QS-WAN · Access control

Network access control by country, IP and time of day

Network access control in QS-WAN decides where a connection is allowed to come from, and when. Each gateway runs in one of three modes against lists of country codes, IP addresses, CIDR blocks and ranges. Weekly schedules add the hours, and those are set per segment.

What it is

A certificate says who. It does not say where, and it does not say when.

Device identity is the part most networks get right. A certificate proves the device is the device it claims to be, the tunnel comes up, and the door opens. What identity cannot tell you is that the connection arrived at four in the morning from a country where you have no staff, no office and no supplier. The credential is valid. The context is wrong, and nothing in the handshake is looking at context.

The mode, on the gateway

A gateway runs in blacklist, whitelist or deactivated. Blacklist blocks what is on the list and allows the rest. Whitelist allows only what is on the list, which is the setting you want if your whole workforce sits in three countries. Deactivated is a named state, not an empty list quietly doing nothing.

The lists, validated as you type

Country codes, single IP addresses, CIDR blocks and address ranges. A malformed CIDR is rejected at the point you enter it. That matters more than it sounds: a broken entry that silently matches nothing looks exactly like a working rule from the outside, and you find out which it was on a bad day.

The hours, on the segment

Weekly time restrictions are set on the VLAN, so a finance segment can be reachable during working hours and closed outside them while a 24-hour operations segment is left alone. The Gateway Scope header carries a count of the schedules currently live.

So the door ends up answering one question instead of three. Valid credential, anywhere, any hour. That is usually more permission than anyone meant to hand out, and it is rarely a decision. It is just what was left switched on.

The mechanism

Four valid certificates, one gateway, and two rules deciding

All four devices below hold a certificate the gateway trusts. Change the mode, then close the segment at night, and watch which ones the network still accepts.

Lisbon PT · 10:14 PT Sao Paulo BR · 10:14 BR Warsaw PL · 10:14 PL Lisbon PT · 03:40 PT Gateway blacklist access control mode Finance VLAN weekly schedule off, open all hours
3 of 4 connections accepted

Four devices with valid certificates ask for the same finance segment: Lisbon at 10:14, Sao Paulo at 10:14, Warsaw at 10:14 and Lisbon again at 03:40. With the gateway on blacklist BR, Sao Paulo is refused and the other three are accepted. Switching to whitelist PT and ES also refuses Warsaw, because a whitelist allows only what is on it. Closing the segment between 20:00 and 08:00 refuses the 03:40 connection as well, and that rule lives on the segment rather than on the gateway.

Why this exists

Four things that go wrong without it

The allowed countries live in a spreadsheet

Somebody keeps the list, somebody else edits the gateway by hand, and the two agree on the day they are written. A mode with a validated list is the same decision with a state you can read.

Nobody wrote down the rule you are actually running

“Valid certificate, anywhere, any hour” is what most networks enforce, and almost nobody chose it. It is the setting that was left on.

A typo blocks nobody, and looks identical to a rule

A malformed CIDR that silently matches nothing behaves exactly like a working entry until the day it matters. Validation on entry is the difference.

Out of hours is a person remembering on a Friday

If closing a segment at night depends on somebody doing it by hand, it happens until the week it does not. A weekly schedule on the VLAN does not forget.

What you get

Fewer doors open at 3am. Fewer questions at the audit.

The person who runs the network wants entries that do not lie to them. The person who signs for it wants a rule they can point at. Same two controls, read two different ways.

For the network

Nothing lands on the device

The mode and the lists live in the console and the gateway does the enforcing. There is no local toggle on the device to talk anyone out of, and no agent change to schedule.

Bad entries die at the keyboard

Country codes, IPs, CIDR blocks and ranges are validated as you enter them, so a malformed entry is rejected on the spot instead of quietly matching nothing.

Hours without a helpdesk ticket

Time restrictions sit on the VLAN, so a segment closes outside working hours on its own. Nobody has to remember to switch anything off.

For the business

Your door stops answering one question

Valid credential, anywhere, any hour is more permission than anyone meant to hand out. This turns it into three questions, and each has an answer you can point at.

A setting, not an assumption

Who can reach us, from where, and at what hours becomes something with a state you can read, including deactivated, which is deliberately a state and not a blank field.

Nothing new on the invoice

This runs on the gateways and segments you already have. No appliance to rack, no second product, and no equipment leaving the building.

How it works

Three steps, and your people are only in the first

Someone taps Connect, and the gateway decides

A person opens their laptop in a hotel lobby and hits one button in the QNova Client. That is the whole of their job here: there is nothing to set and nothing to switch off, because the lists and the schedules live in the console. If the connection does not come up, the client keeps a live log per profile and a history of connection outcomes, so the person has something specific to tell you instead of saying the internet is broken.

You find out without anyone calling you

You read this in the console, not from the phone on your desk. QS-WAN carries a security events feed you can filter by severity and status, and a device inventory that drills down into activity per user. What is connecting across the estate is something you read rather than something you are told.

You turn what you saw into a rule

This is the part that is yours alone. If your whole workforce sits in three countries, you move that gateway from blacklist to whitelist and the rest of the world stops getting a conversation with your door. If a segment has no business being reachable at night, the weekly schedule goes on the VLAN. One decision in the console, and nobody gets visited at their desk.

Before you start

You need the gateways you already run and the segments you already have. There is no appliance to rack and nothing to install on the devices you already have, because both controls are enforced at the gateway.

In detail

The two scopes, and the reconnection that closes the gap

Rules

Firewall rules, per gateway and per user

Access control decides what gets in. Firewall rules decide what it is allowed to reach once it is in, and they are written two ways. A rule set attached to a gateway covers what that gateway serves, which is the right shape when the rule is about a site or a branch. A rule set attached to a user profile follows the person instead of the place, so they connect from a hotel on Tuesday and from the office on Thursday and the rule does not change because the postcode did.

They are applied to the gateways in real time, so a change does not wait for a maintenance window. They are also reapplied when a device reconnects, and that second part is the one worth reading twice: the laptop that spent the month you were tightening everything up sitting in a bag at the back of a car comes back on the current rules, not the ones it left with. Anything that only enforces at the moment you change it has a hole shaped exactly like that laptop.

Scope

What sits around the two controls

DNS profiles per VLAN are created in the console and assigned to segments, so name resolution is part of the policy rather than a separate argument. Changes take a few minutes to reach connected users, and the console says so rather than showing you a tick it has not earned.

The segments themselves are objects you create and draw, which is the subject of microsegmentation. Worth knowing: trust model is a separate control from tunnel mode, so a segment running split tunnel can still be default-deny. Rules that live on the device, such as USB ports and protection settings, travel in a different vehicle: a signed company policy pushed to the fleet.

Where this earns its place

Four mornings this changes

The whole workforce is in three countries

You move the gateway from blacklist to whitelist, put PT, ES and PL on the list, and every other country stops getting a conversation with your door. One change, and nobody gets visited at their desk.

The finance segment has no business being up at night

A weekly schedule goes on that VLAN and it closes at 20:00. The operations segment next to it runs 24 hours and is untouched, because the hours belong to the segment.

A supplier needs one address, and only one

A CIDR block on the whitelist gives them the range they actually use. The entry is validated when you type it, so you find out immediately if it is malformed.

An auditor asks what your rule is

The answer is a mode and a list with a state you can read on screen, including deactivated, rather than a description of what somebody believes is configured.

Works better with

What it sits on top of, and why each one matters

Schedules are set per VLAN, so the segments have to exist before the hours do. Hours are a segmentation decision before they are a scheduling one.

The certificate is still the only thing proving who. Access control adds where and when, and never replaces identity.

What a device may do once it is inside travels as a signed company policy, which is a different vehicle from a gateway rule.

Keeping local traffic local without loosening the segment, and the whole trade-off. A split tunnel VLAN can still be default-deny.

What this does not do

The limits, because they are what make the rest believable

It does not confirm a rule reached a gateway

The database is the authority for what you configured. Propagation out to gateways is best effort, so a green response proves the intent was recorded, not that every gateway in the estate is already enforcing it.

It does not push to a gateway that is offline

With the Tower Connection off, the change saves and the intent is recorded, but it is not pushed. It converges when the gateway comes back. That is the version you want before an audit rather than during one.

It does not give you per-person hours

Schedules are per VLAN, so everyone in a segment shares the same window. Two people who need different hours need different segments.

It does not prove where a human being is

A country rule is a broad filter, deliberately so. It cuts down what can reach you. It is not identity, and the certificate is still doing that job.

Questions people ask

The ones that come up first

What is network access control?

Network access control decides which connections your network accepts, and when. In QS-WAN it is two controls: a mode on each gateway, blacklist, whitelist or deactivated, running against lists of country codes, IP addresses, CIDR blocks and ranges, plus weekly schedules set per VLAN. It is a filter on the way in, not a replacement for what you do once a connection is inside.

Is this the same as the access control on my office door?

No. Badges, doors and turnstiles are a real product category, and it is not this one. Network access control answers a different question: not who gets into the building, but which connections your network accepts and at what hours.

Can two people have different hours?

No. Schedules are set per VLAN, so everyone in a segment shares the same window. If two people need different hours they need to be in different segments, which makes it a segmentation decision before it is a scheduling one.

If QS-WAN says the rule saved, is every gateway enforcing it?

Not necessarily. The database is the authority for what you configured, and propagation out to gateways is best effort, so a green response proves the intent was recorded. A gateway with its Tower Connection off saves the intent and converges when it is back.

Does split tunnel mean my network is open?

No. Tunnel mode and trust model are separate controls in QS-WAN, so a VLAN in split tunnel can still be default-deny. That is how local traffic stays local without the segment getting looser.

Where did the firewall rules page go?

Here. Access control and firewall rules are two tabs of the same dialog in the console, so they are one page on the site. Rules are written per gateway and per user, applied in real time, and reapplied whenever a device reconnects.

Tell us which hours you would close first.

An engineer, a console shaped like yours, and as long as you need. You name the segment and the window, and we set it while you watch. It is free and there is nothing to sign.

Scroll to Top