Remote access and data logging for machine builders

Last updated on 25 September 2026

Author: · LinkedIn

Your machine is at the customer’s site, while the expertise is with your service team. A ServiceGate provides access to the agreed controller for remote diagnostics and collects machine data for monitoring. Here is how Siemens, Beckhoff and Omron may fit into that setup.

Machine building & management

Access

Reach only the agreed controller.

Data

Read selected measurements.

Configuration

Validate the integration before use.

Remote Engineer · Knowledge base

How do you troubleshoot a machine remotely?

When a fault occurs, you need to know whether the controller is running, which fault is active and what happened beforehand. Remote access lets you investigate with the appropriate software. Data logging adds a timeline of operating state, cycle count or temperature. The controller must expose those values: a router cannot create missing sensor data.

Brands, controllers and protocols

Siemens SIMATIC S7: configure service and data separately

For Siemens S7, align the VPN route and permissions with the engineering software. For measurements, assess a suitable S7/Step7 connection or OPC UA. Siemens specifies a runtime licence for the S7-1200 OPC UA server. Check the CPU, firmware, licence and exposed variables before choosing this approach.

Beckhoff TwinCAT: account for ADS routes

With TwinCAT, the ADS route matters as well as IP reachability. Beckhoff explains how variables are exposed through an OPC UA server and how ADS routes are configured. This allows service access and data collection to be separated. The TwinCAT version, server configuration and certificates determine the details.

Omron NX102: OPC UA as a data interface

Omron documents an OPC UA server interface for the NX102. This is a possible entry point for agreed production and status data, not a guarantee for every Omron model. EtherCAT inside the machine serves a different purpose from the connection used for measurements or engineering access.

Connecting an industrial router for remote machine access

Connect the ServiceGate LAN side to the agreed machine network. Specify which controllers and services may be reached and check the return route. Then test one diagnostic connection and a small set of readable data points. Validate counters and timestamps against the local machine display. Broadcast-based discovery does not automatically work across a routed VPN; use a fixed destination address where supported.

For multiple customer sites, assign each router to the correct location in the portal and grant your service team only the agreed access. Record whether each installation uses the customer’s network or a suitable cellular connection for internet access. Templates help reuse settings, but do not replace checking the local network, firewall policy and customer authorisation.

From a connection to useful insight

Example setup, not a customer case: after an alarm, a service team examines the machine over VPN and compares the fault with logged temperatures. This helps assess whether a site visit is necessary and how to prepare. Machine safety functions and fast control loops remain local; an internet connection is not a substitute.

Remote access and data logging, with clear boundaries

All ServiceGate routers support remote access and data logging/monitoring. The actual integration depends on model, firmware, interface and configuration. With VPN, your computer connects to the authorised location; configured VNC, RDP, HTTP or HTTPS services provide another access route through the portal. For logging, configure the protocol, data points and destination. The router receives that configuration and forwards data to the relevant service. Then configure dashboards, alarms and events. A named brand is a technical example, not a statement of certification, partnership or support for every model.

Permissions and traceable connections

Assign routers to locations and grant users or groups only the permissions they need. The portal shows who connected to which location. This records connections, not automatically every action inside the machine. For audit purposes, also define retention periods and any additional log sources. Agree a firewall profile for each customer or location, such as deny by default with explicit exceptions. Segmentation does not replace controller and machine security updates.

What do we need to assess your integration?

  • Brand, exact model, firmware and installed software licences.
  • Network diagram, IP addresses, interfaces and the owner’s approval.
  • Required service tasks and the people who may access the installation.
  • Measurements with register or object lists, units and collection intervals.
  • Requirements for alarms, retention and any on-site logging during connection loss.

Remote Engineer has worked on remote access and controller solutions since 2008. Share your documentation and application with our team. We assess what is standard and where configuration or custom development is needed. Contact us for pricing and a suitable proposal.

Continue with your application

Sources and scope

Manufacturer documentation consulted on 22 September 2026. The examples describe possible architectures, not completed integration tests or customer results. Always check the exact model’s documentation before implementation. Trademarks belong to their respective owners.

In this article

Get more out of your
machine data

Remote Portal dashboard for PLC data monitoring

Try for 30 days FREE!