Remote Gateway Security

Good Morning all... I have read the available posts, documentation, and University videos on remote gateways, but I am still struggling with Security. In my case I have a core Ignition server and I setup via gateway network an incoming connection from an Edge Panel. I have some tags on that Edge panel I need to read from, but I also want to write to a tag from the core server. I am very confused about which of the gateways are supposed to have the security zone defined (edge or core). I am able to consume/read the tags from the Edge Panel on my core ignition server but I cannot write to any of the tags. Does it matter if the connection is incoming vs outgoing from my core server?

The connection direction doesn't matter. You want to write to tags on the Edge gateway, so you want to set the the security zone on the Edge gateway as well. Specifically, the Default Provider Access Level setting under Tag Access needs to be set to ReadWrite.

So the security zone needs to be on both the core gateway and the remote (edge Panel) gateway?

I did finally get it to work... But I am not thrilled about what I did. I setup a new security zone on the EdgePanel Gateway. I called that Security Zone SCADA. I put the IP address of the SCADA server into to Identifier IP address field. I set the Policy on the SCADA security Zone to have read/write access on the Tag Access section. They key was to enable "Trust Remote Security levels". What I dont like is I can write to ALL tags on the EdgePanel from the SCADA server. I would prefer to only give the SCADA access to write to specific tags.

You should also be able to restrict access to individual tags, even with remote tags: https://docs.inductiveautomation.com/docs/8.3/platform/tags/tag-properties/tag-security-properties