BURSUcm
BURSUlink

Reach a computer behind NAT — no port forwarding, no VPN

BURSUlink is a small agent for Windows, macOS and Linux. Install it on a computer that has no public address — behind a home router, a mobile connection or a corporate firewall — link it to your BURSUcloud database, and BURSU Connection Manager opens SSH, RDP, VNC, WinRM and SFTP sessions to it as if it were next door. Nothing to open on the router, nothing to configure on the firewall.

How it works

The agent calls out, so nothing has to let traffic in

The agent runs as a system service and keeps one outbound connection to the nearest BURSUlink relay — the same kind of connection a browser makes, so every router and firewall lets it through. When you open a connection in BURSU Connection Manager, the app asks bursucm.com for a pass: a signed ticket that names the agent, your device and the one connection you are opening, valid for two minutes. The agent checks the signature and the pass, then opens the TCP connection on its side.

The two ends then try to reach each other directly, through the NAT, the way video calls do. When that works, the relay drops out of the path and the session runs end to end at the speed of your line; when a NAT refuses, the relay forwards the encrypted packets — it never holds a key and cannot read them.

  1. Install the agent and link the computer — a one-time code from your database, or a sign-in with your portal account.
  2. In BURSU Connection Manager, set the connection to go through that agent. Every member of the database with access to the connection can use it.
  3. Connect. The app shows whether the session runs directly or through a relay.
bursulink · the path of a connection
Your device and the agent both connect out to a relay; the portal signs a pass; the session goes direct when the NAT allows it, through the relay otherwise. bursucm.com signs the pass relay EU · GE · US · RU · BR CN · JP · IN · GB · EG your device BURSU Connection Manager computer behind NAT BURSUlink agent NAT NAT pass, 2 min heartbeat direct when the NAT allows it, encrypted end to end

Two modes, chosen when you link the computer

An agent reaches its own computer, or acts as a gateway into the network around it. You pick the mode on the portal, and you can change it later.

This computer only

The agent answers for the machine it runs on and nothing else: connections land on 127.0.0.1 of that computer. Right for a home PC, a developer's workstation, a Mac in the office or a single server — the common case, and the safe default.

  • Reaches only services running on that computer
  • No network list to maintain
  • A compromised database cannot be used to reach anything else on that LAN

Gateway into your network

One agent on one machine opens the whole office or server room: switches, hypervisors, NAS boxes, printers, machines that cannot run an agent themselves. What it may reach is an allow-list you write on the portal — network, ports and protocol — and nothing outside it.

  • Allow-list entries like 192.168.10.0/24:22/ssh or 10.0.0.5:3389/rdp
  • Whole-internet, loopback, link-local and cloud metadata addresses are refused by the portal
  • Edit the list any time; the agent picks it up on its next heartbeat

What you get

A jump host without the jump host: the convenience of a VPN with none of its setup, for every protocol the app speaks.

No open ports

Nothing listens on the internet. No port forwarding on the router, no public IP, no firewall rule, no dynamic DNS — the agent only ever connects out, over 443/tcp and 7842/udp.

No VPN to run

No tunnel to bring up before you work, no split routing, no address plan to keep from colliding with the office you are visiting. Open the connection and it is there.

Direct when it can be

The two ends punch through their NATs and talk directly whenever the routers permit it; the relay is the fallback, not the path. Ten relays — Europe, Georgia, the United States, Russia, Brazil, China, Japan, India, the United Kingdom and Egypt — and the agent picks the nearest.

Up after a reboot, before anyone signs in

A Windows service, a systemd unit, a macOS LaunchDaemon: the agent starts with the system and needs no user session, no window, no status icon. A server that rebooted at night is reachable in the morning.

Your database's rights apply

The portal signs a pass only for a member who can open that connection, and only for an agent of the same database. Accounts with two-factor sign-in must have signed in with the code. Per-folder rights and user groups work exactly as they do for direct connections.

Every protocol, one setting

SSH, SFTP, Telnet, RDP, VNC, WinRM and AppleRD go through the agent. A connection is marked 'through agent X' once, in the catalog, and every member of the database sees it that way.

One computer, several databases

Link the same computer to up to eight databases — a contractor's laptop shared between clients, a server two teams administer. Each link has its own key and its own rights; removing one touches nothing else.

Nothing asks again after setup

One administrator consent when the agent is installed. Linking, re-linking, start and stop are done from the agent window with no password prompt — the running service does the work.

Free

BURSUlink is part of BURSUcloud at no charge: as many agents, connections and relays as you need, for every database you own.

Download the agent

One file per platform. Install it on the computer you want to reach, not on the one you connect from.

Windows

Version 0.1.21 · released 2026-10-09
Windows installer (x64 / x86 / ARM64) — beta
x64 / x86 / ARM64 · 7.2 MB · updated 2026-10-09
Download
SHA-256 c5ca45bc66f2b58043d75aeeac0987474b087c4b0e5c5c65184958713efc6fbf

One installer for x86, x64 and ARM64: it installs the service and the status icon, and asks for administrator consent once. Windows 10, Windows 11 and Windows Server. Authenticode-signed.

macOS

Version 0.1.22 · released 2026-10-09
macOS disk image — beta
Universal (Apple Silicon + Intel) · 7.8 MB · updated 2026-10-09
Download
SHA-256 196371fd212820680a2b8c58681ff1e9915a493e024139d82e54359f9c0eed3f

One image for Intel and Apple Silicon. Open it, drag BURSUlink to Applications, start it and press Install in the Service tab — the system asks for an administrator password once. Developer ID signed and notarised by Apple.

Linux

Version 0.1.21 · released 2026-10-09
Debian / Ubuntu package: the service (servers and desktops) — beta
x86_64 · 3.9 MB · updated 2026-10-09
Download
SHA-256 9f987db66d584717e69f691ca07c1dc443efb319a0455c8403b9763b90fc011b
Install sudo apt install ./bursulink_0.1.21_amd64.deb
APT repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo wget -qO /usr/share/keyrings/bursucm.gpg https://bursucm.com/repo/bursucm.gpg
2. Source sudo tee /etc/apt/sources.list.d/bursucm.sources >/dev/null <<'EOF' Types: deb URIs: https://bursucm.com/repo/apt Suites: stable Components: main Architectures: amd64 Signed-By: /usr/share/keyrings/bursucm.gpg EOF
3. Install sudo apt update && sudo apt install bursulink
Debian / Ubuntu package: window and tray icon (install with the service package) — beta
x86_64 · 4.8 MB · updated 2026-10-09
Download
SHA-256 6f8e3eb53f4ef33a2174b55e87f7e90a48ee4f1604b93e8f8c8348674c8661f0
Install sudo apt install ./bursulink-desktop_0.1.21_amd64.deb
APT repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo wget -qO /usr/share/keyrings/bursucm.gpg https://bursucm.com/repo/bursucm.gpg
2. Source sudo tee /etc/apt/sources.list.d/bursucm.sources >/dev/null <<'EOF' Types: deb URIs: https://bursucm.com/repo/apt Suites: stable Components: main Architectures: amd64 Signed-By: /usr/share/keyrings/bursucm.gpg EOF
3. Install sudo apt update && sudo apt install bursulink
Debian / Ubuntu package: the service for ARM servers — beta
ARM64 (aarch64) · 3.9 MB · updated 2026-10-09
Download
SHA-256 2e09c872fe91f87e9700027fc3be318716a5e00ce6f3debeeb36e3ca05afaeed
Install sudo apt install ./bursulink_0.1.21_arm64.deb
APT repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo wget -qO /usr/share/keyrings/bursucm.gpg https://bursucm.com/repo/bursucm.gpg
2. Source sudo tee /etc/apt/sources.list.d/bursucm.sources >/dev/null <<'EOF' Types: deb URIs: https://bursucm.com/repo/apt Suites: stable Components: main Architectures: amd64 Signed-By: /usr/share/keyrings/bursucm.gpg EOF
3. Install sudo apt update && sudo apt install bursulink
Arch package — beta
x86_64
Coming soon
RPM package: the service (servers and desktops) — beta
x86_64 · 3.9 MB · updated 2026-10-09
Download
SHA-256 9b00f29b04e4e684f54d9663649b8839f8c132fbcbe548ecddbbc15074d1dc78
Install sudo dnf install ./bursulink-0.1.21-1.x86_64.rpm
DNF / YUM repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo rpm --import https://bursucm.com/repo/bursucm.asc
2. Source sudo tee /etc/yum.repos.d/bursucm.repo >/dev/null <<'EOF' [bursucm] name=BURSUcm baseurl=https://bursucm.com/repo/rpm enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://bursucm.com/repo/bursucm.asc metadata_expire=6h EOF
3. Install sudo dnf install bursulink
RPM package: window and tray icon (install with the service package) — beta
x86_64 · 4.8 MB · updated 2026-10-09
Download
SHA-256 24ed8ab96aa64bcb033c0ed21185c6dfad9e1a34929620bb44fc51fcfdf9b450
Install sudo dnf install ./bursulink-desktop-0.1.21-1.x86_64.rpm
DNF / YUM repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo rpm --import https://bursucm.com/repo/bursucm.asc
2. Source sudo tee /etc/yum.repos.d/bursucm.repo >/dev/null <<'EOF' [bursucm] name=BURSUcm baseurl=https://bursucm.com/repo/rpm enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://bursucm.com/repo/bursucm.asc metadata_expire=6h EOF
3. Install sudo dnf install bursulink
RPM package: the service for ARM servers — beta
ARM64 (aarch64) · 3.9 MB · updated 2026-10-09
Download
SHA-256 e14de99b2cd72d24fcb050bf97b7f10e09d054ef961c509f1701c675a45251b7
Install sudo dnf install ./bursulink-0.1.21-1.aarch64.rpm
DNF / YUM repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo rpm --import https://bursucm.com/repo/bursucm.asc
2. Source sudo tee /etc/yum.repos.d/bursucm.repo >/dev/null <<'EOF' [bursucm] name=BURSUcm baseurl=https://bursucm.com/repo/rpm enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://bursucm.com/repo/bursucm.asc metadata_expire=6h EOF
3. Install sudo dnf install bursulink

The bursulink package is the service and its command line — all a server needs. On a desktop add bursulink-desktop from the same repository for the window and the status icon. Link a server from the terminal: sudo bursulink-agent enroll --code …

Setting it up

  1. On bursucm.com open your database, then the BURSUlink tab, and press Add agent: name it, choose the mode, and copy the one-time code. It is valid for 15 minutes.
  2. Install the agent on the computer and paste the code into its window — or sign in there with your portal account and pick the database; the computer is linked on the spot.
  3. In BURSU Connection Manager, open the connection's settings and set Connect to Through BURSUlink, choosing the agent. The connection keeps its real host name, so host keys and certificates are checked as before.

Security

  • Every agent and every device has its own key pair, generated on the machine and never sent anywhere; the portal and the relays know only the public halves.
  • A pass is good for one TCP connection, one agent, one device and two minutes; a replayed or altered pass is refused by the agent.
  • Traffic is encrypted end to end between your device and the agent; a relay forwards packets it cannot decrypt.
  • The agent's key is readable by the system account alone; linking from the window is allowed to signed-in users on Windows and to administrators on macOS and Linux.
  • Your database's BURSUlink tab lists every agent with its mode, version, last contact and whether it is online; remove one and its passes stop at once.

Requirements

  • A BURSUcloud database — the agent is linked to it, and its members connect through it
  • Agent: Windows 10 / 11 or Windows Server on x86, x64 or ARM64; macOS on Intel or Apple Silicon; Linux x86_64 with glibc 2.34 or newer (Ubuntu 22.04+, Debian 12+, Fedora, RHEL 9+, Arch)
  • Outbound 443/tcp and 7842/udp from the agent's network; nothing inbound
  • Connecting side: BURSU Connection Manager for Windows first; the macOS, Linux, Android and iOS apps follow
  • Protocols through the agent: SSH, SFTP, Telnet, RDP, VNC, WinRM, AppleRD. Not yet: FTP, AppleRD High Performance, Serial, Web

New to BURSUcm? Take the product tour →

Reach every machine you look after

Create a free BURSUcloud account, link the computer, connect from anywhere.