OT and IT on industrial Ethernet: two definitions of “up”
Industrial Ethernet is ordinary Ethernet plus a clock the process believes. Profinet, EtherNet/IP, Modbus TCP, and vendor cyclic I/O each have a period and a jitter budget. IT Ethernet is a best-effort fabric with security appliances, scanners, and backup windows. When those worlds share a core without a written contract — VLANs, QoS, addressing, who may span a tree, who may patch — the plant gets a network that is “up” in the NOC and dead on the cell. OT/IT diagnostics is the investigation of that disagreement.

How the investigation is actually run
Put both teams in the same room with the same capture. Ask IT to show the last scan window. Ask operations to show the last timeout. If those clocks do not overlap, you do not yet have a conflict, you have two stories. Inventory multicast, IGMP snooping, and whether a firewall sits in the cyclic path. A “standard image” that enables energy-efficient Ethernet should be treated as a configuration defect until proven harmless on that cell.
Addressing after mergers is a paper problem with packets as the symptom. Draw the overlapping subnets. NAT that breaks discovery will look like a flaky PLC. Unmanaged switches with a single uplink into a busy access layer are a physical architecture choice, not an accident of purchasing.
The deliverable is an ownership map and a path that a future change ticket must respect. Without that, the next scanner will recreate the outage. Performance numbers without a protocol are decoration.
Symptoms
A scanner that walks the OT range and takes the PLC to its knees. A backup that floods a VLAN the robot uses. NAT that breaks multicast. An “IT standard image” that enables energy-efficient Ethernet and drops isochronous frames. Building automation on the same closet: see BAS, OT and network coordination.
Causes
No owner of the cell uplink. Default QoS. A firewall in the cyclic path. Overlapping 192.168/16 after a merger. Physical: the “OT switch” is a dusty unmanaged unit with a single uplink into a busy access layer. Performance numbers without protocol context: read packet loss, latency, jitter.
Investigation
Inventory who talks, on which VLAN, with which period. Capture during the fault and during a quiet cycle. Check IGMP, storm control, and CPU. Ask IT and operations for their definition of success before you change a rule. Related interface thinking: engineering at system interfaces.
Conclusions assign ownership and a path design: what may share, what must not, and which measurement will be used next time someone says the network is up. Performance and active diagnostics are the follow-on services, not a new corporate slogan.