QUICK START

Your first private connection.

A verified account, a workspace and two devices.

Windows desktop preview

Download and run the Windows installer, then open AsterSecureConnect from the Start menu. In your workspace's Client downloads, select Open desktop app, then Sign in & connect. Complete browser sign-in and approve the Windows permission request. Device approval and access rules still apply.

Disconnect stops the tunnel and disables automatic startup. Closing the window keeps the app in the tray; Quit closes the interface without stopping the tunnel. Windows 10/11 x64 and .NET Framework 4.8 are required. Publisher signing and real-device tunnel acceptance are still pending.

01

Create your workspace.

Register with your email, verify your address and set up multi-factor authentication. Create a workspace, or accept an invitation from its owner.

02

Install on Linux.

Open Client downloads in your workspace console. Run the Install command, then the Connect workspace command. Your control address, workspace and verified release are already included. Linux x86_64 with systemd is required.

03

Approve and connect.

Complete the browser sign-in and approve the device in the console. The systemd service runs in the background and starts on boot. Repeat for your second device, then use their private IPs for SSH, HTTP or ping.

sudo systemctl status astersecureconnect
sudo journalctl -u astersecureconnect -f
04

Set access deliberately.

New workspaces include an allow-all rule for approved devices and subnets within that workspace. Narrow it with ordered rules: the first matching rule wins, and unmatched traffic is denied.

05

Extend to a private subnet.

Enroll a Linux gateway, select NAT or routing-only forwarding, and publish its subnet. Approve the route and permit the intended traffic in access rules. Routing-only mode also requires a return route on the destination network.

Troubleshooting

Relay certificate signed by unknown authority

Use the current client from this deployment; trial downloads include deployment-bound relay trust. Do not disable certificate verification.

Moving an existing Linux device to systemd

Stop its foreground agent. In Client downloads, open Service & existing device and enter the absolute path to its agent.json. The connection command imports the same identity without deleting the original file.

Devices are approved but cannot ping

Check Connections in the console for route, ACL and reported path status. Verify the destination service, host firewall and TUN support separately.

Does a relay make my connection faster?

Not necessarily. A direct path can be faster than a cross-region relay path. Compare measurements over the same interval; a small sample is not a reliability guarantee.