well, you have two options
1. You give out IP addresses of all the IPT equipments to the remote support engineer, who can access your equipment from anywhere. A bit risky! bearing in mind there are many IPT devices e.g. EM, Teleworker Server, 3300 switch
2. You setup MAP, define all your IPT equipment in there, Remote engineer VPNs to the MAP and gets secure access to your equipment. This way engineer cannot hit your network.
If you are a big organisation, then you should go for option 2.
hope it makes sense.
Ad