OT Network Segmentation Simulator — Industrial DMZ, Jump Host & Conduit Interactive

Interactive OT/ICS network-segmentation workbench modeling an enterprise zone, industrial DMZ, jump host and inner firewall protecting a local PLC and HMI, with a 3D cutaway model, live forwarding-decision tracing, guided experiments, a model-verification bench and a knowledge-check quiz.

← Networking Labs
About this tool — how it works & FAQOpen ▾Close ▴

About the OT Network Segmentation Simulator

This simulator models an industrial control network split into enterprise, industrial DMZ and OT trust zones. An enterprise workstation, perimeter firewall, DMZ historian replica, maintenance jump host, inner firewall, local HMI, PLC and a motor-driven conveyor cell sit on a single cutaway workbench so you can trace exactly which conduits a given request is allowed to cross.

What the simulator shows

• A real-time 3D cutaway of the enterprise workstation, outer (enterprise-to-DMZ) firewall, DMZ historian replica, maintenance jump host, inner (DMZ-to-OT) firewall, local HMI, DIN-rail PLC/remote I/O and a motor-driven conveyor cell, with home view, focus-selected-part, toggleable full enclosure, exploded view, auto-rotate, expand and label toggle controls, and numbered parts matching the companion diagram. • A test-request selector with five traffic patterns: enterprise reads the DMZ historian, OT sends the historian replica, approved maintenance via the jump host, local HMI-to-PLC control, and a direct enterprise-to-PLC command. • Five policy toggles: enterprise-to-DMZ rule enabled, DMZ-to-OT conduit enabled, maintenance window open, operator approval recorded, and a "demonstrate flat-network bypass" toggle that intentionally defeats segmentation. • Auto-traffic with an adjustable interval (0.5–5 s) and a manual "Send test traffic" action, alongside start/stop trial controls. • Play/pause, single 0.1 s step and 1 s step time controls, plus a playback-speed selector (10x slow motion, real time, 10x, 60x/1 minute-per-second). • Six live metrics: permitted requests, denied requests, effective policy zones, maintenance-window state, operator-approval state and test-request count. • A Curves & measurements tab with two charts (effective policy zones over time; permitted vs. denied requests), the full model equations, and snapshot readouts. • An Experiments tab with four guided scenarios (DMZ read, block direct command, approved maintenance, local operation during isolation), a model-verification bench of independent automated checks, and a timestamped event log with a copyable trial report. • A Learn & assess tab with four guided lessons (define zones, constrain conduits, authorize maintenance, keep local autonomy), a two-question knowledge-check quiz, and a written scope/reference statement citing NIST SP 800-82.

Why enterprise, DMZ and OT stay separate zones

The model deliberately blocks a direct enterprise-to-PLC command even when a request is sent: enterprise clients are only permitted to reach an industrial DMZ historian replica, never the control network itself, so business-side systems never gain a direct path to the equipment that runs a process. Maintenance access into the OT zone is treated as an exception that requires all four conditions at once — the outer rule, the inner conduit, an open maintenance window and a recorded operator approval — modeled through a dedicated jump host rather than a standing route.

The "demonstrate flat-network bypass" toggle exists specifically to contrast this with an unsegmented design: enabling it lets a request skip the zone boundaries that the rest of the model enforces, illustrating why collapsing the DMZ into one flat network removes the protection the two firewalls otherwise provide. Meanwhile, local HMI-to-PLC control keeps working even when both enterprise conduits are disabled, showing that segmentation should isolate outside access without stopping legitimate local operation.

Reading the policy zones, conduits and trial report

The equations panel states the maintenance permit condition as outer rule AND inner rule AND window AND approval, notes that local control stays within the OT zone, and that a direct enterprise-to-PLC request is denied unless the unsafe bypass is explicitly enabled. The charts track effective policy zones and the running count of permitted versus denied requests as you change toggles and fire test traffic, so you can see a decision change the moment a required condition is removed.

This is an illustrative zone-and-conduit policy model based on industrial security guidance, not a working security appliance: it does not implement authentication, a data diode, intrusion detection, safety interlock logic or a complete security architecture, and every packet, timestamp and fault injection in the log stays inside the offline simulation.

Frequently asked questions

Why can an enterprise workstation read production data but never command the PLC directly?

The model routes enterprise reads through a DMZ historian replica instead of a direct path into the OT zone. A direct enterprise-to-PLC command is denied by default because it would cross both the outer and inner firewalls into the protected control zone without the explicit conduit, and the only way to override that in the simulator is the dedicated flat-network bypass toggle, which exists to demonstrate the risk rather than to represent normal operation.

What has to be true for a maintenance request to succeed?

The maintenance permit requires all four conditions together: the enterprise-to-DMZ rule enabled, the DMZ-to-OT conduit enabled, an open maintenance window, and a recorded operator approval. The approved-maintenance experiment applies all four at once and routes the request through the jump host; disabling any single one blocks the same request, which is exactly what the model is built to show.

Does blocking enterprise access also stop local plant operation?

No. The local-operation-during-isolation experiment disables both the outer and inner conduits and shows that local HMI-to-PLC requests keep being permitted, because that traffic never leaves the OT zone. Segmentation in this model isolates outside access from the control network without interrupting the local control loop that keeps the conveyor cell running.

What does this OT segmentation model not include?

It is an illustrative zone-and-conduit policy exercise based on industrial security guidance (NIST SP 800-82), not a full security architecture. It excludes authentication, a data diode, intrusion detection, safety-certified interlock logic and complete network hardening, and every request, protocol exchange and fault injection is simulated entirely offline — no traffic reaches a real device.

Related tools & guides