The Update You Can’t Afford to Skip: End of Support for Office 2016 & Office 2019

Read Now
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Data Diode and
Unidirectional Security Gateway Guide

Overview

Data diodes and unidirectional security gateways are cybersecurity solutions that strictly ensure one-way data transfer between two networks of different security classifications. While firewalls have long been the traditional solution to segment network traffic, they are prone to misconfigurations and exploits.

Data diodes and unidirectional security gateways have been common for decades in high-security environments, such as defense and intelligence agency facilities. Data diodes physically enforce one way data transfers by converting data to light via a hardware-enforced, one-way link, ensuring now return path exists. Modern unidirectional security gateways utilize integrated security software and protocol replication to enforce unidirectional data flows.

A Unidirectional Security Gateway builds security services and protocol handling on top of a unidirectional link, enabling more complex, reliable, and operationally usable data transfer, without breaking the one-way guarantee.

With the rise of industrial IoT and digitization, unidirectional security gateways are increasingly being deployed by private enterprises to securely transmit data generated by industrial control and safety systems. This includes nuclear power plants and other electrical power generating facilities, manufacturing facilities, and transport systems to other networks (including the public Internet) while the gateways protect the networks containing these systems from attack.

Unidirectional means data can travel in only one direction. A reasonable way to think of unidirectional security gateways is as “one-way valves for data”, allowing data to flow out, without a way back in. A common scenario is where unidirectional gateways provide one-way data transfers from a high-security network towards a network with a lower security level. Data can be transferred while the high-security network stays protected from attack using that connection. In this scenario, the technology is protecting the systems in the high-security network producing the data being transferred.

AVEVA PI Data Replication Between Three Power Generation Plants and Enterprise Historian

MetaDefender Optical Diode reliably replicates AVEVA Pi historian data using the MetaDefender AVEVA Pi Connector. Data is transferred over a non-routable protocol break enhancing security and confidentiality of the source network.

National Healthcare Provider Requires Secure Transfer of Data Center Alerts and Monitoring Data

MetaDefender Optical Diode securely transfers alerts and monitoring data to a central monitoring location. MetaDefender Modbus, SFTP and SMTP (email) connectors transfer data over an enforced one-way non-routable protocol break.

Secure Cross Domain File Transfer

MetaDefender Transfer Guard couples the air-gap level security provided by Optical Diode with OPSWAT’s award-winning MetaDefender Core file sanitization engine ensuring files are safe to transfer.

  • Hardware-enforced network segmentation
  • File transfer over non-routable protocol break
  • Advanced threat prevention for files entering secure domain
  • Power Plants
    Use Case

    AVEVA PI Data Replication Between Three Power Generation Plants and Enterprise Historian

    MetaDefender Optical Diode reliably replicates AVEVA Pi historian data using the MetaDefender AVEVA Pi Connector. Data is transferred over a non-routable protocol break enhancing security and confidentiality of the source network.

  • Healthcare
    Use Case

    National Healthcare Provider Requires Secure Transfer of Data Center Alerts and Monitoring Data

    MetaDefender Optical Diode securely transfers alerts and monitoring data to a central monitoring location. MetaDefender Modbus, SFTP and SMTP (email) connectors transfer data over an enforced one-way non-routable protocol break.

  • Cross Domain
    Use Case

    Secure Cross Domain File Transfer

    MetaDefender Transfer Guard couples the air-gap level security provided by Optical Diode with OPSWAT’s award-winning MetaDefender Core file sanitization engine ensuring files are safe to transfer.

    • Hardware-enforced network segmentation
    • File transfer over non-routable protocol break
    • Advanced threat prevention for files entering secure domain

See Comparison Table below or get the guide.

Product Comparison Chart

Security GatewaysOptical Diodes
ModelUnidirectional Security GatewayBilateral Security GatewayTransfer GuardOD101-SOD101-DRXE5 / XE15 / XE50 (Fend)SE5 / SE15 (Fend)CE5 / CE15 (Fend)
Thumbnail
Data Flows SupportedMultiple SimultaneousMultiple SimultaneousMultiple SimultaneousMultiple SimultaneousMultiple SimultaneousSingleSingleSingle
Protocols SupportedModbus, OPC (UA, DA, A&E), MQTT, IEC104, DNP3, AVEVA PI historian, ICCP, UDP, TCP, HTTP, HTTPS, SMTP, Video/audio, Ethernet packet transfer, Log Transfer, SNMP Traps, SYSLOG, HMI Screen View, FTP, FTPS, SFTP, Windows File Share, SMB, CIFSModbus, OPC (UA, DA, A&E), MQTT, IEC104, DNP3, AVEVA PI historian, ICCP, UDP, TCP, HTTP, HTTPS, SMTP, Video/audio, Ethernet packet transfer, Log Transfer, SNMP Traps, SYSLOG, HMI Screen View, FTP, FTPS, SFTP, Windows File Share, SMB, CIFS, MS SQLFTP, FTPS,SFTP, Folder and file transfer, Windows File Share, SMB, CIFS, HTTPS, Syslog, TCP, UDPModbus, OPC (UA, DA, A&E), MQTT, IEC104, DNP3, AVEVA PI historian, ICCP, UDP, TCP, HTTP, HTTPS, SMTP, Video/audio, Ethernet packet transfer, Log Transfer, SNMP Traps, SYSLOG, HMI Screen View, FTP, FTPS, SFTP, Windows File Share, SMB, CIFSModbus, OPC (UA, DA, A&E), MQTT, IEC104, DNP3, ICCP, UDP, TCP, HTTP, HTTPS, SMTP, Video/audio, Ethernet packet transfer, Log Transfer, SNMP Traps, SYSLOG, HMI Screen View, FTP, FTPS, SFTP, Windows File Share, SMB, CIFSFTP, FTPS, SFTP, TCP, UDP, Modbus TCP, Modbus RTU, BACnet (in), LON-IP (in), TLS, Syslog, OPSWAT Screen View FTP, FTPS, SFTP, TCP, UDP, Modbus TCP, Modbus RTU, BACnet (in), LON-IP (in), TLS, Syslog, OPSWAT Screen View FTP, FTPS, SFTP, TCP, UDP, Modbus TCP, Modbus RTU, BACnet (in), LON-IP (in), TLS, Syslog, OPSWAT Screen View  
Bandwidth Supported10 Gbps, 1 Gbps, 100 Mbps10 Gbps, 1 Gbps, 100 Mbps10 Gbps, 1 Gbps, 100 Mbps10 Gbps, 1 Gbps, 100 Mbps50 Mbps, 10 Mbps5Mbps, 15 Mbps, 50Mbps15 Mbps, 5 Mbps15 Mbps, 5 Mbps
Form Factor2x 1U Server2x 1U Server2x 1U Server2x 1U Server2x DIN-railDIN-rail / Wall mountDIN-rail / Wall mountDIN-rail / Wall mount
Dimensions (L x W x H)2x 15.75" x 19" x 1.75"2x 15.75" x 19" x 1.75"2x 15.75" x 19" x 1.75"2x 15.75" x 19" x 1.75"2x 6.3" x 2.5" x 7.32"5.1" x 5.8" x 1.6"5.1" x 5.8" x 1.6"5.1" x 5.8" x 1.6"
InputsEthernetEthernetEthernetEthernetEthernetEthernet, Serial RS-485Ethernet, Serial RS-485Ethernet, Serial RS-485
OutputsEthernetEthernetEthernetEthernetEthernetEthernetEthernet, Serial RS-485Ethernet, Cellular 4G LTE
File Sanitization
High Availability
Available Globally
Certification/ AccreditationCommon Criteria EAL4+, FCC/CE/UKCAFCC/CE/UKCACommon Criteria EAL4+, FCC/CE/UKCACommon Criteria EAL4+, FCC/CE/UKCACommon Criteria EAL4+, FCC/CE/UKCA C1D2CE/ETL/RoHSCE/ETL/RoHSCE/ETL/RoHS/
FCC
Metascan™ Multiscanning
With up to 30 Anti-virus engines
Deep CDR™
File sanitization for zero-day threats
Proactive DLP™
Prevent sensitive data leakage
Sandbox
Analyze malware in a controlled environment
File-Based Vulnerability Assessment
Detect application and file-based vulnerabilities
SBOM
Identify vulnerabilities in the software supply chain
Country of Origin Detection
Instantly detect geographic sources
CYBERSECURITY ATTACKS ARE ON THE RISE

Explore Key Use Cases, Certifications, Protocol Support, and a Buyer’s Checklist