When to use: Use this tool to lay out an OT/ICS network using the Purdue model (ISA-95) and segment it into IEC 62443 zones & conduits. Enter device counts per Purdue level and it assigns one VLAN + RFC 1918 subnet per zone, sizes managed switches (STAR or redundant RING with MRP/RSTP), places OT firewalls and an optional Industrial DMZ (Level 3.5) and data diode, and produces a bill of materials. Apply defense-in-depth: deny-by-default conduits between zones and one-way data flow out of the plant.
| Zone | Lvl | VLAN | Subnet | Dev | Sw |
|---|---|---|---|---|---|
| Cell / Area (Field) | L0–1 | 10 | 10.10.0.0/26 | 24 | 3 |
| Supervisory | L2 | 20 | 10.20.0.0/28 | 6 | 2 |
| Site Operations | L3 | 30 | 10.30.0.0/29 | 4 | 1 |
| Industrial DMZ | L3.5 | 35 | 10.35.0.0/29 | 4 | 1 |
| Enterprise (uplink) | L4 | 40 | 10.40.0.0/29 | 2 | 1 |
Industrial OT (operational technology) networks require a fundamentally different security and architecture approach from IT networks because process safety and availability take precedence over data confidentiality. This designer applies the Purdue Model (ISA-95) to assign devices to functional levels, segments them into IEC 62443 security zones with VLAN boundaries, sizes the managed switch infrastructure, and places OT firewalls and an Industrial DMZ to enforce defense-in-depth.
The Purdue Model structures industrial networks into five levels: Level 0 (field devices — sensors, actuators), Level 1 (controllers — PLCs, DCS, RTUs), Level 2 (supervisory — HMI, SCADA), Level 3 (site operations — historian, application servers, engineering workstations), and Level 4 (enterprise — ERP, business IT). Each level boundary is a security conduit; communication between levels must be explicitly authorized and minimized.
IEC 62443 Security Level (SL) requirements increase with the potential consequence of a security breach: SL 1 (protection against casual unintentional violations), SL 2 (protection against intentional violation with simple means), SL 3 (sophisticated attack with OT knowledge), SL 4 (state-level adversary). The Industrial DMZ (Level 3.5) is a screened subnet between the OT network (Level 3) and the enterprise network (Level 4) that hosts historians and data relay servers, preventing direct connectivity between the two domains.
ISA-99 (published as IEC 62443) is the primary standard governing OT cybersecurity, defining zones, conduits, security levels, and the security management system. ISA-95 (IEC 62264) defines the Purdue Model levels and the information flows between enterprise and control systems. IEC 62439-2 defines Media Redundancy Protocol (MRP) for ring topologies with failover times below 200 ms. IEEE 802.1w (RSTP) provides spanning-tree redundancy for star topologies. NERC CIP applies to bulk electric systems and has mandatory cybersecurity requirements including electronic security perimeters (ESPs) and electronic access control.
The single most important design decision is placement and configuration of the OT firewall(s). Deny-by-default policies at each zone boundary mean that only explicitly required communication paths are permitted. For the IDMZ, a three-leg firewall (separate physical interfaces for OT, IDMZ, and enterprise) is preferred over two separate firewalls because it provides a single point of policy management while maintaining zone isolation. Data diodes (unidirectional security gateways) are used where one-way data flow from OT to enterprise is required, such as historian replication, because they physically prevent any data from flowing back into the OT network.
Network redundancy in the cell/area zone (Level 0–1) should use MRP ring topology with industrial managed switches rated for the operating temperature range (-40°C to +70°C for most process environments). Ring failover per IEC 62439-2 MRP is below 200 ms, which is acceptable for PROFINET and EtherNet/IP I/O.
Enter device counts for each Purdue level: field controllers (L0–1), supervisory HMIs and SCADA (L2), and site operations servers (L3). Enter the number of remote sites (each gets a replicated cell zone). Select the cell/area network topology (ring with MRP or star), uplink redundancy (dual or single), switch port density, and security level. Enable the IDMZ option to add a Level 3.5 demilitarized zone and enterprise uplink. The designer outputs the VLAN/subnet plan, switch count, firewall placement, and bill of materials.
The Industrial DMZ (IDMZ or Level 3.5) is a screened subnet that sits between the OT network (Level 3) and the enterprise/IT network (Level 4). It hosts servers that need to exchange data in both directions — historian replication servers, file transfer gateways, remote access jump servers — without allowing direct connectivity between OT and enterprise. Without an IDMZ, an enterprise breach can directly reach PLCs and safety systems. IEC 62443 requires an IDMZ for SL 2 and above.
A zone is a grouping of assets with a common security level and security policy (e.g., the cell/area zone contains PLCs and field I/O at SL 2). A conduit is a communication path between zones with defined security controls — typically a firewall rule set, VPN tunnel, or data diode. Every communication between zones must pass through a conduit. The security level of the conduit must be at least as high as the higher-security zone it connects.
Ring topology (MRP or RSTP) provides sub-200 ms automatic failover when a switch or cable fails, which is essential for continuous process control where a 30-second link outage would cause a process upset or safety shutdown. Star topology is simpler, lower cost, and adequate for supervisory and enterprise zones where link failures are tolerable for seconds to minutes. Cell/area zones for continuous production (refining, power generation, water) should use ring; batch or warehouse applications can use star.
A 16-port switch with dual uplinks (for ring or redundant star) has 14 available access ports. Applying 20% growth headroom reduces the usable density to approximately 11–12 devices per switch. For a cell zone with 24 field devices and controllers, you need approximately 3 switches at 16-port density. The calculator applies this headroom automatically and accounts for whether the PSU occupies a backplane slot.
A data diode (unidirectional security gateway) is a hardware device that physically enforces one-way data flow — data can only move from the OT side to the enterprise side, never in reverse. This is stronger than a firewall (which can be misconfigured to allow reverse traffic) and is used for historian replication, alarm forwarding, and regulatory reporting where data must leave the OT network but no commands must be able to enter. Data diodes are used in critical infrastructure (power grid, water, oil & gas) at SL 3–4.
Try our SCADA Studio
More calculators, simulators, and guides for this discipline.