Your devices are behind CGNAT, 4G/5G SIMs, Starlink, or client firewalls you don't control. Traditional VPNs can't reach them. WireZTNA can.
A lightweight agent on your edge gateway initiates an outbound WireGuard tunnel. No public IP needed. No port forwarding. No firewall changes at the remote site. Engineers connect through the broker — reaching every device on the local network as if they were there.
Your devices work fine locally. But reaching them from outside? That's where everything breaks.
4G/5G carriers share IPs across thousands of SIMs. Port forwarding doesn't exist. SSH reverse tunnels break after 48 hours. VPN site-to-site requires a public IP you don't have.
Your equipment sits in a customer's factory. Their IT won't open ports for you. Their network policy blocks inbound everything. You need access to maintain your machines.
Devices on Starlink, rural LTE, or metered connections. High latency, intermittent links. Your remote access solution needs to survive disconnects and auto-recover.
Traditional VPNs need a public IP on at least one side. WireZTNA doesn't. The edge agent connects outbound — the same direction that always works, on any network.
The WireZTNA publisher agent on your gateway initiates a WireGuard tunnel outbound (UDP to the broker). This is the same direction as web browsing — it passes through any NAT, any firewall, any carrier network. No inbound ports needed. No public IP needed. No cooperation from the site's IT department needed.
Once the tunnel is up, WireGuard's PersistentKeepalive maintains the NAT mapping indefinitely. The tunnel auto-recovers from disconnects. Engineers connect to the broker and traffic routes transparently to the devices behind the gateway — as if they were on the same LAN.
Carrier CGNAT. Shared IP. No inbound. WireZTNA works.
Double NAT. High latency. Dynamic IP. WireZTNA works.
Their firewall. Their rules. Only outbound allowed. WireZTNA works.
Intermittent link. Low bandwidth. Auto-reconnect. WireZTNA works.
One agent on a gateway. Entire OT/IoT network accessible remotely. No network changes at the site.
Remote site (factory, vehicle, field) Cloud / HQ
┌─────────────────────────────────────┐ ┌───────────────────────┐
│ │ │ │
│ PLC ─┐ │ │ WireZTNA Broker │
│ HMI ─┼── LAN ── Edge Gateway ─────┼── 4G/5G ──►│ (cloud-hosted) │
│ Robot─┤ (publisher agent) │ outbound │ │
│ Cam ──┘ 8 MB, arm64/amd64 │ UDP only │ Authenticates │
│ │ │ engineers, routes │
│ 192.168.1.0/24 │ │ traffic to gateway │
└─────────────────────────────────────┘ └───────────┬───────────┘
│
No public IP. No port forwarding. │ WireGuard
No firewall changes. No IT tickets. │ tunnel
│
┌───────────▼───────────┐
│ Engineer laptop │
│ (WireZTNA client) │
│ │
│ Reaches 192.168.1.x │
│ as if on-site │
└───────────────────────┘
One binary on any Linux gateway. Single command install with a one-time token.
Outbound WireGuard to the broker. Survives reboots, IP changes, carrier switches.
Uses WireZTNA client. Authorized by group policy. Sees devices on the remote LAN.
Only authorized engineers. Only assigned networks. Full audit trail. Session expiration.
From a single robot on a customer's floor to a thousand vehicles crossing borders. Same architecture, same simplicity.
A single static binary. No Docker, no Python, no runtime. Runs on anything with a Linux kernel 5.6+.
wireztna-publisher diagnoseinstall --token <url>Any Linux device with network access can be an edge gateway. No special hardware needed.
Because traditional VPNs were designed for offices with static IPs. Not for machines on cellular networks behind triple NAT.
| IPSec / OpenVPN S2S | SSH reverse tunnel | TeamViewer IoT | WireZTNA | |
|---|---|---|---|---|
| Works behind CGNAT | ✗ Needs public IP | ~ Fragile | ✓ | ✓ |
| Full LAN access | ✓ | ✗ Port-by-port | ✗ Single device | ✓ Entire subnet |
| Zero-touch deploy | ✗ Complex config | ✗ Key management | ~ Requires GUI | ✓ One command |
| Auto-reconnect | ~ Manual | ✗ Breaks daily | ✓ | ✓ Watchdog |
| Access control per user | ✗ All or nothing | ✗ Key = full access | ~ Per device | ✓ Per user/group/CIDR |
| Audit trail | ✗ | ✗ | ✓ | ✓ Full flow visibility |
| Self-hosted option | ✓ | ✓ | ✗ Cloud only | ✓ Your infra |
No exposed ports. No standing credentials. No "VPN concentrator" that becomes the single point of compromise.
The gateway initiates outbound. Nothing listens on the site's network. No inbound rules. No attack surface visible to Shodan or network scanners.
WireGuard preshared keys rotate automatically on each session. No certificates to expire. No manual key exchange. No PKI infrastructure to maintain.
Not "everyone with the VPN key gets everything." Engineer A sees factory-1. Engineer B sees factory-2. Groups define who reaches what. Granular to the CIDR or port level.
Access expires automatically (configurable TTL). No permanent tunnels from engineer laptops. Connect when needed, disconnect when done. Full audit of who accessed what, when.
Deploy a gateway agent in 60 seconds. Access your entire remote site from anywhere. Works on day one, on any network.
IoT connectivity is included in every WireZTNA plan. Same platform, same dashboard, same pricing.