IPSec · WireGuard · SiteLink

Site-to-site VPN on a firewall you run

SecureGuard models site-to-site tunnels in the same canonical document as the firewall rules that police them. You validate, preview the rendered daemon diff, commit atomically, and roll back by revision id. There is no cloud NGFW in the path.

What ships for site-to-site

  • IPSec via strongSwan (including IPSec VTI)
  • WireGuard
  • SiteLink
  • Tunnels counted combined toward the Hub tier cap (Community 1 · Home 5 · Business 25 · Enterprise unlimited)
  • Remote-access VPN user caps are a separate Hub entitlement (Community 10 · Home 50 · Business/Enterprise unlimited) — do not mix with site-to-site tunnel counts.
  • OSPF/BGP over tunnels: Business+ only (dynamic routing)

Console VPN group

The console VPN group lists IPSec · WireGuard · Amazon VPC · Cloud VPN · Client VPN · SiteLink · Tailscale · Rubix Link. This page covers site-to-site detail for IPSec, WireGuard, and SiteLink only. See Platform for the full nav.

How a change lands

Validate → render → apply. Preview the rendered strongSwan / WireGuard / SiteLink output before commit. Roll back by revision id if the change is wrong. Install from the latest Hub artifact (re-check Hub at Publish; do not treat any installer build as forever).

Hub prices

Community $0 · Home $149/yr · Business $589/yr · Enterprise $1,495/yr — re-GET Hub before Publish.

Platform · Sophos UTM replacement · Get started · Install · Pricing