Five ways to reach a machine, compared.
Access Gate controls remote sessions on your own network. Each session reaches one machine over one protocol, with no third-party service.
Last updated:
Three questions before you choose.
Every product on this page puts a device at the machine and connects a technician to it. They all do this job well. Ewon is especially strong for a machine builder who needs one connection without involving the customer's IT team. Three questions separate them. The table below uses public vendor documentation, and says so where a capability is not documented.
Who runs the service that connects the technician?
The vendor runs Talk2M and IXON Cloud, so your remote access depends on the vendor. A supply-chain security review will ask you about that third party. You can host Secomea and Siemens yourself. Access Gate needs no connection service outside your network.
What can the engineer reach once connected?
A VPN places the engineer on the machine's LAN. From there, the engineer reaches whatever the network allows, which on most plant floors is every device. A session through Access Gate names one machine and one protocol, and it is recorded. The rest of the plant stays out of reach. Most plants keep their gateway and add Access Gate behind it.
If the internet drops, what still works?
With a cloud-brokered product, the connection service is unreachable, so remote sessions stop. This is usually acceptable. It matters more whether your access policy also depends on that service. If it does, an outage at the vendor becomes a security event at your plant. Access Gate enforces policy on site, so it keeps working in both cases.
Industrial remote access options side by side.
Competitor cells come from each vendor's public documentation, linked below. Where a capability is not publicly documented, the cell says so instead of guessing.
| Capability | Ewon + Talk2M | Secomea | Siemens SINEMA RC | IXON | Trout Access Gate |
|---|---|---|---|---|---|
| Who operates the broker | HMS, via Talk2M | You or Secomea; GateManager offers both | You; you run the SINEMA RC server | IXON, via IXON Cloud | You; the gate controls sessions locally |
| Runs with no third-party service | No; Talk2M connects the user to the gateway | Yes, with a self-hosted GateManager | Yes; the server runs on your infrastructure | No; IXON Cloud connects the user to the gateway | Yes; nothing leaves your network |
| What a session can reach | The machine LAN, over a VPN | A registered device, reached via LinkManager | A device or subnet over the VPN tunnel | A registered device | One user, one asset, one protocol |
| Session recording | Connection logs | Audit logs of connections | Connection logs | Connection logs; session detail varies by plan | Full session recording and playback |
| Segments the plant behind it | No | No | Partial; with Scalance firewalls deployed alongside | No | Yes; controls who reaches what, no VLAN redesign |
| Automatic asset inventory | No | No; you register what should be reachable | No | Partial; the devices you onboard | Yes; automatic discovery of what is on the network |
| Detection and alerting | No | No | Not part of the remote-access product | No | Yes; alerts on unusual traffic, sent to your SIEM |
| Compliance evidence (IEC 62443 / CMMC) | Connection logs only | Access logs you assemble yourself | Logs you assemble yourself | Connection logs | Yes; mapped to IEC 62443 and CMMC |
| What a 15-machine site looks like | One Cosy per machine, each managed on its own | One SiteManager per machine or cell | One server plus a Scalance per enforced boundary | One gateway per machine | One appliance for the site, one policy set |
Sources: Ewon / Talk2M · Secomea · Siemens SINEMA RC · IXON
One-to-one comparisons: Access Gate vs Ewon · Access Gate vs Tosibox · Access Gate vs Secomea · Access Gate vs IXON · Access Gate vs Xage · Access Gate vs BeyondTrust PRA (Bomgar)
Before comparing, see how Ewon remote access and Talk2M work, and where the risk sits.
Where Access Gate runs today.
Trout Access Gate secures defense manufacturers, research institutions and critical-infrastructure operators. These environments run legacy PLCs, SCADA and equipment that cannot take an agent. Customers include Thales, Millbrook Machine, Elna Magnetics, Irish Manufacturing Research, HUN-REN SZTAKI and STBMA.
See customer storiesQuestions about industrial remote access.
Access Gate runs remote sessions on your own network and controls who reaches what behind them, with no third-party connection service.
Industrial remote access is how an engineer, an OEM or a contractor reaches equipment inside a plant without being on site. PLCs, HMIs and drives cannot run agents and often cannot be patched, so a device in front of them handles the access: a gateway, a VPN concentrator or a proxy. The products differ mainly in who operates the connection point and how much a session can reach.
An industrial VPN router provides the connection, but it does not control access. It places the engineer on a network segment, and from there the network layout decides what the engineer can reach. For a single machine at a customer site, this is often acceptable. In a plant you own, a contractor working on one line can then reach every other device on that segment. Attackers use this path to move laterally, and auditors now ask about it. Keep the router for the connection and add a control point behind it.
All three use a gateway at the machine, a client for the technician, and a broker in between. They differ in who runs the broker. The vendor operates Talk2M (Ewon) and IXON Cloud. You can host Secomea's GateManager yourself, and Siemens SINEMA Remote Connect is a server you run yourself. If data sovereignty or a supply-chain security review matters to you, start from this difference.
Yes. Access Gate controls sessions on the appliance itself, so no external connection service and no vendor service is in the path. Like cloud-brokered products, it requires no inbound firewall rules, because it does not publish a service to the internet.
No. Assets keep their IP address, gateway and routing. Access Gate is inserted with a routing or DNS change and represents each asset by an overlay twin. Nothing on the plant floor is reconfigured, and you can stage the change and roll it back like any routing change.
Often you need more than one. These products are good at connecting a technician to a machine. On a site you do not own, a cloud-brokered gateway such as Ewon or IXON may be the only thing you can deploy. The risk is deploying the connection alone. A gateway per machine gives remote access into the plant with no visibility of the traffic and no access control at an OT control point. The recommended architecture uses both. Keep the gateway where it is useful, and connect Access Gate to your existing network behind it. Every session that arrives then goes through identity checks, protocol policy and recording, and reaches only the machine it names.
More pages about OT remote access
Get a straight answer for your plant.
One call with an engineer tells you if Access Gate fits your plant.