Plug & play network microsegmentation for the legacy, medical and OT devices that can't be patched, replaced or firewalled. No firewall project. No network redesign.

Every critical network runs devices that can't protect themselves, and can't be taken offline to fix. Re-segmenting around them or fronting each with a full firewall is effort nobody funds, so they sit unprotected in shared zones.
One small device, many jobs, wherever a full firewall is overkill but an unprotected device is unacceptable.
Hospitals run thousands of connected devices on operating systems certification keeps frozen. Diode protects them at the network, without touching the device.
Sequencers, microscopes and lab analysers run closed, expensive, never-updated software. Diode contains them without disrupting the science.
Place Diode inline in front of PLCs, HMIs, CNC and safety systems: immediate protection, minimal change, a limited blast radius.
The Windows 7 machine running a production line; the HMI the vendor won't update. Diode wraps them in microsegmentation, limiting what can reach them.
Door locks, lifts, cameras, displays and charging stations: building endpoints that ship with no security of their own. Diode gives them a perimeter.
Give vendors access to specific equipment without exposing the network: controlled, logged, time-limited.
Define the policy, deploy the device, then operate the fleet from one controller.
Diode is managed from the same narrowin controller as Explorer: network visibility and microsegmentation on one pane of glass, not two tools to learn.
Deployment simple enough for an OT technician or a medical engineer. No network team required.
Diode ships ready to protect. A baseline profile is already loaded, so there's no rule-building before deployment.
Install between the network switch and the device to protect. Works anywhere, with no reconfiguration of the existing network.
On first boot Diode finds its controller, pulls its policy and starts enforcing. Full L3 separation, active.
Update policies, watch traffic and run every Diode from one dashboard. Changes push out automatically.
The standard Diode appliance. Small enough to sit behind a wall plate or inside a control cabinet, with an optional wireless uplink for spots you can't pull a cable.


| Ethernet | 2 × RJ45 1000M |
|---|---|
| Wireless | n/a |
| Power | USB-C 5V/2A |
| Size | 60 × 60 × 26 mm |

When the standard nodes don't fit (more interfaces, a different form factor, rugged or rack-mount), hardware specified to the site.

No appliance: the Diode runs as a virtual machine on existing infrastructure. Same policy, same controller.
| Enforcement | narrowin Node appliance, inline, or on existing switch infrastructure (Cisco, Aruba, Cumulus) |
|---|---|
| Installation | Inline between the switch and the protected device(s) |
| Mode | Layer 2 transparent (bump-in-the-wire); no IP, no gateway change |
| Filtering | Layer 3/4: IP addresses, ports, protocols |
| Policy model | Default mode per direction + subnet exceptions; allow-list by default |
| 802.1X | Built-in WPA supplicant: authenticates the Diode onto an 802.1X / NAC network |
| Remote access | Certificate-based, switched on when needed |
| Connectivity | Central VPN breakout: backhaul a protected site to one gateway |
| Logging | Local and central, forwardable to narrowin Log Analytics or any syslog target |
| Management | narrowin controller, cloud or on-premises |
| Documentation | /docs/diode (login) → |
No. A data diode enforces one-way traffic by physics. Diode enforces bidirectional Layer 3/4 policy: it filters traffic in both directions by IP, port and protocol, allow-list by default. The name refers to tight, directional control, not hardware-enforced one-way flow.
A firewall is an infrastructure project: sizing, racking, rules, change windows. Diode is a small inline device with a baseline policy, deployed in minutes in front of the one asset that needs it.
Yes, a single device or a small zone of related devices. For larger zones, multiple units or switch-based enforcement may fit better.
Yes. Diode installs inline and is transparent to the network: any switch vendor, no special configuration on existing infrastructure.
Minimal. Diode filters inline and stays transparent on the wire: no IP, no gateway change, no redesign of the surrounding network.
Certificate-based authentication, scoped to specific equipment. Access is a policy you switch on when a vendor needs in and off again afterwards, and it can even be mapped to the device's physical A/B switch. Every session is logged, with no permanent VPN tunnels or exposed ports.

Containing ransomware in hospitals by isolating clinical equipment that certification keeps frozen.
Read →
A qualitative study of how intrusions move laterally through university and hospital networks.
Read →
Turning hundreds of legacy rules into clean IT/OT zones and conduits, aligned to IEC 62443.
Read →
The IEC 62443 / Purdue planning practice Diode came out of, and how to plan with it.
Read →The one that can't be patched, can't be replaced, and can't come off the network. That's the one Diode is for.
Talk to us about your devices