Loading_
Loading_
Time-bound, approval-gated VPN access across FortiGate, Palo Alto and Cisco with automatic expiry.
Measured outcomes
2,840
Stale grants removed
6 min
Median request to active
3
Firewall vendors unified
0
Manual rule edits
VPN access was granted permanently and reviewed annually, which meant contractors from three years ago still had tunnels. Removal depended on someone remembering.
Access is now requested for a purpose and a duration. Approval is routed by target network sensitivity, the rule is pushed to the right firewall, and it expires on its own.
Headline result
0%
access time-bound
Tags
Five capabilities that define the system. Each one exists because something specific was broken.
One request model renders FortiOS, PAN-OS and Cisco ASA/FTD configuration.
Grants carry a TTL; revocation is scheduled at creation, not remembered later.
Approval chain is derived from the target network zone, not the requester’s seniority.
Break-glass path with shortened TTL and mandatory post-incident review.
Recurring grants require re-justification on a configurable cadence.
A vendor-neutral access model compiled into device-native config, pushed through a change-controlled pipeline.
3 components
Zones are classified once; every request inherits the right chain.
3 components
Config is diffed against the running device before push.
3 components
Expiry is a first-class scheduled job with retry and alerting.
No mystery components. Everything below is either open source or a platform you already own.
Interactive mock-ups of the shipped interface. The live environment is available during a demo session.
Purpose, duration and target zone selection
The running environment is available during a booked session — including a sandbox tenant you can drive yourself.
The real sequence, in order. Steps with a command are copy-pasteable.
Helm release with Vault integration for device credentials.
$helm install vpn-portal aiinfraengine/vpn-portalRegister each firewall with a scoped API account and validate connectivity.
$aiinfraengine net device add --vendor fortinet --host fw01.corp.localTag target networks with sensitivity and map approval chains.
Import current rules, assign owners and set expiry dates.
Published rather than hidden behind a call. Volume and multi-year terms move these numbers.
Platform
$2.20per user / month
Deployment
from $31kone-time
Need this scoped against your estate? We will size it properly, in writing, within a week.
Request a quoteWe will walk you through the architecture, the trade-offs we made, and what would change for your environment.