Scenarios / Evaluation models
Illustrative Deployment Scenarios
Use source → hardware-enforced boundary → destination to review data-release paths. Each scenario is an illustrative evaluation model, not a customer case.
Source / Source Zone
Source Zone systems and data
- Sources
- OPC UA servers, Modbus TCP control equipment
- Data
- Equipment status and process variables, Approved register data
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving Module
Within the listed hardware version, topology, and test scope, the Source Module receives defined production-line data and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a data interface usable by destination systems.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- Historians, MES and analytics systems
- Use
- For the Destination Zone to review process trends, equipment status, and approved representations of production data.
Evaluation considerations
- Confirm the approved scope of OPC UA nodes and Modbus registers.
- Confirm data freshness, volume, and acceptable loss conditions.
- Confirm the receiving-side interface and data representation required by Destination Zone systems.
Source / Source Zone
Source Zone systems and data
- Sources
- Facility monitoring systems, Defined PLC and RTU data sources
- Data
- Equipment status and alarms, Approved operational telemetry
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving Module
Within the listed hardware version, topology, and test scope, the Source Module receives approved facility-monitoring data and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a monitoring interface usable by destination systems.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- Centralized monitoring environments, Historian and analytics systems
- Use
- For the Destination Zone to review equipment status, alarms, and approved representations of operational data.
Evaluation considerations
- Define the status, alarm, and telemetry data that need to leave the protected security zone.
- Confirm source polling behavior and freshness requirements for the one-way data path.
- Confirm how Destination Zone monitoring systems will use the data interface provided by the Receiving Module.
Source / Source Zone
Source Zone systems and data
- Sources
- Network devices and hosts, Security control equipment
- Data
- Syslog system events, Security and audit records
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving Module
Within the listed hardware version, topology, and test scope, the Source Module receives event data from defined sources and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a Syslog stream that destination systems can ingest.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- SIEM, SOC and centralized logging systems
- Use
- For event aggregation, review, correlation analysis, and audit retention in the Destination Zone.
Evaluation considerations
- Inventory the in-scope devices, hosts, and event formats.
- Confirm event volume, data freshness, and acceptable loss conditions.
- Confirm how the destination SIEM or logging system will receive and parse the data.
Source / Source Zone
Source Zone systems and data
- Sources
- Report and batch-export jobs, Approved source file locations
- Data
- Operational reports and batch data, File content approved for release
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving Module
Within the listed hardware version, topology, and test scope, the Source Module receives files from approved source locations and sends them across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the files and provides file and destination-facing interfaces.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- File-processing and analytics systems, Subsequent import workflows
- Use
- For the Destination Zone to obtain file copies created by the Receiving Module for analysis, retention, or approved subsequent import.
Evaluation considerations
- Define releasable source locations, file types, and approval workflows.
- Confirm file volume, update frequency, and acceptable loss conditions.
- Confirm destination naming, integrity-checking, retention, and import requirements.