Solutions

For IT teams

The VPN project that ends: roll out in an afternoon, onboard people automatically, stop answering "is the VPN up?"

Rollout is measured in afternoons, not quarters

Connect your IdP, push the client through MDM, approve the first devices — that's the whole project plan for week one. The old VPN runs in parallel while teams migrate at their own pace; nobody's Thursday depends on a flag-day cutover.

  • ✓Works with Okta, Entra ID, and Google Workspace out of the box
  • ✓Standard PKG/MSI installers — no agent to hand-roll
  • ✓Deny-all default, then grant by the groups HR already owns
rollout — wave status
pilot · eng12 devices · week 1100%MIGRATED
wave 2 · sales40 devices · week 2100%MIGRATED
wave 3 · finance28 devices · week 364%IN PROGRESS
legacy vpnconcentratorweek 4SCHEDULED OFF

Deprovisioning is where IT teams fall in love

The departing contractor's account dies in the IdP, SCIM carries it to the network, and every session on every device ends within seconds. No certificate revocation lists, no shared-credential rotation, no "did we get all the keys?" audit.

# contractor's last day, in the IdP
disable user: raj@contractor.dev
 
# what the network does, automatically
✓ sessions terminated   ✓ devices removed
✓ keys revoked        ✓ ACL grants deleted
 
# zero tickets, zero spreadsheets, zero doubt

Your week one

Connect the identity provider

Point OpenVLAN at Okta, Entra ID, or Google Workspace. Users and groups sync; MFA piggybacks on login.

Push the client via MDM

Standard installers for macOS and Windows deploy like any other managed app. Linux servers take one shell command.

Approve devices, set ACLs

Device approval is one click. Start from deny-all and grant by IdP group — least privilege by default.

Turn off the old VPN

Run in parallel for a week, migrate wave by wave, then decommission the concentrator and reclaim its IP block.

Tickets that stop arriving

"VPN won't connect from the hotel"

NAT traversal handles hostile networks; relay fallback covers the rest. Connectivity complaints drop off.

"I need access to X"

Access requests flow through the IdP groups you already manage — no per-app VPN group juggling.

"Setting up the new hire's machine"

MDM installs the client; SSO does the rest. First-day network access without IT touching anything.

"Who has access to the finance server?"

ACLs answer that in one place, mapped to groups that HR already owns.

"Deprovision the departing contractor"

SCIM disables their account; sessions die in seconds, not at the next certificate expiry.

"The appliance is paging again"

There is no appliance. The pager gets quieter.

Proof from the field

IT team FAQs

How long does a full migration actually take?
A mid-size org typically runs four weeks: pilot in week one, two or three migration waves, then the concentrator comes off. The pacing is human scheduling, not technology — the network side is done by day two.
Will it work with our MDM?
Yes — standard PKG, MSI, and deb/rpm packages with documented silent-install flags for Jamf, Intune, Kandji, and the usual suspects. If your MDM can install an app, it can deploy this.
What does helpdesk training look like?
About an hour. There's no client-side config to walk users through — login is SSO, and the settings a user might touch are basically on/off. Most tickets the VPN used to generate simply stop existing.
Do we need to keep the old VPN for anything?
Occasionally a legacy appliance that only routes over IPsec. Those keep working in parallel; every team we've worked with retired the concentrator within a quarter anyway.
What's the break-fix story?
Status page, support channels on every plan, and the console's per-device diagnostics usually answer "is it the network?" before anyone opens a ticket.

Roll it out this week

Most IT teams finish a pilot in a single afternoon.