Designing a Secure Remote Access Solution for On-Prem IoT Devices using AWS Services
- Last Updated: December 24, 2025
eInfochips
- Last Updated: December 24, 2025



Enterprises deploying IoT devices in restricted on-premises environments often need to remotely access device services such as HTTP dashboards or SSH terminals. Since these devices reside inside private networks with no inbound internet access, a secure tunneling mechanism is needed.
In this blog, we will explore a real-world scenario and two AWS-native approaches to it:
The goal is to access Device A's HTTP service from the Cloud without opening firewall ports or VPNs.
| Feature | IoT Secure Tunneling (Localproxy) | SSM Port Forwarding (Gateway) |
|---|---|---|
| Service Access | Any TCP (HTTP/SSH) via localproxy | Any TCP (HTTP/SSH) via SSM CLI |
| Setup Complexity | Medium (Greengrass + IoT Core + localproxy) | Low (just SSM Agent) |
| Device-level Access | Yes | Indirect (via Gateway) |
| Security | TLS, IAM, tunnel tokens, outbound-only | IAM, SSM session policies |
| Best Fit | IoT fleets needing per-device tunnels | Hybrid/on-prem quick troubleshooting |
In this scenario, Device A’s HTTP dashboard is securely accessed by the Cloud operator in two different ways:
Both approaches avoid inbound firewall changes and provide auditable, secure, and temporary remote access to on-prem IoT services.
Alpesh Bhavsar is a Senior Technical Architect with over 18 years of progressive experience in DevOps implementation, cloud architecture, and IT infrastructure management. He has successfully led the design and delivery of secure, scalable, and universally available cloud solutions for both SMBs and large enterprises. Alpesh specializes in architecture design, cost and effort estimation, cloud migration planning, and DevOps culture enablement across organizations.
The Most Comprehensive IoT Newsletter for Enterprises
Showcasing the highest-quality content, resources, news, and insights from the world of the Internet of Things. Subscribe to remain informed and up-to-date.
New Podcast Episode

Related Articles