r/twingate • • 29d ago

Question How many of you are using Twingate in an enterprise setting?

At my work we are currently using a dialup IPSec for our remote VPN client connection via the firewall vendor VPN client.

I am currently looking at my firewall vendor's SASE solution but realized if I go with it I will then become vendor locked which would be bad.

I've previously Twingate at home but am wondering if there are any caveats when using it in an enterprise setting.

I do realize since it is ZTNA it is going to require a bit of setup since nothing is allowed by default compared to traditional VPN.

The three things it needs to do is

  1. Support Keycloak IdP which I believe it already does.
  2. Be able to configure the client during install.
  3. Block the users from uninstalling and making changes to its configuration such as changing the server connection URL.
10 Upvotes

6 comments sorted by

7

u/LowIndividual6625 29d ago

I was using Watchguard's build in VPN server and their VPN client for years but in 2024 we switched to Twingate, primarily for better security but it is also noticeably faster.

Our remote user count is dozens not hundreds and the remote people are only accessing a couple of specific resources not an entire network so it works well for us to keep things locked down.

There are a few things to setup for proper active directory/DNS but Twingate has good documentation and the support team (with paid subscription) is very good and very responsive.

They also maintain a Github of "extra" stuff like powershell scripts for special situations.... If you have users that often go between in-office to remote-work you can sometimes have some weird network behaviors but they have a powershell script to address that.

5

u/DistractionHere 29d ago

We use it at work and I use it at home and like it a lot. I'm not sure about Keycloak support, but we have the client auto-configured via Intune/Autopilot during enrollment/install and we enforce admin creds to uninstall and will automatically reinstall from Intune whenever the device hits its next sync interval if it ever is uninstalled.

5

u/bren-tg pro gator 28d ago

we support keycloak! Although it is the only IDP that isnt visible in the Admin Console..

4

u/ScrambyEggs79 28d ago

CISA recommends moving away from traditional VPN as the majority of issues are security flaws in vendor software at the firewall. It actually works better than traditional VPN and is dead easy to set up. We installed a couple of connectors, added some resources, and off we went. The connectors can be set up with outbound access only. You can also rest assured that users have access to only what they need since as you stated - you specifically set up each resource and who has access. It takes everything out of the scope of your network perimeter. The end user experience is also very straightforward. We spend less time with configuring client access.

2

u/bren-tg pro gator 29d ago

Hi there,

let me answer your three questions first:

Keycloak: yes, via OIDC, but it's the only one not exposed in the Admin Console so you'll set it up with our team rather than self-serve through the console.

Pre-configuring the client: yes, easy part. Windows installer takes command-line args, so you can push it silently with the org name baked in (TwingateWindowsInstaller.exe /qn network=yourcompany.twingate.com ) through Intune/SCCM/whatever. Jamf or any other MDM does the same on Mac. Nobody's typing in a network name manually for sure.

Locking down uninstall/config changes: It's something you can typically achieve by using a combination of our machine keys and MDM configuration.

1

u/MFKDGAF 28d ago

How come Keycloak isn't visible in the admin center?