Portable VPN for field sites

Take the network with you

A construction site, an event, a mobile unit, an emergency response. Teams working somewhere with no infrastructure of its own, over whatever connection happens to be available, needing the same systems and the same rules they would have at head office, for a few weeks and then somewhere else.

The situation

The work has moved to a place that has no network, and it will move again in a few weeks.

Whoever is running it has a connection of some kind, usually somebody’s mobile data or a line that was installed in a hurry. The people on site need the same systems they use in the office, and the organisation needs the same rules to apply, because nothing about the regulator’s expectations moved when the team did.

Why the usual answers do not fit

Set up a proper network takes longer than the deployment lasts, and half of it is thrown away at the end.

Let people use the local connection directly is what actually happens, and it means company work is crossing a network nobody has assessed, on devices that are now outside every rule you wrote.

A consumer VPN protects the link and nothing else. It does not know who the person is, what they may reach, or whether the device is in a state you would allow.

The shape of it

Same identity, same rules, wherever the team is working this week.

The same identity and the same signed rules, on a site that has no infrastructure of its own.

Your network Temporary site, no infrastructure of its ownback to the main networkthe network at the site: not yours, not trusted Laptop Phone QS-WAN Control Tower Gateway Servers Internal appsPublic internet
secure tunnelunprotected pathcontrol channelalready yours
How QS-WAN solves it

The gateway is a physical box you can carry. It arrives configured, it comes up on whatever connection exists, and the site is part of the same private network as every other site, with the same policy and the same encryption.

The rules travel with it.

Access modes, allow lists and schedules are the ones you already wrote. Nothing is re-created for the temporary site, which is where the exceptions usually creep in.

It is visible from the same console.

The temporary site appears next to the permanent ones, so the network map is the whole picture rather than the parts that are easy.

And it comes back.

When the deployment ends, the gateway is recovered and redeployed. There is no estate of forgotten equipment in a cupboard.

Who this is for

This is usually the situation when

What your people see

The same app they had yesterday. They arrive on site, open it, and they are on the company network.

Nobody on a temporary deployment should be learning a tool. The people who end up in these places are usually the busiest and the least interested in your network, and anything they have to configure will be configured wrong at least once.

The hardware

One box, bought once, and it arrives ready to run. We size it to the site before it ships.

For a field deployment, what decides that size is rarely how many people are on the team. It is how much you want to carry.

What we do not know yet

Whether there is a gateway configuration specifically tuned for being moved repeatedly is a fair question and we would rather you asked it directly than assumed an answer from this page.

Integration

What it takes, and what it leaves alone

What you need

A gateway that can travel.

What changes

The location. Not the rules.

What doesn't

Identity, policy and access, unchanged between sites.

Key features of this use case

The features this use case relies on

Network access control

Network mapping

Device enrollment

Talk to a cybersecurity specialist

The people who answer are the ones who build the product.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top