WZ-IT Logo

Remote Access

Securely remote-maintain distributed sites, machines and IoT devices - without VPN client chaos and without a US SaaS in the tunnel to the plant. We build sovereign remote access and remote management platforms with browser-based access (Apache Guacamole), WireGuard site connectivity, role-based access and complete audit trails - proven in production at ABCO Water Systems and nextGYM. Here we explain the fundamentals, the security and compliance requirements (NIS2, IEC 62443) and the architecture behind them.

Basics

Security & compliance

Architecture & connectivity

WireGuard for site connectivity

WireGuard for secure site-to-site connectivity across distributed plants: tunnels, NetBird and Headscale mesh, no open inbound port. Step by step.

What is NetBird? (Zero-trust mesh VPN)

NetBird is an open-source, WireGuard-based zero-trust mesh VPN: it connects servers, devices and sites encrypted and identity-based, without open inbound ports.

What is Headscale?

Headscale is an open-source, self-hosted implementation of the Tailscale control server: a WireGuard mesh without the Tailscale cloud, using official clients.

Expose internal services without a VPN

Expose internal web apps, dashboards and APIs securely - no open ports, no VPN for everyone. Use a self-hosted reverse proxy with an outbound tunnel and SSO.

Multi-tenant operator portal for plants

Multi-tenant operator portal for plants: separating operator, customer and end customer, per-tenant RBAC, white-label and OEM service portals explained.

OT/IT segmentation, DMZ & the Purdue model

OT/IT segmentation with a DMZ and the Purdue model for remote maintenance: jump host and browser gateway in the DMZ, IEC 62443 conduits, no direct PLC access.

SSH bastion / jump host

SSH bastion and jump host explained: ProxyJump, agent-forwarding risks, hardening with key-only, MFA and logging, when a mesh VPN (NetBird/ZTNA) replaces it.

Siemens S7 / PLC remote access without open ports

PLC remote access without open ports: never expose S7 or HMI online. Outbound WireGuard tunnel, browser HMI via Guacamole - a sovereign Ewon alternative.

Decision & comparison

WZ-IT builds and runs Remote Access in production for companies - design, build and operations from one team.

See the remote management platform

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

E-Mail
[email protected]

Leading companies trust WZ-IT

  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • NextGym
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy
  • Negosh
  • ABCO Water Systems
Timo Wevelsiep & Robin Zins - CEOs of WZ-IT

Timo Wevelsiep & Robin Zins

Managing Directors of WZ-IT

1/3 - Topic Selection33%

What is your inquiry about?

Select one or more areas where we can support you.