Solutions

Secure access, shaped around the way work actually happens.

Keep IPv4 internet traffic on a trusted company path, reach a remote machine, open one internal service, connect environments, or publish a protected application — without turning every network into one network.

6 scenario families 12 common situations One consistent access model
All scenarios

Start with what you need to make possible.

Six clear families keep the catalog easy to scan. Inside them are the situations teams handle every day.

01 · Enterprise VPN & Exit

Put IPv4 internet traffic on an approved company path.

  • Travel through a company exitKeep IPv4 traffic on the route authorized for the active Space; IPv6 is not routed through NSGW.
  • Reach a partner allow-listed destinationRoute only the approved IPv4 CIDR through infrastructure your team operates.
Explore enterprise exit
02 · Remote Node Access

Reach the machine you need, wherever it is.

  • Office PC, NAS or serverCross-account sharing uses a directional L3 Grant; same-account access to its own resources stays built in.
  • Remote operations and supportGive an operator access without exposing the surrounding network.
Explore remote access
03 · Private Service Access

For cross-account sharing, open one internal service instead of its host.

  • Private databaseSelect users, groups, or source Nodes for an exact protocol, host, and port.
  • Internal API or admin serviceSame-account access to its own private Services stays built in; cross-account sharing stays narrow.
Explore private services
04 · Office, Cloud & IDC

Connect resources across environments without flattening them.

  • Office-to-cloud operationsCross-account sharing authorizes only the required resources; same-account access to its own resources stays system-provided.
  • IDC and edge reachabilityBring remote Nodes and declared services into the same access model.
Explore hybrid connectivity
05 · Public Application Ingress

Publish an application with the protection it needs.

  • Identity-aware web applicationPair every OIDC, mTLS, API Key, or explicit anonymous L7 mode with a compatible Grant.
  • Public TCP or UDP endpointRestrict L4 ingress by source IP when application-layer identity is unavailable.
Explore public ingress
06 · Workloads & Scoped Sharing

Give automation and outside collaborators the smallest useful path.

  • CI or workload-to-application accessPair workload identity with an enabled compatible Consumer Grant for the explicitly published L7 application.
  • Scoped partner accessGrant a person access to an approved Node or private Service — nothing broader.
Explore scoped access
A deliberate boundary

Every scenario stays inside its real scope.

NetSeed does not turn a narrow requirement into broad network reach. Nodes, Services, Exit, public ingress and workload identity remain distinct choices with distinct controls.

L3

Directional Node access

Cross-account sharing reaches the authorized whole Node through a directional Grant; same-account access to its own Nodes stays system-provided. The host firewall remains final.

L4

Declared private service

Cross-account sharing uses a narrower Service Grant for the stated protocol, host and port; same-account access to its own private Services stays system-provided.

Public

Explicit ingress controls

Pair every L7 authentication or explicit anonymous mode with a compatible Grant; use source-IP controls for public TCP and UDP.

Space

One active context

The App consumes resources authorized to the selected Organization and Network Space.

Your next access path

See the scenario that matches your environment.

Explore the product model, or open the console and start with one Organization and Network.