Factories and organized industrial zones must manage two very different networks under one roof: the guest internet offered to visitors and the operational network that carries the production line. SignLogger separates these two networks, governs every user and device with NAC, and retains the internet-access logs required under Law No. 5651 by signing them every day with the timestamp and e-signature of an authorized certificate authority (TÜBİTAK Kamu SM). Because it is brand-independent and runs on your own infrastructure (VMware/Hyper-V), your data never leaves the company.
This content is for general information only and does not constitute legal advice. For your obligations under Law No. 5651, rely on the current legislation and your legal counsel.
Two different worlds on the factory network: guest and operational
A production facility does not have a single risk profile. Contractors, visitors and suppliers on the guest network should not share a segment with operational devices such as PLCs, SCADA systems, IP cameras and handheld terminals. SignLogger receives guest traffic through a captive portal while keeping operational devices in a separate trust zone, so lateral movement from a visitor device into the production network is blocked.
- Guest network: Captive portal onboarding, identification and internet-access logging.
- Operational network: Only authorized devices and users; isolated access to production systems.
- Staff network: Separate policy and Law 5651 logging for office users.
| Criterion | Guest network | Operational network |
|---|---|---|
| Identification | Captive portal (SMS/sponsor/form, etc.) | NAC device + user validation |
| Access scope | Internet only | Isolated production segments |
| Law 5651 log | Mandatory, stored signed | Access records kept |
| Isolation | Cannot reach production | Isolated from guests |
Device and user access control with NAC
In industrial zones and factories, dozens of different-brand devices join the network every day. Network access control (NAC) determines "who and what" a device is before it connects: an authorized handheld terminal, a registered laptop, or an unknown device? SignLogger runs 802.1x (EAP) authentication on wired ports and, on the guest wireless network, captive portal validation over RADIUS using PAP only.
- Placing devices into the correct VLAN and quarantining unknown devices.
- Time-bound, scope-limited access for contractors and temporary staff.
- Tracing every access to a specific identity via user-to-device mapping.
Law 5651 logs signed every day
Law No. 5651 requires institutions acting as hosting/access providers to keep internet-access records and to safeguard their integrity. SignLogger signs the logs it collects every day with a TÜBİTAK Kamu SM timestamp and e-signature, so it can be proven when a record was created and that it has not been altered afterward. Kamu SM signing works with credits (kontör); the configuration should be planned in advance so the process is not interrupted when credits run out.
Logs are retained for the legally mandated period and can be presented, on request, as a readable and signed whole. Because the entire process runs on in-house infrastructure, the data is never moved outside.
Brand-independent and on-premises
SignLogger is not tied to any particular firewall brand; it works with any firewall that supports RADIUS. In environments like industrial zones, where different companies use different hardware, this lets you comply without changing your architecture. The system is deployed in your virtualization environment (VMware/Hyper-V) and the logs stay on-prem.
Frequently Asked Questions
Why should I separate the guest and production networks in a factory?
Production devices (PLCs, SCADA, cameras) should not be exposed to the internet or to unknown devices. Separate segments prevent a jump from a visitor device into the production network and apply Law 5651 logging only to the relevant traffic.
Which firewalls does SignLogger work with?
SignLogger is brand-independent; it integrates with any firewall that supports RADIUS. You do not need to replace your existing hardware.
How is captive portal authentication performed?
On the guest wireless network, the captive portal authenticates over RADIUS using PAP only. On wired operational ports, 802.1x (EAP) authentication can be used.
How often and how are the logs signed?
SignLogger signs internet-access logs every day with a TÜBİTAK Kamu SM timestamp and e-signature. This makes the creation time and the integrity of each record provable.
What happens if the Kamu SM credits run out?
Kamu SM signing works with credits (kontör). Credit monitoring and, where needed, a fallback configuration with a server certificate are planned in advance so signing is not interrupted when credits are exhausted.
Where is the data stored?
SignLogger runs in your own virtualization environment (VMware/Hyper-V) and all logs remain on your organization's infrastructure (on-prem); the data does not leave.