2.7 Virtual Guarded Network (VGN) Module
The VGN module enables encrypted virtual network connections between branches and locations using WireGuard-based tunneling, as shown in Figure 2.7-1.

Figure 2.7-1 β VGN Management Interface
2.7.1 Main Navigation Tabs
The top-right corner of the module provides five navigation tabs for managing the virtual network, as shown in Figure 2.7.1-1.

Figure 2.7.1-1 β VGN Tab Navigation
Tab | Description |
|---|---|
VGN Chains | Location-to-location tunnel configurations |
Access | User and group-based access control rules |
MFA Policies | Multi-factor authentication requirements |
Logs | Connection, failure, and IP assignment audit logs |
Download Client | Client software for Windows, Mac, Linux, iOS, Android |
2.7.2 VGN Chains Tab
The VGN Chains tab displays all configured virtual network tunnels as individual chain cards, as shown in Figure 2.7.2-1.

Figure 2.7.2-1 β VGN Chains View
2.7.2.1 Search Chains
A Search chains field at the top of the VGN Chains tab allows you to filter chains by name, making it easy to locate specific tunnels in large deployments.
2.7.2.2 Chain Card Structure
Each VGN chain is displayed as a card containing configuration parameters, topology visualization, and action buttons.
Card Header:
The card header displays the chain name (e.g., "Afyon Merkez arasΔ±") and the current operational status (e.g., OFFLINE).
Chain Parameters:
Parameter | Description |
|---|---|
Mode | NAT or other routing modes |
MTU | Maximum Transmission Unit (default: 1420) |
DHCP | Enable or disable automatic IP assignment (Enabled/Disabled) |
Routing | All Traffic or Split Tunnel configuration |
Groups | Number of user groups authorized to access this chain |
Static IPs | Number of manually assigned IP addresses |
Routes | Number of custom network routes configured |
Topology Visualization:
Each card includes a visual chain builder showing the connection flow:
User Entry β Auto Detected (
188.xxx.xxx.xxx) β Internet Exit
Description:
A descriptive text below the topology explains the chain's purpose (e.g., "Afyon Εubesi ile merkez arasΔ±ndaki Εifreli baΔlantΔ± yolu").
2.7.2.3 Chain Action Buttons
Each chain card includes the following action buttons:
Button | Function |
|---|---|
Edit | Modify chain configuration, groups, and static IPs |
Delete | Remove the VGN chain |
Peers | List connected peers and users |
Restart | Restart the VGN service for this chain |
2.7.2.4 Editing a VGN Chain
Clicking the Edit button on a chain card opens the configuration form, as shown in Figure 2.7.2.4-1.

Figure 2.7.2.4-1 β Edit VGN Chain Form
The form is titled "Edit VGN Chain" and includes the following sections:
General Configuration:
Parameter | Description |
|---|---|
Chain Name | A descriptive name for the VGN tunnel |
Description | Purpose and scope of the chain |
Mode | NAT or other routing modes |
MTU | Maximum Transmission Unit (range: 1280-1500) |
DHCP Enabled | Toggle automatic IP assignment |
Route All Traffic in Tunnel | Toggle to force all traffic through the tunnel |
CIDR | Network range in CIDR notation |
DNS Servers | DNS server addresses for the tunnel |
Visual Chain Builder:
The topology visualization displays the connection path:
User Entry β Auto Detected (
188.xxx.xxx.xxx) β Internet Exit
2.7.2.5 Managing Authorized Groups
The Authorized Groups section within the Edit form lists all groups with access to this chain, as shown in Figure 2.7.2.5-1.

Figure 2.7.2.5-1 β Authorized Groups Section
The groups table displays the following columns:
Column | Description |
|---|---|
Name | Group name |
Type | local or LDAP |
LDAP Server | Associated LDAP server (if applicable) |
MFA Policy | Number of MFA policies applied |
Action | Remove the group from authorization |
Click the Add Group button to authorize a new group. The form opens with the following parameters:
Parameter | Description |
|---|---|
Group Type | Select local or LDAP |
Group Name | Select a group from the available list |
MFA Policy | Choose Bypass MFA or select a specific policy number |
2.7.2.6 Managing Static IP Assignments
The Static IP Assignments section within the Edit form lists all manually assigned IP addresses, as shown in Figure 2.7.2.6-1.

Figure 2.7.2.6-1 β Static IP Assignments Section
The static IPs table displays the following columns:
Column | Description |
|---|---|
Username | User assigned to this IP |
IP Address | The reserved IP address (e.g., |
Auth Type | local or LDAP authentication |
Auth Source | Authentication provider (Local or LDAP server name) |
Action | Remove the static IP assignment |
Click the Add IP button to assign a new static IP. The form opens with the following parameters:
Parameter | Description |
|---|---|
Username | User to assign the IP to |
IP Address | The static IP address to reserve |
Authentication Type | Select LDAP or Local |
DHCP Assignment | Enable or disable DHCP for this assignment |
2.7.3 Access Tab
The Access tab manages user authentication and authorization through LDAP server integration and local user accounts, as shown in Figure 2.7.3-1.

Figure 2.7.3-1 β Access Tab View
2.7.3.1 LDAP Server Configuration
The LDAP Server Configuration section manages directory service integrations. A search field allows filtering through configured servers.
The LDAP servers table displays the following columns:
Column | Description |
|---|---|
Name | Server configuration name |
Server URL | LDAP server address |
Base DN | Base Distinguished Name for searches |
Actions | Edit and delete controls |
Click the Add LDAP Server button to configure a new LDAP connection. The form includes the following parameters:
Parameter | Description |
|---|---|
Name | A descriptive name for this LDAP configuration |
Description | Purpose and scope of the LDAP integration |
Server URL | LDAP server hostname or IP address |
Port | LDAP service port |
Base DN | Base Distinguished Name for directory searches |
Bind DN | Distinguished Name for LDAP binding |
Bind Password | Password for the bind user |
Use SSL/TLS | Toggle encrypted connection |
User Search Filter | LDAP filter for user searches |
Group Search Filter | LDAP filter for group searches |
Group Attribute | Attribute used to identify groups |
2.7.3.2 Local Users
The Local Users section manages manually created user accounts. A search field allows filtering through configured users.
The local users table displays the following columns:
Column | Description |
|---|---|
Username | User account name |
User email address (e.g., | |
User Groups | Groups the user belongs to (e.g., |
Actions | Edit and Remove buttons |
Click the Edit button on a user row to modify account details. The edit form includes:
Parameter | Description |
|---|---|
Username | User account name |
Password | Account password |
User email address | |
Phone | Contact phone number |
Discord ID | Discord user identifier |
Telegram ID | Telegram user identifier |
User Groups | Assigned groups (e.g., |
2.7.3.3 User Groups
The User Groups section within Local Users manages group assignments. Click the Users Group button to view and manage groups.
The groups table displays:
Column | Description |
|---|---|
Group Name | Group identifier |
Description | Purpose of the group (e.g., "User group for VPN access.") |
Action | Edit and delete controls |
Click Add Group to create a new user group for VPN access.
2.7.3.4 Adding a New User
Click the Add User button to create a new local user account. The form includes:
Parameter | Description |
|---|---|
Username | User account name |
Password | Account password |
User email address | |
Phone | Contact phone number |
Discord ID | Discord user identifier |
Telegram ID | Telegram user identifier |
User Groups | Assign to existing groups (e.g., |
2.7.4 MFA Policies Tab
The MFA Policies tab manages multi-factor authentication requirements for VGN access, as shown in Figure 2.7.4-1.

Figure 2.7.4-1 β MFA Policies View
2.7.4.1 Policy List Table
The MFA policies table displays the following columns:
Column | Description |
|---|---|
Policy Name | Identifier for the policy |
Description | Purpose and scope (e.g., "No description") |
Timeout | Code entry time limit (e.g., 120s) |
Channels | Enabled MFA channels (e.g., SMS) |
Actions | Edit and Delete icons |
2.7.4.2 Adding a New MFA Policy
Click the Add New Policy button to create an MFA policy. The form includes the following parameters:
Parameter | Description |
|---|---|
Policy Name * | A descriptive name for the policy (required) |
Description | Purpose and scope of the policy |
Timeout (seconds) | Time limit for MFA code entry (range: 30-600 seconds) |
MFA Channels:
Select at least one MFA channel for this policy. Multiple channels can be enabled simultaneously:
Channel | Description |
|---|---|
DISCORD | Discord-based verification |
Email-based verification | |
SMS | SMS-based verification |
TELEGRAM | Telegram-based verification |
TOTP | Time-based One-Time Password (authenticator app) |
Note: You must select at least one MFA channel. The system will display a validation message: "Please select at least one MFA channel."
2.7.4.3 Editing an MFA Policy
Clicking the Edit icon on a policy row opens the "Edit MFA Policy" form with the same parameters described in 2.7.4.2, pre-filled with the existing configuration.
2.7.5 Logs Tab
The Logs tab provides audit trail visibility with three sub-tabs for different log categories, as shown in Figure 2.7.5-1.

Figure 2.7.5-1 β VGN Logs View
All log views include a date range filter and a search text bar for narrowing results by specific criteria.
2.7.5.1 Connections Log
The Connections sub-tab displays successful VPN connection records with the following columns:
Column | Description |
|---|---|
Timestamp | When the connection occurred |
User | Authenticated username |
Client IP | Source IP of the connecting client |
Source | Connection origin |
MFA Policy | MFA policy applied to this connection |
MFA Status | MFA verification result |
Assigned VPN IP | IP address assigned to the client |
Duration | Connection session length |
Status | Connection state |
2.7.5.2 Failures Log
The Failures sub-tab displays unsuccessful connection attempts with the following columns:
Column | Description |
|---|---|
Timestamp | When the failure occurred |
User | Username used in the attempt |
Client IP | Source IP of the connecting client |
Reason | Failure cause description |
2.7.5.3 IP Assignments Log
The IP Assignments sub-tab displays IP address lease history with the following columns:
Column | Description |
|---|---|
Assigned At | When the IP was assigned |
User | Username the IP was assigned to |
VPN IP | The assigned VPN IP address |
Lease Expires | When the IP lease expires |
2.7.6 Download Client
The Download Client button, located alongside the main navigation tabs, opens the client software download page, as shown in Figure 2.7.6-1.

Figure 2.7.6-1 β Download Client Page
The page is titled "Download Guardpot Client" with the subtitle "Choose your platform to download the secure VPN client."
2.7.6.1 Desktop Applications
Platform | Description |
|---|---|
Windows | Windows 10/11 compatible installer |
Linux | Debian, Ubuntu, CentOS packages |
macOS | Available on Mac App Store |
2.7.6.2 Mobile Applications
Platform | Description |
|---|---|
Android | Direct APK download |
iOS | Available on App Store |
2.7.6.3 System Requirements
All clients require internet connection and valid Guardpot credentials. Mobile apps require iOS 12+ or Android 6+.
