Access to your internal network via VPN
Last updated: October 9, 2026
For Strike to assess assets that are only reachable from your internal network, we need VPN access. This article explains which methods we support, what to have ready before you start, and what options exist if your organization uses a different tool.
Supported access methods
Strike currently supports two VPN methods:
Method | Required file |
|---|---|
WireGuard |
|
OpenVPN |
|
Files are stored encrypted and masked across the platform.
Before you start
Have the following information ready:
Which in-scope assets are only reachable through your VPN.
A WireGuard (
.conf) or OpenVPN (.ovpn) profile generated for Strike. We recommend creating a dedicated profile, separate from the one used by your internal users.Who on your team can generate or modify that profile if needed.
Your Strike contact will let you know how to share the profile during onboarding. Before testing begins, we validate that Strike can connect to your network successfully.
If you use a different access method
If your organization uses another remote access tool, for example Fortinet, Palo Alto GlobalProtect, Cisco AnyConnect, or a ZTNA solution, contact your Strike representative. Our team will review your setup and confirm whether we can enable your access method. If it is feasible, setup usually takes around 5 business days.
In the meantime, or if you prefer not to wait, these options usually work:
Generate a WireGuard or OpenVPN profile for Strike. Many teams can enable one for an external testing provider, even if they use a different tool internally.
Start with the assets that don't need a VPN, such as web applications and APIs exposed to the internet. Testing can begin right away, and the assets behind your VPN are added once access is resolved.