Home / Features / Remote access without VPN

Remote access without a VPN or port forwarding.

Reach SSH, RDP and VNC on systems behind a firewall or NAT — over outbound connections and dedicated tunnels, with no inbound port forwarding and no VPN dial-in.

Classic remote access to servers or workstations usually means setting up a VPN or opening ports in the firewall. Both are effort, a security risk and often the reason access behind NAT doesn't work at all. Termiverse turns it around: the agent on the target device holds an outbound, TLS-encrypted connection to the server — so the device is reachable without a single port open to the outside.

How it works

Reachable with no open ports

Outbound only

Agents and browsers connect outbound over TLS. No inbound port forwarding and no VPN are needed — not even behind NAT or carrier-grade NAT.

Tunnel with a target allowlist

For SSH, RDP and VNC to systems behind the firewall there are dedicated tunnel endpoints with a target allowlist (host/CIDR + ports). Normal agents cannot be abused as a proxy.

Wake-on-LAN included

Powered-off machines can be woken over the tunnel via Wake-on-LAN before you connect — ideal for maintenance outside working hours.

Benefits

Why going without a VPN is better

FAQ

Frequently asked questions

Do I really need no port forwarding?
No. Agents and browsers connect outbound over TLS only. No inbound port has to be opened in the firewall.
How secure is the tunnel?
Tunnel endpoints are managed separately and restricted to a target allowlist (host/CIDR + ports). Normal agents cannot be abused as a proxy into other networks.
Does it work with RDP and SSH at the same time?
Yes. Over the tunnel you reach SSH, RDP and VNC to targets behind the firewall — in the browser, with no local client.
Can I reach powered-off devices?
Via Wake-on-LAN a machine behind the firewall can be woken before you establish the connection.
Learn more

Related pages

Ready to run everything from one deck?

Start with the base plan or talk to us about the self-hosted option.

See pricing →