Skip to content →
Log in

Deployment

Place gateways and agents for resilient private access.

Place private gateways#

Deploy Linux gateways where they can route to the applications being published. Use multiple gateways with equivalent reachability when the service requires resilience, and assign the service to each capable gateway.

Add LAN networks only for site-to-site. Set Exit Node to Enabled only for hosts intended to carry internet egress.

Place agents#

Install the agent on supported Linux, Windows, or macOS endpoints. iOS and Android are coming soon. Linux authenticates with pulsectl login; Windows and macOS authenticate from the PulseHA app.

Verify deployment#

  1. Confirm gateways report Online and supported versions.
  2. Confirm devices have current connection and posture.
  3. Publish narrow services.
  4. Create deliberate access scopes.
  5. Simulate, test, and review Audit.

Orbit is a public egress option, not a substitute for a private gateway’s last hop to an internal application.