Topology design
Based on branch count, internet links and central services, we choose hub-and-spoke or full mesh and plan non-overlapping branch subnets.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
If your factory reaches the accounting software through AnyDesk on a PC at head office, the link is slow and hard to control. A business VPN setup connects branch networks to head office through encrypted tunnels over the internet. Remote staff get access only to the servers they actually need.
Business VPN setup means connecting branch offices, factories and remote staff to head office through encrypted tunnels over the internet, with access limited to the servers each of them needs. It suits companies whose factory enters invoices by remoting into a head-office PC with AnyDesk, whose remote staff can't reach the file server, or who don't know who is connected from outside. PikoSystem designs a hub-and-spoke or full mesh topology with non-overlapping branch subnets, builds site-to-site VPN tunnels on IPsec or WireGuard between MikroTik, FortiGate or pfSense routers, sets up client VPN with a separate account per user, and restricts traffic between sites with explicit firewall rules. The result is a branch connectivity diagram, documented tunnel and firewall configuration, a VPN user list and a client setup guide for staff.
Based on branch count, internet links and central services, we choose hub-and-spoke or full mesh and plan non-overlapping branch subnets.
We build IPsec or WireGuard tunnels between MikroTik, FortiGate or pfSense routers at branches and head office, and set up routing between sites.
Client VPN runs on OpenVPN, WireGuard or FortiClient. Every user has a separate account, and access is limited by group.
Traffic between sites is controlled by explicit rules, so each branch reaches only what it needs, such as accounting software or the file server.
Tunnel outages trigger alerts. Where a branch has two internet links, a backup tunnel runs over the second one.
IPsec with IKEv2 is available on almost every business router and firewall and works across vendors, and many devices accelerate it in hardware. The downside is the number of parameters: one mismatch in algorithms or lifetimes and the tunnel never comes up.
WireGuard has a much shorter config, runs over a single UDP port and is fast on ordinary CPUs. On MikroTik it requires RouterOS 7. When both ends are MikroTik or Linux, WireGuard is the simpler option. For links to FortiGate or other vendors, IPsec is usually the safer choice.
MTU is a frequent cause. IPsec overhead enlarges packets, and without TCP MSS clamping on the tunnel, web pages and networked applications half-load while ping looks fine.
Mismatched phase 1 and phase 2 lifetimes, or DPD turned off, can leave one side thinking the tunnel is up while the other has torn it down. A branch behind a modem needs NAT-T, and WireGuard peers need persistent-keepalive so the modem's NAT entry doesn't expire. Branches without a static IP also need DDNS, or every address change breaks the tunnel.
Start with addressing. If both offices use 192.168.1.0/24, routing between them is impossible and one site has to be renumbered, which affects printers, cameras and anything with a manual IP.
Next, the internet link. Many LTE links sit behind carrier-grade NAT and can't accept inbound connections, so the branch must initiate the tunnel and head office needs a static IP. A list of the services and ports each branch needs should be ready before firewall rules are written.
With two or three branches, hub-and-spoke with static routes is enough. As sites are added, maintaining routes by hand gets error-prone, and OSPF over the tunnels distributes them automatically. Full mesh multiplies the tunnel count quickly, so it pays off only between sites that exchange a lot of traffic directly.
In hub-and-spoke, head office's internet link carries all inter-branch traffic. Check its capacity and the central router's encryption throughput before adding the next branch.
We list each branch's equipment, internet link, IP type and the services it must reach.
We propose topology, protocols and access policy and finalize them with you.
One branch is connected and tested first, then the rest are added one at a time.
We test service access, throughput and tunnel behavior during a link failure, then hand over documentation.
A static IP at head office makes things simpler. Branches without one can still connect with the right IPsec or WireGuard settings. We check each branch's link during the initial review.
Set up correctly, yes. Each employee has a separate account, current encryption is used and access is open only to required servers. We can add two-factor authentication, and every login is logged.
Yes. IPsec is supported by MikroTik, FortiGate, pfSense and most business routers, so mixed hardware is common. We match the encryption settings on both ends and test each tunnel.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.