← All articles
Broker — connectivity

SSH and point-to-point device access

A common use case for Broker is remote SSH access to individual infrastructure devices — switches, routers, IoT controllers, industrial equipment — without giving the connecting user or vendor a foothold on the broader network. This article explains how that differs from a traditional VPN and how to think about it operationally.

The VPN problem

A traditional VPN puts a remote user (or vendor, or contractor) onto a network segment. Even with careful subnetting and firewall rules, that segment usually contains more than the one device the person actually needs to reach — and every device on that segment becomes a device the remote party could potentially discover, scan, or pivot toward, whether or not that was ever the intent. This is especially risky for OT and IoT environments, where devices like switches, PLCs, and building-management controllers were often never designed with the assumption that they'd be reachable from an untrusted network segment at all.

The point-to-point alternative

Broker takes a different approach: point-to-point SSH directly to one device, brokered by certificate identity rather than network location. When access is granted (see Granting and revoking access), the Receiver plane terminates a session that connects the requesting identity to exactly that one destination — the rest of the network, including every other device that would normally be reachable on a shared segment, is simply not part of the path. There's no lateral movement to prevent, because there's no lateral network to move through in the first place.

Practical use cases

  • Vendor maintenance windows — a third-party vendor gets SSH to the one switch or controller they're servicing, for exactly the duration of the grant, without a standing VPN credential that outlives the maintenance window.
  • Remote OT/IoT administration — plant or facilities staff reach individual PLCs, HVAC controllers, or building-management systems without those devices being exposed to the general corporate network.
  • Branch and field equipment — devices distributed across many physical sites (ATMs, retail POS controllers, remote sensors) get administered without backhauling traffic through a central VPN concentrator.

What you'll see on the device side

From the target device's perspective, an inbound SSH connection through Broker looks like a normal SSH session — Broker doesn't require special client software on most standard devices. The identity and access control happen on Blacksands' side of the connection, at the Authorizer and Receiver planes described in Understanding the admin console, so device-side configuration stays minimal.