Product images are provided for reference and may not represent the exact model, configuration, or included components.

Overview

SKU: BXS3-PISONET
Condition: New
Availability: Usually Ships in 2-3 Weeks
Warranty Manufacturer Warranty
Write a Review 10% OFF

Cradlepoint BXS3-PISONET Permanent Internet Isolation Device

Hardware-enforced network isolation for critical infrastructure protection

$435.00 $390.99 SAVE $44

Quantity:

Adding to cart… The item has been added
Compatibility guidance available for your deployment
Senior specialists for pre and post-sales support
Authorized sourcing and documentation support
Shipping and lead-time confirmation before install

Laura Bennett, IPSD Senior Specialist

Talk to Laura

200+ hrs training • U.S - based

Senior Specialist • 877-277-7147

Cradlepoint BXS3-PISONET Permanent Internet Isolation Device

$435.00
$390.99

Overview

SKU: BXS3-PISONET
Condition: New
Availability: Usually Ships in 2-3 Weeks
Warranty Manufacturer Warranty

No Bots, Just Experts

Questions about this product? Free pre-sales support from a senior specialist — product questions, compatibility checks, BOM quotes, price confirmation — typically answered within one business day. Need camera placement or system design work? Engineering time is $175 per hour (qty 1 = 1 hour). Hardware buyers get up to one hour ($175) credited back on their order.

Description

Cradlepoint BXS3-PISONET Permanent Internet Isolation Device

Overview

The Cradlepoint BXS3-PISONET is a purpose-built permanent internet isolation appliance designed to create and enforce persistent network segmentation for enterprise security architectures. Unlike temporary air-gap solutions or software-only isolation, the BXS3-PISONET (often searched as BXS3 PISONET) deploys as a dedicated hardware node that physically isolates critical network segments from untrusted external connectivity—a critical requirement for organizations protecting SCADA networks, industrial control systems, secure data enclaves, or compliance-sensitive infrastructure.

This device functions as a hardware enforcement boundary rather than a traditional firewall. It enables security teams to maintain strict isolation policies while preserving the ability to configure controlled, unidirectional data flows where business logic demands them. Deployment by security integrators benefits from the appliance's role as a deterministic network partition device, eliminating reliance on complex software policies or trust assumptions.

Key Features

  • Permanent Isolation Architecture: Operates as a standalone isolation node within network topology, ensuring that critical segments remain air-gapped from the broader network. This prevents lateral movement and external intrusion into protected zones—essential when a single compromised system on the corporate network could otherwise bridge into operational technology (OT) or highly sensitive data tiers.
  • Persistent Enforcement Policy: Maintains isolation policies continuously without requiring manual intervention or software updates to sustain the boundary. The device itself becomes the enforcement point rather than relying on endpoint agents or network configuration drift mitigation.
  • Controlled Connectivity Policies: Where business requirements mandate selective data movement (e.g., uploading sensor logs or receiving configuration updates), the BXS3-PISONET can be configured to enforce unidirectional or tightly scoped flows, reducing the burden of manual air-gap management or sneakernet processes.
  • Network Segmentation Integration: Integrates into existing VLAN, subnet, and security boundary designs without requiring wholesale network redesign. Security architects can deploy the BXS3-PISONET to isolate specific subnets, departments, or functional zones while the remainder of the network operates normally.
  • Standalone Node Deployment: Functions independently within network infrastructure, minimizing dependencies on centralized control systems or cloud-based policy management. This is valuable in environments where external policy connectivity is itself a security risk.
  • Security Integrator Installation: Designed for professional deployment and commissioning by security teams familiar with network segmentation and air-gap enforcement, reducing reliance on vendor-locked managed services.

Integration & Deployment Context

The BXS3-PISONET is positioned as a core component of defense-in-depth strategies for industrial control networks, classified data environments, and mission-critical infrastructure. It complements traditional firewalls and intrusion detection by providing a hardware-enforced boundary that eliminates the assumption that network perimeter defenses will hold under sustained attack or sophisticated lateral movement.

Typical deployment scenarios include isolation of SCADA gateways, enclave protection for classified or high-value intellectual property, quarantine of legacy systems that cannot be updated, and enforcement of strict air-gapping in environments where data exfiltration or ransomware propagation poses existential business risk. The device operates as a network security anchor point within broader industrial automation or enterprise infrastructure designs.

For IT architects evaluating network segmentation strategies, the BXS3-PISONET represents a hardware-enforced alternative to software-only segmentation and to manual air-gap processes. It reduces operational overhead compared to personnel-driven isolated network transfers while maintaining the security properties of true isolation.

When to Choose a Different Approach

If your requirement is temporary isolation, emergency containment, or lab-based testing, consider whether a Cradlepoint network appliance with configurable isolation policies might suit your timeline better. If isolation is needed at the application layer rather than the network layer, or if you require frequent, high-volume data transfer between isolated and non-isolated zones, the cost and operational friction of hardware isolation may outweigh the security benefit—consult a security architect to evaluate the tradeoff between isolation strength and business continuity.

Frequently Asked Questions

Q: What is the difference between the BXS3-PISONET and a traditional firewall?

A: A firewall filters traffic based on rules; the BXS3-PISONET physically enforces isolation by design. It prevents misconfiguration or bypass of segmentation policies, making it suitable for zero-trust or high-assurance isolation requirements where rule-based filtering is considered insufficient.

Q: Can the BXS3-PISONET transfer data between isolated segments?

A: Yes, it can be configured to enforce unidirectional or tightly scoped data flows where required. This allows controlled data movement (e.g., logs or configuration updates) while maintaining the isolation boundary.

Q: Does the BXS3-PISONET require cloud management or external policy servers?

A: No. It operates as a standalone node with persistent enforcement policies, eliminating dependencies on external connectivity for isolation enforcement. This reduces risk in air-gapped or highly restricted network environments.

Q: Is the BXS3-PISONET suitable for SCADA and industrial control network protection?

A: Yes. It is specifically designed for isolation of OT networks, control systems, and critical infrastructure from corporate networks and untrusted external sources.

Q: What skills are required to deploy the BXS3-PISONET?

A: Network segmentation and security integration experience is recommended. The device is designed for deployment by security integrators and IT teams familiar with air-gap enforcement and network boundary design.

Ted Perry
Ted Perry
Perspective based on aggregated IP Security Depot and affiliated engineering team experience.

The BXS3-PISONET is not a firewall replacement; it's a hardware isolation enforcer for environments where network compromise is an existential risk. I deploy these in SCADA-adjacent networks, classified data tiers, and scenarios where a single misconfiguration or policy rule could cascade into catastrophic breach. The device itself becomes the trust boundary rather than the network policies running on top of it.

Technical Highlights:

  • Persistent Isolation Architecture: Hardware-enforced network segmentation that persists without reliance on software policies, rule updates, or external management servers. This eliminates the operational overhead and configuration drift risk inherent in firewall-based segmentation.
  • Standalone Node Design: Operates independently within the network topology. No cloud management, no centralized control dependency, no assumption that external policy connectivity is safe. Particularly valuable in air-gapped or highly restricted network environments.
  • Controlled Connectivity: Supports unidirectional and tightly scoped data flows where business requirements mandate selective movement (logs, updates, sensor telemetry). Reduces the friction of manual air-gap processes while maintaining isolation integrity.

Deployment Considerations:

  • This is not a plug-and-play device for average network teams. Installation and policy commissioning require security integration expertise and clear understanding of your network topology and isolation boundary requirements.
  • Plan for network redesign or VLAN restructuring to route traffic through the BXS3-PISONET. This device enforces segmentation at the network boundary, not within endpoints—positioning and routing discipline are critical to effectiveness.

Deploy the BXS3-PISONET when your isolation requirement is non-negotiable and your threat model includes sophisticated lateral movement or persistent network-level intrusion. It's the right choice for industrial control protection, classified enclaves, and zero-trust segmentation in environments where rule-based filtering is considered insufficient.

Specifications
Product Type: Permanent Internet Isolation Device
Cable Category: NC
Type: Permanent Internet Isolation Device
Warranty: Manufacturer Warranty
Q&A
Reviews
Have Questions?

RELATED PRODUCTS

Image coming soon
Add to Cart The item has been added

Cradlepoint

SKU: TAA-MBA3-R980-5GD-FA

Cradlepoint Inc TAA-MBA3-R980-5GD-FA 3-Year TAA Compliant

TAA-compliant mobile & IoT connectivity with gigabit speed

  • 3-year TAA-compliant mobile/IoT connectivity service
  • Federal/state/local government procurement-aligned
  • Gigabit-class speeds for distributed mobile sites
$2,178.00 $1,952.99 Save $225.01
The item has been added
Free shipping over $499
$2,178.00 $1,952.99 Save $225.01
Add to cart Add to quote
Image coming soon
Add to Cart The item has been added

Cradlepoint

SKU: TAA-MBA3-R980-5GD-A

Cradlepoint Inc TAA-MBA3-R980-5GD-A 5G Mobile Router

TAA-compliant 5G/4G mobile router with Wi-Fi 6 for federal use

  • Ruggedized 5G/4G/3G mobile router for federal use
  • Gigabit-class cellular failover for government fleets
  • 3-year TAA-compliant warranty for federal procurement
$1,899.00 $1,702.99 Save $196.01
The item has been added
Free shipping over $499
$1,899.00 $1,702.99 Save $196.01
Add to cart Add to quote
Cradlepoint MC20-GPO GPIO Expansion Module (view 3)
Add to Cart The item has been added

Cradlepoint

SKU: MC20-GPO

Cradlepoint MC20-GPO GPIO Expansion Module

GPIO expansion module with dual 10-pin connectors for IoT device integration

  • GPIO expansion module for edge router I/O integration
  • Adds 2 FE ports + 1 serial for external sensor wiring
  • Cloud-managed via LTE wireless platform connectivity
$70.00 $69.99 Save $0.01
The item has been added
Free shipping over $499
$70.00 $69.99 Save $0.01
Add to cart Add to quote
Cradlepoint Inc TAA-TBV3-0450-C6-NA-N 3-Year TAA Compliant
Add to Cart The item has been added

Cradlepoint

SKU: TAA-TBV3-0450-C6-NA-N

Cradlepoint Inc TAA-TBV3-0450-C6-NA-N 3-Year TAA Compliant

TAA-compliant LTE IoT module with Gigabit speed for federal procurement

  • IoT connectivity module with LTE wireless backbone
  • Cloud-managed for federal/state/local government use
  • Gigabit-class speeds with Buy American TAA compliance
$615.00 $551.99 Save $63.01
The item has been added
Free shipping over $499
$615.00 $551.99 Save $63.01
Add to cart Add to quote

System Design, Deployment & Technical Support

Support services and planning resources for commercial surveillance, access control, and infrastructure deployments.

Fixed scope • Fixed price

System Design Assistance

  • Get help validating product compatibility
  • Coverage requirements
  • Storage planning and deployment architecture before you buy.
Request Design Help

Deployment & Configuration Support

  • Access fixed-scope support for rollout planning
  • User setup guidance
  • Migration and system standardization across single-site or multi-site deployments
View Support Services

Guides, Tools & Calculators

  • PoE requirements
  • Storage retention
  • Camera selection and deployment methodology
Open Technical Resources