Remote corporate network management: how it works

Remote management of the company network means you don't have to be on site to see what's happening there. This article explains the difference between a cloud panel and a VPN connection, what can and cannot be seen remotely, who should have such permissions and why it is the foundation of multi-location support.
Why remotely manage a company network at all?
The answer "not to drive" is true, but incomplete, because remote management changes something more important than logistics.
Without it, the only source of information about the network condition is a report from the user: someone calls to say it is not working, and only then does the search begin, carried out after the fact, based on someone else's report, and often after the problem has resolved itself.
Remote access reverses this order. You can see that the access point has rebooted five times during the night before anyone reports being out of service in the morning, and you can see that the port is running at a slower speed than it should, although no one has noticed it yet.
This is the difference between reacting and maintaining, and it determines whether constant network maintenance makes sense at all.
Two ways: cloud panel and VPN
Remote access is achieved in two ways that solve slightly different problems.
Cloud panel
Devices in the company's network connect to the manufacturer's panel and this panel becomes the place from which they are managed. Zyxel runs this in the cloud model via Nebula Control Centre, other manufacturers have their own equivalents.
The advantage is that you don't have to open anything at the edge of the network, because the devices themselves establish the connection, going outside. Access works from a browser, many locations can be seen in one place, and the event history saved outside the facility will survive a failure on site.
The limitation remains the dependence on the availability of the manufacturer's service and the connection, and the scope of functions is sometimes related to the licence plan. For some companies, a separate question is that network data passes through the manufacturer's infrastructure.
It's worth knowing one thing about the licensing model, because it is sometimes simplified in sales talks. Basic plan Base Pack is free and includes, among others, touchless implementation, facility panel, firmware management within the facility, alerts and diagnostic tools, but it has operational limitations that are easy to forget: log retention is one day, and the number of organisation administrators was limited to five. Plus and Pro plans extend retention to seven days and a year, respectively, and increase limits, but are licensed per device and require all devices in your organisation to have the same licence type.
The one-day retention of logs has a specific practical consequence: an incident reported on Monday morning and occurring on Friday evening will no longer leave any trace.
VPN
The company sets up its own encrypted tunnel to its network, and the authorized person connects to it and works as if he were on site.
The advantage is full control, because nothing goes through the manufacturer's infrastructure, the solution works regardless of whether the devices have cloud support, and gives access not only to the network, but also to other company resources.
The disadvantage is that you need to configure and maintain this mechanism and have an edge device that supports it. You should also remember that if a link or the very edge of the network goes down, the VPN stops working together with them, so it will not help in diagnosing this failure.
What not to do
There is a third path that is worth ruling out right away: exposing the device management panel directly to the Internet via port forwarding.
This solution is used because it is the simplest, and at the same time it is the worst possible, because the administration panel then becomes available to anyone who reaches this address and port, and the Internet is scanned for such panels in an automated and continuous manner.
If someone proposes this as a means of remote access, it is worth treating it as a warning signal about the rest of the offer.
What can actually be seen remotely
Remote access is not all-seeing and it is worth knowing where its limits are.
You can see the status of the devices, i.e. whether they are working, whether they have restarted and what software version they have, as well as the status of the ports: whether there is a link, what speed they are working at and whether errors are increasing on them. You can see clients in the network along with the traffic they generate, radio conditions from the perspective of access points, events and alerts depending on log retention, and power budget consumption on the switch.
However, it is not visible whether the cable is physically damaged, apart from what can be deduced from the symptoms on the port, or what is happening in the room: whether someone moved the access point or whether new shelves blocked the signal. The quality of the connection is also not visible from the perspective of the user's device standing in a specific place.
Devices that are not part of the managed platform need to be listed separately, as this is the most common source of illusion. The panel only shows what belongs to it, so an old unmanaged switch, once plugged in in a cabinet and forgotten, remains invisible to it, but may also be the cause of the problem.
Who should have access
Remote administrative access is the highest privilege on the network, so it's worth following a few rules.
Accounts should be there registered, and not common, because without it it is impossible to determine who changed what. Any account with administrative privileges should be protected multi-factor authentication. It's also worth separating permission levels, because not everyone needs full administration, and the preview without the right to change is enough in many situations.
The most important rule concerns ownership: is the company that owns the organisation in the paneland the supplier has an account there, not the other way around. In addition, there is an account review for each change, including the employee's departure and termination of cooperation with the contractor, and a change log, if the licensing plan provides for it.
The ownership principle determines what happens when a supplier is changed, because if the organisation in the panel belongs to the contractor, the company does not get the network back, it only asks for it. We develop this in the article about changing the IT company and taking over the administration.
Many locations are changing the bill
Remote management is convenient for one office, but for a third facility it is no longer convenient.
Without a common panel, each location is a separate island with its own configuration, its own passwords and its own history, so making the same change in five objects means five times the same work and five opportunities for mistakes.
Manufacturers respond to this with functions that operate above a single object. Zyxel provides a separate licence in Nebula Control Centre MSP Pack, assigned to the administrator account and including management between organisations, designed specifically for situations where one team maintains multi-client or multi-company environments, and is used in conjunction with organisational licences.
For a company with multiple sites, it's also important that the Pro plan includes configuration management across the organisation, with sync, replication, and templates, which is the difference between "let's set up a fifth site" and "let's apply a template."
When it's not a priority
Not every company needs it right away, so let's be honest when you can put it aside: when it comes to one small office without critical systems, where no one reports problems, when someone on site is able and willing to deal with it, or when the budget is limited and backups or computer protection are more urgent.
In such a situation, it is worth planning remote management during the next hardware replacement, instead of making it a separate project, so it does not become an additional cost, but a criterion for selecting devices.
A panel without an observer is of no use
This is the most important sentence of this article.
Remote management itself doesn't fix anything because it only shows the condition, and someone has to look at the condition, understand what they see, and respond before the symptom reaches users.
Companies buy manageable equipment, configure the panel, and then after three months no one looks at it, and alerts arrive in an inbox that no one reads. The network is then formally managed, although it is not actually managed.
Therefore, the question "who will look at it" is worth asking before the purchase, not after it.
With us, this is exactly the mechanism thanks to which remote service throughout Poland becomes possible: we monitor the status of devices and connections, respond to alerts, carry out updates in agreed service windows and introduce configuration changes without an on-site visit, and the scope and response times are recorded in the contract. How we divide remote work from demanding presence is described in the article about remote and on-site IT support.
In corporate networks, we are a Zyxel Networks Partner and we also implement Ubiquiti UniFi.
The scope of permanent service is described on the website IT care, and implementations and modernisations on the website corporate networks.
Book a free IT review: In an hour online we will discuss how your network is managed today and what you do not see in it.