A diagram showing how RobustVPN from an IoT Gateway acts as a virtual ethernet cable, providing secure remote access for an engineer to program a remote PLC.

Secure Remote Access for Your IoT Gateway and PLC via RobustVPN

Written by: Robert Liao

|

Published on

|

Time to read 7 min

Author: Robert Liao, Technical Support Engineer

Robert Liao is an IoT Technical Support Engineer at Robustel with hands-on experience in industrial networking and edge connectivity. Certified as a Networking Engineer, he specializes in helping customers deploy, configure, and troubleshoot IIoT solutions in real-world environments. In addition to delivering expert training and support, Robert provides tailored solutions based on customer needs—ensuring reliable, scalable, and efficient system performance across a wide range of industrial applications.

Summary

This guide explains how to get secure PLC remote access using your industrial IoT gateway and the RobustVPN service. For machine builders, "truck rolls" to service remote equipment are a massive drain on profit. By using a Robustel IoT Gateway as a plc remote access gateway, you can leverage the RCMS cloud platform to create an on-demand, secure VPN tunnel. This allows your engineers to open TIA Portal or Studio 5000 from their home office and securely program or troubleshoot any PLC, anywhere in the world, as if they were plugged in locally.

Key Takeaways

The Problem: Flying an engineer to a remote site to fix a PLC is a $5,000 problem. Exposing a PLC directly to the internet for remote access is a catastrophic security risk.

The Solution: A Robustel IoT Gateway provides a single box that acts as both a data collector and a secure plc remote access gateway.

The Technology:RobustVPN is a feature within the RCMS platform. It's a cloud-based service that creates a secure, on-demand OpenVPN tunnel between an engineer and a remote IoT Gateway, requiring no complex setup.

How it Works: The engineer's laptop and the remote IoT Gateway both "dial in" to the RCMS cloud. RCMS securely connects them onto the same virtual LAN, giving the engineer direct, secure access to the PLC "behind" the gateway.

The $5,000 Problem: Why PLC Remote Access is a Nightmare (And How to Fix It)

Let's be blunt: a "truck roll" is a polite term for a massive business failure.

You're a machine builder (OEM). Your machine is at a customer's factory in another country. It stops working. Your customer is down, losing thousands of dollars an hour. You have two options, both terrible:

  1. The $5,000 Gamble: You fly your top engineer to the site, spending $5,000 on flights and hotels, only for them to plug in, open TIA Portal, and discover the fix was a one-line code change that took 10 minutes.
  2. The "Insane" Option: You convince the customer's IT team to "port forward" the PLC to the public internet. This is so catastrophically insecure it's bordering on negligence. Your PLC, which has no firewall or password, is now visible to every hacker in the world.

This is the central pain point of modern industry. You need secure remote access, but traditional IT solutions are complex, and insecure solutions are unacceptable. This is why tools like HMS Ewon became popular—they provided a simple, secure tunnel.

But what if your IoT Gateway—the same device you're already using for data collection—could do that and more, all in one box? This is where RobustVPN and the modern IoT Gateway come in.

What is RobustVPN and How Does It Use Your IoT Gateway?

RobustVPN is a powerful, secure VPN service built directly into our Add One Product: RCMS cloud management platform. It is not a complicated IT project; it's a simple, click-to-deploy tool.

Think of it as a secure, on-demand "matchmaking" service.

  • Your IoT Gateway in the field establishes a permanent, secure outbound connection to RCMS. It sits there, quietly and securely managing your machine's data.
  • Your engineer, at their home office, needs to access that machine.
  • The engineer logs into RCMS and clicks "connect."

RobustVPN creates a secure, encrypted, peer-to-peer OpenVPN tunnel between your engineer's laptop and that specific IoT Gateway. It's like a magical, on-demand Ethernet cable that stretches 10,000 miles.


A diagram showing how RobustVPN from an IoT Gateway acts as a virtual ethernet cable, providing secure remote access for an engineer to program a remote PLC.


How It Works in Practice: The 5-Minute TIA Portal Connection

Let's make this real. Your engineer needs to program a Siemens S7-1500 PLC (at IP 192.168.1.10) that is connected to the LAN port of your remote IoT Gateway.

  1. Engineer (Home): Logs into the RCMS web platform. They see a list of all their IoT Gateway devices.
  2. RCMS: The engineer navigates to the RobustVPN tab and adds their PC as a "Client." They also add the "Remote PLC Line 1 IoT Gateway" to the same VPN group.
  3. Engineer (Home): They download the pre-configured RobustVPN client software from RCMS (a simple OpenVPN client) and click "Connect."
  4. The "Magic":RCMS authenticates the engineer and the IoT Gateway, then securely bridges them. The engineer's laptop is now on the 192.168.1.x virtual network.
  5. Engineer (Home): They open TIA Portal. They click "Go Online." TIA Portal scans the virtual network and finds the PLC at 192.168.1.10.
  6. Done. The engineer is now online with the PLC, debugging code and monitoring tags as if they were plugged in locally. No firewall changes. No port forwarding. No security risk.

This entire process turns a 3-day, $5,000 service call into a 15-minute remote session. This is the real ROI of a modern IoT Gateway platform.

Why This is the Best Ewon Alternative

This "One-Box Solution" is the ultimate hms ewon alternative. The Ewon is a fantastic plc remote access gateway. But it's just an access gateway.

The "Two-Box" Problem

If you use a dedicated remote access box (like an Ewon Cosy), you still need a separate IoT Gateway to handle your modern data collection (like Modbus/S7 to MQTT) for cloud analytics. You now have two boxes, two SIM cards, two data plans, and two platforms to manage. It's expensive and complex.

The "One-Box" IoT Gateway Solution

A Robustel edge computing gateway (like the EG5120) is designed to do both jobs in one box.

  • Job 1 (Full-Time): It acts as a powerful IoT Gateway, constantly performing PLC data collection and translating it to MQTT for your cloud dashboards.
  • Job 2 (On-Demand): It sits ready to act as your secure remote access point via RobustVPNat the exact same time.

This consolidation is the key. Your IoT Gateway is no longer just a data pipe; it's your all-in-one service, data, and access hub.


A TCO comparison showing how a single Robustel IoT Gateway (an Ewon alternative) saves cost by combining PLC remote access and data collection in one box.


Security: The "On-Demand" vs. "Always-On" Advantage

A secure IoT Gateway should follow a "zero-trust" model.

  • The Old Way (Firewall Rules): You open a port. That port is open 24/7. It's a permanent security hole waiting to be found.
  • The RCMS Way (On-Demand): The RobustVPN tunnel is not always on. It is created on-demand by an authenticated user in the RCMS platform. The second the engineer is done, they click "Disconnect," and the tunnel vanishes. The remote IoT Gateway is once again invisible.
  • RBAC (Role-Based Access Control): In RCMS, you can control who is allowed to connect. You can put your "Service Techs" in one VPN group that can only access the IoT Gateway for machines they service. Your "Managers" can be in another group that can only view the dashboard but cannot connect.

This is true, granular iot gateway security—a stark contrast to just "opening a port."

Conclusion: Stop Buying a "VPN Box," Start Using Your IoT Gateway

A simple plc remote access gateway solves one problem. A modern industrial iot gateway solves all your problems.

The next time you get a service call from a remote customer, don't look up flights. Look at your IoT Gateway. By pairing a Robustel IoT Gateway with the RCMS and RobustVPN platform, you transform your hardware from a simple data collector into a powerful, secure, and revenue-saving service tool.

This is how you kill the "truck roll." This is how you move from a break-fix business model to a proactive, high-margin service model. And this is why your IoT Gateway is the most valuable service tool you own.


A security diagram comparing risky 'port forwarding' to the secure, on-demand VPN access provided by an IoT Gateway and RCMS.


Frequently Asked Questions (FAQ)

Q1: Is RobustVPN as secure as HMS Ewon's Talk2M?

A1: Yes, absolutely. Both platforms are built on a "zero-trust" model where no device is publicly visible. RobustVPN uses industry-standard, certificate-based OpenVPN, creating an end-to-end encrypted tunnel. All access is brokered and authenticated through the secure RCMS platform, which includes full audit logs and granular, role-based user controls. It's a robust solution for secure remote access.

Q2: Is RobustVPN hard to set up on my IoT Gateway?

A2: No. That's the best part. There is no complex VPN certificate or server configuration on the IoT Gateway itself. You simply "enable" the RCMS service on the IoT Gateway. All the complexity is handled in the cloud platform, making it a "click-to-deploy" solution.

Q3: Can I manage which engineer can access which specific PLC?

A3: Yes. In RCMS, you create VPN "groups." You can create a group called "Customer A - Factory 1" and place only that customer's IoT Gateway devices in it. You then only grant your "Customer A Service Team" access to that specific VPN group, ensuring they can't accidentally see or access machines from Customer B.