In this setup, the edge is not directly connected to the data source but instead to its OPC Classic server through an OPC Classic client, as shown in the following diagram:
The only way to secure this scenario is to place the edge device in a DMZ by means of two firewalls, the first one controlling the interface toward the outside and the second one controlling the interface toward OPC Classic. This is shown in the following diagram:
In this scenario, DCOM traffic occurs ...