Site-to-site networking without the site-to-site attack surface
Connect data centers, branch offices, clouds and edge locations over a zero trust overlay — instead of stitched-together IPsec tunnels, exposed concentrators and flat routable networks.
Legacy site-to-site links trade security for reachability
Exposed gateways
VPN concentrators and firewall endpoints listen on the public internet — a permanent, CVE-prone target that attackers scan for daily.
Network-level trust
Once a tunnel is up, whole subnets can talk to whole subnets. One compromised site becomes lateral movement into every connected site.
Operational drag
Peering meshes, overlapping IP ranges, NAT workarounds, per-site firewall changes — every new site multiplies configuration and risk.
Connect applications, not networks
CloakNet builds outbound-only, mutually authenticated tunnels from each site into a smart overlay fabric. Access is defined per service and per identity — so sites exchange exactly the traffic you intend, and nothing else.
- No inbound firewall rules at any site — endpoints dial out only
- End-to-end mTLS encryption between authenticated identities
- Private address overlap? Irrelevant — the overlay routes by service name, not IP
- Add a new site in minutes with software endpoints or a CloakNet router
- Microsegmented by default: policy decides who reaches what
Where teams use CloakNet site-to-site
- Data center ⇄ multi-cloud VPC connectivity
- Branch and retail sites to core applications
- Partner and B2B connectivity without shared VPNs
- Cloud migration links without opening the perimeter
- Backup & replication paths between facilities
Traditional VPN vs CloakNet overlay
| Capability | Site-to-Site VPN / MPLS | CloakNet Zero Trust Overlay |
|---|---|---|
| Inbound ports on the internet | Required at every gateway | None — outbound only |
| Unit of access | Subnets and routes | Individual services & identities |
| Lateral movement risk | High — flat routed networks | Contained by per-service policy |
| Overlapping IP ranges | NAT gymnastics | Not a problem — name-based routing |
| New site turn-up | Days–weeks of coordination | Minutes with software or a router |
| Encryption | Tunnel-level, hop by hop | End-to-end mTLS per session |
Three steps to zero trust site-to-site
Place an endpoint at each site
A container, VM appliance, or a CloakNet CN350W router at the edge. Each registers with a unique cryptographic identity and connects outbound.
Publish services into the fabric
Expose ERP, file services, databases or entire app tiers as named services — visible only inside the overlay.
Grant access by policy
Bind identities to services. Sites reach exactly what policy allows; everything else stays dark, logged and denied.
Retire your next VPN renewal
Bring us one site pair — we'll cloak it live in a demo.