Compare Trout & Tosibox
Tosibox pairs a Key and a Lock and gives you a working tunnel in minutes. The question is what happens after the tunnel is up.
The problem
Industrial remote access began as a connectivity problem: get the engineer to the machine. Tosibox solved that unusually well. But a tunnel is binary. Once it is open, whoever holds the Key is on the segment, and the network behind it has no opinion about which machine they touch or which protocol they speak.
Trout Access Gate
Every session is brokered rather than tunnelled. The gate authenticates the person, checks policy for that specific asset and protocol, records the session, and denies everything not explicitly allowed. Behind it the network is divided into enclaves, so a compromised session reaches one machine instead of a whole subnet.
Tosibox
A hardware-first industrial VPN: a Lock at the site, a Key for the engineer, cryptographic pairing on first plug-in, and a connection that works with no cloud dependency. It is genuinely quick to deploy and popular for good reason wherever the requirement is reliable remote connectivity to distant sites.
| Feature | Access Gate | Tosibox |
|---|---|---|
| Physical appliance at the site | ||
| Works with no cloud dependency | ||
| Agentless for OT assets | ||
| Fast first connection | Cabled and steering traffic in hours | Key and Lock pair on first plug-in |
| Identity-based access policy | Per user, per asset, per protocol | Access follows the Key, not the person's role |
| Per-session enforcement and recording | Tunnel is opened, then traffic is not brokered | |
| Protocol-level control (Modbus, RDP, SSH) | VPN carries whatever the tunnel allows | |
| Network segmentation | Overlay enclaves between assets | Connects sites; does not segment inside them |
| Automatic asset inventory | ||
| Hosts services next to the assets | Protocol gateways, DNS/NTP, file share, historian | Connectivity device |
| Compliance evidence generation | IEC 62443, NIS2, CMMC mapping | Connection logs only |
| Protects against lateral movement | Default-deny between enclaves | A tunnelled peer reaches the segment |
| Deploys without re-cabling or re-addressing | Assets keep their IP, gateway and VLAN; inserted with a routing or DNS change | Lock plugs in at the site |
| Scales to a whole site, not per machine | One appliance and one policy set for the site | One Lock per site or machine, plus Keys to track |
Access versus connectivity
A VPN answers whether you can reach the site. Zero-trust access answers whether this person may reach this machine, on this protocol, right now. The second is what auditors and insurers now ask about.
The Key is not an identity
Access follows the physical Key, so it moves with the hardware rather than with the person's role. Access Gate binds access to a directory identity with MFA, so revoking it is a policy change rather than recovering a device.
Better behind it than instead of it
A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove Tosibox. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.
Access Gate vs Tosibox FAQ
Identity, protocol policy and a recording on every connection, rather than one tunnel that stays open.
No. The tunnel is encrypted and the pairing model is sound. The limitation is scope: it secures the path, not the session. Once connected there is no per-asset policy, no protocol-level control and no record of what was done.
Time to first connection, and simplicity at very small sites. Plugging in a Lock and pairing a Key is about as simple as industrial remote access gets, and it needs no directory, no policy design and no network planning.
A site is typically cabled and steering traffic within a day. It asks for more thought up front than a Key and a Lock, because you are defining policy, and that policy is the thing a VPN cannot give you.
Usually not, and that is not what we recommend. Tosibox is a capable spot solution for getting a technician to a machine, and on sites you do not own it may be the only thing you can deploy. The risk is not the product, it is deploying connectivity on its own: a Lock per machine gives you doors into the plant with no visibility of what passes through them and no access control at an OT control point. The solid architecture is both. Keep Tosibox where it earns its place, put Access Gate behind it, and every session that arrives still has to pass identity, protocol policy and recording, in a plant that is segmented rather than flat.
No. Assets keep their IP, gateway and routing. Access Gate represents each one by an overlay twin and is inserted with a routing or DNS change.