Platform concepts
Understand the objects that make a PulseHA connection.
A device runs an agent and belongs to a user. A private Linux gateway sits near applications and terminates encrypted tunnels. A service names a destination that the gateway can reach. Access policy grants selected subjects that service through deliberate gateway scope.
Keep controls separate#
- Access decides who receives private-service routes.
- Firewall applies ordered L3/L4 gateway rules.
- Device policy configures agent behavior.
- Device posture evaluates health and blocks only in enforcing configurations.
- Orbit provides public egress; it is not a private application gateway.
- DNS names private services; Secure Web filters internet hosts and domains.
- Analytics shows trends, Audit shows events, and Reports provides fixed-window summaries and exports.
Traffic with no matching access grant is denied. WireGuard carries the data plane, while Console publishes configuration; operators do not hand-edit peers for normal use.