TroutTrout

Compare Access Gate and IXON.

IXON is the most modern product in this category, with real SSO and dashboards that Access Gate does not match. The difference is who it is built for: the machine builder or the plant operator.

The problem

IXON covers the way in to each machine.

IXON solved remote service beautifully: an IXrouter at the machine, an outbound connection to IXON Cloud, a browser session for the engineer, and data logging on top. If you build machines and ship them, that is close to the whole job. If you run the plant those machines sit in, it covers the way in and nothing about what happens between them.

Trout Access Gate

Trout Access Gate

One appliance per site rather than one router per machine. The broker runs on your own network, so no external service is in the path. Each session is scoped to a named asset and protocol, authenticated and recorded. Behind it the plant is divided into overlay enclaves, every asset is discovered automatically, and detection forwards to your SIEM with evidence mapped to IEC 62443, NERC CIP and CMMC.

IXON

IXON

An IXrouter at the machine dials out to IXON Cloud, and the engineer connects through the browser with no inbound firewall rules. IXON Cloud documents Okta SSO on a custom domain plus Google and Microsoft sign-in, enforceable two-factor per role, and built-in data logging, dashboards and alarms. On identity and on machine data it is ahead of most of this category, and Access Gate does not claim to beat it on dashboards.

Feature comparison
FeatureAccess GateIXON
Deploys without re-cabling or re-addressing
Assets keep their IP, gateway and VLAN
IXrouter sits in front of the machine
On-site hardware gateway
No inbound firewall rules needed
The gate brokers locally; nothing published
Outbound-only connection to IXON Cloud
Single sign-on with your identity provider
Entra ID user and group sync, OIDC
Okta SSO on a custom domain, Google and Microsoft sign-in
Enforceable two-factor authentication
Enforceable per role
Machine dashboards and data logging
Can host a historian or dashboard service locally
Built-in data logging, dashboards and alarms
Runs with no third-party cloud service
Nothing leaves your network
IXON Cloud is the platform, not an option
Per-session, per-protocol policy
This user, this asset, this protocol
VPN lands on the machine network
Session recording and playback
Audit trail of connections, not session content
Scales to a whole site, not per machine
One appliance and one policy set for the site
One IXrouter per machine or cell
Network segmentation
Overlay enclaves, no VLAN redesign
Connects machines; does not segment between them
Automatic asset inventory of the whole network
The devices you onboard behind each router
Security detection and SIEM forwarding
Snort rules, curated alert library, Splunk/Elastic/Wazuh
Alarms on machine data, not network security detection
Compliance evidence generation
IEC 62443, CMMC, NERC CIP mapping
Connection and audit logs
Key differences

IXON Cloud sits in the access path.

IXON Cloud is the platform itself, and it is operated in the EU. The point is dependency. It is a third party in scope for your supply-chain security review, and your plant access relies on it staying available.

Access Gate needs one appliance per site.

Fifteen machines means fifteen IXrouters, each with its own configuration and firmware. One appliance per site gives one policy set and one answer to who can reach what.

Access Gate works behind IXON.

A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove IXON. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.

Questions

Questions about Access Gate and IXON.

Per site

One appliance, one policy set and one place to answer who can reach what, instead of one router per machine.

Yes, and it would be wrong to suggest otherwise. IXON Cloud documents Okta SSO on a custom domain, sign-in with Google or Microsoft accounts, and two-factor authentication that can be enforced per role. On identity it is well ahead of the older gateways in this category, and this comparison does not rest on that point.

Machine data and user experience. Built-in logging, dashboards and alarms mean a machine builder gets remote service and remote monitoring from one product with a modern interface. Access Gate can host a historian or dashboard service locally, but it is not an IIoT platform and does not pretend to be.

No. The cloud is the platform rather than an optional broker, which is the structural difference here. Access Gate brokers on the appliance itself, so there is no external rendezvous to depend on, and it keeps the property that makes IXON easy to deploy: no inbound firewall rules, because nothing is published to the internet.

No. IXON is a Dutch company operating in the EU. The concern is dependency. A vendor-run service in your access path is a third party in scope for supply-chain risk management, with the documentation and assurance work that follows. It is also an availability question you did not have before.

Usually not, and we do not recommend it. IXON is a capable tool for getting a technician to a machine. On sites you do not own, it may be the only thing you can deploy. The risk comes from adding connectivity on its own. A IXrouter per machine adds doors into the plant, with no view of what passes through them and no access control at an OT control point. The solid setup uses both. Keep IXON where it earns its place and put Access Gate behind it. Every session that arrives then passes identity checks, protocol policy and recording, in a segmented plant.

Keep comparing

Also looking at cloud security tools?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.