Skip to content →
Log in

WireGuard data plane

Understand how PulseHA distributes encrypted tunnel configuration.

PulseHA uses WireGuard between agents and gateways. The control plane distributes peer addresses and allowed routes from service and policy configuration.

Operator responsibilities#

  1. Enroll devices and gateways through supported flows.
  2. Publish services and access policy in Console.
  3. Verify connection, policy application, and gateway version state.
  4. Revoke a lost device or retired gateway from its inventory page.

Do not hand-edit peer lists or allowed IPs during normal operation; local changes can drift from published configuration.

An established tunnel proves encrypted transport, not authorization or application health. Access policy, posture enforcement, firewall, service reachability, and the destination process can still block a request.

Site-to-site also uses encrypted gateway tunnels and currently applies to all protocols and ports.