Skip to content

VPN gateways

A VPN gateway is a small VM the panel deploys inside a VPC. It runs WireGuard and gives two kinds of secure access into the VPC: road-warrior (individual devices dial in) and site-to-site (a permanent tunnel to another network). Gateways are also the building block for VPC peering.

  • VPC enabled on the hypervisor group. See VPCs.
  • An OS image with WireGuard and qemu-guest-agent installed, with its purpose set to vpn_gateway under Media & DNS > Images.
  1. Create at least one plan. Go to Networking > VPN GW plans and click Create plan. This opens a create page:

Plan Fields

Field What to enter
Name For example vpn-small.
Status Enabled or Disabled.
Credit Price per month Monthly cost in credits. The panel derives the hourly rate from it.
Max Peers (0 = Unlimited) The peer cap per gateway on this plan.
Compute & Memory CPU Mode, RAM (MB), CPU Cores (vCores), CPU Throttle (%), CPU Units, optional CPU Topology (Sockets, Cores, Threads).
Storage Storage Size (GB) and optional Read IOPS (/sec) / Write IOPS (/sec) / Read Throughput (/sec) / Write Throughput (/sec).
Bandwidth & NIC Network Driver, Bandwidth (GB), Upload Speed (Mbit/s) / Download Speed (Mbit/s), Bandwidth Accounting, Bandwidth Overage, Bandwidth Rate (per GB).

VPN plan create form

  1. Bundle plans into a group. Go to Networking > VPN GW plan groups and click Create group. Enter a Name, Display Name, and optional Description, then click Add Plan Group. Click the new group’s row to open its manage drawer: under Plans, check the plans to include; under Locations, check the hypervisor groups that can offer it; then click Save changes. Customers choose from plan groups, so you can offer different plan menus in different locations.

  2. Enable the feature on the location. Go to Infrastructure > Hypervisor groups, open the group, click the Networking tab, and in the VPN gateway section:

    • Turn on its Enabled toggle.
    • Optionally pick a VPN GW Image. If you leave it empty, any enabled image with purpose vpn_gateway is used.
    • Under Select VPN GW Plan Groups, pick the groups customers can choose from.
    • Click Save group.

Customers create gateways from the user panel. In the admin panel go to Networking > VPN gateways for the global list: gateway, owner, VPC, plan, peers, bandwidth, and created date. Filter by status.

VPN gateways list

Open a gateway for its detail page. The header carries Add peer and Delete Gateway, and the page has four tabs:

  • Overview. VPC, user, public IP, VPC IP, tunnel subnet, listen port, bandwidth used, credit value, and the gateway’s WireGuard public key (click to copy).
  • Peers. The peers table, with Add Peer and VPC Peering actions.
  • VPC Peering. The gateway’s VPC-to-VPC peering connections (a subset of its peers). See VPC peering.
  • Security Groups. Groups attached to the gateway’s instance.

VPN gateway detail page

On the Peers tab, click Add Peer:

Field What to enter
Type Road Warrior (one remote device) or Site-to-Site (a tunnel to another network).
Name For example my-laptop or office-network.
Public Key The remote side’s WireGuard public key. Leave empty to auto-generate one.
Endpoint The remote side’s public IP and port, for example 203.0.113.1:51820. Required for site-to-site, optional for road warriors.
Tunnel IP Leave empty to auto-allocate.
Allowed IPs Site-to-site only: comma-separated CIDRs routed into the tunnel, for example 192.168.0.0/16.
DNS DNS servers pushed to the peer.
Preshared Key An optional extra shared secret.
Keepalive Seconds between keepalives.

Each peer row has an enable/disable toggle and a delete action. Changes apply immediately without dropping the other peers.

For site-to-site, also configure the matching peer on the remote endpoint with the gateway’s public key, the gateway’s public IP and listen port, and the VPC subnet CIDRs. Once both sides are configured the tunnel comes up automatically.

VPN gateway peers table

Use the Security Groups tab on the gateway page to attach groups to the gateway instance and control what reaches it. See Security groups.

Each customer profile carries a Max VPN Gateways limit. The default is 5; 0 means unlimited. Edit it on the customer’s page under Customers > Users.

Click Delete Gateway on the gateway page. Deleting bills the remaining hours for the current period, removes all peers including any VPC peerings on both sides, and discards all configuration.

  • Gateway stuck in Deploying. Check the deploy task, confirm the hypervisor has free RAM, storage, and public IPs, and confirm an enabled image with purpose vpn_gateway exists.
  • Peers cannot connect. Confirm the gateway’s detail page shows Connected, the endpoint and keys match on both sides, and UDP traffic on the listen port (default 51820) is not blocked.
  • Customers see no VPCs when creating a gateway. VPN gateway is not enabled on the VPC’s hypervisor group, or no plan group is linked.