ShieldGate Docs

Network firewall

VPN tunnels

WireGuard and IPSec tunnel configuration for the appliance plane.

Goal

Establish site-to-site or remote VPN tunnels managed by the Network VPN Manager.

Prerequisites

  • Routable interfaces and firewall allowances for VPN ports/protocols.
  • network.write.

Steps

  1. Open Network → VPN.
  2. Create a tunnel: choose type (WireGuard or IPSec), names, endpoints, and keys/PSK as required by the form.
  3. Enable the tunnel only after peer config is ready on both sides.
  4. Publish; confirm the appliance reports apply success.
  5. Add routes (L3) or firewall allows for tunnel networks as needed.

Tips

  • This is the network appliance VPN (N8 MVP)—distinct from the HTTPS tunnel / ZTNA features under Advanced.
  • Rotate keys via controlled republish; avoid leaving disabled tunnels with production keys unused.
  • Ensure UDP/ESP paths are allowed on upstream firewalls before debugging ShieldGate.

Verify

  • Tunnel listed and enabled under VPN.
  • Peer handshake / XFRM or wg state healthy on Linux datapath hosts.