Zero-Port Industrial VPN

Industrial VPN: Access Your OT Equipment without exposing your network

Zero Trust architecture with zero inbound ports. Your PLCs, HMIs, and OT equipment remain invisible to the Internet—access is granted only through an AES-256-encrypted OpenVPN tunnel, and only to authorized technicians.

0
Incoming port open
AES-256
Tunnel encryption
<100ms
OpenVPN Latency
NIS2
Compliance
Test the Industrial VPNVPN Documentation
Problem

Why a Traditional VPN Isn't Enough for the OT

Traditional VPN approaches were designed for office IT networks. The industrial OT environment imposes radically different constraints.

🔓

Open incoming ports = attack surface

Traditional VPNs (OpenVPN UDP, IPSec IKE) require incoming ports to be opened in the firewall. Each open port is a potential attack vector, a risk exacerbated by the long lifespan of OT equipment (10 to 20 years without updates).

Configuration complexity = human error

Manually configuring IPSec tunnels using PSK keys, X.509 certificates, and IKE policies is prone to errors. An incorrect configuration can result in unsecured access or take a production site offline for hours.

🌐

No native failover in the event of a network outage

A 4G or fiber outage disrupts the VPN tunnel. Without a failover mechanism built into the industrial router, the site becomes inaccessible—and a technician must travel to the site to restore the connection.

Architecture

Eziwan's Zero Trust Architecture

No incoming ports are open on the OT network. The connection is initiated from the industrial site to the Eziwan cloud—never the other way around.

Technicien
Laptop / Tablet
OpenVPN/IPSec VPNAES-256 Encrypted
Cloud Eziwan
Secure Relay
Outbound tunnelSite Insider
Eziwan Gateway
OT Site DIN Rail
OT Local NetworkNot on display
PLC / HMI
Siemens · Schneider
Zero Trust Principle: No Inbound Ports Open on the OT Network

The Eziwan Gateway establishes an outbound connection to the Eziwan cloud at startup. The technician connects via their OpenVPN client—the session is relayed through the existing tunnel. The PLC is never directly accessible from the Internet.

VPN Comparison

OpenVPN vs. IPSec vs. L2TP

Why OpenVPN Is the Best Choice for Large-Scale Industrial Deployments.

CriterionOpenVPN ⭐IPSec (IKEv2)L2TP / PPTP
ChiffrementAES-256-GCM (TLS)AES-256 (IKEv2)Low (PPTP not recommended)
Firewall Pass-ThroughExcellent — TCP 443Average — UDP 500/4500 (NAT-T)Variable
4G ReconnectionQuick — persist-tunExcellent — MOBIKELente
Configuration ComplexitySimple — .ovpn fileHigh — PKI / IKE / SASimple — credentials
Compatible with OT EziwanNative — Integrated ZTPCompatible — Enterprise InteroperabilityLegacy — legacy
Zero-Touch ProvisioningEziwan Native — Self-EnrollmentSupportedNot available
Features

VPN Features of the Eziwan Gateway

🔑

Automatic Key Management

OpenVPN certificates are generated automatically during Zero-Touch Provisioning. No manual key management is required on-site. Automatic key rotation can be configured from the cloud dashboard.

🔄

VPN Failover on Link Change

If the primary 4G connection fails, failover to the secondary SIM automatically restarts the VPN tunnel without any user intervention. The technician remains connected remotely—recovery takes less than 8 seconds.

👥

Access Control by a Technician

Each technician has their own VPN key. Access can be revoked individually from the dashboard without changing the on-site gateway configuration.

📋

Comprehensive connection logging

All VPN sessions are logged: technician ID, timestamp, source IP address, and duration. Logs can be exported for NIS2 audits and to track maintenance activities.

🌐

Split tunneling and network isolation

Configure which OT subnets are accessible to each technician. Maintenance technicians have access only to their specific PLC, not to the entire industrial network.

Zero-Touch VPN Provisioning

The VPN tunnel is configured automatically when the gateway is started for the first time. Deliver the hardware to the site, plug it in—the VPN is up and running without any remote IT intervention.

Regulatory Compliance

Compliance with NIS2, IEC 62443, GDPR, and CRA

The Eziwan industrial VPN is designed to meet the regulatory requirements for critical infrastructure and operators of vital importance (OVI).

NIS2
NIS2 Directive (EU 2022/2555)

The NIS2 Directive requires critical and important entities to implement remote access control, logging, and incident management. Eziwan's zero-port architecture directly addresses these requirements with exportable audit logs.

IEC 62443
IEC 62443 — Industrial System Security

The IEC 62443 standard defines security levels for industrial control systems (ICS/SCADA). The Eziwan architecture is compatible with Security Levels SL1 and SL2, covering access control and data integrity.

RGPD
GDPR — Technicians' Personal Data

VPN connection logs containing personal data (technician ID, IP address) are stored on European infrastructure with a configurable retention period. Export and deletion options are available from the dashboard.

CRA 2027
Cyber Resilience Act (2027)

The EU's CRA Regulation imposes security-by-design requirements for connected products. Eziwan is ahead of these requirements with signed firmware, secure updates (SUIT manifest), and a vulnerability disclosure policy.

Use Cases

Industrial VPNs by Industry

Remote maintenance, SCADA monitoring, subcontractor access—the industrial VPN supports all OT access scenarios.

🔧

Remote Maintenance of PLCs & HMIs

Remote access to Siemens S7, Schneider M340, and Rockwell ControlLogix PLCs without the need for a technician to travel to the site. The engineer can connect from anywhere using their OpenVPN client—just as if they were physically at the control panel.

🏭

Multi-site Industrial Monitoring

Consolidation of 5 to 500 industrial sites into a centralized dashboard. Each site transmits its SCADA data via a secure tunnel. Full visibility without exposing a single port to the Internet.

🚿

Water, Energy, and Critical Infrastructure

Secure access to wastewater treatment plants, pumping stations, and high-voltage electrical substations classified as NIS2. Comprehensive audit log of all interventions to demonstrate compliance to regulatory authorities.

👷

Access for Subcontractor Technicians

Provide each service provider with VPN access limited to their specific devices, with configurable time windows. Instant revocation upon contract expiration. No sharing of network passwords.

Frequently Asked Questions

Secure Your OT Remote Access Today

Find out how Eziwan's industrial OpenVPN can secure your remote OT access without changing your existing infrastructure.