CorpVPN Β· Zero Trust Network Access

Remote access shouldn't mean
handing over the whole network

The conventional model: authenticate, land on the network, hope the firewall catches the rest.
The CorpVPN model: authenticate, receive per-client rules derived from your org tree, and everything unauthorized is dropped in the forward chain.

WireGuard data plane Β· Two-factor login Β· One key per device Β· Full observability

🚫

Deny by default

Once a client receives its virtual IP, the node pushes forwarding rules one at a time based on that user's authorizations. Packets outside the allowlist are dropped. You don't discover over-reach in an audit afterwards β€” it never gets through.

🌳

Authorization follows your org chart

Policies attach to the organization tree with inheritance, deny subtraction and priority overrides. When someone changes roles, you move them in the tree and permissions recompute. No hand-editing ACLs. Upstream user directories can be synced automatically.

πŸ“Š

Internal access you can actually see

Nodes capture every new connection via NFLOG and roll it up to the control plane. Who, when, from where, to which host and port β€” rendered as an authorization topology and a user access overview in the admin console.

Capabilities

Control plane, data plane, clients and admin console β€” delivered as one system.

Identity and admission

Password plus SMS OTP two-factor login. One key per device with IP/MAC fingerprint binding. Login protection with attempt limits and source banning. CAPTCHA on the login path.

Access control

Resource authorization rooted in the org tree with inheritance and deny subtraction. Rules at CIDR and port-set granularity. Port denylists. Firewall rules pushed to and enforced on the data plane.

Multi-node

Multiple access nodes share one control plane and user directory; clients connect to the nearest. The data plane is stateless, so nodes are plug-and-play. Control traffic runs over a private mesh β€” no management port on the public internet. Nodes are manageable remotely from the console.

Observability and audit

Connection-level access logs collected via NFLOG and aggregated centrally. Source geography map, authorization topology graph, user access Sankey overview. System resource monitoring and metrics. Syslog forwarding into your existing SIEM.

Operations

One console for users, organizations, authorizations, nodes, logs, configuration, firewall and client release management. Scheduled synchronization from upstream user and org directories. Centralized client version distribution and upgrades.

Clients

Windows and mainstream Linux distributions, with first-class support for Kylin and openEuler. Available as a system-tray application or as a command-line / headless build for environments without a desktop.

How it differs from a traditional VPN

The difference isn't whether you can connect. It's what you can reach once you have.

Traditional SSL VPNCorpVPN
Reachable scope after authThe entire internal subnetAuthorized resources only; the rest is dropped
Authorization modelHand-maintained ACLs and user groupsOrg tree with inheritance, subtraction, priority
Tunnel protocolSSL / IPSec, userspace overheadWireGuard, in-kernel
Audit granularityLogin eventsPer-connection logs plus topology and flow views
Horizontal scalingUsually more appliancesStateless nodes, plug-and-play
Domestic Chinese platformsVendor-dependentServer and client both support Kylin / openEuler

Where it fits

Remote and hybrid work

Staff reach internal systems from home or on the road β€” but only the systems their role actually calls for.

Vendors and contractors

Third parties reach a named set of hosts, access expires on schedule, and every connection is on record.

Distributed offices

Each site connects to its nearest node while identity and policy stay centralized.

Compliance and audit

Connection-level logs, traceable sources, and syslog forwarding into the security platform you already run.

Architecture

Control plane and nodes ship as single Go binaries with no runtime dependencies. Nodes require Linux kernel 5.6 or newer.

LayerTechnology
Data plane tunnelWireGuard (in-kernel, high throughput)
Control planeGo + Gin
Admin consoleReact 19 + TypeScript + Apache ECharts
DatabasePostgreSQL 17 (native partitioning, bulk copy)
Flow collectionNFLOG + go-nflog (new connections only, non-terminating, forwarding unaffected)
ClientGo, single cross-platform binary

Want to see it running?

We can walk you through a live environment, or support a proof of concept in your own test network. The design and implementation document is available on request.

A quick note on your company, rough scale (users and sites) and the problem you're trying to solve makes the first conversation much faster.