Automation Glossary • Screened subnet

What Is a Screened Subnet in an OT Network?

Merobix Engineering • • 7 min read

A screened subnet is a DMZ that is wrapped by two firewalls instead of one, with the buffer network sitting between them. In an OT context this back-to-back arrangement puts one firewall on the IT side and another on the OT side, so traffic is inspected twice on its way in or out. This page explains the screened-subnet architecture, why two firewalls beat one, and how each side inspects what passes.

Back to Blog

Screened subnet in one line: A screened subnet is a network segment placed between two firewalls in a back-to-back arrangement, so the DMZ it holds is guarded on both its IT-facing and OT-facing sides. The design forces traffic through two separate inspection points, ideally from different vendors, so a flaw or misconfiguration in one firewall does not by itself open a path between enterprise IT and the plant.

Two Firewalls Wrapping the DMZ

A screened subnet is a specific way to build a DMZ. Instead of a single firewall with three legs, one to IT, one to OT, and one to the DMZ, the screened-subnet design uses two firewalls in series with the DMZ network sitting between them. The outer firewall faces the enterprise IT network, the inner firewall faces the OT control network, and the buffer subnet lives in the space they enclose. This is why it is called a back-to-back or dual-firewall DMZ.

In this layout, anything traveling from IT toward OT must first pass the outer firewall to enter the DMZ, and then pass the inner firewall to leave the DMZ toward the plant. The reverse is true for traffic heading outward. There is no single device whose failure exposes the whole path, because two independent barriers stand between the business network and the controllers, with the shared services of the DMZ safely in the middle.

The screened subnet is best understood as the fortified enclosure around the DMZ concept. The DMZ answers what the buffer is and what services it holds; the screened subnet answers how that buffer is guarded, namely by two firewalls rather than one. Together they form a layered boundary where the mid-zone exists specifically so that no direct connection ever spans from IT to OT.

Why Two Firewalls, and Why From Different Vendors

The argument for two firewalls is defense in depth against a single point of failure. A firewall is software running on hardware, and it can carry vulnerabilities, be misconfigured, or fail. If one firewall is the only thing standing between IT and OT, then one flaw or one bad rule can open the whole path. With two firewalls in series, an attacker or a mistake has to get past both before reaching the plant, which is a substantially higher bar.

Using firewalls from two different vendors strengthens this considerably. If both firewalls run the same product, then a single vulnerability in that product may affect both at once, and defeating one likely means the same trick defeats the other. Choosing two different platforms means a weakness in one is unlikely to exist in the other, so the two barriers fail independently rather than together. Diversity turns two barriers into two genuinely separate hurdles.

This diversity has a real cost, which is honest to acknowledge. Two firewall platforms mean two management interfaces, two rule languages, two update cycles, and two sets of skills for the team to maintain. The screened subnet trades that operational overhead for the assurance that no single product flaw can breach the IT-to-OT boundary. Whether the trade is worth it depends on how critical the boundary is, but for a plant boundary it is frequently judged to be.

Inspection on Both the IT and OT Sides

In a screened subnet, each firewall is tuned to the world it faces. The outer, IT-facing firewall inspects traffic between the enterprise network and the DMZ, enforcing which business hosts may reach which DMZ services and screening out the broad, noisy exposure of the corporate environment before it gets near the buffer. It is the first filter, sized to the threats and traffic patterns typical of the IT side.

The inner, OT-facing firewall inspects traffic between the DMZ and the control network, and it is usually the more conservative of the two. It enforces the tightest rules about what may pass toward the plant, limiting connections to specific DMZ services, specific protocols, and specific directions, on the principle that anything reaching OT deserves the most scrutiny. Because it only ever sees traffic that has already cleared the outer firewall and terminated in the DMZ, it can be very restrictive without breaking legitimate business access.

The combined effect is that traffic crossing the boundary is examined twice, by two independently configured devices, against two rule sets suited to their respective sides. A packet that somehow slips past the IT-side firewall still faces a fresh, strict inspection before it can approach a controller. This double inspection, with the DMZ services forcing every flow to stop and be handled in the middle, is what makes the screened subnet a strong perimeter for an OT network.

Screened Subnets, SCADA, and Remote Access

For a SCADA system, the screened subnet is the heavy-duty version of the boundary that separates the plant from everything else. It is chosen where the consequences of a breach reaching the controllers are serious enough to justify two firewalls and the diversity of two vendors. The DMZ inside it holds the historian mirrors, brokers, and staging servers that let data cross the boundary, while the two firewalls ensure that crossing is always inspected from both directions.

This architecture also frames how remote access and cloud connections are handled safely. A connection carrying data toward a cloud dashboard, or a vendor session reaching in for support, terminates at a service in the screened subnet's DMZ rather than at a control device, and it passes the scrutiny of the firewall on whichever side it approaches. The plant's values can travel up to the cloud and support can be granted, all without any outside session touching a PLC directly.

For field operations that stream data to a shared dashboard, the screened subnet is what lets that visibility coexist with strong isolation. Operators watching a remote site see live values because those values were published into the DMZ and forwarded onward, and the double-firewall wrapper means that convenience never comes at the price of a soft path into the controllers. The subnet is screened precisely so the plant can be watched from anywhere while staying walled off from everywhere.

Frequently Asked Questions

What is the difference between a DMZ and a screened subnet?

A DMZ is the buffer network where shared services sit between IT and OT. A screened subnet is a specific way to build that DMZ using two firewalls in a back-to-back arrangement, with the buffer network between them. In short, the DMZ is the mid-zone and the screened subnet is the dual-firewall enclosure that guards it on both sides.

Why use two firewalls from different vendors?

Two firewalls in series mean an attacker or mistake must defeat both to cross from IT to OT, rather than relying on a single barrier. Using different vendors ensures the two firewalls do not share the same vulnerabilities, so defeating one does not automatically defeat the other. The cost is more management overhead, which is often justified for a plant boundary.

How is traffic inspected in a screened subnet?

Traffic is inspected twice by two independently configured firewalls. The outer, IT-facing firewall filters traffic between the enterprise network and the DMZ, and the inner, OT-facing firewall applies stricter rules on traffic between the DMZ and the control network. Because the inner firewall only sees traffic that already cleared the outer one and terminated in the DMZ, it can be very restrictive.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Cell/area zone  •  Network conduit  •  Flat network  •  Broadcast storm  •  Managed vs unmanaged switch  •  Hub-and-spoke  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →