A bridge-mode industrial firewall and intrusion prevention system designed to protect operational technology and industrial control systems from cyber threats. Positioned transparently at Layer 2 or operating at Layer 3 within the Purdue Model, this device secures industrial endpoints such as programmable logic controllers, distributed control systems, and human-machine interfaces from unauthorized network activity. The appliance utilizes a ruggedized hardware design suitable for extreme temperatures and features specialized deep packet inspection for industrial protocols to block anomalies and protocol-level threats.
The appliance functions as both a firewall and an intrusion prevention system by continuously monitoring network traffic to dynamically learn and enforce operational baselines. It provides network address translation capabilities, stateful packet inspection, and granular device access control policies to establish secure boundaries within flat operational technology networks. By leveraging centralized management interfaces and integration with security information and event management systems, the device facilitates real-time threat detection, automated policy generation, and secure remote access for operational resilience.