Segmentation in brownfield plants

Practical VLAN moves when you cannot air-gap the world.

Greenfield diagrams show crisp DMZ boundaries. Brownfield plants show maintenance laptops, OEM remote links, and a printer someone put on the control subnet. TECHNLOGIX PTY LTD designs segmentation as a sequence of small changes with rollback, not a Big Bang firewall weekend.

Start with inventory truth

Before VLANs, map MAC addresses, protocols, and business owners. Unknown devices are frozen, not trusted. We photograph switch ports and label physically—software diagrams lie until verified.

Phase moves

Typical order: isolate obvious IT clutter from OT; group PLCs and HMIs; place historians and MES interfaces in a controlled zone; add jump hosts for vendor access with session logging. Each phase includes a maintenance window and communication test scripts.

What we refuse

We will not disable plant firewalls to “make it work” without written risk acceptance. Temporary rules get expiry dates. Permanent rules get change tickets.

Victorian reality

Many sites share integrators across competitors’ equipment brands. Segmentation must allow FAT VPNs without opening entire /16 networks. We document allowed flows in ICD style so future projects do not punch random holes.

← Insights · Integration services