Team gateways

The Gateways tab decides which exit regions your members can use, whether they're locked to those and nothing else, and — on the Routing tab — which traffic actually goes through the gateway. Together these give the team one predictable exit IP without proxying everything.

Assigning gateways

Assigned Gateways lists every Reach gateway with its region. Tick the ones your organisation should use and click Save Gateway Settings. Assigned gateways appear in each member's gateway picker alongside any gateways that are open to their personal tier.

Pick the region closest to the resources your team reaches most; see Gateway regions for the current list.

Locking members to assigned gateways

Tick Members only see this organisation's assigned gateways (gateway visibility) and members can no longer choose any other gateway — the open personal gateways disappear from their picker. Use this when your firewalls or SaaS allowlists trust specific exit IPs and a member switching to a different region would lock themselves out.

A member who belongs to two locked organisations sees the union of both organisations' assigned gateways.

The exit IP your firewall will see

Each gateway has a fixed exit IP. Copy it from your dashboard and add it to your cloud firewall, SaaS allowlists or IP-restricted portals — once, for the whole team. The full walkthrough, including automatic firewall sync, is in IP allowlisting & cloud firewall.

Pinning a region through policy

The group policy editor's Gateway selection pins a default gateway for the group, so new members don't have to choose. Members can still switch between the gateways they're allowed to see. Details in Group policy & TCP forwards.

Routing rules: proxy only what needs the gateway

By default a member's routed browsers send everything through the gateway. The Routing tab lets you narrow that to specific destinations — useful when one service (say Microsoft 365) is blocked or slow from a member's local network but you don't want their whole connection proxied.

  • Microsoft 365 preset — one switch routes Outlook, OneDrive, SharePoint and Teams through the gateway and keeps the domain list up to date automatically.
  • Custom rules — match by domain (*.example.com), CIDR (10.0.0.0/16) or process (outlook.exe), and choose Proxy or Direct. Rules can be disabled without deleting them.

Process rules are matched by executable name and enforced by the Windows desktop app. Organisation rules are pushed to every member's client and take precedence over the member's own settings.

Common questions

Members say a gateway "disappeared" from their app.

You turned on gateway visibility and that gateway isn't assigned to your organisation. Either assign it or tell members to pick an assigned one.

Can different groups use different regions?

Yes. Each organisation has its own assigned gateways and policy. Put contractors and staff in separate organisations if they need different regions or rules.

Does assigning a gateway give me a dedicated IP?

The exit IP is fixed per gateway and shared by everyone using that gateway, which is what allowlists need. It isn't reserved for your organisation alone.