Four deployment models
Choose how you enforce the boundary. Scale from there.
The 01Layer Data Diode solution covers the physical interface, the forward-only service path, and the application workflow on both sides. Select the model that matches your security requirements and deployment environment.
01 / Physical Data Diode
Isolation at the fiber.
A purpose-built iNIC-DD interface connects the protected source's transmit port to the destination's receive port over one fiber. No return strand is installed.
Use when the boundary must be physically transmit-only and directly inspectable. Supported DD port rates span 1G, 10G, 25G, 40G, and 100G.
Explore the hardware boundary →
02 / Logical Data Diode
Control in the data plane.
NextIO separates sender and receiver roles and permits the approved source-to-destination service edge across standard, virtual, or cloud interfaces.
Use where a Tx-only hardware interface cannot be installed. Routes, security groups, network policy, and the service graph work together to enforce the allowed direction.
Explore cloud and virtual deployment →
03 / Fully integrated solution
From application message to destination delivery.
Combine application brokers, diode framing, optional encryption, receiving, and message publishing in a complete one-way pipeline.
Use NextIO service enforcement together with iNIC-DD when the design calls for independent controls in both the data plane and the physical interface.
Follow the transfer architecture →
04 / High-density deployment
More boundaries. More processing capacity.
FlowDirector and Service Nodes support architectures with many Data Diode connections, separating traffic delivery from application processing.
FlowDirector interface options reach up to 128 × 100Gb or 32 × 400Gb in 1U, with Service Nodes providing the processing layer.
Explore FlowDirector and Service Nodes →