Run a Google Cloud VPN in a project that's already yours
The licence and the software gateway both run on infrastructure you own, and a cloud project counts as yours. No rack to find, no shipping date, no hardware from us.
Standardised algorithms, FIPS 203 and FIPS 204, kernel drivers attested by Microsoft, and a company accredited by Portugal’s national cyber security centre.
Yes, QS-WAN works as a Google Cloud VPN, on infrastructure you own
Yes. QS-WAN works as a Google Cloud VPN: the QS-WAN licence installs on infrastructure you own, physical or in the cloud, and the software gateway runs on your infrastructure too, so there’s no hardware from us and no rack to go looking for. Which pieces end up inside your Google Cloud project, and how they get there, is settled with your engineers during the deployment. We haven’t published a reference architecture for it, and we won’t sketch one here just to look organised.
What changes on day one, and what pointedly doesn't
Three answers, in the order a network administrator tends to ask the questions.
Put both halves where your infrastructure already is
The QS-WAN licence installs on infrastructure you own, and physical or cloud is your call: it’s a single-host install, and the installer doesn’t ask which one you picked. The software gateway runs on your infrastructure too. So if your servers moved into a cloud project years ago and the only cabinet left in the building belongs to the landlord, that’s the normal case here rather than the awkward one. The QS-WAN licence installs on infrastructure you own, and physical or cloud is your call: it’s a single-host install, and the installer doesn’t ask which one you picked. The software gateway runs on your infrastructure too. So if your servers moved into a cloud project years ago and the only cabinet left in the building belongs to the landlord, that’s the normal case here rather than the awkward one.
Keep the controls you already wrote
Once a gateway is up the cloud stops being a special case, which is the whole point. You define VLANs and LANs with address space reserved up front, and VLAN to LAN edges that open one way by construction instead of by good intentions. Firewall rules apply per gateway and per user, they apply live, and they’re reapplied when a device reconnects, so a laptop that slept through a change doesn’t wake up running the old one. Once a gateway is up the cloud stops being a special case, which is the whole point. You define VLANs and LANs with address space reserved up front, and VLAN to LAN edges that open one way by construction instead of by good intentions. Firewall rules apply per gateway and per user, they apply live, and they’re reapplied when a device reconnects, so a laptop that slept through a change doesn’t wake up running the old one.
Leave the other 99 people alone
About one person in a hundred ever opens the console. Everyone else opens QNova Client, presses one button, and never finds out the gateway moved into a cloud project. Enrolment is a single-use token, valid for 48 hours and burned the moment it’s used, and after that the tunnel can come up at login without the window appearing at all. About one person in a hundred ever opens the console. Everyone else opens QNova Client, presses one button, and never finds out the gateway moved into a cloud project. Enrolment is a single-use token, valid for 48 hours and burned the moment it’s used, and after that the tunnel can come up at login without the window appearing at all.
What runs on your side, and the one drawing we won't make up
Both halves of this run on infrastructure you own. The licence installs on your own infrastructure, physical or in the cloud, and the software gateway runs on your infrastructure too. We’re a product, not a managed service, so nobody here watches your network and no analyst of ours reads your traffic. The one thing this page won’t give you is a picture of the inside of your Google Cloud project: what lands there, and whether it arrives as an image, a template or a manual install, is an engineering answer with a date on it, and a diagram that turns out to be wrong costs you more than no diagram at all.
- The licence installs on infrastructure you own. Physical or cloud is your call.
- The software gateway runs on your infrastructure too.
- All communications are encrypted with post-quantum cryptography, including the handshake that sets a tunnel up.
- Split tunnel and zero trust are two separate controls, so a VLAN in split tunnel can still be default-deny.
- A green result means the intent was recorded. The database is the authority and the push out to gateways and devices is best-effort, so a gateway that's offline converges when it comes back. That matters more here, because cloud instances get rebuilt on purpose and on schedule.
- Not on this page, deliberately: the deployment shape inside a cloud project. No marketplace image is claimed and no deployment template is claimed. Ask, and an engineer answers.
Tell us what you're trying to connect
Which project holds your infrastructure, what’s already running inside it, and is there an office or a data centre at the other end that still has to reach it?