Security verification

Company SSO verification

Reach
Checking Reach Control setup…

Direct connection. Reach Control talks only to this server's same-origin management API.

Server status not checked

Provisioning

Add gateway

Choose where the gateway belongs and which setup instructions to show. Each successful invitation use creates one distinct gateway and assigns it to the selected site.

The gateway is assigned to this site when it enrolls.

Gateway platform

This selects the setup guide. The gateway reports and permanently records its actual platform during enrollment.

Allowed enrollments
The generated vpngw2. value is a bearer secret shown once. Reach never embeds it in a URL, download ticket, setup command, browser storage, or audit entry.

Device security

Change device lifecycle

This is written to the immutable security audit trail.

Enter CONFIRM device exactly.

High-risk recovery and revocation actions require fresh identity verification.

Security verification

Activate gateway profile

This queues a root-level network configuration for unattended application. Verify the exact draft revision and hash, enter the confirmation phrase, then complete fresh identity verification.

Enter ACTIVATE gateway exactly.

The five-minute activation token is used once and never stored by the browser.

Signed gateway update

Update gateway

Loading signed update status...

Select an action to review its immutable identity binding.

Enter UPDATE gateway-id exactly.

Manual SSH update

Checking complete maintenance-helper support...

Create a gateway-bound intent using your signed-in super-admin session, without additional SSO verification. This does not schedule or run an OTA update. The command contains public IDs and hash pins only. Existing enrollment credentials stay protected on the gateway. In your administrator-controlled SSH or RMM session, review the exact plan and answer Y/N locally before changes; invalid answers repeat. The complete migration can interrupt VPN sessions but does not request an OS reboot.

SSO-verified gateway operation

Reboot gateway

This restarts the entire operating system, not just Reach. VPN sessions will disconnect while the gateway reboots. The OS shuts down normally; this is not a hard power reset.

Loading reboot status...

One accepted reboot command per gateway per hour, shared across all administrators, even if it fails or expires. Unused commands expire after two minutes and are never queued for later.

Company SSO must freshly verify this same Reach super-admin account. Password-only verification is not available.

Security verification

Confirm release action

Review the immutable release identity, enter the confirmation phrase, and complete fresh identity verification.

Enter CONFIRM release exactly.

Connection diagnostics

Device health

Loading…

Auto-refreshes every 5 seconds while visible. Endpoint diagnostics normally arrive every 10 seconds; gateway samples follow its heartbeat interval. These are reports, not a continuous packet capture.

Recent connection events

Changes observed in the last 180 reports (up to 24 hours). Structured events only; no credentials, browsing history, packet contents, or raw system logs are collected.