[{"data":1,"prerenderedAt":683},["ShallowReactive",2],{"home-en":3},{"id":4,"title":5,"body":6,"description":671,"extension":672,"meta":673,"navigation":674,"ogImage":675,"path":676,"robots":675,"schemaOrg":675,"seo":677,"sitemap":680,"stem":681,"__hash__":682},"home_en\u002Fen\u002Findex.md","Corporate VPN — a secure, flexible business VPN",{"type":7,"value":8,"toc":668},"minimark",[9,51,104,162,286,371,469,541,561],[10,11,14,22,27,42],"home-hero",{"image":12,"imageAlt":13},"\u002Fimages\u002Fhero-dashboard-en.png","MaxProtocol dashboard — networks and gateways",[15,16,18],"template",{"v-slot:title":17},"",[19,20,21],"p",{},"Secure access to corporate resources in minutes",[15,23,24],{"v-slot:lead":17},[19,25,26],{},"MaxProtocol is a corporate access platform built on Zero Trust Network Access. It is managed from a single web console and lets you:",[15,28,29],{"v-slot:benefits":17},[30,31,32,36,39],"ul",{},[33,34,35],"li",{},"Deploy a protected network with a managed gateway in 10 minutes",[33,37,38],{},"Set access rules for teams and individual employees",[33,40,41],{},"Securely connect local networks, 1C, CRM and ERP systems, file servers, and databases",[15,43,44],{"v-slot:cta":17},[19,45,46],{},[47,48,50],"a",{"href":49},"\u002Fgo\u002Fregistration","Get a demo",[52,53,55,60,65],"advantage-grid",{"tone":54},"muted",[15,56,57],{"v-slot:title":17},[19,58,59],{},"Connect without rebuilding your corporate network",[15,61,62],{"v-slot:subtitle":17},[19,63,64],{},"Getting started requires no hardware gateways and no changes to your existing network architecture. An administrator creates a network in the console, places a connector inside the company infrastructure, and describes the permitted routes.",[15,66,67,80,92],{"v-slot:items":17},[68,69,70,75],"icon-card",{},[15,71,72],{"v-slot:title":17},[19,73,74],{},"Create a network",[15,76,77],{"v-slot:lead":17},[19,78,79],{},"Pick a region for the managed gateway and set the parameters of the isolated network.",[68,81,82,87],{},[15,83,84],{"v-slot:title":17},[19,85,86],{},"Connect your infrastructure",[15,88,89],{"v-slot:lead":17},[19,90,91],{},"Place the connector and build a tunnel to servers, subnets, or internal services.",[68,93,94,99],{},[15,95,96],{"v-slot:title":17},[19,97,98],{},"Assign access",[15,100,101],{"v-slot:lead":17},[19,102,103],{},"Add employees and teams, then allow them only the resources and ports they need.",[105,106,107,112,117,156],"architecture-panel",{},[15,108,109],{"v-slot:title":17},[19,110,111],{},"Cloud management, a protected perimeter inside the company",[15,113,114],{"v-slot:lead":17},[19,115,116],{},"MaxProtocol separates access management from the connection to corporate resources. Administrators work in a cloud console, users connect through managed gateways, and the MaxProtocol connector links to the internal infrastructure.",[15,118,119,132,144],{"v-slot:items":17},[120,121,122,127],"feature-item",{},[15,123,124],{"v-slot:title":17},[19,125,126],{},"Users",[15,128,129],{"v-slot:lead":17},[19,130,131],{},"Employees and teams get access in line with the rules assigned to them.",[120,133,134,139],{},[15,135,136],{"v-slot:title":17},[19,137,138],{},"MaxProtocol infrastructure",[15,140,141],{"v-slot:lead":17},[19,142,143],{},"A cloud console and managed gateways in the regions you choose.",[120,145,146,151],{},[15,147,148],{"v-slot:title":17},[19,149,150],{},"Customer infrastructure",[15,152,153],{"v-slot:lead":17},[19,154,155],{},"The connector provides a controlled route to the permitted internal resources.",[15,157,158],{"v-slot:cta":17},[19,159,160],{},[47,161,50],{"href":49},[163,164,165],"tabs-section",{},[15,166,167,199,230,258],{"v-slot:tabs":17},[168,169,173,178,183],"tab",{"image":170,"imageAlt":171,"label":172},"\u002Fimages\u002Fmain-networks-image-en.png","MaxProtocol console: networks and gateways list","Networks",[15,174,175],{"v-slot:title":17},[19,176,177],{},"Isolated networks and managed gateways",[15,179,180],{"v-slot:lead":17},[19,181,182],{},"Every network gets its own IP subnet, regions, gateways, and rule set. Projects, departments, and separate perimeters can all be kept apart.",[15,184,185],{"v-slot:bullets":17},[30,186,187,190,193,196],{},[33,188,189],{},"Several regions inside one network",[33,191,192],{},"A static public gateway address for allowlists",[33,194,195],{},"Two connectors: OpenVPN XOR and Direct connection",[33,197,198],{},"Deactivate a gateway and its tunnels from the console",[168,200,204,209,214],{"image":201,"imageAlt":202,"label":203},"\u002Fimages\u002Fmain-policy-image-en.png","MaxProtocol console: access policy configuration","Policies",[15,205,206],{"v-slot:title":17},[19,207,208],{},"Access policies",[15,210,211],{"v-slot:lead":17},[19,212,213],{},"Every rule defines an access source, a destination, and an action. The source can be an employee or a team; the destination is an address, a subnet, or a directory record.",[15,215,216],{"v-slot:bullets":17},[30,217,218,221,224,227],{},[33,219,220],{},"Rule priority follows the order of the list",[33,222,223],{},"Default action: allow or deny",[33,225,226],{},"Rules can be switched off temporarily without deleting them",[33,228,229],{},"Only the required TCP and UDP ports are opened",[168,231,235,240,245],{"image":232,"imageAlt":233,"label":234},"\u002Fimages\u002Fmain-dns-image-en.png","MaxProtocol console: private DNS and internet access settings","DNS",[15,236,237],{"v-slot:title":17},[19,238,239],{},"Private DNS and internet access",[15,241,242],{"v-slot:lead":17},[19,243,244],{},"Internal domain names and internet egress routes are configured separately for every network and every user.",[15,246,247],{"v-slot:bullets":17},[30,248,249,252,255],{},[33,250,251],{},"A primary and a backup internal DNS server",[33,253,254],{},"Up to five internal domains per network",[33,256,257],{},"Egress through a chosen region or the user's own IP",[168,259,263,268,273],{"image":260,"imageAlt":261,"label":262},"\u002Fimages\u002Fmain-access-image-en.png","MaxProtocol console: authentication settings and sign-in log","Access",[15,264,265],{"v-slot:title":17},[19,266,267],{},"Authentication and the sign-in log",[15,269,270],{"v-slot:lead":17},[19,271,272],{},"Password sign-in is confirmed with a second factor. An administrator can require app-based authentication across the whole organization.",[15,274,275],{"v-slot:bullets":17},[30,276,277,280,283],{},[33,278,279],{},"A one-time code sent by email",[33,281,282],{},"A code from an authenticator app",[33,284,285],{},"A sign-in log with date and IP address",[287,288,291,296],"operations-section",{"image":289,"imageAlt":290},"\u002Fimages\u002Foperations-dashboards-en.png","MaxProtocol console: activity centre and team management",[15,292,293],{"v-slot:title":17},[19,294,295],{},"The everyday operations that need no support ticket",[15,297,298,311,323,335,347,359],{"v-slot:items":17},[299,300,301,306],"operation-item",{},[15,302,303],{"v-slot:title":17},[19,304,305],{},"Employees",[15,307,308],{"v-slot:lead":17},[19,309,310],{},"invite by email, deactivate without deleting, reset a password.",[299,312,313,318],{},[15,314,315],{"v-slot:title":17},[19,316,317],{},"Roles",[15,319,320],{"v-slot:lead":17},[19,321,322],{},"permissions split three ways: platform admin, billing, regular user.",[299,324,325,330],{},[15,326,327],{"v-slot:title":17},[19,328,329],{},"Rules and directory",[15,331,332],{"v-slot:lead":17},[19,333,334],{},"addresses, subnets and domains, and the access rules that cover them.",[299,336,337,342],{},[15,338,339],{"v-slot:title":17},[19,340,341],{},"Teams",[15,343,344],{"v-slot:lead":17},[19,345,346],{},"grouping by department and project, one employee in several teams.",[299,348,349,354],{},[15,350,351],{"v-slot:title":17},[19,352,353],{},"Networks and regions",[15,355,356],{"v-slot:lead":17},[19,357,358],{},"create a network, add a region, deactivate a gateway.",[299,360,361,366],{},[15,362,363],{"v-slot:title":17},[19,364,365],{},"DNS and internet egress",[15,367,368],{"v-slot:lead":17},[19,369,370],{},"settings held separately for every network and every employee.",[52,372,374,379,459],{"tone":54,"id":373},"why",[15,375,376],{"v-slot:title":17},[19,377,378],{},"How it works inside",[15,380,381,394,407,420,433,446],{"v-slot:items":17},[68,382,384,389],{"icon":383},"settings",[15,385,386],{"v-slot:title":17},[19,387,388],{},"Cloud console",[15,390,391],{"v-slot:lead":17},[19,392,393],{},"A single point of control for organizations, users, networks, gateways, tunnels, and policies.",[68,395,397,402],{"icon":396},"laptop",[15,398,399],{"v-slot:title":17},[19,400,401],{},"Gateways and connectors",[15,403,404],{"v-slot:lead":17},[19,405,406],{},"Managed gateways are deployed automatically in the region you pick and receive a route to the permitted resources through a connector installed inside the customer's infrastructure.",[68,408,410,415],{"icon":409},"flash",[15,411,412],{"v-slot:title":17},[19,413,414],{},"Tunnels",[15,416,417],{"v-slot:lead":17},[19,418,419],{},"Resources are reached over OpenVPN XOR with traffic obfuscation, or over a direct connection via SSH or HTTPS.",[68,421,423,428],{"icon":422},"security",[15,424,425],{"v-slot:title":17},[19,426,427],{},"Network isolation",[15,429,430],{"v-slot:lead":17},[19,431,432],{},"Every network has its own IP subnet, gateways, tunnels, and access rules.",[68,434,436,441],{"icon":435},"document-eye",[15,437,438],{"v-slot:title":17},[19,439,440],{},"Traffic filtering",[15,442,443],{"v-slot:lead":17},[19,444,445],{},"An unlimited number of rules per network, priority by order, and a separate action for traffic that matches no rule.",[68,447,449,454],{"icon":448},"user-shield",[15,450,451],{"v-slot:title":17},[19,452,453],{},"Authentication",[15,455,456],{"v-slot:lead":17},[19,457,458],{},"A password plus a second factor: a code sent to email or a code from an authenticator app.",[15,460,461],{"v-slot:actions":17},[30,462,463],{},[33,464,465],{},[47,466,468],{"href":467},"\u002Fgo\u002Fdocs","Technical documentation",[470,471,473,478,534],"platform-section",{"id":472},"how",[15,474,475],{"v-slot:title":17},[19,476,477],{},"Platform support",[15,479,480,495,508,521],{"v-slot:platforms":17},[481,482,485,490],"platform-item",{"href":483,"os":484},"#","windows",[15,486,487],{"v-slot:title":17},[19,488,489],{},"Windows",[15,491,492],{"v-slot:lead":17},[19,493,494],{},"Microsoft Store or .exe",[481,496,498,503],{"href":483,"os":497},"mac",[15,499,500],{"v-slot:title":17},[19,501,502],{},"macOS",[15,504,505],{"v-slot:lead":17},[19,506,507],{},"App Store or .dmg",[481,509,511,516],{"href":483,"os":510},"ios",[15,512,513],{"v-slot:title":17},[19,514,515],{},"iOS",[15,517,518],{"v-slot:lead":17},[19,519,520],{},"App Store",[481,522,524,529],{"href":483,"os":523},"android",[15,525,526],{"v-slot:title":17},[19,527,528],{},"Android",[15,530,531],{"v-slot:lead":17},[19,532,533],{},"Google Play or .apk",[15,535,536],{"v-slot:cta":17},[19,537,538],{},[47,539,540],{"href":483},"Downloads and installation guides",[542,543,544,549,554],"cta-banner",{},[15,545,546],{"v-slot:title":17},[19,547,548],{},"Test the platform on your own infrastructure",[15,550,551],{"v-slot:lead":17},[19,552,553],{},"Web console access opens as soon as you connect. An administrator deploys the platform, publishes the first corporate resource and configures access policies without assistance. No hardware gateways and no network preparation required.",[15,555,556],{"v-slot:cta":17},[19,557,558],{},[47,559,560],{"href":49},"Request a demo",[562,563,564,569],"faq-accordion",{},[15,565,566],{"v-slot:title":17},[19,567,568],{},"Frequently asked questions",[15,570,571,584,596,608,620,632,644,656],{"v-slot:items":17},[572,573,574,579],"faq-item",{},[15,575,576],{"v-slot:title":17},[19,577,578],{},"How is MaxProtocol different from a regular corporate VPN?",[15,580,581],{"v-slot:lead":17},[19,582,583],{},"A regular VPN lets whoever connects into the network as a whole. Here access is described by rules: the source is a team or a specific employee, the destination is an address or a subnet, the action is allow or deny. Traffic that matches no rule falls back to a default action, including “deny”.",[572,585,586,591],{},[15,587,588],{"v-slot:title":17},[19,589,590],{},"How long does rollout take and what do you need from us?",[15,592,593],{"v-slot:lead":17},[19,594,595],{},"A network with a gateway is deployed in about 10 minutes. Before that — enable multi-factor authentication, invite employees and put them into teams; after that — bring up a tunnel to the server that holds the resource and hand out the app. No work on network equipment is required.",[572,597,598,603],{},[15,599,600],{"v-slot:title":17},[19,601,602],{},"Do we need to buy any hardware?",[15,604,605],{"v-slot:lead":17},[19,606,607],{},"No. The gateway is deployed by the platform in the region you pick. On the company side, the only thing configured is the tunnel to the server that holds the resource: OpenVPN XOR or a direct connection.",[572,609,610,615],{},[15,611,612],{"v-slot:title":17},[19,613,614],{},"Which employee devices are supported?",[15,616,617],{"v-slot:lead":17},[19,618,619],{},"Windows, macOS, iOS and Android. Install from Microsoft Store, App Store and Google Play, or directly from .exe, .dmg and .apk files.",[572,621,622,627],{},[15,623,624],{"v-slot:title":17},[19,625,626],{},"How is access granted and revoked?",[15,628,629],{"v-slot:lead":17},[19,630,631],{},"Access is granted to a team: add an employee to a team and they get access to the networks assigned to it. Revoking means deactivating the account — access to every network in the organisation stops immediately, while the record's data is kept.",[572,633,634,639],{},[15,635,636],{"v-slot:title":17},[19,637,638],{},"What does an administrator see about connections?",[15,640,641],{"v-slot:lead":17},[19,642,643],{},"The activity centre shows employee sign-ins: name, action, date and IP address, with search by employee and sorting by time. The list of recorded events is being expanded.",[572,645,646,651],{},[15,647,648],{"v-slot:title":17},[19,649,650],{},"Will internal domain names keep working?",[15,652,653],{"v-slot:lead":17},[19,654,655],{},"Yes, through private DNS. A network is pointed at one or two of your DNS servers and up to five domains whose queries are sent to them; all other queries go to public DNS.",[572,657,658,663],{},[15,659,660],{"v-slot:title":17},[19,661,662],{},"Can we control how employees reach the internet?",[15,664,665],{"v-slot:lead":17},[19,666,667],{},"Yes. The internet-access policy is set per employee: exit through an egress node in the region you choose, or through a dedicated IP address.",{"title":17,"searchDepth":669,"depth":669,"links":670},2,[],"MaxProtocol is a reliable corporate VPN that unites employees and offices into one protected network with full access control.","md",{},false,null,"\u002Fen",{"title":678,"description":679},"Corporate VPN for business","A secure, flexible B2B VPN with corporate-grade access control, roles, and centralized management.",{"loc":676},"en\u002Findex","XC-E-K3Q6AdNvELfzpGeVc-waFMj4cbzRPJ8gD4zxLI",1788198764866]