A technical blueprint detailing the Layer 2 transparent bridge architecture, independent university laboratory verification, and the physical separation of cellular demarcation from enterprise Wi-Fi.
Yazata is a physical Layer 2 threat defense appliance — our company does not perform on-site Wi-Fi cabling or internal network installations. This document represents our official manufacturer architecture recommendation, essential for ensuring that all ingress and egress traffic across the protected site passes fully through Yazata, and that the ISP-supplied gateway does not create bottlenecks or security blind spots.
Unlike conventional security appliances that force destructive Layer 3 re-architectures, Yazata operates at the Data Link layer as an invisible, transparent physical bridge.
The Layer 2 inline transparency, data integrity, and packet neutralization capabilities of Yazata were independently evaluated and empirically validated under controlled laboratory conditions by Óbuda University.
The laboratory audit utilized dual-sided packet capture between an isolated physical client node and an upstream routing gateway. Key conclusions include:
When the 5G modem, routing engine, stateful NAT table, and office Wi-Fi radios are combined inside a single carrier-supplied CPE box, systematic physical and logical failures inevitably occur:
Yazata's topology recommendations directly adhere to recognized international cybersecurity and network engineering standards:
National Institute of Standards and Technology guidelines mandate the physical and logical separation of wireless infrastructure from perimeter demarcation gateways. Wireless Access Points (WAPs) must be isolated as independently managed, controlled, and inspected security zones.
The Center for Internet Security baseline requires strict isolation of third-party managed customer-premises equipment (CPE). The border router must be relegated to a transparent gateway (Bridge / IP Passthrough), while enterprise traffic inspection is delegated to verifiable, locally audited appliances.
Enterprise WLAN validated architectures establish strict separation of architectural concerns:
• WAN Demarcation: Pure packet transport (Modem / Bridged WAN).
• Security & Inspection: Yazata Layer 2 Shield & Firewall (Deep packet hygiene).
• Access Layer: Dedicated ceiling-mounted PoE APs centrally managed via controller.
Telecom industry technical frameworks explicitly define CPE hardware as boundary Demarcation Hand-off interfaces. Business network infrastructure is classified as an autonomous LAN/WLAN tier, preventing resource exhaustion on carrier hardware.
Select the validated wiring topology tailored to your site's carrier gateway firmware capabilities:
Designed for business networks where the 5G ISP router supports Bridge Mode or IP Passthrough. The public WAN IP is passed directly to the enterprise edge firewall.
Tailored for smaller sites or branch offices where the carrier-provided 5G modem firmware restricts Bridge Mode, forcing the modem to perform primary NAT routing.
Simply hiding the SSID is insufficient. Both 2.4 GHz and 5 GHz wireless radios on the carrier CPE must be completely shut off in device management. This prevents clients from inadvertently bypassing Yazata, stops rogue client associations, and eliminates spectral co-channel noise.
Because Yazata functions as a zero-footprint Layer 2 bridge, it does not modify IP addresses, alter DHCP pools, or reroute subnets. It must be positioned on the physical uplink where all incoming and outgoing enterprise traffic funnels, guaranteeing that DNS filtering and automated threat neutralization apply to every endpoint.
Leave the 5G gateway where cellular signal metrics (RSRP/SINR) are strongest. Distribute internal Wi-Fi via dedicated, ceiling-mounted enterprise access points positioned in the geometric centers of high-density working areas.
Our engineering team assists network architects, system administrators, and integration partners with detailed hardware datasheets and deployment blueprints.