How it works
The agent calls out, so nothing has to let traffic in
The agent runs as a system service and keeps one outbound connection to the nearest BURSUlink relay — the same kind of connection a browser makes, so every router and firewall lets it through. When you open a connection in BURSU Connection Manager, the app asks bursucm.com for a pass: a signed ticket that names the agent, your device and the one connection you are opening, valid for two minutes. The agent checks the signature and the pass, then opens the TCP connection on its side.
The two ends then try to reach each other directly, through the NAT, the way video calls do. When that works, the relay drops out of the path and the session runs end to end at the speed of your line; when a NAT refuses, the relay forwards the encrypted packets — it never holds a key and cannot read them.
- Install the agent and link the computer — a one-time code from your database, or a sign-in with your portal account.
- In BURSU Connection Manager, set the connection to go through that agent. Every member of the database with access to the connection can use it.
- Connect. The app shows whether the session runs directly or through a relay.