Skip to main content
How IoTinix Works

Secure Remote Access in Three Layers

IoTinix replaces exposed public IP access with a secure outbound VPN model. Routers connect outward. Users access devices through a controlled platform layer. Nothing is exposed by default.

Summary

IoTinix is a VPN-first IoT remote access platform. Routers establish outbound encrypted tunnels using OpenVPN or WireGuard to a central control server. The platform authenticates devices, assigns identities and enforces access policies. Authorised users access devices through the portal - never directly from the public internet. No fixed public IP SIM is required. No inbound ports are opened at any site.

The Architecture

Three Layers. One Control Point.

📡

Layer 1

The Device Layer - Your Router

Your industrial cellular router - for example a Teltonika RUT955, RUTX11 or TRB series gateway - is configured with a VPN client profile downloaded from the IoTinix portal. On startup, the router initiates an outbound encrypted tunnel to the IoTinix control server using either OpenVPN or WireGuard.

This outbound-only model is critical. No inbound firewall rules are opened at the router site. The device simply dials out, regardless of whether it is on a private IP SIM, a dynamic IP SIM, a roaming SIM or an eSIM. The type of SIM does not matter.

Teltonika RUT / RUTX / TRB Robustel R-series Any WireGuard client Any OpenVPN client
Encrypted outbound tunnel - WireGuard or OpenVPN
🔒

Layer 2

The IoTinix Control Layer

When the tunnel is established, the IoTinix platform authenticates the device against your account, assigns it a unique identity and registers it in your device inventory. Access policies from your configuration are applied immediately - controlling which users can access this device and in what way.

The platform continuously monitors tunnel health, logs all session events and can send alerts for disconnections or unusual activity. Every device sits behind the control layer - isolated from the internet and from other devices in the estate.

✓ Device authentication
✓ Identity registration
✓ Access policy enforcement
✓ Session logging and audit
✓ Tunnel health monitoring
✓ Alerting and notifications
✓ User role management
✓ Session duration limits
Authorised users only - portal authentication required
💻

Layer 3

The User Access Layer

Engineers and authorised users log into the IoTinix web portal with 2FA enabled. They see only the devices assigned to their role. Selecting a device initiates a secure session through the platform - providing access to the router web interface, SSH, and connected LAN devices.

Sessions are logged, duration-limited and automatically terminated when idle. The user never communicates directly with the device from the public internet - all access flows through the IoTinix control layer.

VPN Protocols

OpenVPN vs WireGuard - Which Should You Use?

WireGuard

WireGuard is the recommended protocol for new deployments. It is faster, uses less CPU on edge devices and has a simpler cryptographic design. Teltonika routers running RutOS 7 support WireGuard natively.

✓Faster connection establishment ✓Lower CPU overhead on routers ✓Simpler configuration ✓Better performance on LTE/5G ✓Supported on RutOS 7+

OpenVPN

OpenVPN is the compatibility choice. It works with older Teltonika firmware versions, a wider range of router brands and environments where WireGuard is not yet available. Reliable and battle-tested across millions of deployments.

✓Broadest router compatibility ✓Works with older firmware ✓Established track record ✓TCP and UDP modes ✓Supported across all router brands

Ready to See It in Action?

Get started free or book a demo to see IoTinix configured on a Teltonika router in a live environment.