FAQ
Frequently asked questions
Answers about QPN and how it fits your network, grouped by topic.
FAQ
Frequently asked questions
Answers about QPN and how it fits your network, grouped by topic.
The basics
What is QPN?
A quantum-safe encryption gateway that protects the connections between your own locations, without replacing the network equipment you already run.
Who is it for?
Organisations that connect sites, OT environments, their own cloud or data centre and remote users. QPN specifically supports OT environments and connections between sites, including over the public internet and in air-gapped networks.
What does it protect?
The connection between your locations: the data in transit. It encrypts at Layer 3, so everything above Layer 3 travels encrypted with it. No software is installed on the equipment behind the gateway.
What does it not do?
It does not replace your central firewall. It does no web filtering, no email malware scanning and no anti-virus, and it is not a defence against denial of service. It does not protect devices behind the gateway: an infected laptop stays infected.
Security and cryptography
Why is it quantum-safe?
Protection runs in two layers. The key agreement is hybrid: a classical part and a post-quantum part are combined into one session key, and neither half on its own produces a usable session key. The post-quantum algorithm in the standard product is ML-KEM, standardised in FIPS 203. Without a valid post-quantum key exchange, no connection is established.
What is "harvest now, decrypt later", and does QPN address it?
Encrypted traffic can be recorded today and stored until it can be decrypted later. QPN does the public key exchange with quantum-resistant mathematics, so traffic captured and stored today stays protected against being broken later by a quantum computer.
What happens if one of the algorithms is broken?
The other one still holds and protects the traffic, and crypto agility allows the post-quantum algorithm to be changed if necessary.
How often are keys renewed?
Both handshakes, classical and post-quantum, renew every two minutes. Private keys never leave the device.
What does my traffic look like on the public internet?
It is visible only in its encrypted form. It cannot be read in unencrypted form, and it cannot be altered without breaking both the classical and the post-quantum encryption.
What happens if the line goes down?
The connection never falls back to unencrypted traffic. It retries automatically, and no user action is needed for it to recover.
Does QPN send data to the manufacturer?
No. The gateway sends no telemetry and has no cloud dependency.
Your network and installation
Do I have to replace my switches, firewall or cabling?
No. QPN co-exists with your firewalls, routers and network architecture, and is integrated by adding or adapting routes. Your central firewall keeps inspecting the traffic it can read. Encrypted QPN traffic cannot be inspected, so the gateway goes in front of the firewall when that inspection has to stay, and it can sit behind the firewall when inspection is not needed on that path.
What do I have to change in my own network?
Usually adding or adapting a few routes. Beyond that it depends on your network and is worked out in the technical call. Where a site still uses public IP addresses, some devices may need to move to private addressing.
Do I need a fixed public IP address?
One end of a connection needs a public IP address or a DNS name. That is usually a virtual gateway in your own data centre or cloud, not the gateway at the site.
Do I have to open ports on my firewall?
At the site, typically not. The listening side, usually the cloud gateway, opens ports on demand, only while an active connection needs them. Where a port range is needed on your external firewall, that is worked out in the technical call.
How long does installation take?
Roughly 30 minutes per gateway, covering installation, basic setup and the first connections. It assumes a laptop connected by LAN cable, an up to date browser and a good understanding of your own network and IP addresses.
What comes in the box?
The gateway, a universal power supply with a cord for your country, a setup guide and LAN cables in different colours. You provide a laptop for the first configuration.
Performance and connectivity
How fast is it?
Up to 1 Gbit/s on a physical gateway. For more, a virtual gateway in your own environment, where the QPN software stack handles up to 10 Gbit/s.
How much latency does it add?
Typically about 1 ms. It varies with CPU load, network load and distance.
How many sites can I connect?
Up to 100 tunnels per physical gateway, and there is no hard limit on the number of gateways in a deployment.
Does it work over satellite or mobile networks?
Yes. LEO satellite and mobile connections such as 5G and LTE, as well as all standard IP connectivity. Carrier grade NAT is not supported. An LTE module is a standard option as an automatic backup path.
Does it work in air-gapped networks?
Yes. QPN does not need internet access and sends no telemetry. Software updates come from an update server, which can also run inside your closed network.
Clients and platforms
Can remote users connect?
Yes. The QPN software client is available for current Windows and macOS. Clients need no incoming firewall ports and support DHCP addresses.
Where does the virtual gateway run?
As a virtual machine in your own data centre or cloud, on a supported Linux platform, with the same web interface as the physical gateways.
What hardware does the gateway use?
Industry-standard x86 hardware. It is fanless, with optional DIN rail, wall and VESA mounting.
Operation, updates and subscription
How do I see that it is working?
A dashboard shows the algorithm in use and both handshake timers, classical and post-quantum, each renewing every two minutes.
How are the algorithms kept up to date?
Automatic updates of the algorithms and the software require an active subscription.
What happens if the subscription ends?
The gateway keeps working in the state it was in. It no longer receives support or security updates.
Can the algorithm be changed on gateways already in use?
Yes. Done by hand on site it costs up to two minutes of interruption per site. A command line procedure needs only a few seconds of service interruption.
Buying and next steps
What does it cost?
That depends on your configuration. Build an indicative configuration with the configurator, or talk to an expert.
How do I get a proposal?
Answer a few questions in the configurator to see which gateways you need and where they go, then discuss it with an expert.
Still have a question?
See which gateways you need and where they go, or talk it through with an expert.

