Solution
A VPN opens the network. Inlinea opens the application.
A VPN puts a person on the network and trusts the network to do the rest. Inlinea grants one resource at a time, per person, per rule, over direct encrypted paths for managed devices and through a branded Workspace for everyone else.
27 systems reachable
Before and after
What changes
Today
- Joining the VPN means reaching every system on the subnet
- Every packet hairpins through a concentrator you size, patch and defend
- Contractors need a client, a VPN account and a managed device
- Nobody can say which systems a person could reach, only which network they joined
With Inlinea
- Access Rules grant resources, never subnets; the rest stays dark
- Peer-to-peer encrypted paths between devices; no concentrator to saturate
- Contractors open the same resources in a browser through ZERA, nothing installed
- Access Diagnostics answers who can reach what, and why, step by step
What solves it
The capabilities behind it
- Inlinea AgentManaged devices join an encrypted private network with direct paths and tunnels that open on demand.
- Access Rules and Trust ChecksGroups to resources, with device posture checked before and during access.
- ZERAThe agentless path: one Workspace for applications, desktops and SaaS links.
- Access DiagnosticsThe answer to every access ticket, from the real rules.
A scenario
How a day goes
- 1Monday, the finance teamManaged laptops run the agent. The Finance group's rule grants the finance application and the reporting server, nothing else. Paths open directly to each host when used.
- 2Tuesday, a contractorA personal laptop opens the Workspace in a browser. The Contractors group sees two cards. The build server is not among them and is not reachable.
- 3Wednesday, a questionWhy can Omar not open the HR portal? Access Diagnostics: no rule grants it. Add him to HR, simulate, confirm, done.
- 4Every dayNo concentrator to patch, no split-tunnel debate, and Traffic Logs showing what each device actually talked to.
Questions buyers ask
Do we switch everything at once?
No. Run Inlinea beside the VPN, move groups one at a time, and retire the concentrator when the last group has moved.
What about people who really need the whole network?
Give that group a rule to the network through a routing device. It is the same identity and the same policy as everyone else, and Traffic Logs still show what they reached.
Is performance better than the VPN?
Traffic on the agent path runs directly between the two devices rather than through a central concentrator, so the path is as short as the network allows.