Home / Deploying an Industrial Router with VPN Support in SCADA Networks
#Industry Blog #News · July 13, 2026 · About 11 minutes
views

Deploying an Industrial Router with VPN Support in SCADA Networks

Written By

Tespro

Industrial Router with VPN Support

Supervisory Control and Data Acquisition systems connect control centers with PLCs, RTUs, meters, sensors, and other field equipment distributed across industrial sites. In applications such as water treatment, energy distribution, transportation, and manufacturing, these locations may be separated by long distances and connected through public cellular or IP networks.

Designing secure remote access therefore requires more than installing a communication device. The architecture must control how data enters and leaves the operational technology network, how users access remote assets, and how communications continue during network failures.

An Industrial Router with VPN Support serves as the secure connection point between field devices and the central SCADA environment.

Key Objectives of SCADA Remote Access Architecture

Several primary objectives should be present in a well-designed architecture.

•Confidentiality: Avoid data reading by unauthorized users.

•Integrity: Modifications to commands, alarms, and process values shall be maintained.

•Availability: Help maintain communication by using redundancy and failover where configured..

•Managed access: SCADA assets access shall be limited to authorized systems and users.

The router is an element of this architecture. The architecture's security depends on segmentation, firewalls, policies, authentication, and monitoring and maintaining the network.

Recommended Architecture Layers

Field Device Layer

The field layer may include:

•PLCs and RTUs

•Smart meters and protection relays

•Sensors and actuators

•Local HMIs

•Serial Modbus devices

•Ethernet-based controllers

These devices should normally remain within a dedicated local OT network rather than being exposed directly to the internet.

An Industrial Router with VPN Support can connect Ethernet and serial assets while creating a controlled boundary between the field network and the external WAN.

Remote-Site Security Layer

The remote site routers will need to carry out several different tasks:

• Split the OT LAN from the public or carrier network

•Apply different firewall rules to the traffic going to and coming from the public network.

•Build a secure and encrypted VPN tunnel.

•Restrict remote management.

•Monitor WAN health and terminate or switch the failed link when needed.

•Failover to a different WAN if it becomes necessary.

When applying firewall policies, the principle of least privilege should apply. This means only the necessary IP addresses, ports, and industrial protocols should be opened.

WAN Connectivity Layer

Remote SCADA sites may utilize:

•4G and 5G cellular networks

•Fixed broadband

•Private APN

•Industrial Wi-Fi

•Multiple WAN links

Critical sites may be equipped with dual SIM or multiple WAN router technologies to lessen reliance on a single carrier. The router should keep track of the primary connection and automatically failover (only where the selected router, SIM policy and firmware support it) to a secondary route if the primary path suffers a communications failure.

Central VPN and OT DMZ

VPN tunnels should normally terminate at a central firewall or VPN gateway located in an OT demilitarized zone.

The OT DMZ can contain:

•VPN concentrators

•Jump servers

•Remote-access gateways

•Monitoring platforms

•Patch and update servers

•Log collection systems

This arrangement prevents remote field connections from reaching SCADA servers directly.

SCADA Supervisory Layer

Components of the supervisory layer consist of SCADA servers, historians, engineering workstations, alarm, and operator systems.

Traffic from the OT DMZ to SCADA should be filtered by internal firewalls. Only approved communication paths should be permitted.

Utilizing VPNs for SCADA Communication

An outbound site-to-site VPN tunnel from a remote location to the control center can be accomplished by using an Industrial Router with VPN.

Commonly used VPN technologies include IPsec and OpenVPN. The VPN technology used should meet all of the required policies.

It is a best security practice to ensure the following:

•Each remote site uses its own unique certificates/credentials.

•There are no shared passwords on different remote site routers.

•Non-used VPN services and management ports are disabled.

•Remote access security employs multi-factor authentication and separating machine-to-machine tunnels from engineering tunnels is best practice.

Even with VPN encryption, endpoint compromise remains a risk; endpoint hardening and monitoring are still required.

•Even though a VPN encrypts traffic, intrusion on an endpoint is still a big concern and is a best practice.

Designing for Network Resilience

The design of the architecture should include:

Connection Failover

It can automatically switch to use a different SIM, different carrier, different cellular technology, or a wired connection.

Local Control Continuity

PLCs and RTUs should control the process even if they are disconnected from the central SCADA system.

Data Storage

Process values of significance may be temporarily stored in the PLC, RTU, edge gateway, or local historian, and sent later when the connection is available again.

Communication Alarms

The SCADA platform should generate alarms when:

•A VPN tunnel disconnects

•A remote site becomes unreachable

•Signal strength falls below an acceptable level

•Repeated failovers occur

•Router configuration changes unexpectedly

Managing Serial and Ethernet Equipment

Many SCADA networks contain both modern Ethernet controllers and older serial devices.

An Industrial Router with VPN Support may help consolidate these connections by supporting:

•RS-232 and RS-485 interfaces

•Serial-to-IP communication

•Modbus RTU-to-Modbus TCP conversion

•Local Ethernet switching

•Protocol-aware data transmission

However, protocol conversion should be carefully documented. Engineers should confirm addressing, polling intervals, timeout values, exception handling, and device compatibility before deployment.

How Tespro Supports SCADA Architecture Projects

As a manufacturer of industrial communication equipment, Tespro is able to extend its service to customers beyond router provision.

Application Assessment

Tespro is able to assess:

•Field device interface

•Conditions in the cellular network

Requirements of the VPN

•Required industrial protocols

•Environmental factors

•Redundancy

Selection of Hardware and Tuning

Depending on the application, Tespro has the ability to recommend the appropriate Industrial Router with VPN, the required interface, antenna configuration, and the preferred mode of the network.

Support for Protocols

For systems that contain PLCs, meters, serial devices, and Ethernet devices, Tespro has the ability to plan for communication and protocol conversion.

Support for Deployment

Tespro is able to assist with support for:

•Configuration of VPNs

Dual-SIM failover

•Firewall and routing policies

•Serial port configuration

•Remote access and management

•Installation and commissioning

Support for Modification and Continued Support

Industrial applications may necessitate the development of custom cellular bands, specialized configurations, or custom firmware and interfaces. Working with the manufacturer directly allows the customer to simplify technical coordination and establish a more reliable pathway for large-scale implementation following the completion of testing.

Final Thoughts

A multilayered technique is needed for the design of SCADA systems that ensures the continuation of local control, the redundancy of the wide area network, and the centralization of control in the local area.

The Industrial Router with VPN provides a controlled communication path to field devices, however, it is the design of the system as a whole that will determine how safe the system is.

Tespro is able, through the provision of industrial networking devices and (support for) communication and protocol integration, as well as support for configuration and application, to assist integrators and end users with the development of secure and maintainable SCADA systems for remote access.

FAQs

Q1. How does Dual SIM increase network reliability?

With Dual SIM, the router has the option to utilize another cellular carrier when one route fails.

Q2. Why is VPN protection crucial for SCADA systems?

Because SCADA systems have data and control command packets at risk of exposure over unsecured networks, use of VPN can protect such packets.

Q3. Can industrial routers connect PLCs and RTUs?

Yes. It is possible for industrial routers to connect to the above-mentioned devices, depending on the router's configuration, as well as other devices utilizing Ethernet, RS-232, and RS-485.

Q4. What VPN protection protocols are used?

Most commonly, industrial remote access is protected with protocols such as IPsec and OpenVPN.

Q5. Is it permissible to connect SCADA systems directly to the internet?

It is not advisable to directly expose SCADA systems. Access should be made through the use of a VPN and a firewall within a controlled network zone.

Recent Articles

Request Your OEM/ODM Solution

Share your requirements, and our hardware and software experts will design a solution optimized for accuracy, reliability, and efficiency.