When to use: Use this tool to lay out an OT/ICS network using the Purdue model (ISA-95) and segment it into IEC 62443 zones & conduits. Enter device counts per Purdue level and it assigns one VLAN + RFC 1918 subnet per zone, sizes managed switches (STAR or redundant RING with MRP/RSTP), places OT firewalls and an optional Industrial DMZ (Level 3.5) and data diode, and produces a bill of materials. Apply defense-in-depth: deny-by-default conduits between zones and one-way data flow out of the plant.
| Zone | Lvl | VLAN | Subnet | Dev | Sw |
|---|---|---|---|---|---|
| Cell / Area (Field) | L0–1 | 10 | 10.10.0.0/26 | 24 | 3 |
| Supervisory | L2 | 20 | 10.20.0.0/28 | 6 | 2 |
| Site Operations | L3 | 30 | 10.30.0.0/29 | 4 | 1 |
| Industrial DMZ | L3.5 | 35 | 10.35.0.0/29 | 4 | 1 |
| Enterprise (uplink) | L4 | 40 | 10.40.0.0/29 | 2 | 1 |