Veratype LabVeratype

A self-contained access authority that grants and revokes network reach instantaneously — across ports, apps, and users — inside your own perimeter.

Two ways to run it: integrated air-gap access with an internal ZTNA, or standalone ZTNA anyone can use. On the routers and firewalls you already have — not a new firewall, not a cloud VPN.

What we offer

Two clear paths — pick what you need

Same access authority. Different depth. Choose the integrated air-gap stack, or run ZTNA on its own.

Offer 1

Integrated air-gap with internal ZTNA

For isolated networks that need both time-limited reach on the perimeter and an internal ZTNA for apps. Users request access; Veratype grants and revokes on your existing gear and publishes services inside the same environment.

Offer 2

Standalone ZTNA

For teams that mainly need identity-aware access to internal apps through a service catalog. Run ZTNA on its own — without the full air-gap integration — so anyone can adopt it for everyday app reach.

Your perimeter

Works with the routers and firewalls you already run

Veratype is not a new firewall. It is the access layer that opens and closes reach on devices you already operate — including MikroTik, Fortinet, Sophos, Cisco, pfSense, OPNsense, and other supported gear.

  • Your hardware stays Grants and revokes land on the routers and firewalls you run today. No rip-and-replace.
  • Air-gap when you need it The integrated path keeps control inside your isolated network. No cloud VPN required for core access.
  • Access that ends cleanly Sessions close on timeout, working hours, or policy — temporary reach does not become standing privilege.
Your firewall Veratype access authority grant · revoke

What it governs

Ports, apps, and users — in both offers

Whether you run the air-gap stack or standalone ZTNA, Veratype decides who can get in, what they can touch, and when access stops.

Ports

Time-limited network access

Staff request IP or port access by SMS, API, or passkey. Veratype applies the change on your MikroTik, Fortinet, Sophos, Cisco, pfSense, OPNsense, or other perimeter device, then removes it when the session ends.

Apps

ZTNA for internal services

Publish a service catalog of internal applications. Users authenticate via internal SSO, external LDAP/AD, or federated SSO; policy allows reach only when the person and the time of day both match — as internal ZTNA in the air-gap path, or as standalone ZTNA on its own.

Users

People, groups, and history

Named users, groups, working hours, and session limits — with a clear record of every access grant and revoke.

How it works

Request access. Enforce policy. Close the session.

You keep the firewall. Veratype runs the decision loop — from the access request to enforcement on your devices to automatic teardown.

Request arrives

A user asks for network or app access through SMS, API, passkey, or identity login — whichever channels your admin enabled.

Policy decides

Veratype checks identity, working hours, and session limits, then applies reach on your existing router or firewall, or through the ZTNA edge for apps.

Access ends

When the session times out or policy says stop, Veratype closes that access on your devices — so no one keeps connectivity they no longer need.

Getting started

Deploy on your network — either path

Install next to the network you already protect. Connect the gear you have. Choose integrated air-gap with internal ZTNA, or standalone ZTNA.

  1. Install the appliance

    Deploy on your site. Access decisions stay under your control — not in a vendor cloud.

  2. Connect your gear

    Point Veratype at MikroTik, Fortinet, Sophos, Cisco, pfSense, OPNsense, or other supported routers and firewalls you already operate.

  3. Choose your path

    Enable the integrated air-gap stack with internal ZTNA, or start with standalone ZTNA for app access and grow from there.

FAQ

Common questions

What two things does Veratype offer?

Two paths. First: integrated air-gap access with an internal ZTNA — grant and revoke reach on your perimeter gear and publish apps inside the same isolated environment. Second: standalone ZTNA that anyone can run for identity-aware access to internal services, without the air-gap stack.

What does Veratype air-gap do exactly?

It provides an external control plane for grant and revoke of network reach across the firewalls and routers you already operate. Many perimeter devices lack a unified, policy-driven access workflow — temporary IP or port opens, session expiry, working-hour limits, request channels, and audit — or they only expose those capabilities inside a single-vendor stack. Veratype centralizes that orchestration outside the box, drives the changes onto your existing gear via their native interfaces, and keeps you from adopting one vendor’s access suite just to get those controls.

Does Veratype replace my firewall or router?

No. Veratype sits with the routers and firewalls you already run — for example MikroTik, Fortinet, Sophos, Cisco, pfSense, OPNsense, and other supported devices. It grants and revokes network reach on those devices. It is not a new firewall.

Can Veratype run in an air-gapped network without a cloud VPN?

Yes. The integrated air-gap path is built for isolated networks. The appliance runs inside your perimeter. Core access control does not depend on a cloud VPN or outbound cloud relay.

Who can use standalone ZTNA?

Anyone who wants on-premise, identity-aware access to internal apps through a service catalog — without needing the full air-gap integration. Standalone ZTNA is the lighter path when you mainly need app reach and policy, not the full air-gap stack.

How does Veratype ZTNA handle identity and SSO?

ZTNA includes an internal SSO for users who authenticate against Veratype’s own identity plane. You can also bind authentication to an external directory — LDAP or Active Directory — or federate to an external SSO / IdP so existing corporate logins continue to work. Internal SSO, LDAP/AD, and federated SSO are configuration choices on the same ZTNA path (integrated air-gap or standalone).

Does Veratype support mTLS?

Yes. Veratype supports mutual TLS (mTLS) so both client and server present certificates during the TLS handshake. That gives certificate-based device or service identity in addition to user SSO — useful when you need stronger proof of the endpoint before granting app or network reach.

How do users request network access?

Administrators choose the channels: SMS, API webhooks, passkeys, and identity login for the app catalog. After policy checks, Veratype opens time-limited reach on your existing firewall or router, then closes it when the session ends.

How much does Veratype cost?

Veratype is licensed software. Pricing depends on which path you choose, named users, number of firewalls or routers, and support needs. Request a walkthrough for a tailored quote.

Work with Veratype Lab

Air-gap with internal ZTNA, or standalone ZTNA?

Tell us which path fits, what routers or firewalls you run, and how many users you need to cover. We will arrange a walkthrough.

Or email [email protected]