Deployment
A licensed platform, run in your own network.
§1 The offer
The licensed platform
The lead offer is a licensed platform. The licensee runs the whole service in its own network, under its own identity, for its own customers. E^NAT IP licenses the software.
The licensee is the service operator. Its service sits between field devices and owners' VPN gateways, and holds the address translation, the device records and the owner connections. Telcos and managed service providers can run MSL-aaS this way as part of their own service.
§2 Roles
Who does what
Operator (the licensee)
Runs and administers the service in its own network, under its own identity.
Tenant
Enrols clients and requests access for them to owners' networks.
Owner
Holds a private network, authorizes which clients may reach it, and sets its NAT binding policy.
§3 Operator limits
Running the service does not mean controlling owners' networks
- The operator can tighten an owner's policy but not loosen it.
- The operator cannot authorize access to an owner's network or create NAT bindings on an owner's side.
- Every operator action is recorded in the hash-chained audit log.
- Tenants hold their own private keys, and the service pins certificates, so an operator acting as a tenant would be detectable.
Known limit: the operator runs the certificate authority. Misuse is designed to be detectable through certificate pinning and audit, not impossible.
§4 Choices
Decisions that stay with the licensee and its customers
- Where it runs. Deployment in a particular region is a choice the licensee makes.
- Who joins. Tenancy is by enrolment only; there is no public sign-up.
- Owners' side. The design requires no changes inside an owner's network; the service connects to the owner's existing VPN gateway as a standard peer. The service peers with gateways that speak WireGuard, or IPsec with IKEv2 and a pre-shared key.
- Leaving. Owner data is held in plain, exportable form, and the owner side is a standard IPsec or WireGuard peer.
§5 Build
What it is built from
Standard-library code over standard system components: nftables, WireGuard, strongSwan and OpenSSL.