Retail chains
Point-of-sale terminals at each branch reach the back-office server without a dedicated leased line to every shop.
Site-to-site VPN
Site-to-site VPN links the local networks behind your routers, so a device at one site can reach a device at another as if they shared a switch. It is included free with every Access router — you do not pay per branch or per route.
Each branch dials out once. The server joins the tunnels into one private network.
A device on Branch LAN 1 can reach a device on Branch LAN 3 without a direct link between the two sites and without either site having a public IP.
When a branch joins the network, the other routers are given the routes they need. When it leaves, those routes are withdrawn. You do not maintain route tables by hand.
One network can carry both WireGuard and SSTP tunnels, so you can include a router or machine that cannot run WireGuard.
Setting it up
You build the network in the dashboard, not by hand on each device. That keeps the branches consistent and makes it obvious what is connected to what.
Give the network a name. It becomes the container that holds the routers whose LANs should reach each other.
Move each Access router into the network from the dashboard. There is no need to visit each site or re-import a script.
The server pushes the necessary routes to every member router. Branch LANs can now reach one another over the encrypted tunnels.
How it is addressed
MUA VPN does not renumber your branch LANs. Each site keeps the local addressing it already uses. The tunnels carry traffic between those networks, and the server holds the routes that describe which network sits behind which router.
Subnets shown in the diagram are illustrative. Your own addressing is used in practice.
Site-to-site VPN is not a separate plan. It is included with every Access router, so connecting a new branch costs the same as adding any other router.
Good fits
Point-of-sale terminals at each branch reach the back-office server without a dedicated leased line to every shop.
Shared files, printers and internal services stay reachable between offices, even when every office is behind CGNAT.
Keep one management network across many customer sites and reach any of them from a single address plan.
View recorders and sensors at remote sites from head office, without exposing them to the public internet.
Start with the 7-day free trial, add your routers, and put them in the same network from the dashboard.