Most MSPs end up with a folder of VPN profiles, one per client, each set up by whoever was on site that day. Half of them are shared logins nobody has rotated. ProxyLink issues one WireGuard peer per engineer that reaches every site their role authorises, and revoking it cuts all of them at once.
You may never need it. Browser RDP, VNC and SSH work with nothing installed on the engineer's machine. This is for the moments a browser tab is not enough: your own Winbox, your own SQL client, your own scanner, pointed straight at the device.
The per site VPN is fine at three clients. It is a liability at thirty.
An engineer leaves and someone has to remember all thirty firewalls. The ones that get missed are the ones nobody logged into recently, which are also the ones nobody is watching.
Different protocol, different subnet, different split tunnel setting, different person's idea of a good config. There is no single place that tells you who can currently reach what.
Two clients both on 192.168.1.0/24 cannot be connected at once. Everyone has hit this, and everyone's workaround is to disconnect one client to reach the other.
A site VPN usually drops you onto the whole network. A junior sent to fix one printer gets the domain controller too, and the audit trail is a connection log, not a session.
One peer per engineer device. Reach is derived from their role, live.
From your team page, issue a WireGuard config to an engineer, with an optional expiry date. One per device, so a laptop and a phone are two peers you can revoke separately. The private key is generated when you press the button, shown to you once, and never stored by us.
An owner or manager reaches every site. An engineer reaches the client groups they are assigned to. An employee reaches only what is assigned to them, which is a whole site if that assignment is a gateway. Reassign them in the dashboard and the VPN follows within minutes, with no config to reissue and nothing to touch on any client firewall.
Bring up the tunnel and use your own tools against the device: Winbox, an SSH client, a database client, a browser, a port scanner. Each device has a stable address that does not move when a client renumbers their LAN, or you can use a name like site-pbx.internal.
Every device you have added to ProxyLink can be given a name that resolves only inside your VPN, answered by ProxyLink's resolver and by nothing else on the internet.
A VPN that reaches every client is only a good idea if it is tightly bounded. These are the bounds.
The rules are bound to that one peer's address. Another peer on the same team, or a deployed device that gets compromised, gains nothing from it.
Return traffic is allowed only on connections the engineer opened. A client's device cannot start a connection to an engineer's laptop.
Peers belonging to different accounts cannot see each other at all. Traffic between them is dropped at the server, not filtered by an application check.
Deleting the peer removes it from the server and tears down its reach. Every client site goes at once, with nothing to remember and no client firewall to log into.
Things you would find out in week two anyway.
Browser sessions are the ones that get recorded and logged for your audit trail. A VPN session is your own tooling talking to a device, so ProxyLink can show that the tunnel was up, not what you did through it. Use the VPN for the work a browser cannot do, not as the everyday route.
We generate the key pair when you issue the peer, hand you the config, and keep only the public key and the preshared key. We cannot show it to you again. If an engineer loses it, revoke the peer and issue another one, which is what you would want to happen anyway.
A peer authorised for a client's gateway reaches every address on that site's LAN and VLANs, whether or not you added it to ProxyLink as a service. That is usually the point, because your own scanner and your own Winbox have to work. But it means you cannot use a peer to limit someone to one printer. If that is what you need, give them the browser session instead, which is per service and is the one that gets recorded.
Peers are issued to members of a team, so it belongs to the MSP tier alongside client groups and the audit log. It is included, and during early access every tier is unlocked.
Free during early access. No credit card. Full MSP feature set.
Get free access →