North-South and East-West Traffic Control¶
L2Proxy applies visibility and enforcement to traffic that crosses a managed enforcement path. Coverage is designed deliberately so that important communication cannot bypass the selected policy point.

Figure — North-South and East-West control directions in hybrid Standalone and Connect placements.
North-South traffic¶
North-South traffic crosses an access or zone boundary, for example:
- remote engineer to plant network;
- enterprise or engineering zone to control zone;
- SCADA to field network;
- central operations to a remote site;
- service partner to assigned industrial equipment.
L2Proxy Connect is particularly valuable for remote access because the authenticated user and session are available with the industrial operation. Standalone L2Proxy services protect other transparent or routed boundaries.
Authenticated encrypted tunnels can carry these protected access paths across an untrusted or shared transport network. Segmentation remains defined by identity, domain, destination, application, and industrial policy—not merely by the existence of a tunnel.
East-West traffic¶
East-West traffic moves within or between industrial areas, for example:
- session to session inside a protected access domain;
- HMI or engineering station to PLC, RTU, or IED;
- one production cell or package unit to another;
- one protected domain to another;
- one plant or substation site to another.
East-West coverage can be provided by domain isolation, client-isolation policy, inter-domain access rules, L2Proxy Connect on managed session paths, and standalone L2Proxy enforcement between physical OT segments.
Coverage model¶
| Traffic path | Primary control |
|---|---|
| Authenticated session to industrial network | L2Proxy Connect plus domain and access policy |
| Session to session | Client isolation, access policy, and L2Proxy Connect inspection |
| Domain to domain | Explicit routed or linked path with access and industrial policy |
| OT zone to OT zone | Standalone L2Proxy at the transparent or routed boundary |
| Site to site | Controlled site connection with policy at the selected enforcement points |
| Passive or investigative path | Standalone observation or offline analysis |
The coverage principle¶
L2Proxy does not claim visibility into traffic that never crosses a managed L2Proxy enforcement or observation point. Production design therefore identifies required data flows, selects the enforcement point for each flow, and verifies both directions with representative traffic.