Remote access shouldn't mean
handing over the whole network
The conventional model: authenticate, land on the network, hope the firewall catches the rest.
The CorpVPN model: authenticate, receive per-client rules derived from your org tree, and
everything unauthorized is dropped in the forward chain.
WireGuard data plane Β· Two-factor login Β· One key per device Β· Full observability
Deny by default
Once a client receives its virtual IP, the node pushes forwarding rules one at a time based on that user's authorizations. Packets outside the allowlist are dropped. You don't discover over-reach in an audit afterwards β it never gets through.
Authorization follows your org chart
Policies attach to the organization tree with inheritance, deny subtraction and priority overrides. When someone changes roles, you move them in the tree and permissions recompute. No hand-editing ACLs. Upstream user directories can be synced automatically.
Internal access you can actually see
Nodes capture every new connection via NFLOG and roll it up to the control plane. Who, when, from where, to which host and port β rendered as an authorization topology and a user access overview in the admin console.
Capabilities
Control plane, data plane, clients and admin console β delivered as one system.
Identity and admission
Password plus SMS OTP two-factor login. One key per device with IP/MAC fingerprint binding. Login protection with attempt limits and source banning. CAPTCHA on the login path.
Access control
Resource authorization rooted in the org tree with inheritance and deny subtraction. Rules at CIDR and port-set granularity. Port denylists. Firewall rules pushed to and enforced on the data plane.
Multi-node
Multiple access nodes share one control plane and user directory; clients connect to the nearest. The data plane is stateless, so nodes are plug-and-play. Control traffic runs over a private mesh β no management port on the public internet. Nodes are manageable remotely from the console.
Observability and audit
Connection-level access logs collected via NFLOG and aggregated centrally. Source geography map, authorization topology graph, user access Sankey overview. System resource monitoring and metrics. Syslog forwarding into your existing SIEM.
Operations
One console for users, organizations, authorizations, nodes, logs, configuration, firewall and client release management. Scheduled synchronization from upstream user and org directories. Centralized client version distribution and upgrades.
Clients
Windows and mainstream Linux distributions, with first-class support for Kylin and openEuler. Available as a system-tray application or as a command-line / headless build for environments without a desktop.
How it differs from a traditional VPN
The difference isn't whether you can connect. It's what you can reach once you have.
| Traditional SSL VPN | CorpVPN | |
|---|---|---|
| Reachable scope after auth | The entire internal subnet | Authorized resources only; the rest is dropped |
| Authorization model | Hand-maintained ACLs and user groups | Org tree with inheritance, subtraction, priority |
| Tunnel protocol | SSL / IPSec, userspace overhead | WireGuard, in-kernel |
| Audit granularity | Login events | Per-connection logs plus topology and flow views |
| Horizontal scaling | Usually more appliances | Stateless nodes, plug-and-play |
| Domestic Chinese platforms | Vendor-dependent | Server and client both support Kylin / openEuler |
Where it fits
Remote and hybrid work
Staff reach internal systems from home or on the road β but only the systems their role actually calls for.
Vendors and contractors
Third parties reach a named set of hosts, access expires on schedule, and every connection is on record.
Distributed offices
Each site connects to its nearest node while identity and policy stay centralized.
Compliance and audit
Connection-level logs, traceable sources, and syslog forwarding into the security platform you already run.
Architecture
Control plane and nodes ship as single Go binaries with no runtime dependencies. Nodes require Linux kernel 5.6 or newer.
| Layer | Technology |
|---|---|
| Data plane tunnel | WireGuard (in-kernel, high throughput) |
| Control plane | Go + Gin |
| Admin console | React 19 + TypeScript + Apache ECharts |
| Database | PostgreSQL 17 (native partitioning, bulk copy) |
| Flow collection | NFLOG + go-nflog (new connections only, non-terminating, forwarding unaffected) |
| Client | Go, single cross-platform binary |
Want to see it running?
We can walk you through a live environment, or support a proof of concept in your own test network. The design and implementation document is available on request.
A quick note on your company, rough scale (users and sites) and the problem you're trying to solve makes the first conversation much faster.