Issue
Product Line
TAC IA Series
Environment
- ENC/JACE controllers
- Niagara Workbench clients
- Remote access over public networks
- Sites where Niagara devices may be exposed to the Internet
Cause
Resolution
Important Disclaimer
The guidance in this article assumes that the network segment contains only Niagara devices.
If Niagara systems are located on a shared network (for example, a corporate LAN), do not implement the described approach independently. Engage the customer’s IT team to determine a secure method that protects both Niagara and corporate assets while still enabling the required access.
Improper VPN configuration can unintentionally expose Niagara devices to the public Internet. If you are not confident in VPN design, routing, or firewall configuration, consult a qualified IT networking professional before proceeding.
What a VPN Provides
A Virtual Private Network extends a private network across the Internet by creating an encrypted tunnel between a VPN client and a VPN gateway. This prevents data visibility to unauthorized parties and hides Niagara services from Internet-based scanning tools.
Why use a VPN with Niagara
- Adds layered security without limiting Niagara functionality
- Prevents Niagara ports from being directly reachable on the Internet
- Requires strong authentication before access is granted
- Reduces attack surface by masking Niagara services behind the VPN gateway
General VPN Deployment Guidance
- A VPN‑capable security appliance (e.g. ZyWALL USG‑20) can be added to provide secure remote access to ENC/JACE devices.
- Open only the required VPN port to the public Internet.
- Use firewall rules to restrict VPN clients to only the Niagara IP ranges and services needed.
- If incorporating non‑Niagara devices, work with IT to avoid exposing critical systems.
- Always validate the final configuration to ensure that no Niagara ports are reachable directly from the Internet.
- Refer to Using a VPN with Niagara Systems for more details.
Frequently Asked Considerations
Do I still need SSL with a VPN?
Yes. SSL protects traffic between the VPN endpoint and the Niagara station.
Does LAN access change?
No. LAN access remains unchanged; only remote access is routed through the VPN.
Does tunneling (HTTP, Fox, Platform) work over VPN?
Yes. Tunneling functions normally but may require IP address updates.
Will VPN affect Workbench access to other networks?
Possibly. Some VPNs change the default route, which may block access to external sites. Static routes may be required.
Is Dynamic DNS supported?
Yes. Register the public IP of the VPN gateway with the DDNS provider.
Is performance impacted?
Only minimally. Connection setup may be slightly slower.