TroutTrout

Compare Access Gate and Tosibox.

Tosibox pairs a Key and a Lock and gives you a working tunnel in minutes. This page covers what happens once the tunnel is up.

The problem

A tunnel decides only who gets in.

Industrial remote access began as a connectivity problem: get the engineer to the machine. Tosibox solved that unusually well. But a tunnel is binary. Once it is open, whoever holds the Key is on the segment, and the network behind it has no opinion about which machine they touch or which protocol they speak.

Trout Access Gate

Trout Access Gate

Every session is brokered rather than tunnelled. The gate authenticates the person, checks policy for that specific asset and protocol, records the session, and denies everything not explicitly allowed. Behind it the network is divided into enclaves, so a compromised session reaches one machine instead of a whole subnet.

Tosibox

Tosibox

A hardware-first industrial VPN: a Lock at the site, a Key for the engineer, cryptographic pairing on first plug-in, and a connection that works with no cloud dependency. It is genuinely quick to deploy and popular for good reason wherever the requirement is reliable remote connectivity to distant sites.

Feature comparison
FeatureAccess GateTosibox
Physical appliance at the site
Works with no cloud dependency
Agentless for OT assets
Fast first connection
Cabled and steering traffic within a day
Key and Lock pair on first plug-in
Identity-based access policy
Per user, per asset, per protocol
Access follows the Key, not the person's role
Per-session enforcement and recording
Tunnel is opened, then traffic is not brokered
Protocol-level control (Modbus, RDP, SSH)
VPN carries whatever the tunnel allows
Network segmentation
Overlay enclaves between assets
Connects sites; does not segment inside them
Automatic asset inventory
Hosts services next to the assets
Protocol gateways, DNS/NTP, file share, historian
Connectivity device
Compliance evidence generation
IEC 62443, CMMC, NERC CIP mapping
Connection logs only
Protects against lateral movement
Default-deny between enclaves
A tunnelled peer reaches the segment
Deploys without re-cabling or re-addressing
Assets keep their IP, gateway and VLAN; inserted with a routing or DNS change
Lock plugs in at the site
Scales to a whole site, not per machine
One appliance and one policy set for the site
One Lock per site or machine, plus Keys to track
Key differences

Access Gate checks each person and machine.

A VPN answers whether you can reach the site. Zero-trust access answers whether this person may reach this machine, on this protocol, right now. The second is what auditors and insurers now ask about.

Access Gate ties access to a person.

Access follows the physical Key, so it moves with the hardware rather than with the person's role. Access Gate binds access to a directory identity with MFA, so revoking it is a policy change rather than recovering a device.

Access Gate works behind Tosibox.

A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove Tosibox. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.

Questions

Questions about Access Gate and Tosibox.

Per session

Identity, protocol policy and a recording on every connection, rather than one tunnel that stays open.

No. The tunnel is encrypted and the pairing model is sound. The limit is scope. It secures the path but does not check the session. Once connected there is no per-machine policy, no protocol-level control and no record of what was done.

Time to first connection, and simplicity at very small sites. Plugging in a Lock and pairing a Key is about as simple as industrial remote access gets, and it needs no directory, no policy design and no network planning.

A site is typically cabled and steering traffic within a day. It asks for more thought up front than a Key and a Lock, because you are defining policy, and that policy is the thing a VPN cannot give you.

Usually not, and we do not recommend it. Tosibox is a capable tool for getting a technician to a machine. On sites you do not own, it may be the only thing you can deploy. The risk comes from adding connectivity on its own. A Lock per machine adds doors into the plant, with no view of what passes through them and no access control at an OT control point. The solid setup uses both. Keep Tosibox where it earns its place and put Access Gate behind it. Every session that arrives then passes identity checks, protocol policy and recording, in a segmented plant.

No. Assets keep their IP, gateway and routing. Access Gate represents each one by an overlay twin and is inserted with a routing or DNS change.

Keep comparing

Also looking at cloud security tools?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.