Skip to content →
Log in

Platform concepts

Understand the objects that make a PulseHA connection.

A device runs an agent and belongs to a user. A private Linux gateway sits near applications and terminates encrypted tunnels. A service names a destination that the gateway can reach. Access policy grants selected subjects that service through deliberate gateway scope.

Keep controls separate#

  • Access decides who receives private-service routes.
  • Firewall applies ordered L3/L4 gateway rules.
  • Device policy configures agent behavior.
  • Device posture evaluates health and blocks only in enforcing configurations.
  • Orbit provides public egress; it is not a private application gateway.
  • DNS names private services; Secure Web filters internet hosts and domains.
  • Analytics shows trends, Audit shows events, and Reports provides fixed-window summaries and exports.

Traffic with no matching access grant is denied. WireGuard carries the data plane, while Console publishes configuration; operators do not hand-edit peers for normal use.