The Access Gate connects to the network you already have. It is not in the traffic path on day one, so plugging it in changes nothing. You then move assets behind it, either one at a time or a whole subnet at once. This page shows where the gate sits in your network, how much of your traffic it can end up protecting, and how you move assets across.
You do not have to redesign anything. The gate works with what you already run: DNS, a router, a managed or an unmanaged switch, even networks that are not routed at all. What you have decides how much it can protect.
Pick your setup below to see where the gate goes, what you have to do, and the coverage you end up with.
How much of your traffic gets protected?
| Coverage | What it means | When you get it |
|---|---|---|
| Full Zero-Trust | The gate sees and controls every flow that matters | Your network is routed, and you have DNS or a managed switch to send traffic through the gate |
| Partial Zero-Trust | The gate controls what it can see. Traffic that stays on the switch never reaches it, so it stays unprotected | You have an unmanaged switch, or protocols that are not routed |
On the partial side the gate can still filter what reaches it at layer 2, by EtherType or MAC. That is coarse: it blocks or allows a type of traffic, not a user on a session.
What decides where the gate goes?
Three things about your current network:
- Is your traffic routed? Routed and routable, or not routed at all (exotic and custom protocols).
- What is on the network? DNS, a router without DNS, or only a switch.
- Is your switch managed? Managed means it supports PVLAN and can steer VLANs. Unmanaged means flat.
From those three answers, the gate is placed beside your router, in place of your router, or as an aggregation switch. The tree above gives you the answer for your case.
How do you move assets behind the gate?
Placing the gate is the first half. The second half is moving assets onto the Secure Twin, the overlay the gate lays alongside your network. The assets keep their own IPs. Nothing is installed on them, and nothing is renumbered or rewired.
You do it gradually, and there are three ways to deploy a Secure Twin:
- One asset at a time, with Twin DNS or Twin IPs. Start here. You bring one asset across, check it, and stop or roll back at any point.
- A whole subnet at once, with Source-Based Routing. One policy route on your router sends everything from a subnet or VLAN through the gate. Nothing on the assets changes.
- Configuration outside the gate, with IP NAT or ARP NAT. Use these when the first two are closed to you. They rely on rules you build and maintain on your own router or switches, so support for them is best-effort.
Next steps
- Quick start: stand up an Access Gate and one protected enclave in about 15 minutes.
- Architecture overview: the four deployment modes, In-Line, Lollipop, Bastion and Multi-Site Mesh, in depth.
- Choose how to connect your machines: the three ways compared, with a step-by-step guide for each method.