MetaDefender Industrial Firewall 3.5.1 is a firmware release that embeds MetaDefender Core™ directly on existing four-port and eight-port appliances. Files are extracted from traffic crossing an OT (Operational Technology) zone boundary and scanned on the device itself, via two commercial anti-malware engines and by Predictive Alin AI. The latter analyzes files for indicators to predict malicious intent, without needing to inspect the file itself, thus extending detection to unknown and zero-day malware.
The scan status and verdict for each file are reported back to the operator.
Until now, a vendor's firmware image or an integrator's project file could cross a boundary inside a fully legitimate session without anyone checking what it carried. This happened because The update a firewall rule authorizes a connection, not its contents. Version 3.5.1 removes the blind spot for every conduit that already has a firewall, with no separate scanning appliance to rack and no agent to install on control assets.
What's New in Release 3.5.1
- File extraction at the boundary. Files are reassembled from inspected sessions crossing an OT zone boundary and handed to the local scanning stack.
- On-device scanning on the appliance. The scanning stack runs locally on the firewall, with no outbound connection required at scan time.
- Two anti-malware engines plus Alin AI. Avira and Bitdefender alongside Predictive Alin AI, tuned to the resource envelope of the appliance. Scanning runs within the thermal and compute limits of ruggedized industrial hardware.
- Detection beyond signatures. Alin AI extends scanning to threats that no engine has a signature for yet, including unknown and zero-day malware.
- Scan status updates. Each file's scan state and resulting verdict are reported back to the operator as scanning completes, rather than only at the end of a batch.
- Full result visibility. Verdicts, engine-level detail and file metadata are surfaced in the interface, giving operators something concrete to hand to an auditor or an incident reviewer.
- Delivered as a firmware update. The capability arrives on the four-port and eight-port appliances already in the field through a standard upgrade, no scanning appliance to rack and no agent on control assets.
Why File Scanning Belongs at the OT Zone Boundary
The conventional answer to file extraction in industrial environments is a separate scanning appliance, usually deployed in the industrial DMZ (Demilitarized Zone). That works, and for high-volume centralized inspection it remains the right architecture. But it also assumes the economics work. However, in a plant with nine production cells, or a utility with dozens of substations, one scanning appliance per zone rarely works.
The result is a familiar compromise. File inspection gets centralized at a single chokepoint, and every zone boundary below it is covered by traffic inspection alone. Files crossing between cells, or reaching an engineering workstation from a vendor session, are inspected once at the perimeter and then trusted everywhere inside it.
Running the scanning engines on the firewall itself removes the need for a separate scanning appliance and delivering them as a firmware update removes the need for new hardware. Any zone boundary that already has a MetaDefender Industrial Firewall can now scan files at that same point, with no added hardware, cabinet space, power draw or maintenance contract. The change is more palpable in connected environments than in fully isolated ones. As enterprise systems, cloud analytics, and remote vendor access reach further into industrial zones, the number of legitimate reasons for a file to cross a boundary keeps growing. Each one is a path that traffic inspection alone can’t fully verify.
Deployment Scenarios: Vendor Access, Industrial DMZ, and Inter-Zone Conduits
Version 3.5.1 is built for the crossings that already exist in most industrial architectures:
- Firmware, patches and configuration files arriving over a remote vendor or contractor session
- Historian and telemetry data leaving the control network toward enterprise or cloud consumers
- File movement between the enterprise network and Level 3 systems in the industrial DMZ
- Transfers between production cells, substations or other peer zones
- Tooling and project file updates reaching engineering workstations inside a zone
Availability, Supported Models, and Upgrade Path
Version 3.5.1 is a firmware release for MetaDefender Industrial Firewall and is available now on the four-port and eight-port models. Existing customers receive file extraction and scanning with the purchase of an additional license with the hardware already deployed; no replacement appliance or additional rack unit is required.
Existing customers should review the release notes for upgrade prerequisites before deploying to production zones.
To discuss where file scanning fits in your zone architecture, get in touch with an OPSWAT expert; we’ll be in touch within 24 hours.
Frequently Asked Questions
Do we need new hardware to get file scanning?
No. Version 3.5.1 is a firmware release for the MetaDefender Industrial Firewall appliances already in the field. The four-port and eight-port models gain file extraction and scanning through a standard upgrade, which is the point: the capability lands at every conduit where a firewall is already installed, rather than at the small number of places an organization could justify buying a separate scanning appliance.
How is an industrial firewall different from an enterprise firewall?
While enterprise firewalls optimize for feature breadth, industrial ones walls optimize for determinism and survivability. An. Industrial firewall is built to survive the physical environment with a wide operating temperature range, no moving parts, DIN-rail or panel mounting, and hazardous-location certification where required. It understands industrial protocols, so it can inspect and enforce policy on traffic that an enterprise firewall treats as opaque. And it is designed around availability first: in a plant, a security control that interrupts a process is often worse than the threat it stopped.
We already have a firewall between IT and OT. What does file scanning add?
Visibility into something the firewall has never been able to describe. A firewall rule authorizes a conversation, not its contents. If a vendor is permitted to transfer a firmware image over an approved protocol from an approved source, the firewall has no basis to object. The session is exactly what policy allows. Malware delivered inside authorized file transfers falls outside what a firewall traditionally examines. File scanning is the layer that looks inside the permitted conversation and tells you what was in it.
Does this replace an air gap or a data diode?
No,. A data diode or unidirectional gateway enforces direction in hardware: there is physically no return path. A firewall enforces policy in software, which means it can be misconfigured. Where regulation or risk tolerance demands hardware-enforced one-way flow, that requirement does not change because files are now being scanned. A diode brings the answer to “can anything come back?” and file scanning answers “what was in what crossed?”
Do we need to install anything on PLCs (Programmable Logic Controllers) or engineering workstations?
No. Extraction and scanning run entirely on the firewall. Nothing is installed on control assets, and no changes are required to the devices inside the zone. This is deliberate, since agent deployment on validated or vendor-supported industrial equipment is often contractually or practically impossible.
What does Alin AI detect that the anti-malware engines do not?
Signature-based engines identify malware that has been seen and catalogued. Alin AI extends scanning to files that do not match a known signature, which is where unknown and zero-day threats sit. In an industrial context that matters most for files arriving through channels a plant cannot easily vet: a contractor's laptop, a vendor's firmware drop, a project file passed between integrators.
Where does this sit in an IEC 62443 zone and conduit model?
At the conduit. The appliance is the enforcement point between two zones, and version 3.5.1 adds content visibility to the policy already enforced there. In Purdue model terms, this most often means the boundary between Levels 3 and 3.5, and between Level 3 and the cell or area zones below it. A more useful framing is simply that it belongs wherever a conduit already carries files.
Does this replace MetaDefender Kiosk for USB (Universal Serial Bus) media?
No, they cover different entry paths. Removable media carried into a facility by a technician never traverses the firewall, so it cannot be scanned there. A physical checkpoint remains the control for that path, and most organizations need both.
How does this help with a compliance audit?
Primarily through evidence. Scanning at the boundary produces a record of what crossed, when, and what the verdict was. That’s the kind of artifact that IEC 62443, NERC CIP and NIS2 reviews tend to ask for and that most organizations reconstruct manually after the fact.
