Skip to main content

VPN replacement

Replace broad network access with named service access

Publish selected private services through Pomerium and enforce identity-aware route policy instead of granting remote users broad private-network reach.

What this pattern controls

Service scope

Expose only the private services that a user needs.

Policy scope

Use identity and current context in route policy.

Protocol scope

Select the documented client path for each protocol.

Migration boundary

Move from subnet access to service routes

Migrate application access one service at a time. Pomerium does not need to expose a private subnet to the user.

  • Inventory the web, SSH, TCP, and UDP services that remote users need.
  • Create one protected route for each selected service.
  • Close direct paths that bypass the Pomerium data plane.

Scope boundary

Keep network functions outside the claim

Pomerium replaces remote application access. It does not replace every site-to-site, device-network, or general network function.

  • Use a browser for protected HTTP applications.
  • Use Native SSH for configured SSH servers.
  • Use Pomerium CLI or Desktop for tunneled TCP and UDP protocols.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo