Meet CMMC without replacing your VPN.
Your VPN encrypts the tunnel. CMMC also needs FIPS-validated encryption, per-session access, per-machine audit logs and deny-by-default control. Access Gate CMMC Edition adds all of them. Keep your VPN, or use the FIPS-certified VPN built in.
Last updated:
What a VPN covers and what it misses.
A VPN creates an encrypted tunnel between a remote user and your network. That satisfies the encryption requirement. But CMMC also requires per-asset access control, session-level audit trails, and microsegmentation within the network. These are separate controls that VPNs were not designed to provide. A C3PAO assessor will ask: who accessed this CNC machine last Tuesday? What commands did they send? How long was the session? Your VPN logs the tunnel. Access Gate logs the session.
What your VPN covers and what you still need.
Six NIST 800-171 controls relevant to remote access. Your VPN addresses encryption. Access Gate adds the remaining controls that assessors expect to see in OT environments.
VPN grants tunnel-level access. Once connected, the user can reach every resource on the network segment. No per-asset, per-protocol, or per-session authorization.
Access Gate authorizes each session individually. RBAC policies restrict access by user, asset, protocol, port, and time window. A vendor gets access to one CNC machine on Modbus TCP only.
VPN logs tunnel establishment: user connected at timestamp. It does not log what the user accessed, which commands were sent, or which assets were reached inside the tunnel.
Access Gate logs every session with user identity, source, destination asset, protocol, command payload, and duration. Logs are tamper-evident and forwarded to SIEM.
Most VPNs support MFA at tunnel establishment. But once the tunnel is open, subsequent connections to internal resources are not re-authenticated. One MFA check covers unlimited internal access.
Access Gate enforces MFA per session. Each connection to a new asset requires re-authentication through the identity gateway. Compromised sessions cannot pivot to other resources.
VPN default is allow-all within the tunnel. The user can reach any IP on the remote subnet. Firewall rules can restrict this, but most deployments route the full subnet.
Access Gate default is deny-all. Only explicitly authorized user-to-asset connections are permitted. Everything else is dropped and logged. No implicit trust within the overlay.
VPN encrypts the tunnel. This satisfies SC 3.13.8 for the tunnel segment only if the VPN uses FIPS-validated cryptography (SC 3.13.11). Traffic inside the remote network after the tunnel terminates is unencrypted.
Access Gate CMMC Edition includes a FIPS-certified VPN that ends at the gate, and Access Gate encrypts user-to-proxy with FIPS-validated TLS. The plaintext segment between proxy and OT asset is isolated in a micro-DMZ with no lateral paths.
VPN creates a point-to-point tunnel that bypasses network boundaries. Remote users appear as local hosts. This undermines segmentation and DMZ architecture.
Access Gate enforces boundaries through overlay microsegmentation. The VPN ends at Access Gate. Remote users then access resources through per-asset proxies and get no address on the local network.
Add the missing controls in four steps.
Deploy beside the VPN.
Connect Access Gate to your existing network. Keep the VPN running. Both work in parallel, and remote access keeps working.
Proxy the critical machines.
Route CUI-handling assets through Access Gate proxies. CNC machines, production controllers, and quality systems get identity-based access control. VPN users continue accessing non-CUI resources.
Move users and vendors.
Move remote users and vendors to Access Gate. They connect through the FIPS-certified VPN built into Access Gate CMMC Edition or through your existing VPN. Each gets scoped access to specific assets, specific protocols, specific time windows. MFA enforced per session.
Consolidate or keep both.
Once CUI-handling access routes through Access Gate, you can keep your existing VPN for general access or consolidate onto the FIPS-certified VPN built into Access Gate CMMC Edition. Either way, your C3PAO evidence is already being generated: session logs, policy configs, denied-access records.
Typical migration takes 1-2 weeks for the CUI boundary. Non-CUI remote access can remain on VPN if desired. The two systems coexist without conflict.
See the migration on your network.
We can walk through your VPN topology and map the migration path for your specific environment.
Questions about VPNs and CMMC.
additional NIST 800-171 controls beyond encryption that CMMC requires for remote access. Access Gate adds all five natively.
Yes. Access Gate and your VPN can coexist. Many organizations start by routing CUI-handling assets through Access Gate while keeping the VPN for general remote access. This reduces migration risk and gives you CMMC compliance on the CUI boundary immediately.
Access Gate supports vendor access, technician remote maintenance, and employee remote work. The difference is granularity: instead of granting subnet-level access, each user gets scoped access to specific assets on specific protocols. A vendor servicing a CNC machine gets Modbus TCP access to that machine only.
Access Gate CMMC Edition includes a FIPS-certified VPN. The VPN carries the user's traffic to Access Gate and ends there. Access Gate then authorizes, logs and encrypts each session to one specific asset through the proxy. Only these authorized sessions route through Access Gate. Internet-bound traffic stays on the user's local network.
If your VPN does not use FIPS-validated encryption, you can decommission it after migration and use the FIPS-certified VPN built into Access Gate CMMC Edition. You can also keep it for non-CUI access. Access Gate deploys as a separate appliance. It does not require changes to your VPN infrastructure during the transition.
Vendor access improves. The vendor's VPN connection ends at Access Gate, so the vendor no longer gets a tunnel into your network. The vendor gets a scoped session to the specific machine they are servicing, with MFA, session recording, and time-limited access. The session log shows exactly what they did. This satisfies CMMC AU 3.3.1 and AC 3.1.1 simultaneously.
Yes. Access Gate supports site-to-site overlay connections between facilities. Each site runs its own Access Gate, and the overlay network connects them with encrypted tunnels. Access policies are enforced at each site independently.
Access Gate proxy adds sub-millisecond latency per session establishment. Once established, throughput is comparable to direct connections. For industrial protocols operating at 10ms scan cycles, the overhead is not measurable. For bulk file transfers, throughput depends on the Access Gate hardware model.
Close the gaps your VPN leaves.
We review your VPN setup and find the CMMC controls it misses. Then we show how Access Gate closes them, in a live demo.
Request a demo