Remote Node Access

Reach the remote machine. Leave its network alone.

For cross-account access, give an approved person or source Node a directional L3 path to one authorized Node — an office PC, NAS, server or edge device. Same-account access to its own Nodes and private Services remains built in, and the destination firewall keeps final say.

Directional GrantWhole Node scopeHost firewall final
Common situations

One access model for the machines teams actually need.

Use Node access when the authorized person needs the machine as a whole. Use a narrower private Service when only one protocol and port are required.

Office

Workstation from home

Reach an office desktop for remote administration or the applications already running on it.

Storage

NAS and file server

Authorize the user or device that needs the remote storage Node without making the entire site reachable.

Operations

Server and appliance support

Give an internal operator explicit access to the machine that needs attention, then remove the Grant when the work changes.

Edge

Field and remote devices

Keep a device reachable across changing local networks without publishing inbound management ports.

The boundary

L3 means the whole Node — and nothing beyond it.

NetSeed makes the scope visible so teams can choose L3 Node access intentionally instead of treating it as a hidden side effect of a broad tunnel.

Direction

Cross-account sharing stays explicit

A Grant permits the selected subject to reach the selected Node without creating a reciprocal rule. Same-account access to its own resources remains system-managed.

Node

The machine is the scope

L3 access applies to the authorized whole Node, not to just one service on it.

Host

The firewall keeps final say

The destination operating system can still permit or reject traffic through its local firewall and services.

Node boundary

Machine-scoped by design

Remote Node access ends at the selected machine; the surrounding office or branch subnet stays outside that path.

Remote access

Authorize the machine the work depends on.

Use the App to consume authorized Nodes, and NSD to keep the Grant directional and explicit.