Remote access that just works

Your team logs in from homes, offices, and airports. Your resources stay reachable — privately, on every device they carry.

Log in from anywhere, arrive on the private network

Home fiber, hotel NAT, conference wifi, a phone on LTE — the client dials out and the mesh finds a path. Nothing at HQ needs to accept inbound connections, so there is no port to attack and no concentrator to fall over at 9am.

  • ✓Direct peer-to-peer paths when physics allows
  • ✓Encrypted relay fallback — still works behind strict NAT
  • ✓Roams between wifi and LTE without dropping sessions
tailnet — this morning
mei@corpMacBook · home office18 msDIRECT
sam@corpiPhone · airport wifi34 msDIRECT
ana@corpWindows · hotel NAT61 msRELAY
raj@corpLinux · coworking27 msDIRECT

Policies follow the person, not the network

"Which VPN group do I join for wiki access?" — a question nobody asks again. Grants map to your identity provider's groups; when someone changes teams or leaves, the network changes with them at SCIM speed.

# finance app: finance group, company devices only
acl finance-app {
  src = ["group:finance"]
  dst = ["tag:corp-device", "finance-app:443"]
}
 
# new hire joins the IdP group → network access, same day
# contractor offboarded → every session, every device, gone

The remote access checklist

🌍

Works from any network

Café wifi, hotel NAT, LTE dongle — the mesh punches out; nothing needs to punch in.

📱

Every device

Laptops, phones, tablets — the same tailnet on each, with the same policies.

🧳

No re-login rituals

Switch networks mid-call and sessions persist; the tunnel re-establishes itself quietly.

🧲

Split by default

Only private traffic rides the tunnel — Netflix and Zoom stay on the local network at full speed.

🚀

Fast enough to forget

Direct peer-to-peer paths mean remote feels local; relays only when physics demands.

🎯

Latency you can measure

Typical direct paths add under 5 ms versus raw internet — video calls and SSH both feel native.

📊

No bandwidth pooling

Every connection is independent — the whole company logging in at 9am doesn't queue behind one appliance.

🔐

Identity on every session

Access follows the person, not the network they dialed from. Offboarding is instant via SCIM.

🔎

Visible to IT

Who's connected, from what device, reaching what — all in the admin console.

🧾

Auditable

Every access event logged and exportable for compliance review.

🖥️

Device posture checks

Require managed, patched, disk-encrypted devices before the tunnel comes up.

🗂️

MDM-friendly deploy

Push the client and config with your existing MDM; users just log in once.

Remote access FAQs

Does all my traffic go through the tunnel?
No — split tunneling is the default. Only traffic destined for your private ranges rides the mesh; everything else stays on the local network at full speed.
What happens on networks that block VPNs?
The client falls back to an encrypted relay over standard HTTPS ports, which works on hotel and conference wifi that blocks everything else. Users rarely notice the difference.
Can contractors use their own laptops?
Yes, with device posture checks — or restrict them to browser-based access through Funnel-style publishing while managed devices get the full client.
How many devices per user?
Up to 10 per person on standard plans — laptop, phone, tablet, and a homelab box all fit comfortably.
Is there a bandwidth cap?
No metering on self-hosted paths. Direct connections are your own bandwidth; relay usage is included, with fair-use limits far above normal work traffic.

Give your team a network they stop noticing

The best remote access review is "it just works" — start free today.