Network firewall
VPN tunnels
WireGuard and IPSec tunnel configuration for the appliance plane.
Goal
Establish site-to-site or remote VPN tunnels managed by the Network VPN Manager.
Prerequisites
- Routable interfaces and firewall allowances for VPN ports/protocols.
network.write.
Steps
- Open Network → VPN.
- Create a tunnel: choose type (WireGuard or IPSec), names, endpoints, and keys/PSK as required by the form.
- Enable the tunnel only after peer config is ready on both sides.
- Publish; confirm the appliance reports apply success.
- Add routes (L3) or firewall allows for tunnel networks as needed.
Tips
- This is the network appliance VPN (N8 MVP)—distinct from the HTTPS tunnel / ZTNA features under Advanced.
- Rotate keys via controlled republish; avoid leaving disabled tunnels with production keys unused.
- Ensure UDP/ESP paths are allowed on upstream firewalls before debugging ShieldGate.
Verify
- Tunnel listed and enabled under VPN.
- Peer handshake / XFRM or
wgstate healthy on Linux datapath hosts.