惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
V
V2EX
IT之家
IT之家
J
Java Code Geeks
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
GbyAI
GbyAI
D
Docker
S
Secure Thoughts
Recent Announcements
Recent Announcements
Webroot Blog
Webroot Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
云风的 BLOG
云风的 BLOG
博客园_首页
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Security Archives - TechRepublic
Security Archives - TechRepublic
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
N
News | PayPal Newsroom
S
Security @ Cisco Blogs
I
InfoQ
Last Week in AI
Last Week in AI
SecWiki News
SecWiki News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
W
WeLiveSecurity
T
Troy Hunt's Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Scott Helme
Scott Helme
T
Tor Project blog
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
Recorded Future
Recorded Future
C
Cyber Attacks, Cyber Crime and Cyber Security
AI
AI
G
Google Developers Blog

NetBird - Networking Knowledge Hub - RSS Feed

NetBird Is Now on the Vultr Marketplace Native NetBird on the GL.iNet Comet Pro (GL-RM10) NetBird v0.71 - IPv6 Overlay Addressing NetBird Exit Nodes - Appear at Home, or Anywhere Else Reporting Bugs and Requesting Features in NetBird Setup and Use Local AdGuard Home Anywhere with NetBird DNS How to Set Up NetBird on PiKVM for Secure Remote KVM Access NetBird v0.69 - CrowdSec IP Reputation for the Reverse Proxy Cloudflare Mesh vs NetBird vs Tailscale: Performance Compared Self-Hosting Nextcloud with Docker and NetBird Implementing Zero Trust with NetBird NetBird v0.67 - Layer 4 Proxy Support for TCP, UDP, and TLS Solwr Enhances Remote Connectivity with NetBird Self-Hosting NetBird with Authentik Jellyfin Media Server - Self-Host Your Movies, TV, and Music Cloudflare Tunnels vs. NetBird Reverse Proxy INFITX Builds Zero-Touch Kubernetes Networking with NetBird NetBird v0.66 - Expose Local Services to the Internet from the CLI Pangolin vs. NetBird Home Assistant Setup Guide with EASY Remote Access NetBird v0.65 - Built-in Reverse Proxy with Custom Domains Docker for Beginners - Everything You Need to Get Started NetBird for SOC 2 Compliance NetBird v0.63 - Custom DNS Zones for Private Network Resolution Vibecode This in a Weekend and Take 5% of the Company NetBird v0.62 - Built-in Local Users with Optional IdP Integration NetBird v0.61.0 - Granular SSH Access Control and Automatic Updates Top 5 Alternatives to OpenVPN Top 5 Open Source Alternatives to Tailscale Top 5 Alternatives to ZeroTier How to Set Up ZeroByte and REST Server for Backups with NetBird How to Install n8n v2.0 with NPM and PM2 ZeroTier vs. NetBird The Ultimate Immich Guide - Ditch Google and Amazon Photos for Good NetBird as Your Help with ISO 27001 Compliance NetBird and Huntress - Secure Network Access for MSPs How to Access Windows Shares from Anywhere with NetBird netgo Relies on Modern ZTNA with NetBird Connect to Your Homelab from Anywhere with a Raspberry Pi NetBird SSH - A New, Identity-Aware Approach The AI Mega Mesh: How to Connect 30+ GPU Cloud Providers Connect Multiple Ollama GPUs to OpenWebUI with NetBird Top 5 Tailscale Alternatives SSH and RDP, now in your browser NetBird–Acronis Integration: Empowering MSPs for Advanced Ransomware and Threat Defense Introducing the Control Center - Remote Access, Beautifully Visualized NetBird at MSP Global 2025 Understanding Overlay Networks - The Basics NetBird and SentinelOne Singularity™ - Automate Threat Response NetBird and Microsoft Intune - Enforcing Device Compliance for Zero Trust Rethinking Zero Trust Security with NetBird and pfSense Improving Unidirectional Access Control Proxmox VE for Beginners Guide with NetBird LXC Stronger Security: NetBird + GitHub Secure Open Source Fund NetBird's MSP Partner Program Signicat Enhances Cross-Cloud Accessibility with NetBird SonicWall SSL VPN NetExtender vs. NetBird NetBird Is Embracing the AGPLv3 License NetBird Profiles Have Landed - Manage Multiple Accounts Effortlessly Rethinking Access Control to Secure Your On-Premises SharePoint Servers Sport Alliance Increases Efficiency with Zero Trust Networking at Scale Rethinking Network Access: qwertiko Goes Zero Trust with NetBird Optimizing Network Efficiency with NetBird's Lazy Connections Use Port Ranges in Access Control Policies Generic HTTP Endpoint for Network Events Streaming NetBird’s Response to Spear-Phishing Campaign Targeting Financial Executives Zero-Trust Access to Internal Resources Without Installing Agents Enhance Network Visibility with NetBird’s Traffic Events Logging TrueNAS Made Easy - Install, Set Up, and Access From Anywhere Top 5 Alternatives for WireGuard Jump Hosts. Gateways for Remote Access NetBird Network Routes and Exit Nodes Security for All - SSO and MFA for Free Enhancing Network Access Control with NetBird's Identity Provider Feature Twingate vs. NetBird Limit Network Access Based on Running Applications FortiClient ZTNA vs. NetBird OpenVPN vs. NetBird Tailscale vs. NetBird Getting Started with an Azure Site-to-Site VPN Getting Started with an On-premise-to-AWS Site-to-Site VPN Secure Remote Access to VPCs, LANs, and Offices regreSSHion - A New OpenSSH Server Remote Code Execution Vulnerability Evolve Bank & Trust Data Breach. What Happened? IPSec Tunneling Demystified. Enhancing Data Security Across Networks Understanding IPSec Tunnel and Transport Modes Understanding the Differences Between IKEv1 and IKEv2 Understanding the IKEv1 Protocol in IPSec ZeroTier versus NetBird - Which Should You Choose? AWS Lambda Serverless Security. Mistakes, Oversights, and Potential Vulnerabilities Using NetBird for Kubernetes Access Serverless Security Vulnerabilities and Best Practices to Mitigate Them Security Best Practices for Serverless Azure Functions A Guide to Remote Access Security for SMEs IoT Security Essentials. How to Achieve Secure Remote Access Open Source Zero Trust Networking Using SSH for Secure Remote Access How We Integrated Rosenpass in NetBird The First Quantum-Resistant Mesh VPN Using eBPF and XDP to Share Default DNS Port Between Multiple Resolvers
What Is a Site-to-Site VPN?
Written byChristoph Berger · 2024-06-25 · via NetBird - Networking Knowledge Hub - RSS Feed

In Aalborg, Denmark, in the medieval age, secret passages under the town connected two convents, two churches, a bridge, and the castle of Aalborghus. Monks could use these passages secretly, protected from any evil outside.

In much the same way, secret virtual private network (VPN) tunnels connect company sites all over the world. Data packets travel securely through these tunnels, protected from eavesdroppers and intruders.

Site-to-site VPNs are essential for securely connecting multiple local area networks (LANs). Organizations with more than one office location use these VPNs to ensure that their internal data traffic remains confidential.

In this article, you'll learn about site-to-site VPNs, including their use cases and their advantages. You'll also take a look at the difference between site-to-site VPNs and remote access VPNs and how NetBird helps create and maintain site-to-site VPNs.

What Is a Site-to-Site VPN?

VPNs exist in different flavors and for different use cases. A site-to-site VPN is designed to connect local networks securely over the internet, turning them into a single network. It does this by creating secure, encrypted tunnels between the local networks. As a result, devices and applications can establish direct connections with devices or applications in a remote location without exposing sensitive information to the internet.

The goal of site-to-site VPNs is to connect whole local networks rather than individual devices. Of course, the definition of a local network can boil down to a single computer running the VPN gateway software, but the VPN does not specialize in device-to-device connections.

At a high level, a site-to-site VPN architecture typically involves three components:

  1. Two or more networks: These are local networks that generally block access from the internet. Local machines may reach out to internet services, but typically, a firewall prevents unauthorized access from the internet to local machines.
  2. VPN gateway: This is a device or an application that is part of a local network and connects to VPN gateways in other local networks to build a secure tunnel.
  3. VPN tunnel: Each pair of VPN gateways establishes an encrypted connection called a tunnel for securely exchanging data between the local networks.

Site-to-site VPN architecture diagram courtesy of Christoph Berger

Use Cases of Site-to-Site VPNs

Following are several use cases where a site-to-site VPN is particularly applicable.

Keep in mind that an organization may have more than one use case for a site-to-site VPN, so you may notice some overlap. In fact, these use cases blend nicely with each other, so there is no need to decide between use cases. A site-to-site VPN is agnostic to what it is used for; it works the same in any case.

Private, Protected Traffic

Organizations handling sensitive or proprietary data have an elevated interest in protecting this data from unauthorized access, both at rest and during transmission.

A possible solution to this could be to restrict the data to particular servers and devices that are connected through an encrypted and mutually authenticated one-to-one connection. However, as every server and device needs individual certificates for authentication, the effort to maintain these connections grows exponentially with the number of servers and devices to be connected.

With a site-to-site VPN, all traffic inside the organization is encrypted by default, and data traveling across locations can neither be intercepted nor tampered with.

Multisite Networking

Companies with multiple offices spread across the country (or even multiple countries) typically want to have all the separate local networks appear as a single, global network.

In the days before VPNs, these companies would have had to lease physical cables from their telecom service provider. The costs were often prohibitive so that only large corporations could afford to have dedicated data lines connecting their remote offices to the headquarters.

Site-to-site VPNs changed the game. The internet connects everything to everything. A site-to-site VPN needs to establish encrypted tunnels only between the sites to keep unwanted traffic and eavesdroppers out. No extra glass fibers or copper wires are required.

Secure Access to Servers

Large companies may decide to run a dedicated data center that provides services for all their offices. Possible applications are central databases, customer relationship management (CRM) systems, or other internal business tools that are available to employees in any location.

Now, those data centers could enable firewall-protected access to the servers and services. Web-based services would use Transport Layer Security (TLS) on port 443 to protect traffic, shell access would run on SSH port 22, and mail traffic would need the respective Internet Message Access Protocol (IMAP) and Simple Mail Transfer Protocol (SMTP) ports open. However, this approach can quickly turn into a firewall maintenance hell. Security incidents are just around the corner.

Site-to-site VPNs avoid this. Rather than protecting individual client-server connections, site-to-site VPNs connect whole networks, making the data center appear to run in the same building as the clients.

Disaster Recovery and Business Continuity

In the event of a service outage at one location, site-to-site VPN allows an organization to switch to a redundant service running at another site.

Modern, scalable software is often designed to scale horizontally by replicating services on multiple servers. If the services are replicated only within a single data center, the whole business of a company relies on the data center to be available. If the data center goes offline for whatever reason, the company's business stalls immediately. With site-to-site VPNs, a company can replicate the services securely across the data center and its own business locations for maximum redundancy. If the data center, or any of the company's local offices, goes offline, the rest of the company can continue to do business.

In this scenario, a site-to-site VPN allows for securely replicating services and reconnecting to services in a remote location should the local services be out of order.

Advantages of Site-to-Site VPNs

The use cases may already have given you an idea about the various advantages of site-to-site VPNs; however, let's go through the particular advantages in detail.

Secure Connectivity

The most fundamental and readily visible advantage of site-to-site VPNs is the secure connectivity between local networks. Organizations don't have to consider replicating infrastructure across their locations as every location has access to the same infrastructure, just as if all sites were sharing a single, uniform network.

Simplified Network Architecture

A site-to-site VPN turns separate, distributed LANs into a single, unified virtual network. This has several benefits. To start, the whole network can be managed and monitored centrally. Network administrators can establish virtual subnetworks across site boundaries, thus managing access efficiently by logical units (such as departments or projects) rather than physical network structure. Additionally, new sites can seamlessly join the existing network, and network configuration can remain consistent across sites.

Access Control

If all sites are connected, like in a single, uniform network, internal network security is important. A network where anyone can access anything is not well-protected against malicious behavior from inside.

Modern site-to-site VPN solutions address this concern through access control. Administrators can set up rules to control which person, device, or appliance can access which resources, whether these resources are single machines or large subnets.

Scalability

As organizations grow and expand, site-to-site VPNs can easily scale to accommodate new locations. Adding a new site remains a straightforward process, regardless of the number of already existing sites.

Difference Between Site-to-Site VPNs and Remote-Access VPNs

Now that you know more about site-to-site VPNs, let's talk about how they differ from (the more traditional) remote-access VPNs. While both types of VPN facilitate secure communications, they serve different needs:

  • A site-to-site VPN connects entire networks, turning them into a single virtual network that spans multiple geographically separate locations.
  • A remote-access VPN provides secure access for individual devices, such as laptops or smartphones, to an organization's local network. Typically, all remote devices connect to only a single central VPN server.

The centralized structure of a remote-access VPN is its biggest weakness. The central server can be overloaded by too many simultaneous connections, and a server outage means immediate connection loss for all remote devices, blocking work for anyone outside the local network.

In contrast, a site-to-site VPN has no single VPN server through which to route traffic. The aforementioned VPN gateways may turn out to be a bottleneck, but with services like NetBird, this isn't an issue (more on this later).

You can even consider a remote-access VPN as a special kind of site-to-site VPN. Think of one large local network and many small ones that contain only one device. NetBird's architecture is agnostic of constructs like site-to-site or remote access.

How NetBird Helps Create and Maintain Site-to-Site VPNs

If you're already familiar with NetBird, you may know that NetBird establishes direct point-to-point connections between devices. No physical gateway appliances are required to tunnel traffic from one site to another. So how does NetBird's model enable the creation of a site-to-site VPN?

Let's assume two separate, local networks. Devices in each of the two networks can access the internet, but firewalls (and, in most cases, also the internet provider) block access to the local network from the outside.

If a device in one local network wants to connect to a device in another local network, it cannot reach out to that device directly.

Now, let's assume the two devices have a NetBird client installed and are registered at a NetBird management server. This server runs outside any of the two local networks and is reachable by both.

A client in one local network that wants to connect to a client in another local network reaches out to NetBird's signaling service, which then contacts the target client to enable both clients to establish a point-to-point connection.

The following image is a slight modification from this architecture documentation , indicating the separate local networks:

Two separate clients connected to the NetBird management server, courtesy of Christoph Berger

The following image shows the connection negotiation in more detail. The two clients determine their public address from the Session Traversal Utilities for network address translator (STUN) service and then ask the signal service to make their public address known to the other client. The signal service then helps to establish the point-to-point connection:

Two clients negotiate a connection using the signal and STUN services, courtesy of Christoph Berger

This way, NetBird achieves site-to-site connectivity without the need to install VPN gateways at each site. NetBird does not require that you think in terms of local versus remote networks (although there is a related concept for groups for access control purposes). The whole virtual network is simply a set of direct point-to-point connections. As mentioned previously, you can even include remote access into the mix. A device with a NetBird client installed can be in any location with access to the internet and connect to other clients in the same NetBird VPN.

If you don't want or can't install NetBird clients on every device of a local network, you can use the NetBird routing feature to simulate a VPN gateway. In this scenario, a NetBird client acts as a routing peer for an entire subnet, effectively mimicking a VPN gateway.

The flexibility of NetBird's managed point-to-point connectivity really shines when modeling various network topologies.

Conclusion

Site-to-site VPNs connect multiple local networks through secure connections to make all networks appear as one and allow machines in one location to access machines in other locations.

Site-to-site VPNs might be laborious to set up, but they don't have to be. NetBird is flexible and agnostic to network topologies. It allows administrators to set up and manage virtual networks with great flexibility and ease.