Architecture Standard

Enterprise 5G WAN & Layer 2 Architecture
The Demarcation Boundary Standard

A technical blueprint detailing the Layer 2 transparent bridge architecture, independent university laboratory verification, and the physical separation of cellular demarcation from enterprise Wi-Fi.

Official Manufacturer Architecture Specification

Yazata is a physical Layer 2 threat defense appliance — our company does not perform on-site Wi-Fi cabling or internal network installations. This document represents our official manufacturer architecture recommendation, essential for ensuring that all ingress and egress traffic across the protected site passes fully through Yazata, and that the ISP-supplied gateway does not create bottlenecks or security blind spots.

What is Layer 2 Technology in Yazata?

Unlike conventional security appliances that force destructive Layer 3 re-architectures, Yazata operates at the Data Link layer as an invisible, transparent physical bridge.

Traditional L3 Security Appliances Intrusive
  • Forced Subnet Modifications: Requires creating new IP subnets, altering existing DHCP server scopes, and rewriting default gateways.
  • Routing Overhead & Double NAT: Introduces complex routing tables and network address translation loops that break VoIP, VPN tunnels, and peer-to-peer services.
  • Configuration Downtime: Printers with static IPs, internal file servers, NAS drives, and IoT controllers frequently disconnect during rollout.
  • Endpoint Software Demands: Requires heavy agent installations, ongoing licensing, and manual client configuration.
Yazata Layer 2 Transparent Bridge Zero Modification
  • Zero Network Footprint: Intercepts frames directly in the physical data path without claiming an active IP gateway identity.
  • Preserved Addressing Architecture: IP addresses, netmasks, gateways, and existing 802.1Q VLAN trunk tags remain 100% untouched.
  • Sub-Millisecond Forwarding: Custom switching fabric introduces less than 1ms of latency, ensuring high-throughput packet transfers.
  • Zero Agent Installation: Delivers hardware-enforced protection across every connected workstation, smartphone, IP camera, and legacy server.

Autonomous DNS Interception

During the standard DHCP handshake, Yazata's internal Layer 2 engine automatically directs client name resolution requests to its built-in enterprise resolver. Advertising networks, telemetry trackers, and phishing domains are dropped at the packet gateway before an HTTP/S connection can ever begin.

Threat Shield IP-Level Defense

A real-time intelligence engine compares all traversing ingress packets against a database of malicious hosts. Connection attempts originating from compromised command-and-control (C2) servers or botnets are blocked inline at the Ethernet frame boundary.

Untouched Internal Fabrics

Local broadcast frames, ARP tables, and device-to-device transfers continue uninterrupted. Office printers, local backup storage, internal surveillance feeds, and ERP systems communicate exactly as they did before Yazata was inserted.

Laboratory Verification: Óbuda University

The Layer 2 inline transparency, data integrity, and packet neutralization capabilities of Yazata were independently evaluated and empirically validated under controlled laboratory conditions by Óbuda University.

10 / 10
DHCP Preservation
10 consecutive automatic address requests completed with zero retries. IP, subnet, and gateway retained with 100% fidelity.
72 / 72
Identical Frame Check
Comparative packet analysis across both bridge interfaces verified 100% bit-level identity for all checked TCP and ARP frames.
320 MiB
SHA-256 Bit-Perfect Data
Five parallel upload/download cycles transferred 320 MiB of test payload. Ingress and egress cryptographic checksums matched perfectly.
18 / 18
Bidirectional Block
Active threat evaluation proved zero TCP connections established for flagged malicious IPs, regardless of origination direction.

Key Findings from the University Evaluation Report

The laboratory audit utilized dual-sided packet capture between an isolated physical client node and an upstream routing gateway. Key conclusions include:

• Automated DNS Orchestration: The DHCP option returned to clients automatically updated the DNS resolver address to Yazata, directing name lookups through the security filter without client-side intervention.
• Zero Payload Corruption: Comparative capture verified that normal business traffic passes cleanly without fragmentation, corruption, or packet alteration.
• Source-IP Threat Neutralization: Outgoing handshake packets to tested endpoints were dropped at the return path, confirming active source-IP enforcement and total connection failure for malicious addresses.
• True Plug-and-Play Readiness: Following physical connection and initial administrator onboarding, the appliance was fully operational within the test environment.

The 3 Fatal Anomalies of All-in-One ISP Routers

When the 5G modem, routing engine, stateful NAT table, and office Wi-Fi radios are combined inside a single carrier-supplied CPE box, systematic physical and logical failures inevitably occur:

1. Physical RF Placement Paradox

The optimal location for a 5G cellular modem is strictly governed by exterior radio signal propagation: window sills, facade walls, or server rooms with external antenna feeds (maximizing RSRP/SINR signal metrics).

Conversely, optimal indoor Wi-Fi propagation demands placement at the building's geometric center, mounted on ceilings with unobstructed Line-of-Sight (LoS) to client devices.
Conflict: Combining both functions inside one physical enclosure forces a mutual exclusion: either the cellular 5G WAN link degrades, or indoor Wi-Fi coverage suffers severe structural attenuation.

2. Hardware SoC Resource Exhaustion

Carrier-provided units utilize cost-constrained (CPE BOM) integrated System-on-Chips. A single core must concurrently process the 5G baseband modem, maintain the stateful connection tracking (conntrack/NAT) table, execute routing, and process multi-band Wi-Fi MAC/PHY frames.

Above 15–20 active concurrent clients, connection tracking tables saturate and CPU utilization spikes to 100%.
Conflict: Packet loss, jitter spikes during video/VoIP calls, thermal throttling, and spontaneous device reboots disrupt daily corporate operations.

3. Security Bypass & Roaming Blind Spots

• Physical Security Bypass: If clients connect to the ISP router's Wi-Fi, their packets never traverse the physical Ethernet cable to Yazata. The protection is entirely bypassed.
• TR-069/TR-369 Exposure: The carrier retains remote management access, with rights to push unannounced firmware updates during business hours.
• Lack of 802.1Q VLANs: No internal segmentation (Corporate, Guest, IoT).
• Sticky Client Syndrome: Clients cling to the weak ISP router signal, breaking 802.11k/v/r fast roaming.
Conflict: Uninspected traffic paths, administrative blind spots, and co-channel spectral noise undermine overall network integrity.

International Standards & Architectural References

Yazata's topology recommendations directly adhere to recognized international cybersecurity and network engineering standards:

U.S. Federal Standards

NIST SP 800-48 Rev. 1 & SP 800-162

National Institute of Standards and Technology guidelines mandate the physical and logical separation of wireless infrastructure from perimeter demarcation gateways. Wireless Access Points (WAPs) must be isolated as independently managed, controlled, and inspected security zones.

Global Security Benchmark

CIS Benchmarks (Network Devices)

The Center for Internet Security baseline requires strict isolation of third-party managed customer-premises equipment (CPE). The border router must be relegated to a transparent gateway (Bridge / IP Passthrough), while enterprise traffic inspection is delegated to verifiable, locally audited appliances.

Hierarchical Design

Cisco CVD & Aruba ESP (Separation of Concerns)

Enterprise WLAN validated architectures establish strict separation of architectural concerns:
• WAN Demarcation: Pure packet transport (Modem / Bridged WAN).
• Security & Inspection: Yazata Layer 2 Shield & Firewall (Deep packet hygiene).
• Access Layer: Dedicated ceiling-mounted PoE APs centrally managed via controller.

Telecom Industry Framework

Broadband Forum (TR-181, TR-069)

Telecom industry technical frameworks explicitly define CPE hardware as boundary Demarcation Hand-off interfaces. Business network infrastructure is classified as an autonomous LAN/WLAN tier, preventing resource exhaustion on carrier hardware.

Official Yazata Deployment Topologies

Select the validated wiring topology tailored to your site's carrier gateway firmware capabilities:

Enterprise Grade — Recommended

Topology "A": Transparent Bridge & Segmented LAN

Designed for business networks where the 5G ISP router supports Bridge Mode or IP Passthrough. The public WAN IP is passed directly to the enterprise edge firewall.

  • 5G Gateway Wi-Fi: 100% DISABLED. Eliminates co-channel spectral noise and prevents uninspected bypass routes.
  • Yazata Shield Layer 2 Transparent Bridge: Deployed inline between the firewall and PoE switch, inspecting all corporate traffic with zero network configuration changes.
  • Full 802.1Q VLAN Trunking: Cleanly isolates Corporate, Guest Wi-Fi, and IoT broadcast domains across the Layer 2 bridge.
  • Uninterrupted Fast Roaming: Dedicated ceiling-mounted APs fully support 802.11k/v/r standards for smooth mobile handoffs.
TOPOLOGY_A_ENTERPRISE.SYS
5G Gateway (Window / Exterior Ant.) Wi-Fi: OFF (100%)
│ Bridge / IP Passthrough (Public IP Hand-off)
▼
Enterprise Firewall (FortiGate / pfSense / UDM) L3 NAT & VLAN
│ LAN Trunk (Zero IP Change)
▼
🛡️ YAZATA SHIELD Layer 2 Bridge
│ Sanitized Frame Stream (<1ms Latency)
▼
Managed PoE Switch (802.1Q) VLAN Trunk
├── PoE Trunk ──► Dedicated APs (Ceiling Mounted)
└── Wired Workstations / Enterprise Servers
SOHO / Cost-Effective

Topology "B": Integrated Gateway & Dedicated AP Mode

Tailored for smaller sites or branch offices where the carrier-provided 5G modem firmware restricts Bridge Mode, forcing the modem to perform primary NAT routing.

  • 5G Gateway Wi-Fi: STRICTLY DISABLED! If left active, wireless clients will bypass Yazata's physical protection entirely.
  • Transparent Yazata Shield Protection: Connected inline between the ISP router's LAN port and the local distribution switch.
  • Zero Double-NAT Architecture: Downstream Wi-Fi Access Points are configured strictly in Bridge / Access Point (AP) mode (disabling internal DHCP/Routing).
TOPOLOGY_B_SOHO.SYS
5G Gateway (NAT Mode) Wi-Fi: 100% OFF!
│ Single Ethernet Cable
▼
🛡️ YAZATA SHIELD Layer 2 Bridge
│ Transparent Inspection (<1ms Latency)
▼
PoE Switch (Distribution) LAN Fabric
├── Ethernet Uplink
▼
Dedicated Access Point (AP Mode Only) No Double NAT

The 3 Golden Rules for System Administrators

1

100% Radio Deactivation on the Carrier Gateway is Mandatory

Simply hiding the SSID is insufficient. Both 2.4 GHz and 5 GHz wireless radios on the carrier CPE must be completely shut off in device management. This prevents clients from inadvertently bypassing Yazata, stops rogue client associations, and eliminates spectral co-channel noise.

2

Yazata Shield Must Sit at the Physical Chokepoint

Because Yazata functions as a zero-footprint Layer 2 bridge, it does not modify IP addresses, alter DHCP pools, or reroute subnets. It must be positioned on the physical uplink where all incoming and outgoing enterprise traffic funnels, guaranteeing that DNS filtering and automated threat neutralization apply to every endpoint.

3

Position Dedicated Access Points Centrally

Leave the 5G gateway where cellular signal metrics (RSRP/SINR) are strongest. Distribute internal Wi-Fi via dedicated, ceiling-mounted enterprise access points positioned in the geometric centers of high-density working areas.

Deploying Yazata in Your Infrastructure?

Our engineering team assists network architects, system administrators, and integration partners with detailed hardware datasheets and deployment blueprints.