Open source · built in Rust

Your VPNs.
One place.
Zero terminals.

Connect multiple FortiGate environments, organize your profiles and know exactly what is going on — without memorizing commands or hand-editing files.

Free and open source Linux, macOS and Windows
TunnelYard
×

Your tunnels

Manage every environment from here.

HQ
Acme HQ Connected

vpn.acme.com · 10443

12m 48s↓ 28.4 MB↑ 4.1 MB
NX
North Client Connected

ssl.north.dev · 443

04m 22s↓ 8.6 MB↑ 1.2 MB
ST
Staging Idle

vpn.staging.internal · 443

Last access yesterday
Live console receiving

20:41:08 Tunnel is up and running.

20:41:08 Routes and DNS configured.

20:41:09 ✓ Connected to Acme HQ

VPN connectedAcme HQ is ready.
Automatic reconnectYou did not have to step in.
Works with
Linux macOS WindowsFortiGate SSL VPN
Less friction, more work done

You just wanted to reach the environment.
Not become a terminal expert.

TunnelYard turns a fragile, repetitive routine into a visual flow that is predictable and easy to follow.

Before
Terminal — bash

$ sudo openfortivpn cliente.conf

INFO: Connected to gateway.

INFO: Authentication succeeded.

ERROR: pppd: The link was terminated.

$ sudo openfortivpn cliente.conf

_

  • Commands and permissions every single time
  • One terminal per client
  • Finding out about drops too late
With TunnelYard
AC
Acme HQvpn.acme.com
Connected
AuthenticateGateway accepted
ConfigureRoutes and DNS
WorkTunnel ready
StatusStable
Uptime12m 48s
Tunnels2 active
  • One click to connect
  • Multiple tunnels side by side
  • Alerts and automatic reconnect
Everything under control

Built for people who live
between environments.

From a single client to an entire collection of accesses: TunnelYard keeps the operational work small, clear and dependable.

Multi-tunnel

Every client.
All at once.

Open independent connections in parallel and see the state of each environment without switching windows.

Profiles

Visual configuration, without losing compatibility.

Create, edit or import openfortivpn .conf files.

Visibility

Know when it connects. And when it drops.

Native notifications and a live console, without watching the terminal.

Background

Close the window.
The tunnel stays up.

Control connections from the tray and start with the system.

Your way

Portuguese, English, light or dark theme.

The interface follows your language and your system appearance.

Least privilege

The interface never needs to run as administrator.

TunnelYard keeps the visual experience separate from privileged operations. When one is needed, the operating system itself asks for your authorization.

See how it works in the code
01
You request the connection

The interface prepares only the profile you picked.

02
The system authorizes

PolicyKit, the native macOS prompt, or UAC.

03
The tunnel runs isolated

Each session has its own lifecycle.

Performance notebook

Every MiB,
on the record.

One local measurement, reported in full — including what it does not prove.

Linux x64 · v2.6.0 debug build · Sep 08, 2026
App with 2 tunnels connected
115.4MiB

Average resident memoryRSS · 60 samples, one per second

Where the memory sits

Interface
86.3 MiB 74.8%

The Rust/GPUI graphical process

VPN engines
29.1 MiB 25.2%

Two openfortivpn plus two pppd

Movement during the minute

0.25 MiB

Total drift across the 60 samples. Resident memory stayed flat for the whole window — which is why there is no chart here: a line would be a straight one.

The numbers have context.
The method is open too.

How we measured

Ubuntu 26.04.1 LTS, x86_64, development build 2.6.0, collected on Sep 08, 2026: 60 readings of VmRSS from /proc/PID/status, one second apart. Interface is the graphical process; engines is the sum of two openfortivpn and two pppd.

We also measured a freshly-opened instance with no tunnels at 241.9 MiB. We are deliberately not showing that next to the number above: it was a different process, with a different lifetime and a different graphical state, so the two are not a controlled comparison and the difference says nothing about what connecting costs.

Summed RSS can count shared pages more than once. Excludes GPU, kernel, shells and desktop services. No credentials were read and existing connections were preserved. Do not extrapolate to macOS, Windows or release builds.

Version 2.7.0

Ready for your system.

Pick your platform and get going. No account, subscription or proprietary license.

v2.7.0

Linux

Debian, Ubuntu, Fedora, RHEL and other distributions.

Pick your processor

The file downloads straight from GitHub.

macOS may ask for confirmation the first time you open it. On Windows ARM64, the native OpenConnect + Wintun client must be installed separately.See every file and instruction.

Less terminal. More flow.

Your next connection
can take one click.

Download TunnelYard, import your profiles and get back to work.