Private Network
Your networks, joined. Your traffic, from your addresses.
One agent at a site becomes the routing device for a whole network. Devices reach it over direct encrypted paths that open on demand. Sovereign Outlinks send a group's internet traffic out through exit gateways you run, with a second gateway for failover, so SaaS allowlists see your own addresses.
Networks
Sites, clouds and servers on one private network
- Routing devicesAn Inlinea Agent with network access becomes the connector for everything behind it. Nothing opens inbound at the site; it dials out.
- Site to siteTwo routing devices join two networks. Routes are granted to groups by Access Rule, so a site is never reachable by everyone.
- High availabilityTwo routing devices for one network: traffic fails over when one is lost, and the Control Center shows a single point of failure the moment there is one.
- DNS servers and zonesPrivate names resolve privately. DNS servers per network and zones per domain, pushed to the devices that need them.
QuietLink
Tunnels that exist only while traffic flows
A device in a large network does not hold hundreds of idle tunnels. QuietLink opens a direct path when traffic asks for it and closes it when traffic stops.
- Direct firstPaths are device to device, encrypted end to end. A relay carries traffic only when a direct path cannot be made, and still cannot read it.
- Light on the deviceFewer live tunnels means less keepalive traffic, less battery and faster reconnects on a laptop that moves between networks.
- Decided by policyA tunnel only opens to a peer an Access Rule allows. The absence of a tunnel is also the absence of reach.
Outlinks
Internet egress you control
- Sovereign OutlinksExit gateways on your own devices, in your own data center. A group's internet traffic leaves from your address, with a second gateway for failover.
- Inlinea OutlinksRegional exit gateways run by Inlinea, with fixed egress addresses, for groups that need a stable address without hosting a gateway.
- PrecedenceWhen two Outlinks reach one group, the lower metric wins and the Control Center marks the other as overridden, so there is never a surprise.
What travels where
Three kinds of traffic, three answers
| Traffic | Path | Who can read it |
|---|---|---|
| Control traffic | Device to your control plane: sign-in, policy, signalling | Your tenant |
| Application traffic, agent path | Device to device, direct, encrypted end to end; relay as fallback | Only the two devices |
| Internet traffic through an Outlink | Device to your exit gateway, then out from your address | Your gateway, as any egress point does |
Questions buyers ask
Do we need to open firewall ports at our sites?
No. Routing devices dial out to the control plane and to their peers. Nothing listens inbound at the site.
What happens when a routing device fails?
With two routing devices on a network, traffic fails over to the second. The Control Center shows availability per network and flags a single point of failure as soon as there is one.
Can traffic ever pass through Inlinea's servers?
Only through a relay, and only when a direct path cannot be made. The relay forwards encrypted packets it cannot read.
How do SaaS allowlists work with Outlinks?
A Sovereign Outlink gives a group one fixed public address, yours. Allowlist it in the SaaS application and traffic from that group arrives from it, from any device, anywhere.