Reach any machine, securely,
with Tailscale and Access Gate.
Staff and vendors reach IT and OT machines without a broad VPN. Tailscale carries the encrypted tunnel. Access Gate checks identity, limits each session to one machine and records it for the audit.
How this design works.
Remote access is one of the services the Access Gate hosts. Here it works with Tailscale to give privileged access across IT and OT. Tailscale provides a WireGuard-based overlay with peer-to-peer encrypted tunnels and no setup on each link. Access Gate adds identity checks, privileged session brokering, OT machine visibility and a central audit trail. The same appliance also runs protocol gateways, DNS and time, a historian and an update server.
An encrypted link with Tailscale.
Tailscale provides the encrypted link with WireGuard tunnels, in place of a traditional VPN concentrator. It integrates with Access Gate through its API.
MFA, then a brokered session.
Access Gate shows an MFA page for each session and proxies the connection. Users never get direct network access to machines.
Access per user and per machine.
Access Gate enclaves segment LAN access per user, per resource and per protocol. Nobody sees a flat network.
A full audit trail.
Every remote session is recorded and logged. Access Gate sends events, anomalies and session alerts to your SIEM.
Three remote access flows.
The diagram shows three flows. Remote users come in through the firewall or router. Vendors connect through Tailscale straight to the Access Gate. Logs go to a cloud SIEM. The Access Gate sits inside the LAN and brokers every session to IT and OT subnets.
(1) A remote user reaches a database.
• Remote user opens Tailscale client, tunnel established to Access Gate • Connection routed to Access Gate proxy • MFA splash page presented, user authenticates • Session extended to Database, no direct network reach for the user • Session recorded and logged
(2) A vendor reaches a control system.
• Remote vendor opens Tailscale client, tunnel established to Access Gate • Access Gate applies ACL, presents MFA splash page + VDI screen • Vendor authenticates • Session extended to Control System only • Session recorded and logged in Access Gate audit trail
(3) Logs go to a cloud SIEM.
• Optional ICS stream log to Access Gate • Access Gate skims logs and processes proxy logs to rsyslog format • Access Gate establishes tunnel to Cloud SIEM and forwards logs
How it covers your audit requirements.
The main remote access requirements, and how Access Gate and Tailscale meet each one.
| Requirement | How Access Gate + Tailscale covers it | |
|---|---|---|
| Multi-factor authentication on remote sessions | Tailscale device auth & Access Gate splash-page for multi-factor authentication | ✓ |
| Least-privilege & role-based access control | Permission Matrix in Access Gate enforces per-user, per-resource, per-protocol rules | ✓ |
| Privileged access management (PAM) identified and proxied | Privileged sessions proxied through Access Gate; no direct network access to OT endpoints | ✓ |
| Session recording & audit trail for privileged sessions | Access Gate logs session events; forwarded to SIEM | ✓ |
| Encrypted remote access (in-transit protection) | WireGuard (Tailscale) provides end-to-end or end-to-hub encryption | ✓ |
| Micro-segmentation | Access Gate enclave model segments LAN access | ✓ |
| Monitoring & alerting on remote access events | Access Gate ships auth events, anomalies, session alerts to SIEM | ✓ |
| Continuous connection inventory | Access Gate logs every remote access session | ✓ |
Download the remote access architecture.
Get the architecture diagram and the requirements checklist in one pack.
One gateway.
Want a simpler start? One Access Gate covers IT and OT, and your perimeter does not change.
Two gateway layers.
Need separate control zones for IT and OT? The two-layer design adds a second layer of protection.
Questions about secure remote access.
machine per session. Tailscale or your current VPN carries the traffic, and Access Gate limits each session to one authorized machine.
No. Access Gate works with the VPN you already run. This design uses Tailscale as the encrypted link, and Tailscale can run next to your current VPN. You can move users over step by step. Once every remote session goes through Tailscale and Access Gate, you can retire the old VPN concentrator or keep it.
Vendors connect through Tailscale straight to the Access Gate (flow 2). Access Gate applies vendor-specific rules, asks for MFA, shows a VDI screen and limits the session to named control systems. Vendors never get broad LAN access.
Yes. Access Gate converts proxy logs to rsyslog format and opens a tunnel to your cloud SIEM. It supports standard syslog forwarding and direct integration with common SIEM platforms.