V VPNAdminPrivate network access

VPN Admin help

Approve devices, manage their access, and publish installers for this portal's network.

Revocation, reinstalling, and deleting are different.

Keeping a device revoked blocks that enrolled identity and its certificates. It cannot obtain a replacement certificate or connect to the managed VPN. Removing a certificate does not bypass revocation.

Revoke also blocks the hardware identifiers reported by agents 1.2.5 and later. An ordinary uninstall/reinstall remains blocked and creates no new pending entry. No TPM is required. Firmware UUID and available system/motherboard serials are hashed; sufficiently privileged users can spoof reported identifiers, but any different device identity still requires your approval. Update existing agents before relying on hardware blocking.

Delete record clears the hardware block and removes revoked entries for that hardware, while leaving all old certificates revoked. A still-installed agent version 1.2.4 or later requests approval again without reinstalling. An uninstalled agent stays absent unless deployment or repair installs it again.

Devices and Revoked
Pending
The agent has requested enrollment. It has no usable site-issued VPN certificate until you approve it.
Approve
Match the approval code shown on the actual PC. Approval issues a client certificate and permits the managed connection, subject to the domain restriction.
Approved
The device is allowed to obtain and renew its certificate. This is permission, not proof that it is currently online.
End session
Asks the firewall to disconnect the current VPN session. An approved agent with automatic connection enabled can reconnect. Use Revoke to block access.
Revoke
Blocks certificate renewal/replacement, publishes certificate revocations to the firewall, and requests session termination. The agent can continue contacting the portal while its VPN is blocked.
Retry enforcement
Retries publishing the firewall revocation list and ending the session. This button is available on revoked records; its presence alone does not mean enforcement failed. An already disconnected client may have no session left to terminate.
Deny pending device
Uses the same revocation and hardware blacklist as Revoke. Moves the request to Revoked and blocks subsequent requests from matching hardware. Delete record clears the block; fresh approval is still required.
Delete record
Available for revoked devices. Removes the entry and permits a running updated agent to request a fresh approval. It does not uninstall software or make an old certificate valid again.
Revoked tab
Shows revoked records separately. Pending and approved records remain on Devices.
Refresh
Reloads device information. The dashboard also refreshes automatically about every five seconds.
VPN status and last contact
VPN state and IP are the agent's last report. More than five minutes without a check-in shows Offline and retains that last report. Offline can mean sleep, shutdown, or a network problem. It does not revoke approval, and a historical IP does not prove an active address allocation.
Agent version
Reported by updated agents. A blank version can mean an older agent that does not report it yet.
Domain restriction and hidden devices

Enable Device domain restriction and enter the permitted Windows AD DNS domain. Matching ignores capitalization. The agent reports Windows' local domain-join state; this is a reported check, not cryptographic proof of domain membership.

New ineligible devices are rejected before enrollment, receive no client certificate, and do not appear in the approval queue or device tabs. Previously enrolled devices that become ineligible are hidden, lose approval, and have their certificates revoked. When eligible again, they require approval.

Deploy agents 1.2.0 or later before enabling this on an existing installation. The check requires no separate AD-issued PC certificate; approved clients use the certificate issued by this portal.

Installers, automatic updates, and RMM repair
Download current MSI
Downloads the latest successfully published installer for this portal. Each package contains its own linked portal address.
Rebuild installer
Builds, signs, verifies, and publishes the agent code currently on the server. New code must be deployed to the portal first. Rebuilding unchanged code keeps the same version; agents automatically install only newer versions.
Build progress
Shows actual build steps and elapsed time. Rebuild is disabled while a build runs. The panel disappears one minute after completion. Download ready installer opens the newly published MSI. A failed build does not intentionally replace the last working download.
Automatic agent upgrades
Agents 1.2.1 and later check their linked portal about hourly and install newer signed releases without the client administrator password. Enrollment and the saved connection pause are retained. The VPN may briefly disconnect during installation. Signing-publisher changes require an administrator-deployed update.
RMM repair and upgrade script
Download it from the relevant portal and run as SYSTEM in 64-bit PowerShell. It installs missing agents, repairs incomplete installations, restores disabled/stopped guardian services, and upgrades older versions. It can run every five minutes; healthy clients check for updates at most hourly. Use -CheckForUpdates for an immediate check and allow enough execution time for downloading/installing.
Certificate repair
The guardian restores an approved certificate using its retained enrollment identity and local key. A deleted key may require a replacement certificate from the portal. Revoked or domain-ineligible devices do not regain VPN access through repair.
GPO deployment
Deploy newer MSIs as upgrades to the existing package. Replace old assigned packages when rolling out a newer release.
Client controls, passwords, and retiring a PC
Change client administrator password
Changes the password used to unlock administration on Windows agents. It is separate from the website login. Online clients receive the policy update; no MSI rebuild is needed.
Automatic connection
Maintains the managed VPN whenever available. When paused by an administrator, it stays paused until explicitly restored. Repair and upgrades preserve that pause.
Restore domain connection
A connect-only recovery control: restores automatic connection when paused. It does not grant permission to disable the managed VPN.
Personal connections
Approved users can import and manage their own profiles without modifying the managed VPN. Connect, Disconnect, and Remove apply to the selected personal profile.
Unlock administration / Log out
The client administrator password unlocks protected controls for a limited session. Log out locks those controls again. Knowing this password does not grant website administrator access or bypass revocation.
Uninstall
Agent 1.2.6 or later can be removed without a VPN password before approval, after verified revocation, or while its verified enrollment is pending/denied. Approved devices require the client administrator password or SYSTEM servicing. Windows administrator elevation is still required. An offline approved device keeps its password protection until it receives the changed status from the portal. Uninstall never clears the hardware blacklist.
Retire a PC permanently
Exclude it from RMM repair and GPO deployment first. Revoke it and uninstall the agent. Keep its revoked record to retain the hardware block. Delete record explicitly permits that hardware to request approval again. Otherwise repair/deployment can reinstall it and produce another approval request. Deleting the website record alone does not uninstall the agent.
Setup, advanced settings, and website login

Initial setup walks through connection details, firewall API access, certificates, the OpenVPN instance, code signing, and final verification/build. Back returns to an earlier step; Save & continue validates and saves the current step. Refresh instances reloads the firewall's VPN choices. Verify the WAN and VPN-to-LAN firewall rules before finishing setup.

Deployment settings lock after setup. Advanced: change deployment settings requires typing CHANGE DEPLOYMENT and temporarily reopens setup. Connection, certificate, or firewall changes can interrupt access; routine approval, revocation, password changes, and the separate domain restriction control do not require reopening the wizard.

Local website login requires the administrator password and passkey. AD FS mode uses the configured AD FS authorization and MFA. Help explains controls; Close or Escape dismisses it. Sign out ends the website session and hides administrator pages.

YOUR NETWORK, WITH YOU

A secure connection.
A simple approval.

Install the Windows client, then ask your administrator to approve your device. Your certificate belongs to your PC.

Download Windows client →

Windows 10/11 · 64-bit · Administrator installation required