Use case · Remote access
Replace the remote-access VPN
Laptops join the same fabric as your offices, so remote staff reach every site through one connection that stays up when a hub does not.
The problem
A traditional remote-access VPN terminates at one head-end. Staff reach that office and are hairpinned to everywhere else; when the head-end fails, everyone is disconnected at once. Configuration files carrying private keys get emailed around.
How Weft does it
- Apps for macOS and Windows, and a Linux client. On Windows the helper runs as a system service, so the tunnel recovers even with nobody signed in.
- Private keys never leave the device. Each client generates its own key and joins by redeeming a one-time invitation. Only the public key is sent.
- Split or full tunnel, per client. Send only company traffic through Weft, or everything.
- Hub failover is automatic. The apps check the tunnel every ten seconds. If the hub stays unreachable they fetch a fresh profile and move to the new one, keeping their key.
- Policy applies to people as well as places. Clients belong to groups, and segmentation decides what each group may reach.
- Posture is reported. The Mac and Windows apps report device posture to the console.