Need secure connectivity that rolls out in minutes, not months? Treat NordLayer as the access layer you configure once and your team uses every day. Start by creating your organization, connecting your identity provider for single sign-on, and selecting the regions where you want gateways. Invite staff and contractors by email or SCIM, then push the lightweight app to Windows, macOS, Linux, iOS, and Android. Require the Kill Switch and DNS leak protection in the default policy so traffic never spills outside the tunnel. If you need auditing, enable activity logs and device posture checks. From there, employees pick a gateway and get to work—no manual network tweaks required.
Lock down access by role. Build groups for engineering, finance, and vendors; map each to dedicated gateways or site-to-site connectors that reach your office LAN, cloud VPCs, or private apps. Use static IP addresses to satisfy IP allowlists in SaaS tools and payment platforms. Apply split tunneling or per-app routing so only business traffic goes through the tunnel, keeping video calls and streaming local. With policy management, you can enforce MFA, restrict P2P to approved gateways, set content filtering on DNS, and export reports for audits. If performance varies, switch protocols to match the network environment.
Practical workflows look like this: writers connect to a fixed-IP gateway before opening the CMS that only trusts that address; developers pull code from Git and reach CI runners in a VPC via a site-to-site link; finance reconciles invoices in a billing portal that blocks unknown IPs; sales teams join from hotel Wi-Fi while the Kill Switch prevents accidental exposure; support engineers open RDP or SSH through remote access without punching new holes in the firewall. Global teams choose their preferred language in the app and connect to the closest location for lower latency.
Operating at scale is straightforward. Create a contractor profile with time-bound membership and auto-expiring credentials. Use templates to onboard new locations: spin up a gateway, assign a static IP, attach policies, and publish to a group. Offboard in one click by revoking tokens and removing devices. When tickets arrive, help desk runs a quick playbook: confirm the app version, test DNS, toggle protocol, move the user to a nearer gateway, verify the Kill Switch, and review logs. For large file movement, route traffic through an approved P2P-enabled gateway; for compliance, export policy states and connection history. NordLayer turns secure remote access into a repeatable workflow you can measure, automate, and trust.
Lite
$8.00 per user / month
5 users minimum
Server performance: up to 1Gbs
Shared Gateway locations: 30+ countries
ThreatBlock
VPN protocol variety
NordLynx VPN protocol
Multi-platform app support
Devices per license: 6
Multi-factor authentication
Always On VPN
Auto-connect
SSO
Activity monitoring reports
24/7 tech-minded live/email support
Core
$11.00 per user / month
Includes features of Lite plan, plus
5 users minimum
Virtual Private Gateway locations: up to 30 countries
up to 30 countries
IP allowlisting
DNS Filtering by category
Custom DNSDeep Packet Inspection (lite)
Manual configuration
Biometrics
Device posture monitoring
Server usage analytics
Premium
$14.00 per user / month
Includes features of Core plan, plus
5 users minimum
Cloud Firewall (FWaaS): 10 rules
Device Posture Security
URL-based split tunneling
Site-to-Site connector
Smart Remote Access
Browser Extension
User provisioning
Custom
Custom
Incl;udes features of Premium plan, plus
Virtual Private Gateway locations: up to 60 countries
Cloud Firewall (FWaaS): Custom
Comments