Secure Remote Access in Three Layers
IoTinix replaces exposed public IP access with a secure outbound VPN model. Routers connect outward. Users access devices through a controlled platform layer. Nothing is exposed by default.
Summary
IoTinix is a VPN-first IoT remote access platform. Routers establish outbound encrypted tunnels using OpenVPN or WireGuard to a central control server. The platform authenticates devices, assigns identities and enforces access policies. Authorised users access devices through the portal - never directly from the public internet. No fixed public IP SIM is required. No inbound ports are opened at any site.
Three Layers. One Control Point.
Layer 1
The Device Layer - Your Router
Your industrial cellular router - for example a Teltonika RUT955, RUTX11 or TRB series gateway - is configured with a VPN client profile downloaded from the IoTinix portal. On startup, the router initiates an outbound encrypted tunnel to the IoTinix control server using either OpenVPN or WireGuard.
This outbound-only model is critical. No inbound firewall rules are opened at the router site. The device simply dials out, regardless of whether it is on a private IP SIM, a dynamic IP SIM, a roaming SIM or an eSIM. The type of SIM does not matter.
Layer 2
The IoTinix Control Layer
When the tunnel is established, the IoTinix platform authenticates the device against your account, assigns it a unique identity and registers it in your device inventory. Access policies from your configuration are applied immediately - controlling which users can access this device and in what way.
The platform continuously monitors tunnel health, logs all session events and can send alerts for disconnections or unusual activity. Every device sits behind the control layer - isolated from the internet and from other devices in the estate.
Layer 3
The User Access Layer
Engineers and authorised users log into the IoTinix web portal with 2FA enabled. They see only the devices assigned to their role. Selecting a device initiates a secure session through the platform - providing access to the router web interface, SSH, and connected LAN devices.
Sessions are logged, duration-limited and automatically terminated when idle. The user never communicates directly with the device from the public internet - all access flows through the IoTinix control layer.
OpenVPN vs WireGuard - Which Should You Use?
WireGuard
WireGuard is the recommended protocol for new deployments. It is faster, uses less CPU on edge devices and has a simpler cryptographic design. Teltonika routers running RutOS 7 support WireGuard natively.
OpenVPN
OpenVPN is the compatibility choice. It works with older Teltonika firmware versions, a wider range of router brands and environments where WireGuard is not yet available. Reliable and battle-tested across millions of deployments.
Ready to See It in Action?
Get started free or book a demo to see IoTinix configured on a Teltonika router in a live environment.