PikoSystem IT engineering services
Network & Virtualization

Business VPN Setup and Secure Branch Connectivity

If your factory reaches the accounting software through AnyDesk on a PC at head office, the link is slow and hard to control. A business VPN setup connects branch networks to head office through encrypted tunnels over the internet. Remote staff get access only to the servers they actually need.

Tools & technology vpn-branch-connectivity
  • IPsec IKEv2
  • WireGuard
  • OpenVPN
  • MikroTik RouterOS
  • FortiGate
  • pfSense
  • FortiClient
  • Zabbix
5work areas
4deliverables
4steps

What is Business VPN & Branch Links?

Business VPN setup means connecting branch offices, factories and remote staff to head office through encrypted tunnels over the internet, with access limited to the servers each of them needs. It suits companies whose factory enters invoices by remoting into a head-office PC with AnyDesk, whose remote staff can't reach the file server, or who don't know who is connected from outside. PikoSystem designs a hub-and-spoke or full mesh topology with non-overlapping branch subnets, builds site-to-site VPN tunnels on IPsec or WireGuard between MikroTik, FortiGate or pfSense routers, sets up client VPN with a separate account per user, and restricts traffic between sites with explicit firewall rules. The result is a branch connectivity diagram, documented tunnel and firewall configuration, a VPN user list and a client setup guide for staff.

When you need Business VPN & Branch Links

  • Our factory remotes into a PC at head office to enter invoices.
  • Remote staff can't reach the company file server.
  • The tunnel between branches drops several times a day.
  • We have no idea who is connected to our network from outside.

What Business VPN & Branch Links includes

01

Topology design

Based on branch count, internet links and central services, we choose hub-and-spoke or full mesh and plan non-overlapping branch subnets.

02

Site-to-site VPN

We build IPsec or WireGuard tunnels between MikroTik, FortiGate or pfSense routers at branches and head office, and set up routing between sites.

03

Remote staff access

Client VPN runs on OpenVPN, WireGuard or FortiClient. Every user has a separate account, and access is limited by group.

04

Inter-branch firewalling

Traffic between sites is controlled by explicit rules, so each branch reaches only what it needs, such as accounting software or the file server.

05

Monitoring and backup tunnels

Tunnel outages trigger alerts. Where a branch has two internet links, a backup tunnel runs over the second one.

What you get from Business VPN & Branch Links

  • Branch connectivity diagram and addressing table
  • Tunnel and firewall rule configuration with notes
  • VPN user list and access groups
  • VPN client setup guide for staff

Business VPN & Branch Links: a practical guide

Site-to-site VPN: IPsec or WireGuard?

IPsec with IKEv2 is available on almost every business router and firewall and works across vendors, and many devices accelerate it in hardware. The downside is the number of parameters: one mismatch in algorithms or lifetimes and the tunnel never comes up.

WireGuard has a much shorter config, runs over a single UDP port and is fast on ordinary CPUs. On MikroTik it requires RouterOS 7. When both ends are MikroTik or Linux, WireGuard is the simpler option. For links to FortiGate or other vendors, IPsec is usually the safer choice.

Why does the tunnel between branches keep dropping?

MTU is a frequent cause. IPsec overhead enlarges packets, and without TCP MSS clamping on the tunnel, web pages and networked applications half-load while ping looks fine.

Mismatched phase 1 and phase 2 lifetimes, or DPD turned off, can leave one side thinking the tunnel is up while the other has torn it down. A branch behind a modem needs NAT-T, and WireGuard peers need persistent-keepalive so the modem's NAT entry doesn't expire. Branches without a static IP also need DDNS, or every address change breaks the tunnel.

Connecting two offices with MikroTik: what to check first

Start with addressing. If both offices use 192.168.1.0/24, routing between them is impossible and one site has to be renumbered, which affects printers, cameras and anything with a manual IP.

Next, the internet link. Many LTE links sit behind carrier-grade NAT and can't accept inbound connections, so the branch must initiate the tunnel and head office needs a static IP. A list of the services and ports each branch needs should be ready before firewall rules are written.

Routing and topology as branch count grows

With two or three branches, hub-and-spoke with static routes is enough. As sites are added, maintaining routes by hand gets error-prone, and OSPF over the tunnels distributes them automatically. Full mesh multiplies the tunnel count quickly, so it pays off only between sites that exchange a lot of traffic directly.

In hub-and-spoke, head office's internet link carries all inter-branch traffic. Check its capacity and the central router's encryption throughput before adding the next branch.

How Business VPN & Branch Links works

  1. 01

    Branch survey

    We list each branch's equipment, internet link, IP type and the services it must reach.

  2. 02

    Connectivity plan

    We propose topology, protocols and access policy and finalize them with you.

  3. 03

    Staged rollout

    One branch is connected and tested first, then the rest are added one at a time.

  4. 04

    Test and handover

    We test service access, throughput and tunnel behavior during a link failure, then hand over documentation.

Business VPN & Branch Links: frequently asked questions

Does every branch need a static IP?

A static IP at head office makes things simpler. Branches without one can still connect with the right IPsec or WireGuard settings. We check each branch's link during the initial review.

Is remote employee access to the network secure?

Set up correctly, yes. Each employee has a separate account, current encryption is used and access is open only to required servers. We can add two-factor authentication, and every login is logged.

Can branches with different router brands be connected?

Yes. IPsec is supported by MikroTik, FortiGate, pfSense and most business routers, so mixed hardware is common. We match the encryption settings on both ends and test each tunnel.

Related searches

  • branch office connectivity
  • site-to-site VPN
  • remote employee access
  • WireGuard setup
  • IPsec VPN
  • connecting offices over the internet

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.