Air-gapped networking

Run a network that never touches the public internet

Some networks should have no path to the internet at all. They still need managing, policy still has to reach them, and devices still need updating, which normally means doing all of it by hand or making one exception that quietly undoes the isolation you built.

The situation

A plant, a substation, a laboratory, a defence supplier’s development network. Something where the decision was made, correctly, that this does not connect.

Then the ordinary work of running a network arrives anyway. Someone has to change a rule, add a device, see what is talking to what, and know it is still configured the way the auditor was told it was.

Why the usual answers do not fit

Managing it by hand works until the network is bigger than one person’s memory. The configuration drifts, the documentation is a year behind, and nobody is quite sure which of the three firewalls is authoritative.

A management platform in the cloud solves that and breaks the isolation, because now there is a path out. The exception is usually described as temporary and is usually not.

A jump host with a one-way connection is the compromise most people land on, and it is the thing the auditor asks about first.

The shape of it

The management layer is inside the boundary too. There is no exception to make.

Some networks are not meant to touch the public internet at all. The console, the gateways and the devices all stay inside.

Your networkno line crosses the boundary, so there is no path to blockthe management layer is inside too Laptop Desktop Phone QS-WAN Control Tower Gateway Servers Internal apps Site resourcesPublic internet
secure tunnelunprotected pathcontrol channelalready yours
How QS-WAN solves it

The control plane runs on your own infrastructure, inside the same boundary as the network it manages. Policy, device enrolment, certificates and the network map all live there. Nothing needs to reach out for the system to work.

The isolation is the design, not a setting.

You are not turning off a cloud connection. There is not one.

You still get the console.

Gateways, devices, policy and the audit trail are visible in one place, which is the part that usually gets traded away when a network goes isolated.

Certificates and identity work without a public authority.

Device identity is issued and revoked inside the boundary.

Who this is for

This is usually the situation when

What we will not claim here

Two things, because this is the audience that checks.

The air-gap behaviour is documented, not independently tested by us. It comes from the product documentation and the installer, and we would rather you knew which of those two it is before you put it in a tender.

Licensing and updates in a fully isolated deployment have a procedure, and it is the first question every engineer asks. Ask us for it directly rather than assuming from this page, because the honest answer depends on which of the three delivery modes you use.

What your people see

The same single agent as everyone else, connecting to the same kind of gateway. The isolation is an architecture decision, not something the person operating a terminal has to think about.

Integration

What it takes, and what it leaves alone

What you need

A host inside the perimeter for the Control Tower stack.

What changes

Management moves inside the boundary instead of outside it.

What doesn't

The boundary itself. No line crosses it in either direction.

Key features of this use case

The features this use case relies on

Device enrollment

Certificate management

Network mapping

Talk to a cybersecurity specialist

The people who answer are the ones who build the product.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top