TroutTrout
Industrial remote access

Five ways to reach a machine, compared.

Access Gate controls remote sessions on your own network. Each session reaches one machine over one protocol, with no third-party service.

Last updated:

Reach any machine, securely.

Three questions before you choose.

Every product on this page puts a device at the machine and connects a technician to it. They all do this job well. Ewon is especially strong for a machine builder who needs one connection without involving the customer's IT team. Three questions separate them. The table below uses public vendor documentation, and says so where a capability is not documented.

Who runs the service that connects the technician?

The vendor runs Talk2M and IXON Cloud, so your remote access depends on the vendor. A supply-chain security review will ask you about that third party. You can host Secomea and Siemens yourself. Access Gate needs no connection service outside your network.

What can the engineer reach once connected?

A VPN places the engineer on the machine's LAN. From there, the engineer reaches whatever the network allows, which on most plant floors is every device. A session through Access Gate names one machine and one protocol, and it is recorded. The rest of the plant stays out of reach. Most plants keep their gateway and add Access Gate behind it.

If the internet drops, what still works?

With a cloud-brokered product, the connection service is unreachable, so remote sessions stop. This is usually acceptable. It matters more whether your access policy also depends on that service. If it does, an outage at the vendor becomes a security event at your plant. Access Gate enforces policy on site, so it keeps working in both cases.

Side by side

Industrial remote access options side by side.

Competitor cells come from each vendor's public documentation, linked below. Where a capability is not publicly documented, the cell says so instead of guessing.

CapabilityEwon + Talk2MSecomeaSiemens SINEMA RCIXONTrout Access Gate
Who operates the brokerHMS, via Talk2MYou or Secomea; GateManager offers bothYou; you run the SINEMA RC serverIXON, via IXON CloudYou; the gate controls sessions locally
Runs with no third-party serviceNo; Talk2M connects the user to the gatewayYes, with a self-hosted GateManagerYes; the server runs on your infrastructureNo; IXON Cloud connects the user to the gatewayYes; nothing leaves your network
What a session can reachThe machine LAN, over a VPNA registered device, reached via LinkManagerA device or subnet over the VPN tunnelA registered deviceOne user, one asset, one protocol
Session recordingConnection logsAudit logs of connectionsConnection logsConnection logs; session detail varies by planFull session recording and playback
Segments the plant behind itNoNoPartial; with Scalance firewalls deployed alongsideNoYes; controls who reaches what, no VLAN redesign
Automatic asset inventoryNoNo; you register what should be reachableNoPartial; the devices you onboardYes; automatic discovery of what is on the network
Detection and alertingNoNoNot part of the remote-access productNoYes; alerts on unusual traffic, sent to your SIEM
Compliance evidence (IEC 62443 / CMMC)Connection logs onlyAccess logs you assemble yourselfLogs you assemble yourselfConnection logsYes; mapped to IEC 62443 and CMMC
What a 15-machine site looks likeOne Cosy per machine, each managed on its ownOne SiteManager per machine or cellOne server plus a Scalance per enforced boundaryOne gateway per machineOne appliance for the site, one policy set

Sources: Ewon / Talk2M · Secomea · Siemens SINEMA RC · IXON

One-to-one comparisons: Access Gate vs Ewon · Access Gate vs Tosibox · Access Gate vs Secomea · Access Gate vs IXON · Access Gate vs Xage · Access Gate vs BeyondTrust PRA (Bomgar)

Before comparing, see how Ewon remote access and Talk2M work, and where the risk sits.

In production

Where Access Gate runs today.

Trout Access Gate secures defense manufacturers, research institutions and critical-infrastructure operators. These environments run legacy PLCs, SCADA and equipment that cannot take an agent. Customers include Thales, Millbrook Machine, Elna Magnetics, Irish Manufacturing Research, HUN-REN SZTAKI and STBMA.

See customer stories

Questions about industrial remote access.

Access Gate runs remote sessions on your own network and controls who reaches what behind them, with no third-party connection service.

Industrial remote access is how an engineer, an OEM or a contractor reaches equipment inside a plant without being on site. PLCs, HMIs and drives cannot run agents and often cannot be patched, so a device in front of them handles the access: a gateway, a VPN concentrator or a proxy. The products differ mainly in who operates the connection point and how much a session can reach.

An industrial VPN router provides the connection, but it does not control access. It places the engineer on a network segment, and from there the network layout decides what the engineer can reach. For a single machine at a customer site, this is often acceptable. In a plant you own, a contractor working on one line can then reach every other device on that segment. Attackers use this path to move laterally, and auditors now ask about it. Keep the router for the connection and add a control point behind it.

All three use a gateway at the machine, a client for the technician, and a broker in between. They differ in who runs the broker. The vendor operates Talk2M (Ewon) and IXON Cloud. You can host Secomea's GateManager yourself, and Siemens SINEMA Remote Connect is a server you run yourself. If data sovereignty or a supply-chain security review matters to you, start from this difference.

Yes. Access Gate controls sessions on the appliance itself, so no external connection service and no vendor service is in the path. Like cloud-brokered products, it requires no inbound firewall rules, because it does not publish a service to the internet.

No. Assets keep their IP address, gateway and routing. Access Gate is inserted with a routing or DNS change and represents each asset by an overlay twin. Nothing on the plant floor is reconfigured, and you can stage the change and roll it back like any routing change.

Often you need more than one. These products are good at connecting a technician to a machine. On a site you do not own, a cloud-brokered gateway such as Ewon or IXON may be the only thing you can deploy. The risk is deploying the connection alone. A gateway per machine gives remote access into the plant with no visibility of the traffic and no access control at an OT control point. The recommended architecture uses both. Keep the gateway where it is useful, and connect Access Gate to your existing network behind it. Every session that arrives then goes through identity checks, protocol policy and recording, and reaches only the machine it names.

Get a straight answer for your plant.

One call with an engineer tells you if Access Gate fits your plant.