Executive Summary¶
L2Proxy helps industrial organizations see, govern, and prove the operations carried over their networks. It evaluates industrial protocol meaning together with equipment, policy, process state, and—when L2Proxy Connect is used—the authenticated user and live session.
The industrial problem¶
Remote access and conventional firewalls can establish who connected and which network destination was reachable. They do not necessarily explain whether the user read a measurement, changed a setpoint, operated a breaker, modified a controller, or violated an approved industrial sequence.
L2Proxy closes this visibility and control gap.
What the platform delivers¶
| Product capability | Customer result |
|---|---|
| L2Proxy Dissector | Decodes industrial operations beyond address and port information |
| Equipment and Protection Management | Organizes points, states, limits, commands, and baseline protection around real plant assets |
| Industrial Policy Management | Converts approved user, equipment, operation, and safety intent into managed policy |
| L2Proxy Connect | Links authenticated users and sessions directly to industrial operations and decisions |
| Industrial segmentation and microsegmentation | Limits reachability and permitted activity by domain, identity, session, equipment, and operation |
| Standalone L2Proxy Services | Protects independent transparent, routed, passive, and offline paths |
| Stateless and stateful protection | Evaluates individual operations and multi-message sequences, timing, feedback, and prerequisites |
| Industrial Event Normalization | Presents technical traffic as asset-aware, human-readable industrial events |
| Event Archive and Evidence | Retains traceable protocol, session, policy, and operational evidence |
| Guided Engineering Tools | Accelerates rule creation with templates, autocomplete, help, and validation |

Figure — Core operating chain used across the Raymon platform.
One operating outcome¶
Authenticated user
↓
Live access session
↓
Industrial equipment and operation
↓
Equipment-aware and stateful policy
↓
Record / Allow / Block
↓
Readable event and traceable evidence
Two complementary enforcement models¶
- L2Proxy Connect applies identity-aware industrial policy inside an authenticated access session.
- Standalone L2Proxy Service applies the same protocol-aware policy at an independent industrial boundary or observation path.
The two models can coexist at the same site.
Why customers select L2Proxy¶
- industrial least privilege based on equipment and operation—not connectivity alone;
- direct user-to-session-to-operation traceability for remote work;
- North-South and East-West control across managed L2Proxy enforcement paths;
- protected access domains and protocol-aware industrial microsegments;
- explainable decisions that operations and engineering can review;
- reusable equipment knowledge and guided policy engineering;
- stateful controls for sequences such as authorization, command, response, and feedback;
- readable industrial events linked to detailed evidence;
- progressive adoption from observation and validation to approved blocking.
Responsible product boundary¶
L2Proxy is an independent network-level industrial inspection and decision platform. It does not replace process interlocks, protection relays, safety instrumented functions, operator authority, endpoint controls, or the customer's management of change.
Continue with How to Use This Catalog or Industrial Outcomes.