EN

03Scenarios

Menu

Scenarios / Evaluation models

Illustrative Deployment Scenarios

Use source → hardware-enforced boundary → destination to review data-release paths. Each scenario is an illustrative evaluation model, not a customer case.

01 / Evaluation model

Illustrative deployment scenario

Smart Manufacturing OT Visibility

An illustrative evaluation model in which defined production-line equipment status and process data are released one way from the Source Zone to establish visibility for manufacturing and analytics systems in the Destination Zone.

View evaluation details
  1. Source / Source Zone

    Source Zone systems and data

    Sources
    OPC UA servers, Modbus TCP control equipment
    Data
    Equipment status and process variables, Approved register data
  2. Hardware-enforced boundary

    Hardware-enforced one-way boundary

    Source Modulesource-to-destination one-way fiber data transferReceiving Module

    Within the listed hardware version, topology, and test scope, the Source Module receives defined production-line data and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a data interface usable by destination systems.

  3. Destination / Destination Zone

    Destination Zone systems and uses

    Destinations
    Historians, MES and analytics systems
    Use
    For the Destination Zone to review process trends, equipment status, and approved representations of production data.

Evaluation considerations

  • Confirm the approved scope of OPC UA nodes and Modbus registers.
  • Confirm data freshness, volume, and acceptable loss conditions.
  • Confirm the receiving-side interface and data representation required by Destination Zone systems.

02 / Evaluation model

Illustrative deployment scenario

Critical Infrastructure Monitoring

An illustrative evaluation model in which defined operational data from a protected facility are released one way so that an external monitoring environment can continuously review necessary status information.

View evaluation details
  1. Source / Source Zone

    Source Zone systems and data

    Sources
    Facility monitoring systems, Defined PLC and RTU data sources
    Data
    Equipment status and alarms, Approved operational telemetry
  2. Hardware-enforced boundary

    Hardware-enforced one-way boundary

    Source Modulesource-to-destination one-way fiber data transferReceiving Module

    Within the listed hardware version, topology, and test scope, the Source Module receives approved facility-monitoring data and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a monitoring interface usable by destination systems.

  3. Destination / Destination Zone

    Destination Zone systems and uses

    Destinations
    Centralized monitoring environments, Historian and analytics systems
    Use
    For the Destination Zone to review equipment status, alarms, and approved representations of operational data.

Evaluation considerations

  • Define the status, alarm, and telemetry data that need to leave the protected security zone.
  • Confirm source polling behavior and freshness requirements for the one-way data path.
  • Confirm how Destination Zone monitoring systems will use the data interface provided by the Receiving Module.

03 / Evaluation model

Illustrative deployment scenario

One-Way Security Log Export

An illustrative evaluation model in which system and security events are exported one way from the Source Zone for use by centralized logging and analytics environments in the Destination Zone.

View evaluation details
  1. Source / Source Zone

    Source Zone systems and data

    Sources
    Network devices and hosts, Security control equipment
    Data
    Syslog system events, Security and audit records
  2. Hardware-enforced boundary

    Hardware-enforced one-way boundary

    Source Modulesource-to-destination one-way fiber data transferReceiving Module

    Within the listed hardware version, topology, and test scope, the Source Module receives event data from defined sources and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a Syslog stream that destination systems can ingest.

  3. Destination / Destination Zone

    Destination Zone systems and uses

    Destinations
    SIEM, SOC and centralized logging systems
    Use
    For event aggregation, review, correlation analysis, and audit retention in the Destination Zone.

Evaluation considerations

  • Inventory the in-scope devices, hosts, and event formats.
  • Confirm event volume, data freshness, and acceptable loss conditions.
  • Confirm how the destination SIEM or logging system will receive and parse the data.

04 / Evaluation model

Illustrative deployment scenario

One-Way Data and File Release

An illustrative evaluation model in which approved reports, batch exports, and files are released one way from the Source Zone and made available as copies for subsequent workflows in the Destination Zone.

View evaluation details
  1. Source / Source Zone

    Source Zone systems and data

    Sources
    Report and batch-export jobs, Approved source file locations
    Data
    Operational reports and batch data, File content approved for release
  2. Hardware-enforced boundary

    Hardware-enforced one-way boundary

    Source Modulesource-to-destination one-way fiber data transferReceiving Module

    Within the listed hardware version, topology, and test scope, the Source Module receives files from approved source locations and sends them across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the files and provides file and destination-facing interfaces.

  3. Destination / Destination Zone

    Destination Zone systems and uses

    Destinations
    File-processing and analytics systems, Subsequent import workflows
    Use
    For the Destination Zone to obtain file copies created by the Receiving Module for analysis, retention, or approved subsequent import.

Evaluation considerations

  • Define releasable source locations, file types, and approval workflows.
  • Confirm file volume, update frequency, and acceptable loss conditions.
  • Confirm destination naming, integrity-checking, retention, and import requirements.