Ask SecureGuard a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Site-to-site VPN on a firewall you run
SecureGuard models site-to-site tunnels in the same canonical document as the firewall rules that police them. You validate, preview the rendered daemon diff, commit atomically, and roll back by revision id. There is no cloud NGFW in the path.
What ships for site-to-site
- IPSec via strongSwan (including IPSec VTI)
- WireGuard
- SiteLink
- Tunnels counted combined toward the Hub tier cap (Community 1 · Home 5 · Business 25 · Enterprise unlimited)
- Remote-access VPN user caps are a separate Hub entitlement (Community 10 · Home 50 · Business/Enterprise unlimited) — do not mix with site-to-site tunnel counts.
- OSPF/BGP over tunnels: Business+ only (dynamic routing)
Console VPN group
The console VPN group lists IPSec · WireGuard · Amazon VPC · Cloud VPN · Client VPN · SiteLink · Tailscale · Rubix Link. This page covers site-to-site detail for IPSec, WireGuard, and SiteLink only. See Platform for the full nav.
How a change lands
Validate → render → apply. Preview the rendered strongSwan / WireGuard / SiteLink output before commit. Roll back by revision id if the change is wrong. Install from the latest Hub artifact (re-check Hub at Publish; do not treat any installer build as forever).
Hub prices
Community $0 · Home $149/yr · Business $589/yr · Enterprise $1,495/yr — re-GET Hub before Publish.
Platform · Sophos UTM replacement · Get started · Install · Pricing