EN

01Product

Menu

Product / Technical evaluation

A hardware one-way boundary in one 1U dual-module appliance

Falcon-1000 houses the Source Module and Receiving Module in one appliance. Evaluate it in terms of the Source Zone and Destination Zone, physical direction, and destination-side data utility.

Product
Falcon-1000
Form
Single 1U dual-module appliance
Modules
Source Module + Receiving Module
Direction
Source → Destination

Product composition / One product

One product, two independent modules

Hardware view / public annotationOne product / one chassis
Falcon-10001U dual-module appliance

Source-Zone-facing compute module

Source Module

Connects to the Source Zone
One-way fiber

Destination-Zone-facing compute module

Receiving Module

Connects to the Destination Zone
Single 1U chassis envelopeTwo independent compute modules
Falcon-1000 is one 1U dual-module hardware product. The Source Module and Receiving Module are housed in the same chassis; they are not two appliances or separate product models. This public view identifies module roles and the designated direction. It does not represent ports, internal topology, or specification values.

Architecture / Product topology

External security zones, two modules inside one appliance

Source Zone / Data origin

Source Zone

  • OT, control, and protected networks
  • Device state, events, and files
  • Outside the appliance
Falcon-1000Single 1U appliance / dual-module system

Source endpoint

Source Module

Receive and transmit
Source-to-destination one-way fiber data transfer

Receiving endpoint

Receiving Module

Receive and provide interface
Designated cross-domain data path / Source → Destination

Destination Zone / Data use

Destination Zone

  • IT, DMZ, and SOC
  • MES, SIEM, and analytics
  • Outside the appliance
One-way data path: Source Zone → Falcon-1000 → Destination Zone.

Boundary evidence / Independent checks

Threeboundary checks

  1. Physical direction

    No destination-to-source physical return channelFor the listed hardware version, topology, and test scope, the designated cross-domain fiber link constrains data direction from source to destination.
  2. Network reachability

    No routed return path in the listed topologyIn the listed topology, the Destination Zone has no route back to the Source Zone through the hardware boundary.
  3. Destination utility

    The Destination Zone can use the provided data interfaceThe Receiving Module receives the data and provides a representation the destination system can use.

Data path / Evaluation sequence

Source data intake, one-way transfer, and destination interface delivery

  1. 01 / Collect

    Source Module data intake

    The Source Module receives defined data from the Source Zone and maps it into a representation that can cross the one-way boundary.

  2. 02 / Transfer

    One-way fiber data transfer

    For the listed hardware version, topology, and test scope, the designated physical link constrains data direction from source to destination. The hardware boundary does not provide a destination-to-source physical data channel.

  3. 03 / Reconstruct

    Receiving Module destination interface

    The Receiving Module receives the data and provides an interface or representation that the destination system can use.

Integration boundaryThe Destination Zone uses the interface provided by the Receiving Module. It is not an extension of the original bidirectional session.

Control boundary / Comparison

Hardware one-way boundary compared with firewall rules

Evaluation areaHardware one-way boundaryFirewall rules
Direction controlA physical one-way path constrains the cross-domain data direction.Network policy defines the permitted traffic.
Return data pathThe hardware boundary provides no destination-to-source physical data channel.Reachability and permitted directions depend on the deployed network and rules.
Control roleConstrains the physical direction of cross-domain data.Enforces traffic and access policy within security domains and at network boundaries.

This table compares control boundaries; it does not rank control strength or replace defense in depth with a hardware one-way boundary. Firewalls and other security controls retain their own roles.