OT network segmentation / Solution design

Connect the factory without flattening IT and OT

Introduce controlled data exchange and time-limited engineering access while preserving the local operation of production cells.

Manufacturing environment for this solution design
Built around the way you workArchitecture · Equipment · Delivery
01

Keep production cells autonomous

02

Restrict cross-zone traffic to named services

03

Control supplier maintenance access

Architecture / 01

How the solution connects

Independent uplinks meet a controlled network boundary. Local access is separated by purpose.

Connect the factory without flattening IT and OT: proposed architectureCorporate IT services connects to OT firewall + jump host (Primary path). Approved remote engineer connects to OT firewall + jump host (Primary path). OT firewall + jump host connects to Catalyst distribution (Policy boundary). Catalyst distribution connects to Production cell A (Separate zone). Catalyst distribution connects to Production cell B (Separate zone). Catalyst distribution connects to Historian / integration zone (Separate zone). Logical overview; final cabling and firewall rules are specified during design.01 / TRANSPORT02 / CONTROL03 / DISTRIBUTE04 / ACCESS ZONESWANWANCorporate IT servicesApproved remote engineerOT firewall + jump hostCatalyst distributionProduction cell AProduction cell BHistorian / integrationzone
Logical data pathConceptual design · final ports, policies and quantities are specified for the site
Read the connection map
  • Corporate IT servicesOT firewall + jump host · Primary path
  • Approved remote engineerOT firewall + jump host · Primary path
  • OT firewall + jump hostCatalyst distribution · Policy boundary
  • Catalyst distributionProduction cell A · Separate zone
  • Catalyst distributionProduction cell B · Separate zone
  • Catalyst distributionHistorian / integration zone · Separate zone

The challenge on the ground

Connecting machinery to reporting systems often creates an accidental bridge between the corporate network and equipment never designed for unrestricted access. Engineers need visibility, but a cloud outage or an office incident should not become a dependency for local machine control.

Start with the actual controller protocols and operating constraints.

Inside the design

Use managed Catalyst switching for the plant distribution layer, with dedicated access segments for each cell. Place an appropriately sized industrial firewall and an integration zone between OT and corporate services. These security appliances are project-specific additions to the hardware BOM.

Only named flows cross that boundary: for example, a historian collector may read a controller while general office clients cannot. Use RUT956 cellular access for a separately protected maintenance path, not an unfiltered back door into PLC networks.

Operating it day to day

Route supplier access through an approved jump host with individual identities, MFA and an expiry window. Log the session and remove access at the end of the work order.

Keep machine safety and real-time control local. Back up controller and switch configurations before maintenance, and agree the rollback decision with production rather than treating firmware updates as ordinary office patching.

What to test before handover

  1. Demonstrate that an office client cannot initiate a session into a production cell.
  2. Verify each historian flow against the approved protocol and destination list.
  3. Disable the WAN and confirm local production control remains available.
  4. Exercise supplier access, expiry and the maintenance rollback procedure.

Technical references

Equipment / 02

The bill of materials

3 scoped items

One plant area with separate production cells, a corporate office network and a designated integration/engineering zone. Quantities below describe the example; your proposal confirms the final equipment and services.

01In this design
Cisco

Cisco Catalyst C9300-48P-E switch

C9300-48P-E

Plant distribution switching

Uplink modules and optics selected against the network design.

View product
02In this design
Teltonika

Teltonika RUT956 industrial LTE router

RUT956200000

Protected cellular maintenance transport

Access must terminate at the approved firewall/jump-host boundary.

View product
03In this design
APC

APC Smart-UPS SMT1500RMI1U - 4x C13, USB, Rackmount 1U, 1500VA

SMT1500RMI1U

Network power continuity

Validate runtime and equipment load for this 230 V model.

View product

Complete the installation

The equipment above is one part of the project. Include these items in the final scope.

  • Industrial firewalls and jump host
  • Cell switches, optics and fibre
  • Identity, logging and backup services
  • Rack, grounding and environmental provisions
Details worth knowing

Questions before you specify

Are VLANs enough to protect production?

They separate broadcast domains. The design also needs enforced routing/firewall policy, controlled administration and a documented set of permitted flows.

Can a supplier connect directly over cellular?

The cellular transport should lead to the controlled maintenance boundary. Direct unrestricted access to controllers defeats the segmentation design.

From reference to reality / 03

Let’s design it for your site.

Send us the details below. We can turn the reference architecture into a scoped design, equipment schedule and quotation.

Start your project

Bring these to the first conversation

  • 01Cell and controller inventory
  • 02Protocol and traffic-flow matrix
  • 03Downtime windows and rollback owner
  • 04Supplier access and logging requirements
← Explore all solution designs