Remote access to a PLC network without opening a port
One outbound Cloudflare Tunnel from an edge PC does two jobs: login-gated HMIs any browser can open, and private engineering access to the PLC subnet that only enrolled laptops can reach.
Remote access to a PLC network usually means a VPN appliance, a port forward, or a vendor’s cloud box. This setup uses none of them. A small dual-homed edge PC runs cloudflared, which makes an outbound-only connection to Cloudflare. No inbound firewall rule exists anywhere.
That one tunnel handles two different needs, in two different ways:
| Need | How it’s handled |
|---|---|
| Viewing: check an HMI from a phone or any browser, with nothing to install | A public hostname, gated by Cloudflare Access (an email one-time PIN or company SSO) |
| Engineering: CODESYS, SSH, switch web pages, Modbus by IP | A private network route, reachable only from devices enrolled in the Zero Trust org and running the Cloudflare One client |
The PLCs never get a public hostname. The difference matters: an HMI behind a login is fine to reach from anywhere, but a network where one wrong click changes a live process shouldn’t be reachable by knowing a URL at all.
The edge PC
This can be any small PC with one network card on the office network, for internet access, and one on the PLC network. Here it’s a WAGO Edge PC (752-9400) running Ignition Edge and a Node.js dashboard, with one Ethernet port on each network. It doesn’t have to be special hardware, though. An industrial PC, a PLC running an edge gateway app, or a Raspberry Pi would all work. The edge PC’s own routing table does the work of reaching the PLC subnet. Cloudflare only carries the packets to it.
1. Public hostnames for the HMIs
tunnel: <tunnel-name>
credentials-file: /root/.cloudflared/<tunnel-id>.json
ingress:
- hostname: hmi.example.com
service: http://localhost:8088 # Ignition gateway + Perspective
- hostname: status.example.com
service: http://localhost:3000 # Node.js dashboard
- service: http_status:404 # catch-all, must stay last
Then add one Cloudflare Access self-hosted application per hostname: an Allow policy listing the right email addresses, one-time PIN login, and a 24-hour session. Requests are authenticated at Cloudflare’s edge before a single packet reaches the edge PC. Nothing in the tunnel config changes.
2. Private routes for engineering
cloudflared tunnel route ip add <plc-subnet>/24 <tunnel-name>
cloudflared tunnel route ip add <edge-pc-ip>/32 <tunnel-name> # SSH to the edge PC itself
Route the whole PLC subnet, so devices added later are reachable without any extra configuration. For anything on the office network, route only a narrow /32: the edge PC itself, or one specific device. Never route the whole office LAN.
Then in the Zero Trust dashboard:
- Add a device enrollment policy that decides who may enroll a laptop.
- Set the device profile → Split Tunnels to Include mode, listing exactly the routes you registered.
- On each laptop, install the Cloudflare One client, join the team and log in. The PLC network then behaves as if the laptop were plugged in on site.
Gotchas
- A private route has to be configured in two places: registered on the tunnel and covered by Split Tunnels. The default profile excludes all of
192.168.0.0/16, so a freshly added route silently goes nowhere. - The catch-all ingress rule must be last. If anything follows it,
cloudflaredrefuses to start, and every hostname on the tunnel goes down at once. - For a second DNS zone, add the tunnel CNAME by hand (proxied, pointing at
<tunnel-id>.cfargotunnel.com).cloudflared tunnel route dnscan quietly file the record under the zone its certificate was issued for. - Broadcast discovery doesn’t cross the tunnel. The CODESYS gateway scan and e!COCKPIT’s network scan find nothing. Connect by IP instead.
- Cloudflare One and Tailscale can coexist on one laptop, but Cloudflare One takes over DNS, and its
100.96.xaddress sits inside Tailscale’s CGNAT range. Expect some head-scratching. - Use SSH keys on the edge PC, especially once its
/32route makes it reachable from off site.
What it costs
A domain on Cloudflare DNS and a Cloudflare Zero Trust account. The free tier covers a handful of users and devices. You don’t need a static public IP, port forwarding, or a VPN server to maintain.