VPN Works Live demo How to run it
Loading the engine

Step 1 of 6

See what the agent does

Linux terminal, replayed from the recorded run
opened denied by the policy could not be reached deciding
0
connections
0
opened
0
denied
0
failed
not sent yet
the deploy token

What vpnw recorded

#DestinationPathDecisionResultSent / received
Nothing yet.

Run the agent under your own policy

Edit the policy, choose a path and run the agent's five requests again. Each decision is made by the Alpha's policy engine, compiled for this page. Whether a server then answers comes from the recorded demo network: the public names resolve on the direct path, and the office exit knows the tracker as well.

The same command as on Linux: vpnw guard --policy agent.toml -- python3 agent.py

Test one destination

Ask the engine about any host and port, under the policy above. For a name, you can say what it resolves to, to see how the policy treats the answer. The examples include the tricks agents get pushed into.

What is real here

Real

  • Every line in the terminal: recorded from real runs of the VPN Works Alpha on Linux on with the demo kit's run-demo.sh --record, vpnw's lines and the stand-ins' alike.
  • The table under each step: vpnw's own trace of that run, in its JSON Lines format.
  • The decisions in the two panels above and the draft computed in step 2: the Alpha's own Go code (policy engine, request plan and learn), compiled to WebAssembly for this page. A test compares that request plan with the running broker in 119 cases.

Stand-ins

  • The agent, its task, the servers, the office exit and the attacker. They ran as small Python programs inside a private network namespace, with addresses that exist only there. Nothing reached the real internet.
  • The pace: each run took under a tenth of a second and is replayed slowly enough to read.
  • In the panels above, whether a server answers: that comes from the demo network, not from a live connection.