Skip to content

Installing nuVPN Gateway on Windows Server

Install on Windows Server in your office or in the cloud using a signed installer (MSI).

  • Windows Server.
  • We recommend using a server or virtual machine dedicated to the gateway.
  • No existing NAT on the machine. If the server already runs NAT, such as a Hyper-V NAT network or Routing and Remote Access, installation stops and displays the reason. In this case, install on a different server.
  • Local administrator privileges.
  • A public IP address or port forwarding from the office router to the server.
  • An installation code from the partner panel.
  1. Download the installer

    On the license page in the partner panel, download the MSI file and copy the installation command with your code. Command format:

    Terminal window
    msiexec /i nuVPN-Gateway.msi TOKEN=<INSTALL_TOKEN>
  2. Run as administrator

    Open a command prompt as administrator and run the command. The installer checks that there is no existing NAT and that the VPN address range does not overlap with the local network.

  3. Find the initial password

    During an MSI installation, the initial password is not displayed. It is saved in C:\ProgramData\nuVPN Gateway\initial-password.txt, which only SYSTEM and Administrators can read. The console sign-in page displays this path until you change the password for the first time. You must change the password when you first sign in. Changing the password deletes the file.

    To generate a new one-time password, run nuvpn-gateway reset-password in a command prompt with administrator privileges. The command displays the new password and replaces the file.

  4. Open the UDP port

    The UDP port is displayed when installation finishes. Open this port for traffic to the server in your cloud provider's firewall or on the office router.

The console is accessible only from the internal network and through the VPN, not from the internet. The gateway does not listen for console connections on a public address.

After three failed login attempts from the same address, that address is blocked for 24 hours. You can remove the block from the server.

  • An outage at nuVPN does not disconnect users who are already connected, and you can still revoke access. User revocations in the local console are enforced even without a connection to nuVPN servers. You cannot generate new profiles until the service is restored.
  • If the directory is unavailable, no user's access is revoked. Synchronization waits until the directory is available again.
  • Restarting the server or service does not delete users. The gateway starts with the same user list, and devices reconnect.
  • The gateway updates automatically. If an update fails, the gateway reverts to the previous version and devices keep working.
  • You remain responsible for Windows Update. We recommend scheduling a regular maintenance window so that restarts do not catch employees by surprise.
  • Uninstalling the software from Windows removes the gateway and all its settings from the server.