Skip to content

Layered Industrial Controls

L2Proxy Connect combines secure remote-access controls with L2Proxy industrial policy. The two layers have different responsibilities and become stronger when used together.

L2Proxy Connect layered controls from authentication to enforcement and evidence

Figure — Layered controls on the Connect path: authentication, authorization, session brokerage, and industrial enforcement.

Layer 1: connection and session control

The access layer manages capabilities such as:

  • VPN user lifecycle;
  • authentication and credential control;
  • user groups and inherited access settings;
  • effective user policy;
  • virtual access-domain separation;
  • session limits and client restrictions;
  • ordered access rules;
  • live sessions and session history;
  • controlled disconnect;
  • security logs, audit, reports, and alerts.

These controls determine who may establish and maintain access.

Layer 2: industrial operation control

The L2Proxy layer evaluates:

  • industrial protocol and function;
  • equipment, endpoint, point, and object;
  • read, control, configuration, and maintenance operations;
  • command code and requested value;
  • permitted ranges and states;
  • Select-Before-Operate and other sequences;
  • prior authorization and session continuity;
  • command feedback and timeouts;
  • Record, Accept, and Drop outcomes.

These controls determine what the authenticated session may do to the industrial process.

Why both layers matter

Access-only decision Combined L2Proxy Connect decision
Vendor may connect to the site Vendor may connect and perform diagnostic reads only on the assigned package unit
Engineer belongs to the protection group Engineer may read relay state and use only approved reset operations
User may reach the transformer controller User may request only valid tap positions through the approved sequence
DER specialist has an active session Intertie Close is allowed only under approved voltage and synchronization conditions

Connection policy cannot normally interpret the industrial meaning of a DNP3, Modbus, IEC 104, or S7comm operation. Protocol policy alone does not inherently know the authenticated VPN user. L2Proxy Connect brings the two contexts into one decision path.

Separation of policy ownership

The layers remain independently governable:

Policy area Typical owner
User, group, authentication, and session controls Remote-access or OT infrastructure owner
Equipment, point, command, value, and sequence policy Operations, protection/control engineering, and OT security
Combined activation and review Customer change authority

This prevents industrial rules from becoming hidden inside general VPN configuration and prevents session administration from being mixed into protocol expressions.

Customer-facing positioning

L2Proxy Connect delivers identity-aware industrial least privilege:

Approved identity
AND approved equipment
AND approved operation
AND approved process condition
→ permitted industrial activity

It supports a ZTNA-style outcome for industrial remote access without claiming to replace every enterprise identity, endpoint posture, or access-broker product.

Next: User and Session-Aware Policy.