mabl Link is a secure tunnel between the mabl cloud and your private network. Use it to run cloud tests against applications that are not accessible from the public internet without opening inbound firewall ports or setting up a VPN.
mabl Link is designed for teams with demanding security requirements, such as financial services and cybersecurity firms. It works through the mabl Link Agent, a small application that you run inside your network, so that you can test apps in private environments, including:
- Internal QA and staging environments with non-public DNS names
- Local development environments, such as localhost
- Non-publicly routable IP addresses, such as 10.0.0.0/8 or 192.168.0.0/16
- Ephemeral cloud environments reached through a virtual private cloud (VPC) or AWS Direct Connect
mabl Link highlights
- End-to-end encrypted connections between mabl and your network
- Outgoing connections only, so most firewalls need no changes
- Resolves non-public DNS names inside your network
- Installers for Windows, Linux, and macOS, a Docker image, and the mabl CLI, with automatic updates
- High availability and more capacity by running multiple Link Agents on the same tunnel
- Tunnels that belong to one workspace or are shared by every workspace in your company
- Control over which people, including mabl support, can reach your tunnels
- Built-in monitoring and connection diagnostics
- No VPN client or server
How it works
The Link Agent opens a secure outgoing connection from your network to the mabl cloud. When a test that uses mabl Link runs in the cloud, its traffic travels back through that connection, and the Link Agent connects to your application from inside your network.
The following diagram shows the pieces involved. The green arrow is the tunnel the Link Agent opens, and the blue arrows are the connections a test makes while it runs in the mabl cloud against a private environment.
Limitation
For mobile test execution, mabl Link support is currently limited to API steps, JavaScript snippets, and database queries. Link is not currently available for mobile cloud training.
If your environment requires private access for all test steps, you can allowlist mabl IP addresses instead.
Establishing the connection
The process starts with running the Link Agent on a machine, server, or VM in your network that can reach the applications you want to test. You can install it with the Windows installer, the Linux and macOS installer, the Docker image, or the mabl CLI. See Link Agent setup for the options.
When the Link Agent starts, it connects to the mabl cloud over one of two protocols:
- QUIC, over UDP port 443. QUIC is the faster option, and the Link Agent uses it whenever it can reach mabl directly.
- Secure WebSocket (WSS), over TCP port 443. WSS works through HTTP proxies and on networks that block outgoing UDP traffic.
Each protocol has one fixed endpoint. The Link Agent chooses between them for the network it is on and switches to WSS on its own if QUIC is not available, so your firewall only needs to allow one of them. For the addresses, see Link Agent requirements.
Link 3.0 and legacy Link
Link Agents older than version 3.0 use the legacy Link protocol, which connects over a secure WebSocket to a host name generated for each agent, of the form {host}.link.mabl.com. Link 3.0 connects to the two fixed endpoints above instead and connects much faster. The legacy Link service shuts down on March 15, 2027. See Migrating from legacy Link to Link 3.0.
We recognize the importance of security and privacy when you let mabl reach your non-public environments, so mabl Link builds security into every layer:
- Every connection between mabl and your Link Agent is encrypted end to end with TLS 1.3, inside the encrypted tunnel.
- Tunnels are isolated per customer. Link tunnels are never shared between customers.
- Only your cloud test runs and the people you allow can use your tunnels. Workspace owners and company admins choose which roles, if any, can reach a tunnel from the mabl desktop app or CLI, and whether mabl support can reach it for troubleshooting. Both are off until you turn them on.
There is typically no need to change your firewall rules, because most firewalls already allow outgoing connections on port 443. If your company firewall restricts outgoing traffic, your IT or security team needs to allow the addresses in Link Agent requirements.
To limit what mabl can reach within your network, restrict the Link Agent's outgoing connections in one of the following ways:
- Use a Link Agent configuration file with connection filters that specify which destinations the Link Agent may connect to. We recommend this option, because it gives you granular control over outbound traffic without changes to your network architecture.
- Implement restrictions in your network or host. Run the Link Agent in a DMZ, or on a dedicated host, VM, or container with firewall rules that only allow it to reach the applications under test.
No need for VPN client or server
mabl Link does not depend on or use any virtual private network (VPN) technologies. There is no need to install or configure a VPN client or server to use mabl Link.
Connecting to the system under test
Once the connection is established, mabl can run tests against applications in your private network. DNS resolution happens on the Link Agent host, so names are resolved within your environment, not in the mabl cloud.
Each tunnel belongs to a workspace, or to your company so that every workspace in it can use the tunnel. See Company-scoped Link tunnels. A test can only route traffic through a tunnel that belongs to its own workspace or company, which prevents accidental cross-talk between teams.
Learn more
Set up mabl Link
- Link Agent requirements
- Sizing and scaling Link Agents
- Link Agent setup
- Migrating from legacy Link to Link 3.0
Use and share tunnels
- Running tests over mabl Link
- Company-scoped Link tunnels
- Personal Link tunnels
- Controlling access to Link tunnels