Inlinea Agent
A private network that only exists where it is needed.
The Inlinea Agent joins a device to an encrypted private network built on WireGuard®: direct paths, device to device, with a relay only as a fallback. Tunnels open when traffic asks for them, and the agent a person installs already knows your control plane.
- direct paths
- P2P
- Device to device, encrypted end to end; a relay only when a direct path cannot be made.
- ports opened inbound
- 0
- Routing devices and application hosts dial out to the control plane.
- operating systems
- 3
- macOS, Linux and Windows, as a service with a command line, plus the desktop app.
- policy with ZERA
- 1
- The same identity, groups and Access Rules as the agentless path.
How it works
Peer to peer, coordinated centrally
- 1EnrolThe device joins your deploymentThe agent is preconfigured with your control plane, so there is no server address to type. Enrollment Keys and enrollment approvals decide which devices may join.
- 2DecidePolicy resolves what it may reachAccess Rules and Trust Checks are evaluated before a path opens and again as context changes. Nothing is reachable by default.
- 3ConnectA direct encrypted path opens on demandQuietLink opens a tunnel only when traffic asks for it, straight to the other device. A relay carries the traffic only when no direct path can be made.
- 4ReportFlows and health come backTraffic Logs record the connections a device made and refused, with the Access Rule that decided each one, when you switch collection on.
Why peer to peer
No concentrator to size, patch or saturate
Hub and spoke VPN
- Every packet hairpins through a concentrator, wherever the two ends are
- The concentrator is the bottleneck and the single point of failure
- Joining the VPN means joining the network and everything on it
- Capacity is bought for the peak and idle the rest of the time
Inlinea private network
- Paths run directly between the two devices, encrypted end to end
- The control plane coordinates and never carries application traffic
- Reach is granted per resource, by Access Rule, never per subnet
- Tunnels exist only while traffic flows, so large fleets stay light
Built for the field
An agent that holds up on real devices
- Agent ProfilesPer group, decide what the desktop app and tray show, which settings the organisation owns, and protect quit, disconnect, sign out, stop and uninstall behind a support passcode, a device-bound support code or a temporary override.
- QuietLinkTunnels open only when traffic asks for them, so a device in a large network keeps a handful of live paths instead of hundreds.
- Enrollment Keys and approvalsControlled device onboarding: keys with scope and expiry, and an approval step before a new device is admitted.
- Routing devicesOne agent at a site becomes the connector for a whole network: site to site, cloud networks, and the private side of ZERA.
Platforms
Where the agent runs
| Platform | Delivery | Notes |
|---|---|---|
| macOS | Desktop app, service and command line | Preconfigured for your deployment; the tray shows connection state |
| Windows | Desktop app, service and command line | Service for always-on devices and servers |
| Linux | Service and command line, desktop app | Headless servers, routing devices and workstations |
| iOS and Android | Mobile agents | People on the move reach the same resources under the same rules |
Questions buyers ask
Does the agent send our traffic through Inlinea?
No. Application traffic on the agent path runs directly between the two devices, encrypted end to end, and Inlinea cannot read it. The control plane coordinates identity, policy and signalling; a relay carries traffic only when a direct path cannot be made, and it still cannot read it.
How does a device know which deployment to join?
The agent you distribute is built for your deployment and already knows your control plane. There is no server address to type, and a custom address remains available for special cases.
Can a user remove or stop the agent?
Only if your Agent Profile allows it. Quit, disconnect, sign out, stop and uninstall can be placed behind a support passcode, a device-bound support code or a temporary override, and every attempt is reported.
What about servers and sites without a person?
Run the agent as a service on the host, or as a routing device that connects a whole network. Enrollment Keys enrol them without an interactive sign-in.
What does the agent report?
Connection flows when Traffic Logs collection is on, the Agent Profile it applied and protection events, and connection health. Never payloads.