Below video explain download and installation process of Systegrate DiodeLink Console™.
DiodeLink Console 1.0 – New Release
A practical way to move industrial and operational data from OT to IT through a hardware-enforced one-way path—without turning every integration project into a custom engineering effort.
For many industrial teams, the real challenge is not collecting data. It is moving that data safely out of protected environments and into reporting, analytics, monitoring, historian, or enterprise systems. Systegrate DiodeLink Console 1.0 addresses exactly that problem. It combines one-way transfer enforced by a physical data diode with a clear administration model for streams, certificates, file exchange, and service operations.
In practice, the platform runs as a pair of services: a Sender on the OT side and a Receiver on the IT side. The Sender reads data from local sources, the diode allows traffic to travel in one direction only, and the Receiver reconstructs or republishes the data for downstream consumers. That model allows teams to keep segmentation strong while still making operational data usable.
How it works in one glance
Figure 1. DiodeLink Console operates as a Sender/Receiver pair around a hardware data diode, carrying data from OT to IT without a reverse channel.
The operating model is intentionally straightforward. Each node has a diode-side interface and a separate data or management interface. Administrators create a stream once per use case, use the same stream ID on both nodes, start the stream, and then verify status, metrics, and logs. The command-line interface, diodecmd, is the control surface for stream lifecycle, optional features, certificate handling, and license operations.
What stands out in DiodeLink Console 1.0
Hardware-enforced directionality
Traffic flows from Sender to Receiver only. The user manuals consistently position the diode link as the only path between OT and IT zones.
Seven replication stream types
UDP, Files, MQTT, SNMP, Modbus, OPC UA, and CIP cover the most common operational data exchange patterns.
Built-in file access options
SFTP, SMB, and NFS features let teams present replicated files in forms that Linux and Windows operators already understand.
Built-in MQTT broker option
The MQTT feature can enable a Mosquitto-based broker, create the default replication stream, and secure client access with TLS or mutual TLS.
Security administration included
Certificate import, trust-store maintenance, client certificate generation, and CRL handling are part of the standard administration model.
Operational visibility
Stream status, live metrics, logs, export/import, and table or JSON output help administrators standardize operations and troubleshooting.
Replication streams: the real value of the platform
DiodeLink Console is not just a transport tunnel. Its value comes from how it turns different OT data patterns into repeatable, one-way replication services. Instead of forcing every source to behave the same way, it provides protocol-specific stream models.
| Stream type | How it works | Typical result on the IT side |
|---|---|---|
| UDP | The Sender listens for packets and forwards them through the diode. The Receiver forwards them to a configured destination. Unicast, multicast, and broadcast patterns are supported. | A downstream application receives the same packet flow on the expected host, group, or target network. |
| Files | The platform watches a managed directory tree, applies include/exclude masks and retry logic, and moves files through the one-way path. | Replicated files become available to IT-side users or processes, optionally exposed through SFTP, SMB, or NFS. |
| MQTT | The Sender subscribes to a source broker topic, transfers messages one-way, and the Receiver publishes them to a destination broker. QoS and authenticated TLS setups are supported. | IT-side clients can consume mirrored MQTT topics locally or through the built-in broker. |
| SNMP | The Sender reads SNMP data and trap events from a source agent. The Receiver feeds a mirror agent on the IT side. | Monitoring tools can query an IT-side SNMP endpoint instead of reaching back into OT. |
| Modbus | The Sender polls selected registers, coils, inputs, or ranges from OT devices. The Receiver exposes the replicated state through Modbus TCP or RTU. | SCADA, MES, or historians can read a local Modbus replica as if it were a nearby device. |
| OPC UA | The Sender performs discovery and sends ordered frames for metadata, values, and diagnostics. The Receiver rebuilds a read-only virtual OPC UA server. | IT-side OPC UA clients can browse and read a structured replica without direct OT connectivity. |
| CIP / EtherNet/IP | The Sender captures cyclic implicit I/O from OT-side PLCs. The Receiver acts as a local edge server for IT-side PLC clients, with plain or secure TLS/DTLS modes. | Replicated cyclic I/O reaches IT-side PLC consumers while keeping OT isolation intact. |
Why these stream models matter
Each stream solves a different integration problem:
- UDP fits telemetry, syslog-style messages, PLC broadcasts, and lightweight sensor traffic.
- Files fit document exchange, batch data export, reports, recipes, and hand-off workflows between teams or systems.
- MQTT fits event-driven OT/IIoT data and broker-based integration patterns.
- SNMP fits network or device monitoring when the IT side needs visibility without direct device access.
- Modbus fits classic industrial register replication for SCADA and historian use cases.
- OPC UA fits structured, browsable industrial information models and diagnostics.
- CIP fits cyclic industrial controller data flows used in EtherNet/IP environments.
That breadth is important. Many organizations do not have just one data pattern in OT. They have several, and they need a platform that can standardize how those patterns cross a one-way boundary.
Security and administration without side tools
The user manuals show a platform designed for operations, not only for deployment day. Administrators can enable optional features, create shares, rotate or replace certificates, manage trust and revocation lists, generate client certificates for mutual TLS, and export or import stream definitions. For teams that need consistent procedures, this matters as much as raw protocol coverage.
Another practical detail is licensing. The documented workflow includes a built-in 180-day trial, request/import steps for full licenses, and support for hardware-bound, software-bound, or hostname-bound assignment models. That makes lab rollout, validation, and production conversion easier to plan.
Ready to explore it in your own environment? Now is a particularly good time to do it. Trial software can be requested here: https://systegrate.com/#request-trial. For a limited time, the trial period is 180 days.
Summary: what replication is possible?
DiodeLink Console 1.0 can replicate:
- packet-based traffic through UDP in unicast, multicast, and broadcast scenarios,
- batch and drop-zone workflows through file replication,
- brokered messages through MQTT,
- monitoring data and traps through SNMP,
- industrial register state through Modbus,
- industrial information models and live values through OPC UA,
- cyclic controller I/O through CIP / EtherNet/IP.
It can also present replicated content in operator-friendly ways through SFTP, SMB, NFS, and a built-in MQTT broker, while keeping certificate, trust, logging, and stream lifecycle tasks under one administration model.
For organizations building a secure OT-to-IT bridge, that is the key takeaway: Systegrate DiodeLink Console 1.0 is not only a management tool for a data diode. It is a practical replication layer that translates one-way transfer into usable services for operations, engineering, and enterprise consumers.