Skip to content

A VPN nobody can forget to switch on.

Service overview

Most VPNs depend on the employee remembering to connect. TelHarbor's does not: if the tunnel is not up and validated, the softphone, the chat and remote support simply do not start. There is no way to work outside it.

Fail-closed: the difference is what happens when it fails.

It is a design decision, not a configuration checkbox.

A normal VPN

If the tunnel drops, traffic still goes out over the home or coffee-shop network. The user never notices and the call travels where it should not.

Fail-closed

Without an active, validated tunnel the services do not start. You lose the convenience of "carrying on regardless" and you gain that corporate traffic is never outside the tunnel.

What it protects

Telephony, chat, remote support, terminal and file transfer. Everything that touches the operation goes through it or does not go at all.

One key per device, not one for everyone.

The classic corporate VPN mistake is a single configuration file circulating by email.

Here each device has its own key pair and its own address inside the network. Nobody shares credentials, so you always know which specific device connected, not "the sales user".

When someone leaves or loses a laptop, that device is revoked from the portal and stops connecting immediately. No changing everyone else's key and no handing out a new file.

Split tunnel means only corporate traffic enters the tunnel. The employee's personal browsing goes out over their own connection: it neither loads the company link nor parades their private life past it.

Softphone
Chat
Remote support
Terminal
File transfer
Portal

Why WireGuard.

Not a fad: three properties you notice in daily use.

It reconnects itself

Switching from Wi-Fi to mobile data, the tunnel re-establishes with no intervention. Mid-call, that is the difference between a blip and a dropped call.

Light on resources

It uses less battery and CPU than traditional VPNs, which matters on laptops and phones.

Smaller attack surface

A small, auditable protocol with modern cryptography and none of the tangled configuration of the alternatives.

Who it makes sense for

  • Teams serving customers from home.
  • Companies with several sites.
  • Operations where calls carry sensitive data.
  • Anyone who needs to know which device connected and when.
  • Anyone who does not want their PBX exposed to the internet.

It comes included, not quoted separately.

The VPN is part of the TelHarbor UCaaS platform: provisioned with the device, managed from the same portal that holds extensions and users, and it needs no dedicated network team to run.

FAQ

Frequently asked questions about the business VPN

What does a fail-closed VPN mean?

That if the tunnel is not up and validated, the services do not start: no softphone, no chat, no remote support, no terminal, no file transfer. In a normal VPN the traffic would go out over the local network without the user noticing.

What happens when an employee leaves?

Their device is revoked from the portal and stops connecting immediately. Because each device has its own key pair, nothing changes for anyone else.

Will the VPN slow down browsing?

No, because it uses split tunnel: only corporate traffic enters the tunnel. Personal browsing goes out over the employee's own connection.

Does it work when I switch from Wi-Fi to mobile data?

Yes. WireGuard re-establishes the tunnel by itself when the network changes, which is exactly what stops a call in progress from dropping.

Is it charged separately?

No. It is part of the UCaaS platform and is provisioned along with the device, from the same portal where extensions and users are managed.