Integrations
Omnix Private Mesh
Connect enrolled Windows and Android devices through the bundled WireGuard tunnel after making the hub reachable.
Omnix Private Mesh gives enrolled Omnix devices a private route to approved branch services when they aren't on the branch LAN. WireGuard is bundled in the Windows and Android apps. You don't need a separate WireGuard app, a VPN subscription, or a WireGuard account.
The tunnel encrypts traffic, authenticates each enrolled peer, and routes only the private Omnix subnet. It does not make the hub reachable by itself.
Same-network use needs no router setup
A phone on the same branch Wi-Fi as the Windows hub can connect over the LAN. You don't need port forwarding, DDNS, a public address, or Private Mesh for that same-network connection.
Remote access is different. A phone on mobile data must be able to dial the hub's WireGuard UDP port. Reserve the hub's LAN address, forward that UDP port in the branch router, and use DDNS if the public address changes. Follow Set up remote access before testing away from the branch.
If the branch internet line is behind carrier-grade NAT, port forwarding cannot reach it. Omnix does not currently operate a relay, so that line needs a public address from the internet provider or a different connection before direct remote access can work.
What the mesh routes
Private Mesh routes only the private Omnix subnet used by enrolled branch devices. Ordinary web browsing, video, messaging, banking apps, and other internet traffic continue to use the phone's normal Wi-Fi or mobile connection.
This is split routing, not a whole-phone consumer VPN. Omnix doesn't use the tunnel to hide your public IP address or move all phone traffic through the branch.
Android permission
The first time you connect Private Mesh, Android shows its system VPN permission dialog. Accept it once so Android can create the Omnix tunnel. The prompt comes from Android even though WireGuard is already bundled in Omnix. While the tunnel is connected, Android keeps a persistent Omnix Private Mesh notification. Android requires that notification for the foreground VPN service, and it remains until the tunnel stops.
Android can ask again after the app is reinstalled, its storage is cleared, VPN permission is reset or revoked, or another VPN takes over Android's single VPN slot. Don't install another VPN app to answer this prompt. If you deny it, Omnix can still work on the branch LAN, but Private Mesh stays off until permission is granted.
Connect a phone
Set up internet reachability first, then enrol the phone through the Windows desktop hub. The enrolment supplies the device identity and approved branch routes. Open Profile on Android, confirm the active branch, then tap Connect Private Mesh. The control shows the current mesh state and changes to Disconnect Private Mesh while the tunnel is running.
Test the first remote connection with Wi-Fi switched off on the phone. Wait for Connected, then refresh branch data or run a sync. Seeing Connected is not enough if the hub service itself is stopped, so confirm that fresh branch data arrives.
Security boundaries
Each phone needs its own enrolment. Revoke a lost or retired device from the Windows hub so it can no longer join the mesh. A device still needs Omnix user and branch permission after the tunnel connects. Network reachability alone doesn't grant access to business records.
Forward only the WireGuard UDP port shown by Omnix. Do not expose the browser companion, branch service, database, or another Omnix port on the public internet. The browser companion remains read-only and LAN-only. Read Connect the browser companion for its network requirements.
Troubleshooting
The app reports a specific mesh state instead of treating every failure as the same problem. Set up remote access explains Mesh not configured, Connecting, Connected, Hub unreachable, VPN permission denied, and Mesh unavailable.
Something missing?
If a step is wrong or unclear, tell us — we update the docs when a real question comes in. Book a demo for a walkthrough, or email support@omnix.co.ke.
More in Integrations
KRA eTIMS setup
Connect Omnix to KRA eTIMS so every sale is auto-signed, and generate your VAT3 return.
Set up Omnix remote access
Publish the hub endpoint, reserve its LAN address, forward WireGuard UDP, allow it through Windows Firewall, and test from mobile data.
M-Pesa (Daraja & Paystack)
Accept M-Pesa via STK push, Paybill/Till, or Paystack. Step-by-step on getting every key and entering it.
Get your Paystack keys
Sign up for Paystack in Kenya, complete onboarding on their site, and copy your API keys into Omnix.