Skip to content

VPN Access Policies

Access policies define who may reach which assets through which VPN gateway, optionally requiring an approved change and time windows.

Requires module.vpn and vpn.update (or Admin) to manage policies. Users need vpn.read to view.

ElementDescription
GatewayEdge appliance at a site (WireGuard endpoint, installed by Monozu)
PrincipalsUsers or groups granted access
Allowed assetsExplicit hosts (by asset), not whole subnets
Change requirementOptional link to an approved change before connect
ScheduleOptional time-bound access
  1. Go to VPNAccess Policies (/vpn/policies).
  2. Create or edit a policy; select gateway, members, and allowed assets.
  3. Save. Users in scope see the gateway on the VPN overview when they connect.

Policies are enforced by the VPN Hub; cloud.monozu.io stores policy and session metadata.