Save it now
Enrollment secret (shown once)
This value cannot be retrieved again after dismissal.
Reach Control
Network overview
Device, gateway, user, and policy posture across every organization you may access.
Fleet activity
Recently seen devices
Data plane
Gateway readiness
Not yet refreshed
Software distribution
Downloads
Download published Reach software and verify it before installation.
Windows x64
Endpoint installers
With Reach 0.3.29 or later, install for a managed device, or sign in and use only your approved user VPN without enrolling the computer. Existing managed-device enrollment is preserved during upgrades.
Raspberry Pi arm64
Gateway package
For Raspberry Pi OS or Debian Bookworm/Trixie on 64-bit ARM.
Temporary download authorization
Raspberry Pi install commands
Generate a fresh command when you are ready to use it.
Recommended: activate the gateway's managed Linux profile, then place its
bound vpngw1. value in /root/reach-gateway.vpngw with mode 0600.
For a reusable vpngw2. invitation, also stage its strict registration configuration as
/root/reach-gateway.json with mode 0600. The command never embeds either file
and removes the staged copy only after a successful install.
For an existing installation with no recorded version. Preserves its configuration and enrollment. If the gateway already reports a version, use Gateways → Update for OTA or Manual SSH maintenance.
Super-admin
Release administration
Upload a verified candidate as a draft, review its server-recorded identity, then publish it.
Upload release candidate
The server independently verifies allowed types, size, SHA-256, version, and Windows signatures.
For Windows, upload the MSI first, the optional delivery EXE second, and the detached-signed release manifest last. The manifest freezes that installer set. A Raspberry Pi bundle creates its own one-file draft.
| Release | Package | Integrity | State | Created | Actions |
|---|
Structure
Organizations
Review every organization you may access, then open its focused administration workspace.
Create organization
A new organization starts with a Default Site, private-network policy templates and an initial administrators-only access group. Enroll a gateway, review its network setup, then add the users or groups you want to allow. Each organization can customize its own policies.
| Organization | Access | Sites | Users | Devices | Gateways | Policies | Actions |
|---|
Organization routing
Sites
Group gateways and endpoints into routing locations, then control how new user sessions select a gateway.
Create site
Gateway pools
Site routing and health
Priority is evaluated first for failover. Weight influences round robin; least connections uses current active-session counts.
Endpoint location
Device site assignments
Every device belongs to exactly one site in its organization.
| Device | Organization | Current site | Assignment |
|---|
User destinations
User site access
Choose each user's default and additional sites, with an optional user access policy for each site.
Edit site access
User site access
| User | Organization | Configured access | Actions |
|---|
Live authorization
Active user sessions
Active grants are joined to fresh per-peer gateway handshakes and cumulative transfer counters when the selected gateway reports them.
| User | Site | Gateway | Connection | Gateway traffic | Expires |
|---|
Endpoints
Devices
Compare reported Device/User VPN status with the requested device state. Check-ins alone do not prove VPN connectivity; reports older than three minutes are marked unknown.
| Device | Organization | Last seen | Lifecycle | Reported VPN status | Desired state | Policy | Actions |
|---|
Data plane
Gateways
Generate bounded enrollment codes, then manage each gateway after it enrolls. Agent healthy requires a healthy heartbeat within three minutes and the desired revision applied. Open Configure to check Device/User VPN network readiness and finish Linux gateway setup.
Next steps
Continue gateway setup
Use the one-time enrollment value above with the selected platform.
.vpngw file and transfer a copy through a protected channel; the
staging commands validate and remove that transferred copy. For multiple-use invitations, keep the
original only in a protected administrator vault until every intended gateway enrolls, then delete it
and revoke the code.
Linux / Raspberry Pi
Checking for a published signed gateway package…
Recommended
Interactive setup
Copy and run this two-line command on the Linux gateway. The installer downloads and authenticates the current signed release, opens a guided configuration wizard, and asks for the enrollment value through a hidden terminal prompt. Paste it only when prompted; it never appears in command history or process arguments.
The download must succeed before execution can start, and no network response is
piped into a shell. Remove the second line if you want to inspect the script first. A reusable vpngw2.
invitation still requires the wizard to collect and validate strict gateway configuration and
registration.
Advanced / unattended setup
Use this flow when deployment automation has already prepared separate protected enrollment and strict configuration files. Never put the enrollment value itself in a command, environment variable, URL, or log.
File-based installer
Replace both absolute placeholder paths before running the command. The files must be private regular files controlled by root or by the invoking administrator. Reach copies them into volatile root-only storage for installation and leaves the caller-owned source files in place for deployment automation to retain or remove.
Manual pinned-package fallback
Use the lower-level flow below only when you need to inspect and execute a specific portal release ticket instead of resolving the current signed release automatically.
The command asks only for the transferred file's absolute path, restricts it
to mode 0600, validates the bounded value, atomically writes root-only
/root/reach-gateway.vpngw, then removes that source copy. The value never appears in
shell history or process arguments.
Before installing this invitation, you must stage an approved
strict gateway configuration at /root/reach-gateway.json with mode 0600.
The configuration supplies the gateway name, endpoint, peer pools, allowed destination networks,
egress interface, and NAT policy.
Windows Server
Windows Server 2022/2025 uses the Reach Windows Gateway service and official WireGuard provider.
Download the one-time .vpngw file above, then copy and run this command
in elevated Windows PowerShell first. It creates and proves a fixed local staging directory, displays
the exact incoming path, and pauses. Transfer the file there through a protected channel in a second
administrator session, return to the waiting command, and press Enter. The command restricts the source
ACL, reads through an exclusive bounded handle, validates the value, and removes the incoming file.
%ProgramFiles%\Precision Computer Reach Gateway SecureStage\gateway.code.
Active gateway enrollment codes
Only non-secret metadata remains after generation. Revoke a code to stop future enrollments.
| Code ID | Site | Uses | Created | Expires | Actions |
|---|
Connect this site
Gateway network setup
Select a gateway to load its managed profile.
1. Enroll the gateway. 2. Review and activate its network settings below. 3. Use Access to assign users or groups to this site. Network readiness does not grant access.
Technical delivery status
Optional router port forwarding
Optional direct path
Manual UDP port forwards
Configure each mapping on the gateway's router. Reach uses it only after an authenticated peer check succeeds.
| Peer | Router mapping | Reachability | Last check |
|---|
Server-authoritative draft
Review changes
Current desired document
Proposed draft document
| Gateway | Endpoint | Platform | Revision | Last seen | Actions |
|---|
Configuration
VPN access policies
Keep machine startup access separate from the destinations a signed-in person may use.
Machine identity
Device tunnel routes
Available before sign-in for computer-level services. Keep these routes narrow; for example, Active Directory domain controllers, DNS, certificate services, and Reach management.
Applies to the enrolled devicePerson identity
User access routes
Available only after Reach Login authorizes the signed-in person. These destinations may be broader for business applications and never expand the device tunnel's machine routes.
Default deny without an explicit assignmentYour authorization
Your effective VPN access
Only the routes and DNS servers listed here can be requested after Reach Login.
This page shows authorization scope, not live connection state. Use the Reach tray icon for connection status.
Signed-in people
User access routes
Create an organization-scoped destination boundary, then explicitly assign it to a portal user.
Create user access policy
User assignments
Each portal user can have one user access policy per organization. Assigning another policy replaces the current assignment.
| Portal user | Organization | User access policy | Assigned | Actions |
|---|
Enrolled machines
Device tunnel routes and behavior
Signed device policies control pre-login connectivity, providers, DNS, trusted-network behavior, and machine route scope.
Edit existing policy
Device policy
Create device policy
Compatibility
OpenVPN credentials
Manage Peplink-compatible usernames and encrypted passwords.
Edit or rotate
OpenVPN credential
Add OpenVPN credential
| Name | Organization | Username | Revision | Actions |
|---|
Provisioning
Device enrollment
Issue a bounded bootstrap code for silent or interactive deployment.
| Label | Code ID | Policy | Uses | Expires | Actions |
|---|
Trust
Signing keys
Review policy-signing trust and stage carefully controlled rotations.
| Key ID | State | SPKI SHA-256 | Created | Actions |
|---|
Connectivity
NAT traversal
Configure outbound Cloudflare TURN relay credentials for managed WireGuard peers behind NAT or CGNAT.
Cloudflare Realtime
TURN provider
Configuration has not loaded.
Access & security groups
Site assignments grant access. All applicable policies narrow it. A deny always wins. Gateway preferences never grant permissions.
Access
Users
Create named operators, assign organizations and roles, and revoke sessions.
Edit access
User
Change your display name here. Use Account for your password and sessions; another super-admin must change your role, organizations, or account status.
Create user
| User | Role | Organizations | Status | Actions |
|---|
Identity
Account
Review your access, update your password, and control active sessions.
Profile and access
- Name
- —
- Username
- —
- Role
- —
- Organizations
- —
- Session expires
- —
Change password
Manage company account
Your password and sign-in methods are managed by Company SSO.
Open Company SSO profile