πŸ“„2. Guardpot Platform Administration

2.7 Virtual Guarded Network (VGN) Module

8 min read86 viewsUpdated May 20, 2026

The VGN module enables encrypted virtual network connections between branches and locations using WireGuard-based tunneling, as shown in Figure 2.7-1.

Figure 2.7-1 – VGN Management Interface


2.7.1 Main Navigation Tabs

The top-right corner of the module provides five navigation tabs for managing the virtual network, as shown in Figure 2.7.1-1.

Figure 2.7.1-1 – VGN Tab Navigation

Tab

Description

VGN Chains

Location-to-location tunnel configurations

Access

User and group-based access control rules

MFA Policies

Multi-factor authentication requirements

Logs

Connection, failure, and IP assignment audit logs

Download Client

Client software for Windows, Mac, Linux, iOS, Android


2.7.2 VGN Chains Tab

The VGN Chains tab displays all configured virtual network tunnels as individual chain cards, as shown in Figure 2.7.2-1.

Figure 2.7.2-1 – VGN Chains View

2.7.2.1 Search Chains

A Search chains field at the top of the VGN Chains tab allows you to filter chains by name, making it easy to locate specific tunnels in large deployments.

2.7.2.2 Chain Card Structure

Each VGN chain is displayed as a card containing configuration parameters, topology visualization, and action buttons.

Card Header:

The card header displays the chain name (e.g., "Afyon Merkez arasΔ±") and the current operational status (e.g., OFFLINE).

Chain Parameters:

Parameter

Description

Mode

NAT or other routing modes

MTU

Maximum Transmission Unit (default: 1420)

DHCP

Enable or disable automatic IP assignment (Enabled/Disabled)

Routing

All Traffic or Split Tunnel configuration

Groups

Number of user groups authorized to access this chain

Static IPs

Number of manually assigned IP addresses

Routes

Number of custom network routes configured

Topology Visualization:

Each card includes a visual chain builder showing the connection flow:

User Entry β†’ Auto Detected (188.xxx.xxx.xxx) β†’ Internet Exit

Description:

A descriptive text below the topology explains the chain's purpose (e.g., "Afyon şubesi ile merkez arasındaki şifreli bağlantı yolu").

2.7.2.3 Chain Action Buttons

Each chain card includes the following action buttons:

Button

Function

Edit

Modify chain configuration, groups, and static IPs

Delete

Remove the VGN chain

Peers

List connected peers and users

Restart

Restart the VGN service for this chain


2.7.2.4 Editing a VGN Chain

Clicking the Edit button on a chain card opens the configuration form, as shown in Figure 2.7.2.4-1.

Figure 2.7.2.4-1 – Edit VGN Chain Form

The form is titled "Edit VGN Chain" and includes the following sections:

General Configuration:

Parameter

Description

Chain Name

A descriptive name for the VGN tunnel

Description

Purpose and scope of the chain

Mode

NAT or other routing modes

MTU

Maximum Transmission Unit (range: 1280-1500)

DHCP Enabled

Toggle automatic IP assignment

Route All Traffic in Tunnel

Toggle to force all traffic through the tunnel

CIDR

Network range in CIDR notation

DNS Servers

DNS server addresses for the tunnel

Visual Chain Builder:

The topology visualization displays the connection path:

User Entry β†’ Auto Detected (188.xxx.xxx.xxx) β†’ Internet Exit


2.7.2.5 Managing Authorized Groups

The Authorized Groups section within the Edit form lists all groups with access to this chain, as shown in Figure 2.7.2.5-1.

Figure 2.7.2.5-1 – Authorized Groups Section

The groups table displays the following columns:

Column

Description

Name

Group name

Type

local or LDAP

LDAP Server

Associated LDAP server (if applicable)

MFA Policy

Number of MFA policies applied

Action

Remove the group from authorization

Click the Add Group button to authorize a new group. The form opens with the following parameters:

Parameter

Description

Group Type

Select local or LDAP

Group Name

Select a group from the available list

MFA Policy

Choose Bypass MFA or select a specific policy number


2.7.2.6 Managing Static IP Assignments

The Static IP Assignments section within the Edit form lists all manually assigned IP addresses, as shown in Figure 2.7.2.6-1.

Figure 2.7.2.6-1 – Static IP Assignments Section

The static IPs table displays the following columns:

Column

Description

Username

User assigned to this IP

IP Address

The reserved IP address (e.g., 10.100.0.26)

Auth Type

local or LDAP authentication

Auth Source

Authentication provider (Local or LDAP server name)

Action

Remove the static IP assignment

Click the Add IP button to assign a new static IP. The form opens with the following parameters:

Parameter

Description

Username

User to assign the IP to

IP Address

The static IP address to reserve

Authentication Type

Select LDAP or Local

DHCP Assignment

Enable or disable DHCP for this assignment


2.7.3 Access Tab

The Access tab manages user authentication and authorization through LDAP server integration and local user accounts, as shown in Figure 2.7.3-1.

Figure 2.7.3-1 – Access Tab View

2.7.3.1 LDAP Server Configuration

The LDAP Server Configuration section manages directory service integrations. A search field allows filtering through configured servers.

The LDAP servers table displays the following columns:

Column

Description

Name

Server configuration name

Server URL

LDAP server address

Base DN

Base Distinguished Name for searches

Actions

Edit and delete controls

Click the Add LDAP Server button to configure a new LDAP connection. The form includes the following parameters:

Parameter

Description

Name

A descriptive name for this LDAP configuration

Description

Purpose and scope of the LDAP integration

Server URL

LDAP server hostname or IP address

Port

LDAP service port

Base DN

Base Distinguished Name for directory searches

Bind DN

Distinguished Name for LDAP binding

Bind Password

Password for the bind user

Use SSL/TLS

Toggle encrypted connection

User Search Filter

LDAP filter for user searches

Group Search Filter

LDAP filter for group searches

Group Attribute

Attribute used to identify groups


2.7.3.2 Local Users

The Local Users section manages manually created user accounts. A search field allows filtering through configured users.

The local users table displays the following columns:

Column

Description

Username

User account name

Email

User email address (e.g., [email protected])

User Groups

Groups the user belongs to (e.g., grup1)

Actions

Edit and Remove buttons

Click the Edit button on a user row to modify account details. The edit form includes:

Parameter

Description

Username

User account name

Password

Account password

Email

User email address

Phone

Contact phone number

Discord ID

Discord user identifier

Telegram ID

Telegram user identifier

User Groups

Assigned groups (e.g., grup1)


2.7.3.3 User Groups

The User Groups section within Local Users manages group assignments. Click the Users Group button to view and manage groups.

The groups table displays:

Column

Description

Group Name

Group identifier

Description

Purpose of the group (e.g., "User group for VPN access.")

Action

Edit and delete controls

Click Add Group to create a new user group for VPN access.


2.7.3.4 Adding a New User

Click the Add User button to create a new local user account. The form includes:

Parameter

Description

Username

User account name

Password

Account password

Email

User email address

Phone

Contact phone number

Discord ID

Discord user identifier

Telegram ID

Telegram user identifier

User Groups

Assign to existing groups (e.g., grup1)


2.7.4 MFA Policies Tab

The MFA Policies tab manages multi-factor authentication requirements for VGN access, as shown in Figure 2.7.4-1.

Figure 2.7.4-1 – MFA Policies View

2.7.4.1 Policy List Table

The MFA policies table displays the following columns:

Column

Description

Policy Name

Identifier for the policy

Description

Purpose and scope (e.g., "No description")

Timeout

Code entry time limit (e.g., 120s)

Channels

Enabled MFA channels (e.g., SMS)

Actions

Edit and Delete icons


2.7.4.2 Adding a New MFA Policy

Click the Add New Policy button to create an MFA policy. The form includes the following parameters:

Parameter

Description

Policy Name *

A descriptive name for the policy (required)

Description

Purpose and scope of the policy

Timeout (seconds)

Time limit for MFA code entry (range: 30-600 seconds)

MFA Channels:

Select at least one MFA channel for this policy. Multiple channels can be enabled simultaneously:

Channel

Description

DISCORD

Discord-based verification

EMAIL

Email-based verification

SMS

SMS-based verification

TELEGRAM

Telegram-based verification

TOTP

Time-based One-Time Password (authenticator app)

Note: You must select at least one MFA channel. The system will display a validation message: "Please select at least one MFA channel."


2.7.4.3 Editing an MFA Policy

Clicking the Edit icon on a policy row opens the "Edit MFA Policy" form with the same parameters described in 2.7.4.2, pre-filled with the existing configuration.


2.7.5 Logs Tab

The Logs tab provides audit trail visibility with three sub-tabs for different log categories, as shown in Figure 2.7.5-1.

Figure 2.7.5-1 – VGN Logs View

All log views include a date range filter and a search text bar for narrowing results by specific criteria.


2.7.5.1 Connections Log

The Connections sub-tab displays successful VPN connection records with the following columns:

Column

Description

Timestamp

When the connection occurred

User

Authenticated username

Client IP

Source IP of the connecting client

Source

Connection origin

MFA Policy

MFA policy applied to this connection

MFA Status

MFA verification result

Assigned VPN IP

IP address assigned to the client

Duration

Connection session length

Status

Connection state


2.7.5.2 Failures Log

The Failures sub-tab displays unsuccessful connection attempts with the following columns:

Column

Description

Timestamp

When the failure occurred

User

Username used in the attempt

Client IP

Source IP of the connecting client

Reason

Failure cause description


2.7.5.3 IP Assignments Log

The IP Assignments sub-tab displays IP address lease history with the following columns:

Column

Description

Assigned At

When the IP was assigned

User

Username the IP was assigned to

VPN IP

The assigned VPN IP address

Lease Expires

When the IP lease expires


2.7.6 Download Client

The Download Client button, located alongside the main navigation tabs, opens the client software download page, as shown in Figure 2.7.6-1.

Figure 2.7.6-1 – Download Client Page

The page is titled "Download Guardpot Client" with the subtitle "Choose your platform to download the secure VPN client."

2.7.6.1 Desktop Applications

Platform

Description

Windows

Windows 10/11 compatible installer

Linux

Debian, Ubuntu, CentOS packages

macOS

Available on Mac App Store

2.7.6.2 Mobile Applications

Platform

Description

Android

Direct APK download

iOS

Available on App Store

2.7.6.3 System Requirements

All clients require internet connection and valid Guardpot credentials. Mobile apps require iOS 12+ or Android 6+.

Was this article helpful?

Your feedback helps us improve our documentation.

Send feedback