ZeroTier¶
ZeroTier is a private VPN. Joining a ZeroTier network is how you give a remote engineer (or yourself, off-site) direct, private network access to the gateway — it underlies both ForwPort and remote access to the Cockpit console itself when you're away from the plant network.

At the top:
- Node ID — this gateway's ZeroTier node identifier.
- Online — whether the ZeroTier client currently has connectivity.
- Version — the installed ZeroTier client version.
Below that, a table lists every network this gateway has joined, with its name, status, and assigned addresses.
Handle IDs and links as sensitive
A ZeroTier Network ID grants access to whoever has it (after the network owner authorizes the device). Treat network IDs — and any addresses assigned on them — the same way you'd treat a shared password: don't post them anywhere public.
Joining a network¶
- Get the 16-character hex Network ID from whoever manages the ZeroTier network you're joining (often the remote engineer or your integrator).
- Enter it under Network ID (16 hex chars).
- Click Join.
The new network appears in the table once the gateway has joined it. Note that joining is often not enough by itself — the network's owner typically also has to authorize this device from their ZeroTier controller before traffic flows.
Leaving a network¶
This may remove remote access
Click Leave on a network's row, then confirm:
Leave ZeroTier network {networkId}? This may remove remote access through it.
If this is the network a remote engineer (or you, off-site) relies on to reach the gateway, leaving it may cut that access off. Make sure you have another way to reach the gateway before leaving a network you rely on.