Master da Web
Managed VPN Gateway · remote access + site-to-site

Business VPN for your team and every office, in one gateway

VPN Gateway brings remote access over OpenVPN and site-to-site VPN over IPsec IKEv2 or WireGuard together in one managed service, inside the same cloud as your Cloud Servers. You add the people and pick the router; we hand you a ready-made configuration, watch every tunnel and look after the server.

  • Unlimited VPN users
  • Ready-made config for your router
  • No extra charge for traffic

On WhatsApp: get your questions answered and a plan recommendation for your network.

From

R$84.92/month on the annual plan

or R$99.90/month billed monthly

2 in 1

People and offices on the same gateway, with one public IP and one bill

VPN users on every plan, each with their own login

9

Platforms with a ready-made config: MikroTik, pfSense, FortiGate, Cisco, AWS, Azure and more

30 s

How often the gateway reports the real state of every tunnel

Two ways in

People from anywhere. Whole offices. The same door.

Remote access and site-to-site VPN do not have to be two products. Here they live on the same gateway: one public address, one panel and one bill.

Remote access · for people

Your team inside the network, wherever they are

Each person gets their own user and an OpenVPN profile. From a laptop at home or a phone on the road, they reach your servers by private IP, over an encrypted tunnel, as if they were in the office.

  • Profiles for Windows, macOS, Linux, iOS and Android
  • Credentials sent by email
  • Suspend one person without disconnecting anyone else
  • UDP for speed or TCP 443 for restrictive networks

Connected now

  • ana.souza

    10.8.0.6 · 2h14 ago

    Connected
  • carlos.lima

    10.8.0.9 · 38 min ago

    Connected
  • contractor.ext

    Access suspended

    Suspended
Site-to-site · for places

The whole office joined to the cloud, with nothing to install

A site-to-site connection joins the network of an office, a branch or another cloud to your private network. The router carries the tunnel, and machines on both sides can reach each other — no VPN client on every computer.

  • IPsec IKEv2 or WireGuard, whichever your router supports
  • A configuration file ready to paste
  • Works even when the office has a dynamic IP
  • A strong pre-shared key generated for you

Site-to-site connections

  • São Paulo head office

    IPsec IKEv2 · 192.168.10.0/24

    Connected
  • Belo Horizonte branch

    WireGuard · 192.168.20.0/24

    Connected
  • AWS us-east-1

    IPsec IKEv2 · 172.31.0.0/16

    Connecting
Site-to-site VPN without the headache

Pick your router. The VPN configuration comes ready.

Configuration is where most IPsec tunnels get stuck: encryption proposals, networks on each side, NAT, firewall. In the panel you pick the device, enter the office networks and download a complete file, including the NAT and firewall rules that device needs.

  1. 1

    Pick the device

    MikroTik, pfSense, OPNsense, FortiGate, Cisco, Linux, AWS, Azure or any IPsec or WireGuard device.

  2. 2

    Enter the site's networks

    The panel validates the ranges before applying and refuses anything that overlaps your VPC.

  3. 3

    Paste and connect

    Apply the file on the router and watch the tunnel come up in the panel.

head-office.rsc · RouterOS 7
Ready to paste
# mw-matriz-sp — site-to-site to 198.51.100.20# Paste into the RouterOS terminal. Safe to re-run./ip ipsec profileadd name=mw-matriz-sp hash-algorithm=sha256 enc-algorithm=aes-256 dh-group=ecp256,modp2048 dpd-interval=30s/ip ipsec proposaladd name=mw-matriz-sp auth-algorithms=sha256 enc-algorithms=aes-256-gcm pfs-group=ecp256/ip ipsec peeradd name=mw-matriz-sp address=198.51.100.20/32 exchange-mode=ike2 profile=mw-matriz-sp/ip ipsec identityadd peer=mw-matriz-sp auth-method=pre-shared-key secret="••••••••••••••••"/ip ipsec policyadd peer=mw-matriz-sp tunnel=yes src-address=192.168.10.0/24 dst-address=10.200.0.0/24/ip firewall natadd chain=srcnat action=accept place-before=0 src-address=192.168.10.0/24 dst-address=10.200.0.0/24

VPN configurations generated for

  • MikroTikReady-made file
  • pfSenseReady-made file
  • OPNsenseReady-made file
  • FortiGateReady-made file
  • Cisco IOSReady-made file
  • LinuxReady-made file
  • WireGuardReady-made file
  • AWSValues sheet
  • AzureValues sheet

Another device?

If it speaks IPsec IKEv2 or WireGuard, it works: you get a sheet with every parameter.

Check my device
Built for the real world

What usually breaks a VPN tunnel, solved in advance

Dynamic IP at the office? No problem

The office router starts the connection and the gateway recognises it by its own identity, not its address. When the ISP changes the IP, the tunnel re-establishes — no static IP, no dynamic DNS.

Diagnostics in plain language

If a tunnel will not come up, the panel says why: a different key on each end, incompatible encryption, networks that do not match, or the other end never trying — and what to do about each.

A strong key you can replace

The pre-shared key is 40 characters, generated in a format that survives being pasted into any router, and can be replaced at any time. Every time it is shown is recorded in your activity log.

Routes delivered to your VPC

Each site's networks are announced to your VPC servers over DHCP, and the gateway allows forwarding between both sides. No routing to configure on the gateway.

The real state of every tunnel

Connected, connecting or down, with traffic per connection, refreshed every 30 seconds. If the gateway has not reported, the panel says it does not know — it never invents an outage.

Grows with your business

From 1 to 10 site-to-site connections included, depending on the plan. Opened another branch? Move to a larger plan and your existing connections keep working.

VPN Gateway plans

Every feature on every plan. Choose by capacity.

Unlimited users, a dedicated public IP, remote access and site-to-site on any plan. Larger plans carry more simultaneous connections and more sites.

VPN Gateway 1G

For small teams and one office

R$99.90/month

Billed monthly

  • 1 vCPU · 1 GB RAM
  • ~10 simultaneous users*
  • 1 site-to-site connection
  • Unlimited VPN users
  • Public IP included
  • OpenVPN, IPsec IKEv2 and WireGuard
  • 1 Gbit network, no traffic charges
  • 24/7 support
I want this plan

VPN Gateway 2G

For a head office and a branch

R$129.90/month

Billed monthly

  • 2 vCPU · 2 GB RAM
  • ~20 simultaneous users*
  • 2 site-to-site connections
  • Unlimited VPN users
  • Public IP included
  • OpenVPN, IPsec IKEv2 and WireGuard
  • 1 Gbit network, no traffic charges
  • 24/7 support
I want this plan
Most popular

VPN Gateway 4G

For businesses with several branches

R$199.90/month

Billed monthly

  • 3 vCPU · 4 GB RAM
  • ~40 simultaneous users*
  • 5 site-to-site connections
  • Unlimited VPN users
  • Public IP included
  • OpenVPN, IPsec IKEv2 and WireGuard
  • 1 Gbit network, no traffic charges
  • 24/7 support
I want this plan

VPN Gateway 8G

For operations with many locations

R$299.90/month

Billed monthly

  • 4 vCPU · 8 GB RAM
  • ~80 simultaneous users*
  • 10 site-to-site connections
  • Unlimited VPN users
  • Public IP included
  • OpenVPN, IPsec IKEv2 and WireGuard
  • 1 Gbit network, no traffic charges
  • 24/7 support
I want this plan

*Typical-use estimate; varies with each team's traffic and applications.

Not sure which plan?Talk to an expert on WhatsApp
Remote access with OpenVPN

From first access to monitoring, all in the panel

People, profiles and connections managed without opening a terminal.

Users and credentials

Create as many users as you need, each with their own login. Email the credentials, reset passwords and suspend access while keeping the account.

  • Unlimited users
  • Sent by email
  • Suspend without deleting

Connection profiles

Download the .ovpn file or create a temporary download link for whoever is connecting. The same profile works in any OpenVPN client.

  • Windows and macOS
  • Linux
  • iOS and Android

Network under your control

UDP on port 1194 for speed or TCP on 443 to get through restrictive networks, adjustable MTU, and the option for one user to connect several devices.

  • UDP 1194 or TCP 443
  • Adjustable MTU
  • Several devices per user

Live connections

See who is connected right now, from which real IP, with which virtual IP, for how long and how much traffic has passed.

  • Active sessions
  • Real and virtual IP
  • Traffic per session
NAT Gateway mode

Servers with no public IP, reaching the internet through an IP you know

Mark the gateway as the default route and your whole VPC reaches the internet through it. Servers without a public address get a way out, and all traffic leaves from a single IP — easy to allowlist at a partner, a bank or an API.

  • Fewer public IPs to pay for
  • One egress IP for allowlists
  • VPC servers out of direct reach from the internet
VPC servers
VPN Gateway
Internet

All outbound traffic uses the gateway's public IP

Part of your cloud

VPN Gateway protects the cloud your servers already run in

The gateway sits inside your VPC, next to your Linux and Windows Cloud Servers. Order it together with your instances or add it to a private network you already use.

Engineering you never see

Built to keep working when something goes wrong

An agent inside the gateway checks every change before applying it and undoes anything that fails. You only see the result.

Automatic rollback

Every change goes through a health check. If something does not answer as it should, the gateway returns to its previous configuration by itself and the panel shows what failed.

Changes without disconnecting anyone

Adding, suspending or removing a person is applied while the service runs. Whoever is connected stays connected.

Signed commands

The gateway only runs instructions digitally signed by the platform and checks every signature before acting. No remote session is kept open to manage it.

Profiles that survive updates

The certificate authority and connection parameters are preserved across updates and reinstalls. The profile your team already uses keeps working.

Networks validated before applying

Ranges that overlap your VPC, the remote-access pool or another site are refused with an explanation, before they break routing.

Modern encryption

AES-GCM with SHA-2 for OpenVPN and IPsec, and WireGuard for those who prefer simplicity. Obsolete algorithms such as DES are never offered.

Why managed

VPN Gateway, or build your own VPN on a VPS?

What mattersMaster da Web VPN GatewayYour own VPN on a VPS
Server setup, updates and securityHandled by usUp to you
Remote access and site-to-siteOn the same gatewayTwo services to configure
Office router configurationReady-made fileBy hand, by trial and error
A change that goes wrongAutomatic rollbackYou find out when it drops
User managementIn the panel, with email deliveryFrom the command line
Tunnel diagnosticsIn the panel, in plain languageReading logs
Support24/7Up to you
How it works

From first conversation to first tunnel in four steps

  1. 01

    Talk to us

    Tell us about your operation and we recommend the right plan. The gateway is created in your VPC with its own public IP.

  2. 02

    Add your team

    Create users and email their credentials straight from the panel.

  3. 03

    Connect your offices

    Pick the router, download the ready-made configuration and apply it.

  4. 04

    Watch everything

    Connected people, active tunnels and traffic, in the same panel.

Your private network, open only to those who should get in

Tell us how many people and how many offices you want to connect. Our team recommends the plan, explains every step and stays with you until your first tunnel is up.

Customers

Success Stories

See what our clients say about our cloud infrastructure

We continue with Master da WEB for maintaining a stable service today, with performance and availability of services very satisfactory, aligned with good cost-benefit, in addition to having qualified technical support that meets our demands satisfactorily.
ITC Services logo

Bosco JR.

ITC Services

FAQ

Frequently Asked Questions

Clear answers to the most common questions about our services.