← SCADA & Automation Studio
🛰️

Industrial Network Architecture Designer

Purdue / ISA-95 · ISA-99 / IEC 62443 Zones & Conduits

When to use: Use this tool to lay out an OT/ICS network using the Purdue model (ISA-95) and segment it into IEC 62443 zones & conduits. Enter device counts per Purdue level and it assigns one VLAN + RFC 1918 subnet per zone, sizes managed switches (STAR or redundant RING with MRP/RSTP), places OT firewalls and an optional Industrial DMZ (Level 3.5) and data diode, and produces a bill of materials. Apply defense-in-depth: deny-by-default conduits between zones and one-way data flow out of the plant.

Device Counts (per Purdue level)
PLC/RTU/IED + Eth I/O
dev
HMI/SCADA/eng WS
dev
historian/servers
dev
sites
Topology & Redundancy
Purdue Zone Stack
L4 · Enterprise (uplink)VLAN 40
▲ firewall / conduit ▲
L3.5 · Industrial DMZVLAN 35
▲ firewall / conduit ▲
L3 · Site OperationsVLAN 30
▲ uplink ▲
L2 · SupervisoryVLAN 20
▲ uplink ▲
L0–1 · Cell / Area (Field)VLAN 10
Cell/Area & Supervisory rings (MRP/RSTP) · dual uplink
Total Managed Switches
8
8 plant + 0 remote (0 sites)
Zone / VLAN / Subnet Plan
ZoneLvlVLANSubnetDevSw
Cell / Area (Field)L0–11010.10.0.0/26243
SupervisoryL22010.20.0.0/2862
Site OperationsL33010.30.0.0/2941
Industrial DMZL3.53510.35.0.0/2941
Enterprise (uplink)L44010.40.0.0/2921
Subnet prefix sized for device count + ~30% growth (RFC 1918). One VLAN per IEC 62443 zone.
Boundary / Security Placement
OT Firewall (L3 ⇄ IDMZ)
Stateful inspection, deny-by-default; conduit between Site Ops and IDMZ
IDMZ ⇄ Enterprise Firewall
Or single firewall with dedicated DMZ interface (3-leg)
Bill of Materials
8×
Managed Switch — 16-port (L2/L3 OT, MRP/RSTP)
Ring-capable (MRP <200 ms / RSTP)
1×
OT Firewall (L3 ⇄ IDMZ)
Stateful inspection, deny-by-default; conduit between Site Ops and IDMZ
1×
IDMZ ⇄ Enterprise Firewall
Or single firewall with dedicated DMZ interface (3-leg)
16×
SFP Uplink Module (1G/10G fiber)
2 per switch (redundant uplink)
8×
Fiber Patch (LC-LC, uplink runs)
One duplex pair per uplink path
Standards & References
ISA-95 / Purdue Model — functional levels L0–L4
ISA-99 / IEC 62443 — zones, conduits & security levels (SL 1–4)
IEC 62439-2 (MRP) — media redundancy <200 ms
IEEE 802.1w (RSTP) — rapid spanning tree
RFC 1918 — private IPv4 address space (10.0.0.0/8)
Defense-in-depth — IDMZ (L3.5), deny-by-default, one-way data

About the OT Network Architecture Designer

Industrial OT (operational technology) networks require a fundamentally different security and architecture approach from IT networks because process safety and availability take precedence over data confidentiality. This designer applies the Purdue Model (ISA-95) to assign devices to functional levels, segments them into IEC 62443 security zones with VLAN boundaries, sizes the managed switch infrastructure, and places OT firewalls and an Industrial DMZ to enforce defense-in-depth.

How OT network architecture is designed

The Purdue Model structures industrial networks into five levels: Level 0 (field devices — sensors, actuators), Level 1 (controllers — PLCs, DCS, RTUs), Level 2 (supervisory — HMI, SCADA), Level 3 (site operations — historian, application servers, engineering workstations), and Level 4 (enterprise — ERP, business IT). Each level boundary is a security conduit; communication between levels must be explicitly authorized and minimized.

IEC 62443 Security Level (SL) requirements increase with the potential consequence of a security breach: SL 1 (protection against casual unintentional violations), SL 2 (protection against intentional violation with simple means), SL 3 (sophisticated attack with OT knowledge), SL 4 (state-level adversary). The Industrial DMZ (Level 3.5) is a screened subnet between the OT network (Level 3) and the enterprise network (Level 4) that hosts historians and data relay servers, preventing direct connectivity between the two domains.

Applicable codes and standards

ISA-99 (published as IEC 62443) is the primary standard governing OT cybersecurity, defining zones, conduits, security levels, and the security management system. ISA-95 (IEC 62264) defines the Purdue Model levels and the information flows between enterprise and control systems. IEC 62439-2 defines Media Redundancy Protocol (MRP) for ring topologies with failover times below 200 ms. IEEE 802.1w (RSTP) provides spanning-tree redundancy for star topologies. NERC CIP applies to bulk electric systems and has mandatory cybersecurity requirements including electronic security perimeters (ESPs) and electronic access control.

Design considerations

The single most important design decision is placement and configuration of the OT firewall(s). Deny-by-default policies at each zone boundary mean that only explicitly required communication paths are permitted. For the IDMZ, a three-leg firewall (separate physical interfaces for OT, IDMZ, and enterprise) is preferred over two separate firewalls because it provides a single point of policy management while maintaining zone isolation. Data diodes (unidirectional security gateways) are used where one-way data flow from OT to enterprise is required, such as historian replication, because they physically prevent any data from flowing back into the OT network.

Network redundancy in the cell/area zone (Level 0–1) should use MRP ring topology with industrial managed switches rated for the operating temperature range (-40°C to +70°C for most process environments). Ring failover per IEC 62439-2 MRP is below 200 ms, which is acceptable for PROFINET and EtherNet/IP I/O.

How to use this calculator

Enter device counts for each Purdue level: field controllers (L0–1), supervisory HMIs and SCADA (L2), and site operations servers (L3). Enter the number of remote sites (each gets a replicated cell zone). Select the cell/area network topology (ring with MRP or star), uplink redundancy (dual or single), switch port density, and security level. Enable the IDMZ option to add a Level 3.5 demilitarized zone and enterprise uplink. The designer outputs the VLAN/subnet plan, switch count, firewall placement, and bill of materials.

Frequently asked questions

What is the Industrial DMZ and why is it required?

The Industrial DMZ (IDMZ or Level 3.5) is a screened subnet that sits between the OT network (Level 3) and the enterprise/IT network (Level 4). It hosts servers that need to exchange data in both directions — historian replication servers, file transfer gateways, remote access jump servers — without allowing direct connectivity between OT and enterprise. Without an IDMZ, an enterprise breach can directly reach PLCs and safety systems. IEC 62443 requires an IDMZ for SL 2 and above.

What is the difference between ISA-99 zones and conduits?

A zone is a grouping of assets with a common security level and security policy (e.g., the cell/area zone contains PLCs and field I/O at SL 2). A conduit is a communication path between zones with defined security controls — typically a firewall rule set, VPN tunnel, or data diode. Every communication between zones must pass through a conduit. The security level of the conduit must be at least as high as the higher-security zone it connects.

When should I use a ring topology vs. a star topology?

Ring topology (MRP or RSTP) provides sub-200 ms automatic failover when a switch or cable fails, which is essential for continuous process control where a 30-second link outage would cause a process upset or safety shutdown. Star topology is simpler, lower cost, and adequate for supervisory and enterprise zones where link failures are tolerable for seconds to minutes. Cell/area zones for continuous production (refining, power generation, water) should use ring; batch or warehouse applications can use star.

How many devices can a 16-port managed switch support per zone?

A 16-port switch with dual uplinks (for ring or redundant star) has 14 available access ports. Applying 20% growth headroom reduces the usable density to approximately 11–12 devices per switch. For a cell zone with 24 field devices and controllers, you need approximately 3 switches at 16-port density. The calculator applies this headroom automatically and accounts for whether the PSU occupies a backplane slot.

What is a data diode and when is it used instead of a firewall?

A data diode (unidirectional security gateway) is a hardware device that physically enforces one-way data flow — data can only move from the OT side to the enterprise side, never in reverse. This is stronger than a firewall (which can be misconfigured to allow reverse traffic) and is used for historian replication, alarm forwarding, and regulatory reporting where data must leave the OT network but no commands must be able to enter. Data diodes are used in critical infrastructure (power grid, water, oil & gas) at SL 3–4.

🎓

Try our SCADA Studio

More calculators, simulators, and guides for this discipline.

Related tools & guides

Network Latency SimulatorSIL EstimatorSCADA System DesignerRS-485 Network Sizing