SecureLink VPN Clients
SecureLink provides native VPN client applications for secure remote access to your organization's network. Each client is purpose-built for its platform, delivering a consistent and reliable connection experience.
How It Works
SecureLink VPN clients connect via the App VPN (wg1) tunnel on your organization's edge devices. Two protocols are supported:
- WireGuard — Lightweight, high-performance tunneling with ChaCha20-Poly1305 encryption
- IKEv2 — Standards-based IPSec with certificate authentication, native OS support on macOS, iOS, and Windows
The connection flow:
- Setup — The client discovers your orchestrator and authenticates via SSO
- Device registration — The client registers with the orchestrator and receives VPN configuration (keys, certificates, and endpoint)
- Edge assignment — Your client is assigned to the nearest or designated edge device
- Secure tunnel — The client establishes an encrypted tunnel to the assigned edge
Available Platforms
| Platform | Status | Distribution |
|---|---|---|
| macOS | Available | Direct download |
| iOS | Coming Soon | App Store |
| Android | Coming Soon | Google Play |
| Windows | Coming Soon | Direct download / MSI installer |
| Linux | Coming Soon | .deb / .rpm packages, CLI tool |
Common Features
All SecureLink VPN clients share a common set of capabilities:
- Dual protocol support — WireGuard or IKEv2 based on your edge's App VPN configuration
- Auto-connect — Automatically reconnect when the network changes or the device wakes from sleep
- Connection health monitoring — Detect stale handshakes and auto-reconnect with exponential backoff
- Certificate-based authentication — Clients authenticate using credentials and certificates issued by the SecureLink orchestrator
- Real-time metrics — View bytes sent/received, connection duration, and handshake health