Beckhoff TwinCAT remote access through a ServiceGate
Last updated on 25 September 2026
Reaching a Beckhoff controller over VPN is the first step. Working with TwinCAT also requires the correct ADS configuration and permissions on the target system. Check each layer separately.
Remote Engineer · Knowledge base · 22 September 2026
Beckhoff remote access: configure network access and TwinCAT separately
The ServiceGate provides access to the agreed machine segment. The Remote Portal controls which users or groups may connect to that location. TwinCAT adds its own communication configuration between the engineering environment and the runtime on the controller or industrial PC.
Beckhoff distinguishes the IP address from the AMS Net ID. The IP address is the network destination; the AMS Net ID identifies the TwinCAT system. Check both before adding a route. Permission to reach a location does not replace permissions in Windows, the controller or the TwinCAT project.
What should you record first?
- Exact Beckhoff model, operating system, TwinCAT version and build number.
- Target IP address, subnet and AMS Net ID, plus the engineering computer's network details.
- A matching project copy, licences, recovery procedure and an authorised contact at the machine.
- The agreed task: diagnostics, engineering, operation or read-only data collection.
TwinCAT cannot find the controller over VPN: check the ADS route
Establish the authorised VPN connection and check the network route to the target. Then add the appropriate ADS route following Beckhoff's instructions. Also assess the route from the target back to the engineering environment; the required setup depends on the ADS variant selected.
Beckhoff's Broadcast Search operates within the current subnet. Across a routed VPN, a system may therefore be missing from the search list even though its IP address is reachable. Use the known target address where appropriate. Adding a route requires suitable target-system privileges; do not publish these credentials in a shared project document.
Secure ADS and firewall policy
Check that both TwinCAT systems support the intended Secure ADS configuration. Beckhoff documents options including certificates and pre-shared keys. Choose an arrangement that fits your management policy and assign responsibility for renewal. A VPN and Secure ADS protect different parts of the connection; one does not automatically replace the other.
Restrict firewall traffic to the required sources, destinations and services. Do not leave security disabled as a workaround. When troubleshooting, check the IP route, AMS identity, ADS route, certificate trust and system permissions separately.
Read Beckhoff machine data for data logging and monitoring
For operating hours, temperatures or status values, plan a separate data connection alongside remote access. A suitable TwinCAT OPC UA server can expose selected variables. Check the server feature, licence and symbol configuration for the actual installation.
All ServiceGate routers support data logging and monitoring. We match the OPC UA configuration to the server, security settings and required measurements. A working ADS route does not mean the ServiceGate can automatically log every TwinCAT variable. Dashboards and alarms use the selected data.
Example architecture and acceptance checks
Consider a machine builder investigating a stoppage and then tracking the associated status value. The engineer uses TwinCAT for authorised diagnostics; a separately configured data channel provides the trend. This is an illustrative architecture, not a report of a completed customer test.
Test diagnostics, data quality and access revocation separately. Keep time-critical control and EtherCAT traffic local; an internet VPN is not a replacement for the local real-time network. Programming changes still require a maintenance window, backup and local safety arrangements.
Secure access also needs ongoing management
A separate machine segment and appropriate permissions restrict reachability. They do not replace security updates for the router, controller and machine software. Agree firewall rules, permitted actions and local safety procedures with the owner.
Sources and scope
Based on the technical documentation below, consulted on 22 September 2026, and the described Remote Engineer functionality. Manufacturer documentation supports protocol behaviour and requirements, not certification of the ServiceGate integration. Examples are illustrative; confirm model compatibility and settings for your installation.
Continue in the knowledge base
Need remote access, data logging or a custom integration? Share your application with our team. We provide pricing in a proposal tailored to your needs.
In this article


