Back to main siteBack Contact us
Solution Brief

NordLayer

VPN and Remote Access

Remote access without building a network to reach

NordLayer provides secure remote access as a subscription rather than as hardware. Users connect to a managed gateway, the organization is given a fixed address it can allow at the applications it protects, and access is granted per user and per resource rather than by admitting somebody to the whole network. This brief covers what that model does well, what it does not attempt, and how to judge whether it fits.

VendorNordLayer
CategoryVPN and remote access
Reading timeAbout three minutes
I

Executive summary

Traditional remote access places an appliance at the office and has staff connect back to it. That works while the office is the centre of the estate. It works poorly once the applications have moved to cloud platforms, because traffic travels to the office only to turn around and go back out.

The subscription model inverts this. The gateway is operated by the vendor, staff connect to the nearest one, and the organization receives a stable address it can use as a condition of access at each application. No hardware is bought, and the office stops being a bottleneck for people who no longer work there.

Takeaway: the question is where your applications live, not where your people are.

II

Why the fixed address matters more than the encryption

Encryption between a laptop and a gateway is commodity. Every product in this category does it competently, and on a modern web application the traffic was already encrypted anyway.

The genuinely useful property is a dedicated address. Given one, an organization can tell a cloud application to accept connections from that address and refuse everything else. A stolen password then stops being sufficient, because the attacker is not coming from the permitted address.

That turns a remote access product into an access control, which is a different and considerably more valuable thing.

HOME TRAVEL OFFICE GATEWAY one fixed address FINANCE APP CRM FILE STORE EVERYONE ELSE refused
Exhibit A. The applications accept one address. A valid password from anywhere else is not enough.

Takeaway: buy this for the allow list it makes possible, not for the tunnel.

III

The approach in practice

Deployment is a client application and a directory connection. Staff sign in with the identity they already use, and group membership determines which resources their connection may reach.

Network segmentation is available so that a connected user reaches only the resources assigned to their team, rather than being placed on a flat network with everything else. This is the difference between remote access and remote admittance.

For organizations still running something on their own premises, a gateway can be installed there too, so the same client reaches both cloud applications and the remaining local systems without staff having to know which is which.

Takeaway: adoption depends on the client being unremarkable to use, which is a real evaluation criterion.

IV

What changes, and what does not

ConcernBeforeAfter
Stolen password aloneOften sufficientBlocked by address restriction
Traffic path to cloud appsVia the officeDirect through a nearby gateway
Hardware to maintainAn applianceNone
Scope of a connectionThe whole networkAssigned resources only
Endpoint compromiseStill a problemStill a problem

Key findings

  • The dedicated address is the control worth paying for; the encrypted tunnel is not a differentiator.
  • Segmentation matters as much as access, because admitting somebody to a flat network is most of the historic risk.
  • This protects the route, not the device. A compromised laptop connects perfectly well.
  • It is not a substitute for multi factor authentication; the two address different failures and belong together.

Takeaway: treat it as one control among several, not as the perimeter restored.

V

Recommendation

For distributed teams using cloud applications, and for organizations wanting to retire a remote access appliance, this is a sound and inexpensive fit. It is particularly effective where cloud applications support address restrictions, since that is where the control becomes real rather than notional.

For an organization whose systems remain largely on its own premises, with staff mostly in the building, the case is thinner and a conventional appliance may serve better. Equally, a large enterprise pursuing a full zero trust architecture will find this a component rather than the answer.

Takeaway: verify your critical applications support address restriction before buying on that basis.

Next steps

Schedule the access readout

A short session listing which applications staff reach remotely, which of them could be restricted to a single address, and what a stolen password would currently achieve.

Schedule the readout

Get in touch with Your Company

Questions about this solution? Reach us directly.