Industrial DMZ: 6 Essential Rules to Separate IT and OT

Share:
Cybersecurity
Industrial DMZ: 6 Essential Rules to Separate IT and OT

Business users want plant data, vendors want remote access and IT wants to push patches, yet every direct path into the control network is a path for attackers too. A buffer zone in the middle lets data flow while no session ever crosses straight through.

Purdue Level 3.5 Firewalls Jump Host Replicated Historian

Connecting the office network directly to control systems is one of the most common and dangerous OT mistakes. A dedicated buffer network between them brokers every exchange so neither side talks to the other directly.

Hello everyone, today we are going to learn what an industrial DMZ is, where it sits in the Purdue model, which services live inside it, and which rules keep IT to OT traffic under control.
industrial DMZ

What Is an Industrial DMZ?

An industrial DMZ, often called IDMZ or level 3.5, is a separate network zone between the enterprise IT network and the operations network, where all traffic between the two ends and is brokered by dedicated servers. It builds on the Purdue model for ICS security.

Palo Alto Networks explains that levels 0 to 3 are the OT side and levels 4 to 5 are the IT side. Level 3.5 was not part of the original Purdue model but is now considered essential.

Level 3.5 buffer zone between enterprise and control networks
Image credit: InstruNexus

The core rule is that no traffic passes straight through. A user on the office network connects to a server in the DMZ, and that server separately connects to the plant.

In IEC 62443 terms, the zone is a conduit with strong controls, as described in IEC 62443 zones and conduits.

What Lives in the Industrial DMZ

Replicated Historian

A copy of plant data for business users.

Best for: reports, dashboards, analytics
Data
Remote Access Gateway

Jump host with MFA for vendors and engineers.

Best for: support sessions
Access
Patch and AV Servers

Stage updates before they enter OT.

Best for: WSUS and antivirus updates
Updates
File Transfer Broker

Scanned, logged file exchange.

Best for: recipes, reports, backups
Files

The historian mirror means business users never query the real process historian. Replication runs outward from OT only.

Remote sessions land on a jump host and are recorded, following the practices in PLC remote access security.

industrial DMZ at Purdue level 3.5

Firewall Designs

Enterprise NetworkLevel 4 and 5 users
IT Side FirewallAllows only DMZ services
Industrial DMZBrokers every exchange
OT Side FirewallAllows only defined OT flows
Control NetworkLevel 3 and below

The Cisco and Rockwell Automation CPwE design guide describes securely traversing data across the IDMZ with back to back firewalls or a three legged firewall. Many sites use two different firewall vendors for extra defence.

Rules must deny by default and allow only listed ports between named hosts. Any rule that allows IT to OT directly defeats the design.

6 Essential Industrial DMZ Rules

1
No Direct Traffic
Every flow terminates in the DMZ.
2
Deny by Default
Allow only documented ports and hosts.
3
No Shared Accounts
Separate domains or credentials for IT and OT.
4
MFA for Remote Access
Record and time limit sessions.
5
Scan Files and Media
Check every file entering OT.
6
Monitor and Log
Send logs to a security monitoring system.

These rules support a zero trust OT architecture, where every connection is verified. They also appear in most SCADA security checklists.

Avoid dual homed computers with one card in IT and one in OT, as explained in air gapped vs segmented networks.

Why Brokers Reduce Connections

Direct paths = OT servers × IT consumers
Brokered paths = OT servers + IT consumers

Example:
6 OT data sources and 40 IT consumers
Direct design = 240 firewall paths to manage
Industrial DMZ design = 46 paths, over 80 percent fewer

Fewer paths mean fewer firewall rules, simpler audits and a smaller attack surface. That is the practical value of a broker based design.

Connection Count Calculator

Direct vs Brokered Paths
Result
Direct 240 paths, brokered 46 paths, 81 percent fewer

Very small systems may see little saving. The security benefit of breaking direct sessions still applies.

Benefits
  • No direct IT to OT sessions.
  • Smaller attack surface.
  • Controlled vendor access.
  • Easier audits and compliance.
Challenges
  • Extra servers to maintain.
  • Replication design effort.
  • Needs skilled firewall management.
  • Temptation to add exceptions.

Understanding common types of cyber attacks helps justify each rule to management.

Cisco and Rockwell IDMZ Guide PDF

PDF
Securely Traversing IACS Data Across the Industrial Demilitarized Zone
Cisco and Rockwell Automation design and implementation guide

Industrial Demilitarized Zone Video

Industrial DMZ FAQ

What is an industrial DMZ?
It is a buffer network at Purdue level 3.5 between IT and OT. All traffic ends there and is brokered by dedicated servers.
Why not just use one firewall?
A single firewall that allows direct sessions still exposes control systems. The DMZ ensures no connection crosses straight from IT to OT.
What servers belong in it?
Replicated historians, remote access gateways, patch and antivirus servers and file transfer brokers are typical. Each has tightly limited rules.
How do vendors connect remotely?
They log in to a jump host in the DMZ with multi factor authentication. Sessions are recorded and limited in time.
Is it required by standards?
IEC 62443 zones and conduits and most sector guidance expect this separation. It is considered basic good practice today.
Can data flow both ways?
Only through defined brokers and ports. Outbound replication from OT is preferred, and inbound flows are kept to a minimum.
What is the biggest mistake?
Adding convenience rules that allow direct IT to OT traffic. Every exception should be justified, documented and reviewed.

Related Articles

External References

What We Learn Today

  • An industrial DMZ brokers every exchange between IT and OT.
  • Historian mirrors, jump hosts and patch servers live in level 3.5.
  • Deny by default and never allow direct IT to OT sessions.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *