Skip to main content
VPN & Remote Access

Office and Remote-User VPN, Built In

Six ways to connect branch offices and remote workers to just the resources they need: WireGuard, IPsec, OpenVPN, L2TP, the zero-setup Firecradle VPN, and a self-healing Tinc mesh. Manage every tunnel from one dashboard. There is no extra fee per tunnel.

๐Ÿ”’ WireGuard ยท IPsec ยท OpenVPN ยท L2TP ยท Firecradle VPN ยท Tinc mesh

Six VPN Types, One Appliance

Pick the type that fits your client, your partner, or your rules. They all run on the same appliance, with no separate license.

WireGuard
A modern, lightweight VPN for both office-to-office and remote-user tunnels. Firecradle builds each client key for you, then hands it over as a QR code or a config file. Setting up a laptop or phone takes about two minutes.
IPsec
A standard VPN protocol for office-to-office and remote-user tunnels, built on strongSwan. It supports strong encryption and several ways to prove identity. Most other firewall brands also speak this protocol.
OpenVPN
A VPN protocol for both remote users and office-to-office tunnels. It can check a certificate, a password, or both. Each client gets a single file with everything it needs already inside.
L2TP/IPsec
Works with the VPN client already built into Windows, Mac, iPhone, and Android. Staff install nothing. They just add a connection and sign in.
Firecradle VPN
The easy way in, with no certificates to hand out. People sign in with the same Firecradle username and password they already have. You turn it on with one switch, and they download one file.
Tinc mesh
Links many sites together so each one can reach the others directly. It finds the best path on its own and heals itself if a link goes down. Keys are made for you.
Two Connection Modes

Connect Offices. Connect People.

A site-to-site tunnel links two networks together for good. This might connect a branch office to headquarters, or one data center to another. A remote-access tunnel is different. It starts on demand, when one user's laptop or phone dials in from wherever they are. Firecradle sets up both types from the same screens, using whichever protocol fits.

How a Tunnel Comes Up
The Other Side Connects
A branch gateway or a remote user's device dials in
Identity Is Checked
A shared key, a certificate, or a login - plus a second step for remote users
The Firewall Opens the VPN Port
No separate firewall rule to remember
Traffic Follows Your Rules
Only the allowed networks are reachable
A Watchdog Checks the Link
A dropped connection reconnects on its own
Sample Tunnel Status
Name
branch-hq-01
Protocol
IPsec (IKEv2)
Mode
site-to-site
Remote Gateway
203.0.113.9
State
ESTABLISHED
Last Handshake
12s ago
โœ“ Tunnel up - both local and remote subnets reachable

Set Up a New User in Minutes

Every protocol hands over a ready-made file or code. There is no page of settings to type in by hand.

QR Code or File Export
WireGuard users get a QR code to scan, or a file to download. Nobody has to type in a key by hand.
Ready-Made OpenVPN Files
OpenVPN users get one file with everything already built in, ready to import.
MFA for Remote Users
Ask for a second login step, on top of a certificate or password, before a remote session connects.
Centralized Management
Create tunnels, add users, and check connection status for every protocol from the same dashboard.

Real-World Use Cases

Remote Workforce Access

Challenge: Remote staff need safe access to internal files and apps, without exposing them to the open internet.

How it's handled:
โœ…WireGuard users get set up in minutes by scanning a QR code
โœ…A second login step is required before OpenVPN or IPsec sessions connect
โœ…The firewall opens only the VPN port on the internet side
โœ…Internal resources stay hidden to anyone outside the tunnel

Branch Office Interconnect

Challenge: Two branch offices need an always-on, encrypted link between their networks, without paying for a dedicated line.

How it's handled:
โœ…An IPsec tunnel connects the two sites with a shared secret key
โœ…Both networks are defined once, with no routes to enter by hand
โœ…A dropped link reconnects on its own after an outage
โœ…Traffic between sites is always encrypted, never sent in the open

Key Advantages

โœ…Six VPN types on one appliance: WireGuard, IPsec, OpenVPN, L2TP, Firecradle VPN, and Tinc mesh, with no separate license
โœ…Office and remote-user tunnels covered from the same setup screens
โœ…Ready-to-use files: WireGuard QR codes and full OpenVPN client bundles
โœ…A second login step is available for remote users, on top of a certificate or password
โœ…The firewall opens tunnel ports on its own, so you never do it by hand

Connect Every Site and Every Remote User

WireGuard, IPsec, OpenVPN, L2TP, Firecradle VPN, and Tinc mesh, included in every appliance, with no extra fee per tunnel.

No credit card required ยท Cancel anytime ยท 30-day free trial