MiroxMirox
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Tickets
    • Forecasts
    • Reports
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Cooperations
    • File Storage
    • VPN Services
  • Data Export

    • Export Metric API
    • MiroxQL Query Language
    • External Report Generation
    • Grafana
    • API Overview
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Raw Data Export for Excel
  • Remote Access
  • AI in Mirox
  • History Import
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Tickets
    • Forecasts
    • Reports
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Cooperations
    • File Storage
    • VPN Services
  • Data Export

    • Export Metric API
    • MiroxQL Query Language
    • External Report Generation
    • Grafana
    • API Overview
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Raw Data Export for Excel
  • Remote Access
  • AI in Mirox
  • History Import
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Setting Up Two-Factor Authentication
    • Managing Your Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Managing Plant Contacts
    • Managing Network Devices
    • Configuring Data Loggers
    • Configuring Components
    • Configuring VPN Servers per Agent (Direct VPN)
    • Data Volume per Plant
    • Importing a Plant's History
  • Organization

    • Managing Member Permissions
    • Creating Cooperations
    • Using File Storage
    • Organization VPN Services
  • Data Export

    • Export Metric API
    • MiroxQL Query Language
    • External Report Generation
    • Using Grafana as an External Read Platform
    • API Overview
  • Support

    • Request an Integration
  • mrxnode

    • mrxnode Overview
    • mrxnode How-To Guide
    • Container Deployment
    • mrxnode Command Cheatsheet
    • Troubleshooting

Organization VPN Services

An organization VPN service connects Mirox to a shared VPN gateway on your own network — one tunnel that several plants sit behind. Where a direct VPN is a per-plant tunnel to that plant's own router, an organization VPN is the right shape when your plants are already reachable through one central gateway: a headquarters firewall, a telecontrol network, or a carrier-managed VPN concentrator.

You manage VPN services in the Organization settings, on the VPN tab.

Open in Mirox

Open your organization's VPN services. In the app: Organization settings, VPN tab.

Concept

  • One VPN service = one WireGuard tunnel from Mirox to your gateway. Organization VPN services are WireGuard-only; a plant whose router needs OpenVPN or IPsec uses a direct VPN instead.
  • Plants are assigned to the service, each with the subnet (network range) that hosts its devices behind the gateway. Mirox routes exactly those ranges through the tunnel — never everything.
  • The same tunnel serves monitoring (data collection from loggers and inverters) and remote access for your team, subject to the normal permission system.
  • Each plant's Networking page shows the assigned VPN with its live connection state; the plant's connection pipeline on the Overview tab includes the VPN as its own stage.

The VPN Services Table

ColumnWhat it tells you
NameThe service's name in your organization.
TypeThe tunnel protocol — WireGuard.
ParksHow many plants are assigned to this service.
RegionWhich Mirox cloud region terminates the tunnel.
StatusWhether the service is active, paused, or still being rolled out.
AvailabilityThe tunnel's connection history.
TrafficBytes exchanged through the tunnel recently.

Creating a VPN Service

  1. Click Create VPN service.
  2. General — name and optional description.
  3. WireGuard Config — upload the gateway's WireGuard configuration file (.conf) or enter the endpoint, keys and allowed ranges manually. This is the configuration of your gateway — Mirox dials it.
  4. Save. Mirox rolls the tunnel out; the status switches to active once the gateway answers.

Who can manage VPN services

Creating, editing, pausing and deleting VPN services — and assigning plants — requires an organization Moderator or Admin. VPN configurations are never editable through job-level or cooperation permissions.

Assigning Plants

Each assignment maps one plant to the subnet that hosts its devices behind the gateway:

  1. Open the service and choose Assign park.
  2. Pick the plant and enter its subnet (CIDR), e.g. 10.20.30.0/24.
  3. Optionally set a ping endpoint — a device inside that subnet (typically the gateway's inner address or a logger) that Mirox probes to judge whether the plant network behind the tunnel is actually reachable, not just the tunnel itself.

After assignment the plant's data collection and network device discovery run through the shared tunnel. A plant can combine an organization VPN with additional direct VPNs — devices are matched to the tunnel whose subnet contains them.

Operating a VPN Service

  • Pause / Resume — pausing keeps the configuration but stops the tunnel; every assigned plant's site network becomes unreachable until an admin resumes it. Paused is an intentional state: the plants' Networking pages show a banner rather than an error.
  • Restart — cycles the tunnel without changing configuration; useful after changing settings on your gateway.
  • Change region — moves the Mirox end of the tunnel to a different cloud region, e.g. after latency or routing changes on your side. Expect a short reconnect.
  • Edit — update name, description, or the WireGuard configuration (for example after rotating keys on your gateway).
  • Delete — removes the service; assigned plants keep their monitoring but lose the shared route to their devices. Reassign those plants to another VPN or set up direct VPNs first.

Tunnel up, plant down?

The service's availability reflects the tunnel to your gateway. Whether each plant's network behind the gateway answers is judged separately (the ping endpoint and the monitored devices). A healthy tunnel with a silent plant network points at routing on your gateway or the plant's local network — not at the VPN service.

Who Can Configure It

RoleVPN services
Organization Admin / ModeratorCreate, edit, pause/resume, restart, change region, assign/remove plants, delete
Technical Manager on a plantSees the assigned VPN's state on the plant's Networking page
Other roles / cooperation partnersSee connection status where they can see the plant; no configuration access

Distinction From Related Concepts

ConceptWhat it connectsScopeWho controls it
Organization VPN service (this page)Mirox ↔ one shared gateway on your networkSeveral plants behind one gatewayOrg Moderator/Admin
Direct VPNOne plant's agent ↔ that plant's own routerOne plantOrg Moderator/Admin
Personal VPNOne user's device ↔ all their authorized plantsPer userEach user
Browser ProxyThe browser ↔ one device web interfacePer device, on demandPlant operator

Related Features

  • Direct VPN — the per-plant alternative when there is no shared gateway
  • Using the VPN — the personal profile for individual remote access
  • Managing Network Devices — discovery and monitoring through the tunnel
  • Local Network Inspector — how reachability through the tunnel is judged
  • Access Audit Logging — the audit trail covering all remote access
Prev
Using File Storage
MIT Licensed | Copyright 2026 Mirox Verwaltungs GmbH | Privacy