Who on this VPN needs to reach what?
An office of 30 people and 12 internal systems on a flat VPN, where any login can reach anything. Scope learns who uses what from two weeks of traffic and drafts rules. A person reviews them. Then the week after is replayed under the draft, and so is a stolen login. Every number below is computed in this page by Scope's own code.
Loading Scope's engine
Step 1 of 6
A flat VPN: every login reaches every system
Thirty people in five teams connect to the office over one VPN. Twelve internal systems sit behind it. Like many company VPNs, this one is flat: once someone is logged in, every system and every port is in reach.
People, by team
Internal systems
Three weeks of traffic new connections per day
On this VPN, a stolen login reaches all 12 systems. Step 5 shows it.
Step 2 of 6
Learn who uses what
Scope reads every connection in the two weeks and counts, for each person and destination, the days it was used. When every active member of a team used a destination on two days or more, it becomes a team rule. What only some people used becomes a personal rule for each of them, if they used it on two days or more. Anything used on a single day goes under review and stays blocked until a person decides.
Who may reach which system
Every connection in the two weeks is allowed by the draft, except the three destinations under review.
Step 3 of 6
A person reviews the draft
Nothing is enforced until someone reads the draft. It is a plain text file: team rules, personal rules, and for each person what went under review, each with the evidence behind it. Three entries were seen on one day only. Allow one here and the draft below changes with it.
draft.toml you can edit it
Reading it
[groups.sales] lists what every member of the sales team may reach; [people.alice] what Alice may reach on top of her team's rules. Each entry is address:port/protocol, and an address range or a port range works too, as in 10.0.2.0/24:8000-8100/tcp.
Anything not listed is refused. Entries under review are refused too, until they move into allow.
The review is the only step that needs a person. Steps 4 to 6 use the draft as it stands here.
Step 4 of 6
Replay the week after
Before anything is enforced, the week after the learning window is replayed as if the draft had been in force. What it would have blocked is a list for the reviewer, not a surprise for the office.
| Person | System | Service | Connections | Why it would be blocked |
|---|
Step 5 of 6
Someone logs in as Alice
Late one evening, someone uses Alice's VPN login to try every system on 12 common ports: 144 attempts.
In the tests, these 144 attempts were made as real connections through Linux, first with no rules and then with the rules from step 6 loaded. The firewall let through exactly the attempts this page shows.
Step 6 of 6
The rules for the gateway
The reviewed draft becomes an nftables script for the Linux gateway. Loading it replaces one table and leaves every other rule alone. In watch mode it refuses nothing and only counts what it would refuse, so it can run for a week before it bites.
In the tests, the script for the learned draft was loaded into Linux's firewall in a private test network. Every person, and one address that belongs to no one, then tried every system on the 12 ports of step 5: 4,464 real connections. The firewall and Scope's simulator agreed on every one.
What is real here
Real
- The code: Scope's own Go code, compiled to WebAssembly for this page. It learns the draft, reads your edits, decides every replayed connection and writes the rules.
- The numbers: the same as in the Scope Alpha report, which ran the same code on the same generated office with the vpnw-scope command.
- The rules: in the tests, the nftables script was loaded into Linux in a private test network and checked against Scope's simulator on 4,464 real connections, and on 36,881 for a generated office of 2,000 people. They agreed on every one.
Generated
- The office: its people, teams, systems and three weeks of traffic, made from seed 20260907 by the same generator the tests and the report use.
- No network: nothing in this page connects anywhere. In step 5, "reached" and "refused" are Scope's decisions, which the tests matched against the kernel.