Optional, not required

One VPN for Every Client Site. Not One Per Site.

Most MSPs end up with a folder of VPN profiles, one per client, each set up by whoever was on site that day. Half of them are shared logins nobody has rotated. ProxyLink issues one WireGuard peer per engineer that reaches every site their role authorises, and revoking it cuts all of them at once.

You may never need it. Browser RDP, VNC and SSH work with nothing installed on the engineer's machine. This is for the moments a browser tab is not enough: your own Winbox, your own SQL client, your own scanner, pointed straight at the device.

Why One Per Site Stops Working

The per site VPN is fine at three clients. It is a liability at thirty.

Offboarding is a checklist you will not finish

An engineer leaves and someone has to remember all thirty firewalls. The ones that get missed are the ones nobody logged into recently, which are also the ones nobody is watching.

Every profile is a different day's decision

Different protocol, different subnet, different split tunnel setting, different person's idea of a good config. There is no single place that tells you who can currently reach what.

Client LANs collide

Two clients both on 192.168.1.0/24 cannot be connected at once. Everyone has hit this, and everyone's workaround is to disconnect one client to reach the other.

Full LAN access, or nothing

A site VPN usually drops you onto the whole network. A junior sent to fix one printer gets the domain controller too, and the audit trail is a connection log, not a session.

How It Works

One peer per engineer device. Reach is derived from their role, live.

1

Issue a peer to a team member

From your team page, issue a WireGuard config to an engineer, with an optional expiry date. One per device, so a laptop and a phone are two peers you can revoke separately. The private key is generated when you press the button, shown to you once, and never stored by us.

2

Their role decides what it reaches

An owner or manager reaches every site. An engineer reaches the client groups they are assigned to. An employee reaches only what is assigned to them, which is a whole site if that assignment is a gateway. Reassign them in the dashboard and the VPN follows within minutes, with no config to reissue and nothing to touch on any client firewall.

3

Connect and work normally

Bring up the tunnel and use your own tools against the device: Winbox, an SSH client, a database client, a browser, a port scanner. Each device has a stable address that does not move when a client renumbers their LAN, or you can use a name like site-pbx.internal.

Address or Name, Your Choice

Every device you have added to ProxyLink can be given a name that resolves only inside your VPN, answered by ProxyLink's resolver and by nothing else on the internet.

engineer laptop, tunnel up
$ ssh [email protected]
$ curl -k https://site-nvr.internal/
$ nmap -sn 10.128.4.0/24
Names are yours to choose per device. Two clients on the same 192.168.1.0/24 get different addresses here, so you can be connected to both at once.

What the Peer Can and Cannot Do

A VPN that reaches every client is only a good idea if it is tightly bounded. These are the bounds.

Reach is per engineer, not per team

The rules are bound to that one peer's address. Another peer on the same team, or a deployed device that gets compromised, gains nothing from it.

Devices cannot call back

Return traffic is allowed only on connections the engineer opened. A client's device cannot start a connection to an engineer's laptop.

Never another tenant

Peers belonging to different accounts cannot see each other at all. Traffic between them is dropped at the server, not filtered by an application check.

Revoke means revoke

Deleting the peer removes it from the server and tears down its reach. Every client site goes at once, with nothing to remember and no client firewall to log into.

Worth Knowing Before You Choose It

Things you would find out in week two anyway.

The browser path is still the better default

Browser sessions are the ones that get recorded and logged for your audit trail. A VPN session is your own tooling talking to a device, so ProxyLink can show that the tunnel was up, not what you did through it. Use the VPN for the work a browser cannot do, not as the everyday route.

The config is generated on our server and shown once

We generate the key pair when you issue the peer, hand you the config, and keep only the public key and the preshared key. We cannot show it to you again. If an engineer loses it, revoke the peer and issue another one, which is what you would want to happen anyway.

The unit you hand out is a site, not a device

A peer authorised for a client's gateway reaches every address on that site's LAN and VLANs, whether or not you added it to ProxyLink as a service. That is usually the point, because your own scanner and your own Winbox have to work. But it means you cannot use a peer to limit someone to one printer. If that is what you need, give them the browser session instead, which is per service and is the one that gets recorded.

It is a team feature

Peers are issued to members of a team, so it belongs to the MSP tier alongside client groups and the audit log. It is included, and during early access every tier is unlocked.

One Peer Per Engineer. Every Client Site.

Free during early access. No credit card. Full MSP feature set.

Get free access →