Sign in

Find your organisation

Every organisation has its own Inlinea address. Type the first word of yours, or the whole address, and we will take you there.

Take the tourBook a demo

Inlinea Agent

A private network that only exists where it is needed.

The Inlinea Agent joins a device to an encrypted private network built on WireGuard®: direct paths, device to device, with a relay only as a fallback. Tunnels open when traffic asks for them, and the agent a person installs already knows your control plane.

controldirect, encryptedManaged laptopInlinea AgentApplication hostInlinea AgentControl planeIdentity, policy, signallingPrivate siteRouting deviceCloud networkRouting deviceDevicesCoordinates onlyYour networks
Devices with the Inlinea Agent connect directly to each other and to routing devices; the control plane only coordinates.
direct paths
P2P
Device to device, encrypted end to end; a relay only when a direct path cannot be made.
ports opened inbound
0
Routing devices and application hosts dial out to the control plane.
operating systems
3
macOS, Linux and Windows, as a service with a command line, plus the desktop app.
policy with ZERA
1
The same identity, groups and Access Rules as the agentless path.

How it works

Peer to peer, coordinated centrally

  1. 1EnrolThe device joins your deploymentThe agent is preconfigured with your control plane, so there is no server address to type. Enrollment Keys and enrollment approvals decide which devices may join.
  2. 2DecidePolicy resolves what it may reachAccess Rules and Trust Checks are evaluated before a path opens and again as context changes. Nothing is reachable by default.
  3. 3ConnectA direct encrypted path opens on demandQuietLink opens a tunnel only when traffic asks for it, straight to the other device. A relay carries the traffic only when no direct path can be made.
  4. 4ReportFlows and health come backTraffic Logs record the connections a device made and refused, with the Access Rule that decided each one, when you switch collection on.

Why peer to peer

No concentrator to size, patch or saturate

Hub and spoke VPN

  • Every packet hairpins through a concentrator, wherever the two ends are
  • The concentrator is the bottleneck and the single point of failure
  • Joining the VPN means joining the network and everything on it
  • Capacity is bought for the peak and idle the rest of the time

Inlinea private network

  • Paths run directly between the two devices, encrypted end to end
  • The control plane coordinates and never carries application traffic
  • Reach is granted per resource, by Access Rule, never per subnet
  • Tunnels exist only while traffic flows, so large fleets stay light

Built for the field

An agent that holds up on real devices

Platforms

Where the agent runs

PlatformDeliveryNotes
macOSDesktop app, service and command linePreconfigured for your deployment; the tray shows connection state
WindowsDesktop app, service and command lineService for always-on devices and servers
LinuxService and command line, desktop appHeadless servers, routing devices and workstations
iOS and AndroidMobile agentsPeople on the move reach the same resources under the same rules

Questions buyers ask

Does the agent send our traffic through Inlinea?
No. Application traffic on the agent path runs directly between the two devices, encrypted end to end, and Inlinea cannot read it. The control plane coordinates identity, policy and signalling; a relay carries traffic only when a direct path cannot be made, and it still cannot read it.
How does a device know which deployment to join?
The agent you distribute is built for your deployment and already knows your control plane. There is no server address to type, and a custom address remains available for special cases.
Can a user remove or stop the agent?
Only if your Agent Profile allows it. Quit, disconnect, sign out, stop and uninstall can be placed behind a support passcode, a device-bound support code or a temporary override, and every attempt is reported.
What about servers and sites without a person?
Run the agent as a service on the host, or as a routing device that connects a whole network. Enrollment Keys enrol them without an interactive sign-in.
What does the agent report?
Connection flows when Traffic Logs collection is on, the Agent Profile it applied and protection events, and connection health. Never payloads.

Open the application. Never the network.