Glossary · Industrial communication
VPN (virtual private network)
Also known as: Virtual private network, VPN tunnel
German: VPN (Virtual Private Network)
In networking, a virtual private network (VPN) is an encrypted and authenticated connection over a shared or public network, such as the internet, that makes remote devices or networks appear as if they were connected to a private network. Common technologies are IPsec, OpenVPN and WireGuard.
- Industrial communication
- OT security
In one sentence
A VPN is an encrypted, authenticated tunnel over a public network that links remote devices or sites as if they were local.
Example
A service engineer connects to a machine's router through a VPN that the plant operator enables only for the duration of the service call.
How it applies
- Remote service: VPNs are the common basis for Remote access to machines. The VPN should end in a dedicated zone, not directly in the control network, and access should be limited to the systems needed.
- Security: Strong authentication (ideally multi-factor), current software, individual accounts instead of shared credentials, and logging are essential. A VPN encrypts the path; it doesn't check what the connected user does.
- Operation: The plant operator should control when a VPN is active. Permanently open service tunnels are a frequent audit finding.
- Documentation: The documentation team describes the VPN concept (endpoints, authentication, who can enable access), the responsibilities of machine builder and operator, and the procedure for starting and ending a remote session. Relevant requirements come from IEC 62443.
VPN vs. remote access
A VPN is a transport mechanism. Remote access is the overall capability, including authorization, supervision and logging. A secure remote access solution usually includes a VPN, but a VPN alone isn't one.