: determine exactly what occurred during a remote maintenance window.

Investigation path:

  1. Identify the user and session interval.
  2. Review connection and session history.
  3. Filter industrial dissections and rule matches by session.
  4. Read normalized equipment and operation descriptions.
  5. Inspect accepted and blocked commands.
  6. Open original protocol evidence when required.
  7. Export the approved investigation record.

Next: Layered Industrial Controls.