Put the contractor into a separate VPN identity or group and apply firewall rules that permit access only to the required device, port and time window. Where practical, place the target equipment in its own VLAN and deny access to router administration and other site networks.
Use named accounts rather than shared passwords, record connection logs and remove access when the task is complete. A jump host or remote-management platform can provide an additional control point. Test the rules from the contractor’s perspective—being able to connect does not prove that unwanted paths are blocked. The exact controls depend on the router and management system, so capability should be confirmed before deployment.
Public Q&A
How can remote access be restricted so a contractor can reach one device without being given access to the whole site network?
Useful next steps
Use this answer as a practical starting point. Current scope, specifications, compatibility, availability, pricing, timing and next steps should be confirmed directly with Comset where they affect a decision.
Related visual examples
A short visual sample connected to this answer or its topic.


