products/Diode

Protect the devices you can't touch.

Plug & play network microsegmentation for the legacy, medical and OT devices that can't be patched, replaced or firewalled. No firewall project. No network redesign.

narrowin Diode appliance
narrowin · access-policy
[ Walkthrough ]

See a device segmented in minutes.

[ The reality ]

You can't touch it. You can't replace it.

Every critical network runs devices that can't protect themselves, and can't be taken offline to fix. Re-segmenting around them or fronting each with a full firewall is effort nobody funds, so they sit unprotected in shared zones.

  • Medical, lab and OT devices can't self-protect: certification freezes patching, vendors drop support
  • Re-segmenting them or fronting each with a full firewall is a project nobody funds
  • So they stay in large, shared segments with nothing between them
  • An infected device becomes the base for lateral movement to every unprotected device
[ Use cases ]

Where Diode fits.

One small device, many jobs, wherever a full firewall is overkill but an unprotected device is unacceptable.

01

Medical & clinical devices

Hospitals run thousands of connected devices on operating systems certification keeps frozen. Diode protects them at the network, without touching the device.

02

Research instruments

Sequencers, microscopes and lab analysers run closed, expensive, never-updated software. Diode contains them without disrupting the science.

03

OT crown jewels

Place Diode inline in front of PLCs, HMIs, CNC and safety systems: immediate protection, minimal change, a limited blast radius.

04

Legacy systems

The Windows 7 machine running a production line; the HMI the vendor won't update. Diode wraps them in microsegmentation, limiting what can reach them.

05

Smart facility & IoT

Door locks, lifts, cameras, displays and charging stations: building endpoints that ship with no security of their own. Diode gives them a perimeter.

06

Vendor & remote access

Give vendors access to specific equipment without exposing the network: controlled, logged, time-limited.

[ Capabilities ]

What Diode does.

Define the policy, deploy the device, then operate the fleet from one controller.

Definedecide what the device may talk to
Endpoint profiles
Research instrumentoutbound open
Medical devicemonitoring only
Charging stationinternet only
Legacy workstationisolated
A handful of standardised profiles instead of per-device rules: assign one and the Diode enforces it.
Default modes
ENDPOINT DIODE NETWORK
A default mode each direction (outbound and inbound) sets the baseline before a single exception.
Subnet exceptions
Default · inboundDENY ANY
10.20.0.0/24ALLOW
10.30.5.0/24ALLOW
Exceptions are subnets, not port-by-port rules: an allow-list anyone can read at a glance.
Deployget it inline, without a project
Plug & play, inline
SWITCH DEVICE inline · no redesign
Install between the switch and the device. No VLAN changes, no network redesign. An OT tech can do it.
Auto-enrolment
First boot — Diode powers on inline
Finds its controller automatically
Pulls its profile & policy
Enforcing — full L3 separation
On first boot the Diode finds the controller, pulls its policy and starts enforcing.
L2 transparent mode
L2
transparent bridge, inline
No IP, no gateway, no device reconfiguration
Diode runs as a transparent Layer 2 bridge: no IP, no gateway change, no reconfiguration on the device or the switch. It stays invisible on the wire and filters in both directions.
Operaterun the fleet, day to day
Central management
DIODEPROTECTING
DIODE-A7Ward 4 · MRI
DIODE-C2Cell 3 · PLC
DIODE-D9Lab · sequencer
DIODE-E1Garage · charger
31 Diodes · 4 sites · one controller
Every Diode in one controller, cloud or on-premises. Policy changes push out automatically.
Traffic logging
ALLOW→ 10.20.0.4 : 44322:14
ALLOW→ 10.20.0.7 : 888322:14
DENY← 10.0.3.9 : 2322:13
DENY← 10.0.8.1 : 44522:11
Every allowed and blocked flow, logged locally and centrally, forwardable to narrowin Log Analytics or your own log management.
Secure remote access
vendor access● on
Service engineer · HMI-PANEL
certificate-authenticated · scoped to one device
policy on · switch off when done · fully logged
Certificate-based, switched on when needed, fully logged access for vendors. No VPN, no open ports.
One controller

Diode is managed from the same narrowin controller as Explorer: network visibility and microsegmentation on one pane of glass, not two tools to learn.

[ How it works ]

Protection in minutes, not project phases.

Deployment simple enough for an OT technician or a medical engineer. No network team required.

1

Pre-configured policy

Diode ships ready to protect. A baseline profile is already loaded, so there's no rule-building before deployment.

2

Plug in inline

Install between the network switch and the device to protect. Works anywhere, with no reconfiguration of the existing network.

3

Auto-connect

On first boot Diode finds its controller, pulls its policy and starts enforcing. Full L3 separation, active.

4

Manage centrally

Update policies, watch traffic and run every Diode from one dashboard. Changes push out automatically.

[ Hardware & Deployment ]

Node A100M

The standard Diode appliance. Small enough to sit behind a wall plate or inside a control cabinet, with an optional wireless uplink for spots you can't pull a cable.

Ethernet2 × RJ45 100M
Wireless300M 802.11 b/g/n
PowerMicro-USB 5V/1A
Size58 × 58 × 25 mm
narrowin Node A100M appliance
Other options
narrowin Node D1000M

Node D1000M

Gigabit · new
Ethernet2 × RJ45 1000M
Wirelessn/a
PowerUSB-C 5V/2A
Size60 × 60 × 26 mm
narrowin Custom Node

Custom Node

Built to the deployment

When the standard nodes don't fit (more interfaces, a different form factor, rugged or rack-mount), hardware specified to the site.

narrowin Virtual Node

Virtual Node

Virtual deployment

No appliance: the Diode runs as a virtual machine on existing infrastructure. Same policy, same controller.

[ Details ]

The specifics.

Technical specifications
Enforcementnarrowin Node appliance, inline, or on existing switch infrastructure (Cisco, Aruba, Cumulus)
InstallationInline between the switch and the protected device(s)
ModeLayer 2 transparent (bump-in-the-wire); no IP, no gateway change
FilteringLayer 3/4: IP addresses, ports, protocols
Policy modelDefault mode per direction + subnet exceptions; allow-list by default
802.1XBuilt-in WPA supplicant: authenticates the Diode onto an 802.1X / NAC network
Remote accessCertificate-based, switched on when needed
ConnectivityCentral VPN breakout: backhaul a protected site to one gateway
LoggingLocal and central, forwardable to narrowin Log Analytics or any syslog target
Managementnarrowin controller, cloud or on-premises
Documentation/docs/diode (login) →
Frequently asked

Is this a data diode?

No. A data diode enforces one-way traffic by physics. Diode enforces bidirectional Layer 3/4 policy: it filters traffic in both directions by IP, port and protocol, allow-list by default. The name refers to tight, directional control, not hardware-enforced one-way flow.

How is it different from a full firewall?

A firewall is an infrastructure project: sizing, racking, rules, change windows. Diode is a small inline device with a baseline policy, deployed in minutes in front of the one asset that needs it.

Can one Diode protect multiple devices?

Yes, a single device or a small zone of related devices. For larger zones, multiple units or switch-based enforcement may fit better.

Does it work with any network equipment?

Yes. Diode installs inline and is transparent to the network: any switch vendor, no special configuration on existing infrastructure.

What about performance impact?

Minimal. Diode filters inline and stays transparent on the wire: no IP, no gateway change, no redesign of the surrounding network.

How is remote access secured?

Certificate-based authentication, scoped to specific equipment. Access is a policy you switch on when a vendor needs in and off again afterwards, and it can even be mapped to the device's physical A/B switch. Every session is logged, with no permanent VPN tunnels or exposed ports.

[ Related work ]

Deep dives into microsegmentation.

Bring us your most stubborn device.

The one that can't be patched, can't be replaced, and can't come off the network. That's the one Diode is for.

Talk to us about your devices