VPN

With ThinVPN your devices reach the company network securely from home. The VPN technology underneath is NetBird — the open-source platform by the German company of the same name (ZTNA over WireGuard). You set up the connection once and then enable individual clients with a click. You find everything under the VPN navigation item in the sidebar.

Recommendation: For the VPN feature you should book the ThinForge VPN option. To enable it in the first place, you receive a URL and a key from thinforge.org, with which you activate the VPN feature. See the price table for terms.

Before you start

While no connection exists yet, the tab only shows the "VPN not set up" card with a setup button. To get started you need the two details (URL and key) that you receive after booking the VPN option from thinforge.org:

  • ThinVPN address — the full address of your VPN server, e.g. https://vpn.yourcompany.com.
  • Access token — the key you receive from thinforge.org after booking the VPN option.
Note: Don't confuse the access token with an activation key. Activation keys are device-specific and are created automatically when you enable a client — you never enter them yourself.
VPN not set up
Until it is set up, the VPN area only shows the "VPN not set up" card with the setup button.

Setting up VPN

Clicking "Set up VPN" opens a wizard with three steps:

  1. Connection — enter the ThinVPN address and access token, then "Test connection & continue".
  2. Register server — the ThinForge server registers with the VPN server. The detected hostname and LAN subnet are shown.
  3. Done — confirmation that setup is complete.

After that, internal names (such as hosts of your local domain) resolve automatically through the tunnel on your devices. This requires a local domain set in the Network area under DNS.

VPN wizard step 1
Step 1 of the wizard: enter the ThinVPN address and access token and test the connection.
VPN wizard step 2
Step 2: the ThinForge server registers with the VPN server — detected hostname and LAN subnet are confirmed.

The VPN view after setup

Once everything is set up, the view shows a Status at the top (a green "ThinVPN active" chip and the number of enabled clients) and the Connection card with the current address and status, with the actions "Test connection", "Rotate token" and "Disconnect & delete".

Below that you find several tabs:

  • Clients — a table of all known devices and their VPN status.
  • Configuration — the reconciled VPN state and the allowed connections (Local resources).
  • Groups — the VPN groups.
  • Tasks — the running and completed VPN tasks.
Note: "Disconnect & delete" tears down the entire setup on the VPN server — including all enabled devices. This step cannot be undone; setting up again creates everything cleanly from scratch.
Configured VPN view
The configured VPN view: status, connection card and the Clients, Configuration, Groups and Tasks tabs.

Configuring groups, clients and allowed connections

In the Groups tab you manage the VPN groups. A group is a named collection of devices — it is later used to grant allowed connections to a specific selection of clients. Use "New group" to create a group with a name (e.g. "Accounting"). The Peers column shows how many devices are currently in the group. Three system groups are fixed and cannot be deleted; you can freely create and remove any further groups.

In the Clients tab the devices are organised by the group they belong to. When you enable a device (action "Enable"), the dialog lets you pick the group the client joins — prefilled with the default group "Clients". This group membership decides which allowed connections apply to the device. A client has no address rule of its own; its access follows solely from its group.

The actual allowed connections (Freigaben) are defined in the Configuration tab. There, the upper card shows the reconciled target state (network, routing, groups and existing allowed connections) read-only; with "Apply config" a changed state is pushed to the VPN server immediately. Below it, in the Local resources card, you create an allowed connection via "New resource". An allowed connection consists of:

  • Name — a label for the allowed connection (e.g. "W22").
  • Host address — the target that should become reachable: either a single IP (a single host, e.g. 192.168.20.3) or a whole network range in CIDR notation (e.g. 192.168.20.0/24).
  • Source group — the group whose members are allowed to reach the target (prefilled with "Clients").
  • Access rules — one protocol per rule (TCP, UDP or all) and the allowed ports (comma-separated).

An allowed connection cannot be edited afterwards — to change one you delete it and create it again. Using the delete icon in the row removes an allowed connection after a confirmation and deletes it from the VPN server right away.

Default behaviour: A freshly enabled client reaches only the ThinForge server on its own (for name resolution and management) — nothing else. Every additional access must be granted explicitly as an allowed connection. So if you want a group to reach a single host or a whole network range in the company network, you add that target as an allowed connection with the matching source group. This is how "server only" (no extra allowed connection) differs from "network range" (an allowed connection with a network-range address).
VPN configuration
The "Configuration" tab: the synced VPN state (network, groups, policies) and below it the "Local resources" — the shares.

Enabling and disabling devices

In the VPN clients table each device has an actions column:

  • Enable — ThinForge prepares the device and enables it at the next sync. Once it connects, the status changes to "active". You can prepare devices well before they go home — the activation never expires.
  • Disable — after a confirmation, VPN access is revoked immediately and removed from the device. You can re-enable it at any time.
Important: You can prepare the activation in advance, but the client only receives the configuration once it is powered on and reachable in the ThinForge server's LAN. The agent then picks it up at the next sync and sets up the tunnel — until the tunnel exists, the device can only reach the server locally. After that, VPN access also works from outside.

After that the client builds the tunnel fully automatically as soon as the device is outside the company network — the employee does not have to start, click, or enter anything. In the office, i.e. on the ThinForge server's LAN, the client tears the tunnel down again by itself, so the direct network access is used there.

Frequently asked questions

Does the remote employee have to do anything? No. The VPN client starts automatically when the device runs outside the office and switches itself off again in the office.

What if a device is lost? Disable the client in the VPN tab — access is revoked immediately.

What if the VPN server is briefly unreachable? Existing connections keep running. New activations are only possible again once the server responds.

Why do I see "VPN tier limit reached"? Your plan allows only a certain number of active clients. Disable a device you no longer need or upgrade your license.