Site-to-site VPN

Connect every branch LAN into one private network.

Site-to-site VPN links the local networks behind your routers, so a device at one site can reach a device at another as if they shared a switch. It is included free with every Access router — you do not pay per branch or per route.

Three branch LANs connected through the MUA VPN server Three branch networks each connect over an encrypted WireGuard tunnel to the MUA VPN server. Every branch can reach every other branch. MUA VPN server hub · 10.66.0.1 Branch LAN 1 192.168.10.0/24 Branch LAN 2 192.168.20.0/24 Branch LAN 3 192.168.30.0/24 encrypted WireGuard tunnels

Each branch dials out once. The server joins the tunnels into one private network.

Every branch reaches every other

A device on Branch LAN 1 can reach a device on Branch LAN 3 without a direct link between the two sites and without either site having a public IP.

Routes pushed automatically

When a branch joins the network, the other routers are given the routes they need. When it leaves, those routes are withdrawn. You do not maintain route tables by hand.

WireGuard and SSTP together

One network can carry both WireGuard and SSTP tunnels, so you can include a router or machine that cannot run WireGuard.

Setting it up

Adding a branch is a drag, not a config change.

You build the network in the dashboard, not by hand on each device. That keeps the branches consistent and makes it obvious what is connected to what.

  1. 1

    Create a network

    Give the network a name. It becomes the container that holds the routers whose LANs should reach each other.

  2. 2

    Drag your routers in

    Move each Access router into the network from the dashboard. There is no need to visit each site or re-import a script.

  3. 3

    Traffic flows between branches

    The server pushes the necessary routes to every member router. Branch LANs can now reach one another over the encrypted tunnels.

How it is addressed

Your LAN addressing stays yours.

MUA VPN does not renumber your branch LANs. Each site keeps the local addressing it already uses. The tunnels carry traffic between those networks, and the server holds the routes that describe which network sits behind which router.

  • Each branch keeps its existing LAN subnets
  • Routes between branches are managed for you
  • Add or remove a branch without touching the others
  • Inter-branch traffic is carried inside the tunnels

Subnets shown in the diagram are illustrative. Your own addressing is used in practice.

Included free

Part of every Access router

Site-to-site VPN is not a separate plan. It is included with every Access router, so connecting a new branch costs the same as adding any other router.

See pricing

Good fits

Where site-to-site pays for itself.

Retail chains

Point-of-sale terminals at each branch reach the back-office server without a dedicated leased line to every shop.

Branch offices

Shared files, printers and internal services stay reachable between offices, even when every office is behind CGNAT.

Managed sites

Keep one management network across many customer sites and reach any of them from a single address plan.

Cameras and monitoring

View recorders and sensors at remote sites from head office, without exposing them to the public internet.

Bring your branches into one network.

Start with the 7-day free trial, add your routers, and put them in the same network from the dashboard.