Enterprise VPN & Internet Exit

Give remote devices an approved company internet path.

Use an Exit authorized to the active Organization and Network Space for the IPv4 default route or selected IPv4 CIDRs. NetSeed automatically chooses a usable WG or WSS transport. IPv6 is not routed through NSGW and is fail-closed by default.

IPv4 default route or CIDRWG / WSS automaticFail closed
Common situations

A company VPN for the trusted routes your team actually uses.

The Exit belongs to the selected Space and follows the routes your organization actually authorizes.

IPv4 default route

Remote work on untrusted networks

Keep IPv4 traffic on the company-controlled default route when working from a hotel, café or temporary office.

Selected IPv4 CIDR

Partner allow-listed systems

Send only approved IPv4 destination ranges through the company Exit while other traffic follows the device's normal path.

Operations

Consistent egress ownership

Route team traffic through infrastructure your organization operates and monitors instead of unmanaged local gateways.

Restricted networks

Transport that adapts

Let the client choose between WG and WSS based on the path that is actually usable, without asking the user to diagnose transport.

What the promise means

Predictable control, with honest boundaries.

Space-scoped choice

A user can select only an Exit authorized to the single active Space.

Explicit IPv4 route scope

An Exit may carry the IPv4 default route or only its configured IPv4 CIDRs. IPv6 is not routed through NSGW.

No silent bypass

Fail-closed behavior protects the intended path when the selected Exit cannot be used.

Company-operated exits

Exit locations, availability and addressing come from the infrastructure your organization operates for controlled routing.

Company internet path

Make the approved route easy to use.

Install the App to consume authorized Exits, or open NSD to manage the Organization and Network that owns them.