Skip to content

Networks & Infrastructure

VPN & Site-to-Site Connectivity

We build VPN connectivity so branch sites operate as one network and remote users work securely. We define who reaches what, instead of granting access to the entire network, and hand over a register so access can be withdrawn the moment it is no longer needed by a person or a site.

Who it is for

  • Businesses with two or more locations
  • Companies with ERP or files centralised and users elsewhere
  • Organisations with permanent or periodic remote working
  • Sites where remote access is currently provided by open ports

When we are NOT the right choice

  • If unrestricted access with no rights model is expected
  • If provider circuits are inadequate and no upgrade is planned
  • If there is no administrative control of the endpoint equipment

PROCESS

The process

Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.

  1. 01Access requirements inventory

    We record which applications and data must be reachable, by whom, and from where. This defines the solution rather than the other way round.Time: 2-5 working daysDeliverable: A table of who needs what

  2. 02Topology and rights design

    We design site addressing so ranges do not collide, and define rights per user group rather than per individual request.Time: Alongside the studyDeliverable: Addressing and policy design

  3. 03Link implementation

    We implement with IPsec or WireGuard depending on the equipment, with automatic reconnection and state monitoring.Time: 1-3 days per siteDeliverable: Live link with automatic reconnection

  4. 04User access and testing

    We configure remote user access, test the real applications rather than connectivity alone, and hand over written instructions.Time: During implementationDeliverable: Written connection instructions per user

  5. 05Handover and management

    We hand over a register of who has access to what, and the procedure for withdrawing it when someone leaves.Time: On completionDeliverable: Access register and withdrawal procedure

What is included

  • Access requirements inventory per user group
  • Addressing design without range collisions
  • Implementation of links between sites
  • Remote user access with defined rights
  • State monitoring and alerting
  • Documentation and access withdrawal procedure

What is not included

  • Provider contracts and circuit upgrades
  • Third party software licences
  • Support of personal user devices, unless agreed
  • Endpoint equipment owned by a third party without access

Technology and equipment

  • MikroTik RouterOS
  • IPsec
  • WireGuard
  • Ubiquiti UniFi
  • Omada / TP-Link

From practice

Remote access usually starts as an exception: one user, one open port, one temporary arrangement. Two years later nobody knows how many people have access or to what, nor which of those accounts belong to people who have left.

The value of a VPN is not only encryption. It is that access becomes recorded and revocable. That is why we always hand over the register alongside the link itself.

Prerequisites

  • Stable internet connectivity at each site
  • Administrative control of endpoint equipment
  • A list of users and groups with their requirements
  • A work window for routing changes

Cost

Implementation is quoted per interconnected site, with equipment and labour itemised. Ongoing management, monitoring and user changes sit within the support agreement at a monthly charge.

We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.

What moves the cost

  • Number of sites to interconnect
  • Number of remote users
  • Whether new endpoint equipment is required
  • Complexity of the rights model per group

Frequently asked questions

What is the difference between site-to-site and user VPN?

Site-to-site permanently joins two locations so they operate as one network. A user VPN grants access to one person from wherever they are. Both often coexist in the same business.

Will ERP be slow over VPN?

Speed is set by the provider circuits and by how the application behaves. During the inventory we establish whether the application tolerates remote use or needs a different approach.

What happens when an employee leaves?

Access is withdrawn following the procedure we hand over. That is why we document who has access to what: without a register, stale access stays live for years.

Does this work with vessels?

Yes. Remote access to a vessel is built on the same principles, adapted to a satellite link and to the interruptions that come with it.

NEXT STEP

Request a connectivity study

We document who needs access to what and propose a topology with rights, costs and a timeline.

GET IN TOUCH

Tell us what you need

Four fields. An engineer replies, not a sales desk.

Fields marked * are required.

By sending this form you accept the processing of your details under our Privacy Policy.