VPN & secure remote access
VPN connectivity and secure remote access
We design and operate secure remote access around what your infrastructure actually needs — whatever the vendor and whatever the protocol.
The problem
A VPN grows by accident, and then nobody knows who can reach what
Each new need gets closed with its own tunnel: one branch on IPsec, one contractor on L2TP, everyone else on a shared account. A year later it is a pile of configurations with no documentation, keys that were never rotated, and access for someone who left months ago.
- Keys and passwords are never rotated
- Access is to everything, not to a service
- Active sessions are not visible anywhere
- The protocol was chosen by whoever set it up first
What we deliver
VPN connectivity and secure remote access
The access model
Who reaches which service and under what condition — segmentation before the tunnel, not after it.
Protocol selection
Driven by the hardware, the clients and the firewall constraints you already have.
Site-to-site topology
Hub-and-spoke or full mesh, wired into routing and failover.
Key and peer management
Central issuance, expiry and revocation — in a system, not a spreadsheet.
Visibility and logging
Who is connected now, who was yesterday, and from where.
Documentation and handover
A diagram, a runbook and end-user instructions.
Architecture
Architecture
- 01Access modelWho needs what — staff, partner, vendor
- 02ProtocolChosen for the platform and the client
- IPsec
- IKEv2
- WireGuard
- SSTP
- 03TopologySite-to-site and remote users kept apart
- MikroTik
- FortiGate
- Cisco
- 04Keys and peersIssue, rotation and revocation
- WireGuard Portal
- RADIUS
- MFA
- 05VisibilityActive sessions, and the logs
- Graylog
- Session log
- 06HandoverDocumentation, and instructions for the user
Operator consoles
Operator consoles
These exact systems run on the group's own infrastructure — the screenshots are processed before publication.
WireGuard Portal — peers managed in one place
WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.
Capabilities
Capabilities
Every item is marked: verified production experience, or engineering capability.
IPsec
ProvenSite-to-site links, interoperability across vendors (Cisco / FortiGate / Juniper / MikroTik), IKEv1 and IKEv2.
- IKEv1
- IKEv2
- site-to-site
L2TP/IPsec
ProvenSupport for legacy clients and native OS integration — no extra software to install.
- L2TP
- native client
SSTP
ProvenA firewall-friendly tunnel over TCP 443, for Windows-oriented environments.
- TCP 443
- Windows
WireGuard (MikroTik RouterOS)
ProvenA modern, high-throughput tunnel with low latency — native on RouterOS.
- WireGuard
- RouterOS
WireGuard Portal
ProvenCentralised peer and key management with self-service provisioning — instead of mailing config files by hand.
- peer management
- self-service
Cisco AnyConnect (ASA / FTD)
CapabilityRemote-access VPN on Cisco ASA/FTD infrastructure, over SSL or IPsec.
- AnyConnect
- ASA
- FTD
FortiClient
CapabilityRemote-access VPN on FortiGate infrastructure — SSL VPN and IPsec modes, with endpoint compliance integration.
- FortiClient
- SSL VPN
- endpoint compliance
Technology stack
Technology stack
- Protocols
- IPsecIKEv2L2TPSSTPWireGuard
- Platforms
- MikroTikFortiGateCiscoJuniper
- Clients
- WireGuardAnyConnectFortiClientnative OS
- Peer management
- WireGuard PortalRADIUSMFA
Supported clients
Supported clients
The protocol and the client follow what already runs in your network — not what we would rather deploy.
WireGuard
Native on MikroTik RouterOS, with peer management centralised through the portal.

Cisco AnyConnect
Remote access on ASA/FTD infrastructure, in SSL or IPsec mode.
FortiClient
SSL VPN and IPsec on FortiGate, with endpoint compliance checks.
Engagement model
Engagement model
Project
A one-off scope: audit, migration or implementation with a fixed outcome.
Retainer
Monthly engineering hours — specialist access on demand.
Co-managed
NetWizard and your in-house team together, with split responsibility.
Use cases
Use cases
Branches on one network
Several locations joined by site-to-site tunnels with routing and failover — instead of separate, hand-built links.
Remote team and contractors
Each person gets their own peer and access only to the services they need; when they leave, one revocation.
Vendor access to equipment
Temporary, time-boxed access to one device, fully logged.
FAQ
FAQ
Which protocol should we use?
The one your hardware and your clients already tolerate. WireGuard is the fastest, but a legacy client needs L2TP/IPsec, and behind a strict firewall SSTP over TCP 443 is what gets through. The recommendation comes after the audit.
Can you work on our existing FortiGate or Cisco?
Yes — we work on what is already installed. Replacing a vendor only comes up if the existing platform genuinely cannot cover a requirement.
Is MFA possible?
Yes, at the RADIUS layer — in remote-access scenarios it is part of the design, not an add-on.