Skip to content

North-South and East-West Traffic Control

L2Proxy applies visibility and enforcement to traffic that crosses a managed enforcement path. Coverage is designed deliberately so that important communication cannot bypass the selected policy point.

North-South and East-West industrial traffic directions in a hybrid Raymon deployment

Figure — North-South and East-West control directions in hybrid Standalone and Connect placements.

North-South traffic

North-South traffic crosses an access or zone boundary, for example:

  • remote engineer to plant network;
  • enterprise or engineering zone to control zone;
  • SCADA to field network;
  • central operations to a remote site;
  • service partner to assigned industrial equipment.

L2Proxy Connect is particularly valuable for remote access because the authenticated user and session are available with the industrial operation. Standalone L2Proxy services protect other transparent or routed boundaries.

Authenticated encrypted tunnels can carry these protected access paths across an untrusted or shared transport network. Segmentation remains defined by identity, domain, destination, application, and industrial policy—not merely by the existence of a tunnel.

East-West traffic

East-West traffic moves within or between industrial areas, for example:

  • session to session inside a protected access domain;
  • HMI or engineering station to PLC, RTU, or IED;
  • one production cell or package unit to another;
  • one protected domain to another;
  • one plant or substation site to another.

East-West coverage can be provided by domain isolation, client-isolation policy, inter-domain access rules, L2Proxy Connect on managed session paths, and standalone L2Proxy enforcement between physical OT segments.

Coverage model

Traffic path Primary control
Authenticated session to industrial network L2Proxy Connect plus domain and access policy
Session to session Client isolation, access policy, and L2Proxy Connect inspection
Domain to domain Explicit routed or linked path with access and industrial policy
OT zone to OT zone Standalone L2Proxy at the transparent or routed boundary
Site to site Controlled site connection with policy at the selected enforcement points
Passive or investigative path Standalone observation or offline analysis

The coverage principle

L2Proxy does not claim visibility into traffic that never crosses a managed L2Proxy enforcement or observation point. Production design therefore identifies required data flows, selects the enforcement point for each flow, and verifies both directions with representative traffic.

Next: Zero-Trust-Aligned Industrial Access.