TroutTrout

Reach any machine, securely,
with Tailscale and Access Gate.

Staff and vendors reach IT and OT machines without a broad VPN. Tailscale carries the encrypted tunnel. Access Gate checks identity, limits each session to one machine and records it for the audit.

Overview

How this design works.

Remote access is one of the services the Access Gate hosts. Here it works with Tailscale to give privileged access across IT and OT. Tailscale provides a WireGuard-based overlay with peer-to-peer encrypted tunnels and no setup on each link. Access Gate adds identity checks, privileged session brokering, OT machine visibility and a central audit trail. The same appliance also runs protocol gateways, DNS and time, a historian and an update server.

An encrypted link with Tailscale.

Tailscale provides the encrypted link with WireGuard tunnels, in place of a traditional VPN concentrator. It integrates with Access Gate through its API.

MFA, then a brokered session.

Access Gate shows an MFA page for each session and proxies the connection. Users never get direct network access to machines.

Access per user and per machine.

Access Gate enclaves segment LAN access per user, per resource and per protocol. Nobody sees a flat network.

A full audit trail.

Every remote session is recorded and logged. Access Gate sends events, anomalies and session alerts to your SIEM.

Architecture diagram

Three remote access flows.

The diagram shows three flows. Remote users come in through the firewall or router. Vendors connect through Tailscale straight to the Access Gate. Logs go to a cloud SIEM. The Access Gate sits inside the LAN and brokers every session to IT and OT subnets.

(1) A remote user reaches a database.

• Remote user opens Tailscale client, tunnel established to Access Gate • Connection routed to Access Gate proxy • MFA splash page presented, user authenticates • Session extended to Database, no direct network reach for the user • Session recorded and logged

(2) A vendor reaches a control system.

• Remote vendor opens Tailscale client, tunnel established to Access Gate • Access Gate applies ACL, presents MFA splash page + VDI screen • Vendor authenticates • Session extended to Control System only • Session recorded and logged in Access Gate audit trail

(3) Logs go to a cloud SIEM.

• Optional ICS stream log to Access Gate • Access Gate skims logs and processes proxy logs to rsyslog format • Access Gate establishes tunnel to Cloud SIEM and forwards logs

TAG Architecture: Secure Remote Access with an encrypted VPN + Access Gate
Compliance

How it covers your audit requirements.

The main remote access requirements, and how Access Gate and Tailscale meet each one.

RequirementHow Access Gate + Tailscale covers it
Multi-factor authentication on remote sessionsTailscale device auth & Access Gate splash-page for multi-factor authentication✓
Least-privilege & role-based access controlPermission Matrix in Access Gate enforces per-user, per-resource, per-protocol rules✓
Privileged access management (PAM) identified and proxiedPrivileged sessions proxied through Access Gate; no direct network access to OT endpoints✓
Session recording & audit trail for privileged sessionsAccess Gate logs session events; forwarded to SIEM✓
Encrypted remote access (in-transit protection)WireGuard (Tailscale) provides end-to-end or end-to-hub encryption✓
Micro-segmentationAccess Gate enclave model segments LAN access✓
Monitoring & alerting on remote access eventsAccess Gate ships auth events, anomalies, session alerts to SIEM✓
Continuous connection inventoryAccess Gate logs every remote access session✓
Architecture pack

Download the remote access architecture.

Get the architecture diagram and the requirements checklist in one pack.

Done

One gateway.

Want a simpler start? One Access Gate covers IT and OT, and your perimeter does not change.

View architecture

Two gateway layers.

Need separate control zones for IT and OT? The two-layer design adds a second layer of protection.

View architecture
FAQ

Questions about secure remote access.

1

machine per session. Tailscale or your current VPN carries the traffic, and Access Gate limits each session to one authorized machine.

No. Access Gate works with the VPN you already run. This design uses Tailscale as the encrypted link, and Tailscale can run next to your current VPN. You can move users over step by step. Once every remote session goes through Tailscale and Access Gate, you can retire the old VPN concentrator or keep it.

Vendors connect through Tailscale straight to the Access Gate (flow 2). Access Gate applies vendor-specific rules, asks for MFA, shows a VDI screen and limits the session to named control systems. Vendors never get broad LAN access.

Access Gate performs protocol-level inspection on industrial protocols (Modbus, EtherNet/IP, OPC-UA) and standard IT protocols (RDP, SSH, HTTP/S). Sessions are broken and re-established through the proxy for full visibility.

Yes. Access Gate converts proxy logs to rsyslog format and opens a tunnel to your cloud SIEM. It supports standard syslog forwarding and direct integration with common SIEM platforms.