A normal VPN
If the tunnel drops, traffic still goes out over the home or coffee-shop network. The user never notices and the call travels where it should not.
Most VPNs depend on the employee remembering to connect. TelHarbor's does not: if the tunnel is not up and validated, the softphone, the chat and remote support simply do not start. There is no way to work outside it.
It is a design decision, not a configuration checkbox.
If the tunnel drops, traffic still goes out over the home or coffee-shop network. The user never notices and the call travels where it should not.
Without an active, validated tunnel the services do not start. You lose the convenience of "carrying on regardless" and you gain that corporate traffic is never outside the tunnel.
Telephony, chat, remote support, terminal and file transfer. Everything that touches the operation goes through it or does not go at all.
The classic corporate VPN mistake is a single configuration file circulating by email.
Here each device has its own key pair and its own address inside the network. Nobody shares credentials, so you always know which specific device connected, not "the sales user".
When someone leaves or loses a laptop, that device is revoked from the portal and stops connecting immediately. No changing everyone else's key and no handing out a new file.
Split tunnel means only corporate traffic enters the tunnel. The employee's personal browsing goes out over their own connection: it neither loads the company link nor parades their private life past it.
Not a fad: three properties you notice in daily use.
Switching from Wi-Fi to mobile data, the tunnel re-establishes with no intervention. Mid-call, that is the difference between a blip and a dropped call.
It uses less battery and CPU than traditional VPNs, which matters on laptops and phones.
A small, auditable protocol with modern cryptography and none of the tangled configuration of the alternatives.
The VPN is part of the TelHarbor UCaaS platform: provisioned with the device, managed from the same portal that holds extensions and users, and it needs no dedicated network team to run.
That if the tunnel is not up and validated, the services do not start: no softphone, no chat, no remote support, no terminal, no file transfer. In a normal VPN the traffic would go out over the local network without the user noticing.
Their device is revoked from the portal and stops connecting immediately. Because each device has its own key pair, nothing changes for anyone else.
No, because it uses split tunnel: only corporate traffic enters the tunnel. Personal browsing goes out over the employee's own connection.
Yes. WireGuard re-establishes the tunnel by itself when the network changes, which is exactly what stops a call in progress from dropping.
No. It is part of the UCaaS platform and is provisioned along with the device, from the same portal where extensions and users are managed.