Whether two sites, twenty home office workstations or connecting cloud servers to the company network: you get a network concept with clean routing, user management, two-factor authentication and documentation that other technicians can work with as well.
What is included
- Site-to-site VPN between sites, data centres and cloud providers with WireGuard or IPsec, redundant on request
- Home office and client VPN with WireGuard, OpenVPN or IPsec for Windows, macOS, Linux, iOS and Android
- Two-factor authentication, certificates or integration with Active Directory, Entra ID and RADIUS
- VPN gateways on OPNsense, pfSense, MikroTik, UniFi or Linux servers, high availability with CARP or keepalived
- Routing and firewall rules within the VPN: only the services that are needed are reachable, split tunnel or full tunnel as required
- Replacement of port forwarding, open RDP access and remote maintenance tools with a VPN
- Zero-trust alternatives such as Tailscale or NetBird when classic gateways do not fit
- Onboarding and offboarding of users, documentation, monitoring of the connections
Typical assignments
- Two sites of a company are coupled via WireGuard on OPNsense firewalls, file server and telephony work across sites.
- Twenty home office workstations get WireGuard with two-factor authentication, the open remote desktop port is closed.
- Servers at a cloud provider are connected to the data centre via IPsec, database and backup now only run encrypted internally.
- A NAS with port forwarding is placed behind a VPN, access stays just as convenient for all employees.
Process
Request
Describe your needs briefly via the form, WhatsApp or the live chat.
Assessment
Within one business day you receive an assessment with effort, price and a proposed date.
Implementation
I do the work personally, remotely via secured access or on site, and keep you updated throughout.
Handover and invoice
Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.
Questions about this service
WireGuard, IPsec or OpenVPN?
WireGuard is fast, lean and easy to audit, my first choice for new installations. IPsec when you couple firewalls from different vendors or requirements demand it. OpenVPN when it is already running and clients depend on it.
Is a VPN not complicated for employees?
No. On notebooks and smartphones the connection is one click or starts automatically as soon as the company network is needed. Effort only arises during setup, and I take care of that.
Can you also connect cloud servers to our network?
Yes. Servers at Hetzner, OVH, AWS, Azure or KernelHost GmbH are connected via VPN so that database, backup and administration only run over the internal network and no ports are open to the internet.
Remote for companies across Germany, alignment via video call, ticket or chat.