NordLayer

Step-by-step workflows to deploy and use NordLayer for secure remote access
4.6 
Rating
20 votes
Your vote:
No screenshots
Used by 1 person
Notify me upon availability

Need secure connectivity that rolls out in minutes, not months? Treat NordLayer as the access layer you configure once and your team uses every day. Start by creating your organization, connecting your identity provider for single sign-on, and selecting the regions where you want gateways. Invite staff and contractors by email or SCIM, then push the lightweight app to Windows, macOS, Linux, iOS, and Android. Require the Kill Switch and DNS leak protection in the default policy so traffic never spills outside the tunnel. If you need auditing, enable activity logs and device posture checks. From there, employees pick a gateway and get to work—no manual network tweaks required.

Lock down access by role. Build groups for engineering, finance, and vendors; map each to dedicated gateways or site-to-site connectors that reach your office LAN, cloud VPCs, or private apps. Use static IP addresses to satisfy IP allowlists in SaaS tools and payment platforms. Apply split tunneling or per-app routing so only business traffic goes through the tunnel, keeping video calls and streaming local. With policy management, you can enforce MFA, restrict P2P to approved gateways, set content filtering on DNS, and export reports for audits. If performance varies, switch protocols to match the network environment.

Practical workflows look like this: writers connect to a fixed-IP gateway before opening the CMS that only trusts that address; developers pull code from Git and reach CI runners in a VPC via a site-to-site link; finance reconciles invoices in a billing portal that blocks unknown IPs; sales teams join from hotel Wi-Fi while the Kill Switch prevents accidental exposure; support engineers open RDP or SSH through remote access without punching new holes in the firewall. Global teams choose their preferred language in the app and connect to the closest location for lower latency.

Operating at scale is straightforward. Create a contractor profile with time-bound membership and auto-expiring credentials. Use templates to onboard new locations: spin up a gateway, assign a static IP, attach policies, and publish to a group. Offboard in one click by revoking tokens and removing devices. When tickets arrive, help desk runs a quick playbook: confirm the app version, test DNS, toggle protocol, move the user to a nearer gateway, verify the Kill Switch, and review logs. For large file movement, route traffic through an approved P2P-enabled gateway; for compliance, export policy states and connection history. NordLayer turns secure remote access into a repeatable workflow you can measure, automate, and trust.

Review summary

Features

  • Multi-protocol connectivity
  • Apps for Windows, macOS, Linux, iOS, Android
  • Single Sign-On (SSO) integration
  • Kill Switch enforcement
  • DNS leak protection
  • Static IP and dedicated gateways
  • Split tunneling and per-app routing
  • Site-to-site connectors to LAN/VPC
  • Policy management and MFA
  • Activity logging and reporting
  • Remote access for RDP/SSH
  • Anonymous/private browsing
  • Multi-language interface
  • Peer-to-peer controls on approved gateways
  • SCIM user provisioning
  • DNS content filtering

How It’s Used

  • Rapid onboarding of remote employees across devices and platforms
  • IP allowlisting for CMS, CRM, and payment portals using static IPs
  • Secure developer workflows to reach Git, CI/CD, and private registries
  • Traveling staff protection on hotel and public Wi-Fi with Kill Switch
  • Vendor and contractor access with time-bound, scoped permissions
  • Hybrid office-to-cloud access via site-to-site connectors
  • Help desk troubleshooting using protocol switching and logs
  • Large asset transfer through controlled P2P-enabled gateways
  • Compliance reporting with exportable policies and connection history
  • BYOD enforcement of DNS security and mandatory tunneling

Plans & Pricing

Lite

$8.00 per user / month

5 users minimum
Server performance: up to 1Gbs
Shared Gateway locations: 30+ countries
ThreatBlock
VPN protocol variety
NordLynx VPN protocol
Multi-platform app support
Devices per license: 6
Multi-factor authentication
Always On VPN
Auto-connect
SSO
Activity monitoring reports
24/7 tech-minded live/email support

Core

$11.00 per user / month

Includes features of Lite plan, plus
5 users minimum
Virtual Private Gateway locations: up to 30 countries
up to 30 countries
IP allowlisting
DNS Filtering by category
Custom DNSDeep Packet Inspection (lite)
Manual configuration
Biometrics
Device posture monitoring
Server usage analytics

Premium

$14.00 per user / month

Includes features of Core plan, plus
5 users minimum
Cloud Firewall (FWaaS): 10 rules
Device Posture Security
URL-based split tunneling
Site-to-Site connector
Smart Remote Access
Browser Extension
User provisioning

Custom

Custom

Incl;udes features of Premium plan, plus
Virtual Private Gateway locations: up to 60 countries
Cloud Firewall (FWaaS): Custom

Comments

4.6
Rating
20 votes
5 stars
0
4 stars
0
3 stars
0
2 stars
0
1 stars
0
User

Your vote: