Pangolin 1.24: Exit Nodes and Improved Clients

Pangolin 1.24 is here, and most of it lives in the clients. The headline feature is exit nodes: a device can now send its internet traffic out through one or more sites you choose, using exit nodes for secure outbound routing. The tunnel can also come up automatically instead of waiting for someone to open the app and connect. Windows and Mac got a major UI overhaul, and iOS picked up a lot of new features.

Release Highlights

Exit Nodes

By default Pangolin is a split tunnel, which is what you want on most networks. Traffic between your sites and clients goes through Pangolin, and everything else, a browser tab or a call to a public API, stays on the device's normal internet connection.

When you do want the full tunnel, create a private resource, set the type to Exit Node, and attach one or more sites. A client that selects that resource sends its internet traffic out through one of those sites on the default routes (0.0.0.0/0 and ::/0). From the outside the device looks like it is on the site's network, which is useful on untrusted Wi-Fi or when a service only answers from a particular country.

Create an exit node resource

1 / 2

If the resource has more than one site, the client picks the one with the lowest latency, highest throughput, and availability. Access works the same way as any other private resource, through roles, users, and machine clients, and because an exit node has no destination of its own it allows TCP, UDP, and ICMP.

On Mac, Windows, iOS, and Android, open the exit node control and pick the resource, or choose None to stop. From the CLI:

pangolin select exit-node

If the client is already running, the change applies immediately. Otherwise it waits for the next pangolin up. Pass --exit-node with the resource's nice ID to skip the prompt. To confirm routing, look up the device's public IP, which should be the exit node's address.

Other Pangolin resources still resolve while an exit node is active, including resources on sites that are not attached to that exit node. Turn on Exit Node Takes Precedence Over Resources when you want every route and DNS alias to go through the exit node instead, and the other resources drop until you turn it off.

Private exit node resources require Pangolin CLI v0.18.0+ or Newt v1.18.0+. Upgrade your site connector before deploying.

On-Demand and Staying Connected

macOS 0.12.0 and iOS 0.11.0 use Apple's Network Extension API, so the system brings the tunnel up when a network appears instead of waiting for someone to open Pangolin and tap Connect.

Connect Automatically On is a switch for each interface. Connect enables on-demand for that interface, and Disconnect turns it off. On a Mac, Ethernet connects while the machine is on Ethernet and Wi-Fi connects while it is on Wi-Fi. iOS has the same Wi-Fi control, plus Cellular for when the device is on a mobile network.

You can also narrow Wi-Fi down further. Any Wi-Fi Network connects on every SSID. Only these Wi-Fi Networks limits that to the names you list, and Except these Wi-Fi Networks skips the ones you list.

Mac also has Start at Login, which opens Pangolin when you log in. With that and on-demand both enabled, the app opens at login and the tunnel connects for the interfaces you turned on.

macOS, Start at Login and Connect Automatically On

1 / 5

Windows has no on-demand API, so Windows 0.15.0 uses Start at Login to open Pangolin when you sign in and Connect at Start to connect the tunnel whenever Pangolin opens. With both enabled, Pangolin launches and connects at login.

Android uses the system VPN setting. Open Pangolin there and turn on Always-on VPN. Always-on shipped in Android 0.8.0.

The new preferences are explained in the platform docs for Mac, iOS, and Windows.

Improved Client UI

Windows 0.15.0 rebuilds the preferences window and the system tray from scratch so they line up with the Mac client. It now has a clean look and feel, and a consistent UI.

Similarly, the Mac menu bar gets a makeover. The dropdown used to close as soon as you connected, or as soon as you switched account, organization, or exit node, so changing two of those in a row meant opening the menu twice. It stays open now, including while the tunnel is connecting, and the transitions are animated. Hovering over the connection status in the menu lists the connected sites, each with its own details. The Windows tray is updated to match these changes as closely as possible.

Windows system tray

1 / 3

The Status page in preferences also has an expanded formatted view on all platforms. Click a site and a card shows whether the client-to-site connection is a relay or a direct connection, whether that site is the exit node, the endpoint, when it was last seen, and more. In order to see this information previously you had to switch the page over to JSON view.

Windows, site details

1 / 2

Mac and Windows both have an Accounts page in the preferences window for adding, switching, and removing accounts. The menu bar and the tray could already do this, and the window now matches them.

Windows, Accounts

1 / 3

iOS 0.11.0 brings home screen widgets, a Control Center control, Shortcuts actions for connect, disconnect, and status (usable with Siri), status in the Dynamic Island and Lock Screen Live Activity, and more. macOS 0.12.0 adds Siri app intents. Android 0.8.0 adds a Quick Settings tile that toggles the VPN, the same kind of control as the iOS Control Center button.

iOS widgets and Dynamic Island

1 / 7

Subnet Router

A Linux machine client can advertise a subnet, so devices on that network reach Pangolin resources without running the client themselves. Use it for a printer, a camera, or a VPC you are not going to install software on one host at a time. Start the client as root with the subnet router flag, which enables forwarding and installs the nftables rules.

sudo pangolin up client --id <id> --secret <secret> --endpoint <endpoint> --subnet-router

A subnet router lets devices without the Pangolin client reach private resources, while their own internet routing stays as it is. An exit node sends a Pangolin client's internet traffic out through a site.

The install, the firewall notes, and how to add the route on the network's gateway are in the subnet router docs.

General Improvements and Bug Fixes

Windows 0.15.0 also includes an onboarding flow alongside the new login.

As always, this release also includes various UI improvements and bug fixes throughout the product.

About Pangolin

Pangolin is an open-source Secure Access Service Edge (SASE) platform built on WireGuard® that unifies modern networking and security for teams connecting to apps, infrastructure, and AI workloads. Designed as an open, self-hostable alternative to complex legacy suites, Pangolin brings together a zero-trust VPN, zero-trust reverse proxy, privileged access management, and an identity-aware AI gateway under a single identity and policy model. Whether deployed on-premises using a lightweight user-space connector or managed via Pangolin Cloud, it gives organizations transparent, auditable, and frictionless control over their entire digital footprint.

Stop managing networks. Start managing access.

Keep reading