| Layer 2 Ethernet Gateway | Forwards Ethernet frames according to MAC addresses. | L2 bridging; no native inter-subnet routing. | Not applicable. | IEEE 802.3, IEEE 802.1Q, IEEE 802.1D-compatible bridging concepts. | Copper or fiber Ethernet ports; optional SFP/SFP+ slots. | LAN segmentation, VLAN aggregation, and transparent network extension. |
| Layer 3 Ethernet Gateway | Routes traffic between separate IP networks. | IPv4 and, where supported, IPv6 routing; static routes and dynamic routing may be available. | Optional; commonly includes one-to-one NAT or port translation. | IEEE 802.3, IEEE 802.1Q, and often IEEE 802.1X for access control. | Multiple copper or fiber Ethernet interfaces; management port may be separate. | Enterprise, campus, data-center edge, and industrial network interconnection. |
| NAT Firewall Gateway | Connects private networks to external networks while enforcing traffic policies. | L3 routing with stateful inspection and policy-based forwarding. | Typically supports NAT44, NAPT/PAT, port forwarding, and configurable address pools. | IEEE 802.3 and IEEE 802.1Q; security functions are generally specified outside the IEEE 802.3 family. | WAN, LAN, DMZ, and optional management Ethernet ports. | Internet edge, branch offices, remote sites, and protected control networks. |
| VPN Ethernet Gateway | Provides encrypted connectivity between remote users, sites, or networks. | L3 routing; may also provide VLAN-aware L2 extension through tunneling. | Usually supports NAT and NAPT for overlapping or private address spaces. | IEEE 802.3 and IEEE 802.1Q; VPN protocols commonly include IPsec or TLS-based mechanisms. | WAN and LAN Ethernet ports; optional cellular or fiber uplinks. | Site-to-site connectivity, secure remote access, and multi-location operations. |
| Industrial Ethernet Gateway | Connects operational technology networks, controllers, sensors, and enterprise systems. | May combine L2 bridging, L3 routing, VLANs, and protocol-aware segmentation. | Optional; used when plant, machine, and enterprise address spaces must remain separated. | IEEE 802.3, IEEE 802.1Q, IEEE 802.1X, and in some designs IEEE 802.3ad link aggregation. | Rugged copper or fiber Ethernet; serial, fieldbus, or cellular interfaces may be integrated. | Factory automation, substations, transportation, utilities, and remote monitoring. |
| Managed PoE Ethernet Gateway | Aggregates and manages Ethernet connectivity and power delivery for powered devices. | Usually combines L2 switching with optional L3 routing and VLAN support. | Optional and dependent on the gateway platform. | IEEE 802.3, IEEE 802.3af, IEEE 802.3at, IEEE 802.3bt, and IEEE 802.1Q. | PoE copper Ethernet ports; uplink ports may use copper or fiber. | Wireless access points, IP cameras, VoIP endpoints, access control, and building systems. |
| Time-Sensitive Networking Gateway | Transports time-critical Ethernet traffic with bounded latency and synchronized timing. | L2 switching is central; L3 routing may be included for network-domain integration. | Generally avoided in deterministic traffic paths; may be used at a controlled network boundary. | IEEE 802.3, IEEE 802.1AS, IEEE 802.1Qbv, IEEE 802.1Qbu, and IEEE 802.1Qci. | Industrial copper or fiber Ethernet with hardware timestamping where required. | Motion control, automotive networks, professional audio/video, and deterministic automation. |