Skip to content

VPN & secure remote access

VPN connectivity and secure remote access

We design and operate secure remote access around what your infrastructure actually needs — whatever the vendor and whatever the protocol.

The problem

A VPN grows by accident, and then nobody knows who can reach what

Each new need gets closed with its own tunnel: one branch on IPsec, one contractor on L2TP, everyone else on a shared account. A year later it is a pile of configurations with no documentation, keys that were never rotated, and access for someone who left months ago.

  • Keys and passwords are never rotated
  • Access is to everything, not to a service
  • Active sessions are not visible anywhere
  • The protocol was chosen by whoever set it up first

What we deliver

VPN connectivity and secure remote access

The access model

Who reaches which service and under what condition — segmentation before the tunnel, not after it.

Protocol selection

Driven by the hardware, the clients and the firewall constraints you already have.

Site-to-site topology

Hub-and-spoke or full mesh, wired into routing and failover.

Key and peer management

Central issuance, expiry and revocation — in a system, not a spreadsheet.

Visibility and logging

Who is connected now, who was yesterday, and from where.

Documentation and handover

A diagram, a runbook and end-user instructions.

Architecture

Architecture

  1. 01Access modelWho needs what — staff, partner, vendor
  2. 02ProtocolChosen for the platform and the client
    • IPsec
    • IKEv2
    • WireGuard
    • SSTP
  3. 03TopologySite-to-site and remote users kept apart
    • MikroTik
    • FortiGate
    • Cisco
  4. 04Keys and peersIssue, rotation and revocation
    • WireGuard Portal
    • RADIUS
    • MFA
  5. 05VisibilityActive sessions, and the logs
    • Graylog
    • Session log
  6. 06HandoverDocumentation, and instructions for the user
Access to a service rather than to the whole network — from model to handover

Operator consoles

Operator consoles

These exact systems run on the group's own infrastructure — the screenshots are processed before publication.

The WireGuard Portal interface administration screen — peer counts and interface parameters; keys and addresses are redacted.

WireGuard Portal — peers managed in one place

WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.

WireGuardpeer managementself-serviceMikroTik

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

IPsec

Proven

Site-to-site links, interoperability across vendors (Cisco / FortiGate / Juniper / MikroTik), IKEv1 and IKEv2.

  • IKEv1
  • IKEv2
  • site-to-site

L2TP/IPsec

Proven

Support for legacy clients and native OS integration — no extra software to install.

  • L2TP
  • native client

SSTP

Proven

A firewall-friendly tunnel over TCP 443, for Windows-oriented environments.

  • TCP 443
  • Windows

WireGuard (MikroTik RouterOS)

Proven

A modern, high-throughput tunnel with low latency — native on RouterOS.

  • WireGuard
  • RouterOS

WireGuard Portal

Proven

Centralised peer and key management with self-service provisioning — instead of mailing config files by hand.

  • peer management
  • self-service

Cisco AnyConnect (ASA / FTD)

Capability

Remote-access VPN on Cisco ASA/FTD infrastructure, over SSL or IPsec.

  • AnyConnect
  • ASA
  • FTD

FortiClient

Capability

Remote-access VPN on FortiGate infrastructure — SSL VPN and IPsec modes, with endpoint compliance integration.

  • FortiClient
  • SSL VPN
  • endpoint compliance

Technology stack

Technology stack

Protocols
IPsecIKEv2L2TPSSTPWireGuard
Platforms
MikroTikFortiGateCiscoJuniper
Clients
WireGuardAnyConnectFortiClientnative OS
Peer management
WireGuard PortalRADIUSMFA

Supported clients

Supported clients

The protocol and the client follow what already runs in your network — not what we would rather deploy.

  • WireGuard

    Native on MikroTik RouterOS, with peer management centralised through the portal.

  • Cisco AnyConnect

    Remote access on ASA/FTD infrastructure, in SSL or IPsec mode.

  • FortiClient

    SSL VPN and IPsec on FortiGate, with endpoint compliance checks.

Engagement model

Engagement model

Project

A one-off scope: audit, migration or implementation with a fixed outcome.

Retainer

Monthly engineering hours — specialist access on demand.

Co-managed

NetWizard and your in-house team together, with split responsibility.

Use cases

Use cases

Branches on one network

Several locations joined by site-to-site tunnels with routing and failover — instead of separate, hand-built links.

Remote team and contractors

Each person gets their own peer and access only to the services they need; when they leave, one revocation.

Vendor access to equipment

Temporary, time-boxed access to one device, fully logged.

FAQ

FAQ

Which protocol should we use?

The one your hardware and your clients already tolerate. WireGuard is the fastest, but a legacy client needs L2TP/IPsec, and behind a strict firewall SSTP over TCP 443 is what gets through. The recommendation comes after the audit.

Can you work on our existing FortiGate or Cisco?

Yes — we work on what is already installed. Replacing a vendor only comes up if the existing platform genuinely cannot cover a requirement.

Is MFA possible?

Yes, at the RADIUS layer — in remote-access scenarios it is part of the design, not an add-on.

Tell us about your infrastructure