Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Schneider Electric
Community
Community
Notifications
close
  • Categories
  • Forums
  • Knowledge Center
  • Blogs
  • Ideas
  • Events & Webinars
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register

Contact Support

Close

Ask our Experts

Have a question related to our products, solutions or services? Get quick support on community Forums

Email Us

For Community platform-related support, please email us

New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).

Using a VPN with I/A Series Niagara G3 Systems

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

Search in

Improve your search experience:

  • Exact phrase → Use quotes " " (e.g., "error 404")
  • Wildcard → Use * for partial words (e.g., build*, *tion)
  • AND / OR → Combine keywords (e.g., login AND error, login OR sign‑in)
  • Keep it short → Use 2–3 relevant words , not full sentences
  • Filters → Narrow results by section (Knowledge Base, Users, Products)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Select a Country

Please select a country to continue with beta search.

  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
  • Using a VPN with I/A Series Niagara G3 Systems
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • CraigEl
    CraigEl

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Building Automation Knowledge Base
Start a Topic
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
0 Likes
3520 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

Using a VPN with I/A Series Niagara G3 Systems

Product_Support
‎2018-09-11 08:25 AM

Last Updated: CraigEl Champion ‎2026-02-26 10:49 PM

Issue

Guidance is required on how to implement a VPN to securely access I/A Series Niagara G3 systems and understand how VPN usage affects Niagara communication and system behavior.

Product Line

TAC IA Series

Environment

  • ENC/JACE controllers
  • Niagara Workbench clients
  • Remote access over public networks
  • Sites where Niagara devices may be exposed to the Internet

Cause

Direct exposure of Niagara devices to the Internet presents security risks such as port scanning, unauthorized access attempts, or exploitation of open services. A VPN provides an encrypted access layer but must be applied correctly to prevent accidental exposure.

Resolution

Important Disclaimer

The guidance in this article assumes that the network segment contains only Niagara devices.
If Niagara systems are located on a shared network (for example, a corporate LAN), do not implement the described approach independently. Engage the customer’s IT team to determine a secure method that protects both Niagara and corporate assets while still enabling the required access.

Improper VPN configuration can unintentionally expose Niagara devices to the public Internet. If you are not confident in VPN design, routing, or firewall configuration, consult a qualified IT networking professional before proceeding.


What a VPN Provides

A Virtual Private Network extends a private network across the Internet by creating an encrypted tunnel between a VPN client and a VPN gateway. This prevents data visibility to unauthorized parties and hides Niagara services from Internet-based scanning tools.

Why use a VPN with Niagara

  • Adds layered security without limiting Niagara functionality
  • Prevents Niagara ports from being directly reachable on the Internet
  • Requires strong authentication before access is granted
  • Reduces attack surface by masking Niagara services behind the VPN gateway

General VPN Deployment Guidance

  • A VPN‑capable security appliance (e.g. ZyWALL USG‑20) can be added to provide secure remote access to ENC/JACE devices.
  • Open only the required VPN port to the public Internet.
  • Use firewall rules to restrict VPN clients to only the Niagara IP ranges and services needed.
  • If incorporating non‑Niagara devices, work with IT to avoid exposing critical systems.
  • Always validate the final configuration to ensure that no Niagara ports are reachable directly from the Internet.
  • Refer to Using a VPN with Niagara Systems for more details.

Frequently Asked Considerations

Do I still need SSL with a VPN?
Yes. SSL protects traffic between the VPN endpoint and the Niagara station.

Does LAN access change?
No. LAN access remains unchanged; only remote access is routed through the VPN.

Does tunneling (HTTP, Fox, Platform) work over VPN?
Yes. Tunneling functions normally but may require IP address updates.

Will VPN affect Workbench access to other networks?
Possibly. Some VPNs change the default route, which may block access to external sites. Static routes may be required.

Is Dynamic DNS supported?
Yes. Register the public IP of the VPN gateway with the DDNS provider.

Is performance impacted?
Only minimally. Connection setup may be slightly slower.

Labels (1)
Labels:
  • TAC IA Series
Attachments
Tags (3)
  • Find more articles tagged with:
  • 14707
  • CraigEllis26
  • RandyDavis23
Was this article helpful? Yes No
No ratings

Link copied. Please paste this link to share this article on your social media post.

You’ve reached the end of your document

WHAT’S NEXT?

Ask our Experts

Didn't find what you are looking for? Ask our experts!

My Dashboard

Check out the new Feeds and activities that are relevant to you.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support

    Ask our Experts

    Have a question related to our products, solutions or services? Get quick support on community Forums

    Email Us

    For Community platform-related support, please email us

Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2026 Schneider Electric

Welcome!

Welcome to your new personalized space.

of

Explore