All systems operational Your IP: 18.97.14.83 info@cloudhosting.lv +371 66 66 29 69 Client area
Site-to-site VPN · CloudHosting

Site-to-site VPN your offices never have to think about

Managed IPsec or WireGuard tunnels between your offices, our cloud and your data centre gear. We design, deploy and monitor them, you just use the network.

  • IPsec or WireGuard
  • Offices, cloud and DC in one network
  • Monitored around the clock
Site-to-site VPN

What a managed VPN gives you

One private network

Offices, remote staff and servers in our cloud reach each other over encrypted tunnels with sane addressing.

Modern crypto

WireGuard where speed matters, IPsec where the other side requires it. Configured properly either way.

Watched, not forgotten

Tunnels are monitored with alerting; a flapping link gets an engineer before users file tickets.

Works with your gear

MikroTik, Fortinet, pfSense or cloud endpoints: we integrate what you already run.

What the service includes

  • Network design with addressing and routing plan
  • IPsec or WireGuard tunnel configuration
  • Connection of offices, cloud VPS and colocated gear
  • Failover paths for critical links where needed
  • Monitoring with alerting on tunnel health
  • Change support when offices move or grow

Price depends on the number of sites and endpoints: request a quote for your topology.

How it works

  1. 1

    Design

    We map sites, subnets and equipment, and pick IPsec or WireGuard per link.

  2. 2

    Deploy

    Tunnels are configured, routed and tested with your team, site by site.

  3. 3

    Operate

    We watch tunnel health and adjust the setup when your topology changes.

Site-to-site VPN questions

What is a site-to-site VPN?

A site-to-site VPN joins whole networks, for example two offices or an office and a cloud, into one private network over an encrypted tunnel. The tunnel runs between the routers or firewalls at each location, so every device behind them reaches the other side securely without a VPN client installed on every laptop or phone. For day-to-day users nothing changes: file shares, internal tools and printers simply work as if everyone sat in one building. We build these tunnels with IPsec or WireGuard, plan the addressing so the networks do not clash, and monitor the links around the clock so problems are seen early.

IPsec or WireGuard: which one do I need?

In most cases you do not have to decide: in a managed setup we pick the protocol per link based on what each side supports. WireGuard is faster and simpler, so we prefer it wherever both endpoints allow it, for example between a MikroTik router and our cloud. IPsec remains the right choice when the far end is a corporate firewall that only speaks IPsec, which is still common in larger companies and with partners you do not control. Both protocols are configured with modern settings either way. If you already know a constraint on your side, mention it when requesting a quote and we will plan around it.

How much does a managed site-to-site VPN cost?

There is no fixed list price because every topology is different: connecting two offices and a cloud is a smaller job than a network of many sites with failover paths. The price depends on the number of sites and endpoints you want connected. Network design with an addressing and routing plan, tunnel deployment and 24/7 monitoring are part of the service, not separate line items you discover later. To get a concrete number, send us a short list of your locations, what equipment sits at each one and which links are critical for you, and we will return a quote for that exact setup.

Can you connect our office to servers in your cloud?

Yes, that is the most common request we get. We build an encrypted tunnel from your office router straight into your private network on our VPS or colocation, so your servers behave like another room in the office. Staff open internal applications, databases and file shares by their private addresses, and those services no longer need to be exposed to the public internet at all. We plan the addressing together so office and cloud subnets do not overlap, configure routing on both ends and test it with your team. After that, adding another server on the cloud side is just a routing entry, not a new project.

Do we need special hardware in the office?

Usually not. Most offices already have a router or firewall that can terminate a tunnel: we work with common platforms such as MikroTik, Fortinet and pfSense, and with cloud endpoints where a site has no physical gear at all. During the design stage we check what each location runs, its software version and remaining capacity, and reuse it whenever that is safe. If the office has nothing suitable, for example only an ISP box that cannot be configured, we recommend an appropriate device and configure it for you. You stay the owner of your equipment; we simply manage the VPN part of its configuration.

What happens if a tunnel drops?

Every tunnel we run is monitored with alerting, so a drop is noticed by our engineers, not discovered by your users. The first step is diagnosis: a failed ISP line, a rebooted router and a changed configuration on the far side all look different and need different fixes. The tunnel is then brought back or, where a backup path exists, traffic is failed over to it. For critical sites we design that second path in advance during the network design stage, so a single line failure does not stop your work. A link that keeps flapping gets attention before it turns into an outage, which is the main practical difference from an unmanaged setup.

Can remote employees use the same VPN?

Yes. Remote staff join the same private network as your offices and the servers in our cloud. In practice this means one addressing plan and one set of firewall rules covers everyone, instead of a separate remote-access product living next to the site tunnels. A person working from home reaches the same internal services as a colleague at a desk in the office, under the same access rules. This also keeps administration simpler: when someone leaves, you revoke one access, and when a service moves from the office to the cloud, nobody has to reconfigure their client. Tell us roughly how many remote users you expect and we will include them in the design.

Where are your servers located?

Our own Tier 3+ data centre is in Riga, Latvia, and we run our own network under AS58269, so the infrastructure your tunnel lands on is operated by us end to end. A second region is available in Amsterdam, the Netherlands, and a Dubai location can be arranged on request. A tunnel from your office terminates directly in your private network next to your VPS or colocated equipment, whichever region it lives in. If your sites are spread across countries, we take that geography into account during the design stage, for example by connecting each office to the nearest region. Ask us which placement fits your topology when you request a quote.

Ready to start?

Deploy in minutes or talk to an engineer about what fits your project.