Secure Communications

Site-to-Site VPN

Without a private link, staff either pass files around on memory sticks or someone exposes a server to the internet to make it reachable. We join your sites into one encrypted network, so neither is necessary.

What this protects

Every site working as one business

Sites that cannot reach each other push work back onto people. Exposed servers push risk onto the whole company.

Everyone reaches the same systems

A shared drive in another office should be as easy to reach as the one on your desk, without emailing files back and forth.

Servers off the public internet

A private tunnel means internal systems never need a public address, which removes a whole class of exposure.

Trading through a lost line

Redundant links mean a failed connection does not cut a site off. The tunnel fails over and the work carries on.

Joining sites properly rather than by accident

Without a private link, staff either copy files onto memory sticks or someone exposes a server to the internet so people can reach it from elsewhere. The first is a data-loss incident waiting to happen. The second is worse.

A site-to-site VPN is a permanent encrypted tunnel between your firewalls. Traffic between offices travels inside that tunnel and is unreadable in transit, and internal systems never need a public address at all. From the user side, the shared drive in the other office simply appears alongside everything else.

The firewall rule problem

When we take over a network, one of the first things we look at is the firewall rule list, and it reads like a confession. A rule opened for a single project in 2019, marked temporary in the comments, still sitting there years later. A rule meant to let one contractor reach one server, now pointing at a range that covers half the network.

Rule hygiene is unglamorous and it matters. Every unnecessary open port is a door somebody forgot to close, and an attacker does not care that it was only meant to be there for a fortnight.

What a well-built link includes

  • Encrypted tunnels between each pair of sites, using current protocols
  • Routing handled so internal systems stay off the public internet
  • Redundant paths where a single internet line is a business risk
  • Firewall rules reviewed on a schedule, not left to accumulate
  • Monitoring on every tunnel, so a silent drop is noticed the same day
  • Documentation of the topology, so the next engineer is not guessing

Related options

Site-to-site VPN

Encrypted tunnels between your own offices over your existing internet lines. The core choice for most multi-site businesses.

SD-WAN

Software-defined routing that manages multiple links between sites and sends traffic down the best available path.

Cloud connectivity

Private connections to Microsoft 365 and Azure, so cloud traffic does not take the scenic route over the public internet.

Questions we get asked about Site-to-Site VPN

For most businesses, a site-to-site VPN over decent business broadband is perfectly adequate. A dedicated private line earns its cost when you move large volumes between sites, or when the traffic is genuinely latency sensitive.

It can, because traffic crosses the internet rather than a local switch. For heavy file access, a well-specced connection and sensible caching close most of the gap. We will size it honestly rather than oversell it.

That site loses its link to the others. If that is a business risk, we add a second connection and failover, so the tunnel re-establishes over the backup line.

Remote users are usually better served by zero trust access than by a full tunnel back to head office. The two approaches work together rather than competing.

The tunnels themselves are fairly stable. The work sits in the firewall rules, the monitoring and the firmware, which is exactly the part people let slide when nobody owns it.

Not sure whether you need site-to-site vpn?

Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.