← Retour au plan
Nexus One: Mastering Your Sovereign Device · Leçon 7 sur 8

7. Remote Access and Local Login

Enable or disable the secure tunnel for remote access, authorise local login with the six-character code, and understand when each option is appropriate.

Nexus One keeps your data on-premises — only results travel back to the platform. But sometimes you need to reach the device when you are not physically next to it. That is where the two access options come in:

Remote access (secure tunnel) — Opens an encrypted tunnel from the OUPI platform to your device, protected by your OUPI login. It is off by default, meaning no one — not even you — can reach the device remotely until you explicitly enable it. Toggle it per device from the console.

Authorize local login — When someone is physically at the device, it displays a six-character code. From the console you approve (or deny) that code, confirming the person is allowed to log in locally.

These two mechanisms serve different scenarios: remote access is for managing or working with the device from anywhere; local login authorization is for validating that a physical user in front of the device is legitimate.

Why is remote access off by default?

Sovereignty means you control every door into your device. With the tunnel disabled, the device is an island — it processes work dispatched by missions and returns results, but no interactive session can reach it from outside your premises. Enabling the tunnel is a deliberate decision you make per device (or per group), and you can revoke it at any time from the console. Access is always scoped by your OUPI login credentials, anchors, and grants, so even with the tunnel open, only authorized actions are possible.

When to use which option

Enable remote access when you need to check telemetry, manage anchors, review skills, or troubleshoot a device you cannot physically reach — for example a Nexus One at a remote site. Keep it enabled only as long as needed; disable it afterward to minimize your attack surface.

Authorize local login when a colleague or technician is standing in front of the device and needs to interact with it directly. They read the six-character code from the device screen, you confirm it in the console, and they are in. This avoids sharing credentials and gives you an approval step for every physical session.

Astuce

Group devices by location (e.g., "Site A", "Workshop") so you can toggle remote access or review local-login requests for an entire site at once, instead of handling each device individually.

Astuce

After enabling remote access for a maintenance window, remember to disable it when you are done. The default-off posture exists for a reason: fewer open tunnels means a smaller surface to protect.

À vous de jouer

Open My connections and select one of your paired Nexus One devices. In its console, locate the remote-access toggle and enable it, then disable it again. Next, find the "Authorize local login" section and review how the six-character code approval works. Confirm both controls respond as expected.

Suivre ce cours dans OUPI → Cet exercice se fait dans la plateforme OUPI.
À retenir

Your Nexus One is sovereign by design: remote access is off by default, and local login requires your explicit approval via a six-character code. Enable the secure tunnel only when you need to reach a device remotely — it is protected by your OUPI login, scoped by anchors and grants, and revocable at any time. Use local-login authorization to validate physical users without sharing credentials. Group devices to manage these settings at scale.