Overlay Networks

Intro

Sometimes you need to securely connect devices on L4. This may be a link between your app and reverse proxy, Modbus TCP connection, or anything else lacks built-in secured transport. This is where Overlay Networking comes to play. You may think of it as a just fancier name for VPN :)

There are three kinds of overlay networking we use:

  1. Sporadic WireGuard tunnels.

  2. Nebula

  3. Tailscale with Headscale.

WireGuard

There is nothing much to say about. You just set up point-to-point or hub-and-spoke tunnels between nodes you’d like to connect. There is no centralised infrastructure for maintaining such tunnels.

Nebula

Nebula is a simple overlay network which intentionally lacks control nodes or planes, which makes it resilient to partial network outages. We use Nebula in our LAN for Critical Infrastructure to withstand potential gateway outages.

Read more about Nebula in the dedicated wiki article.

Tailscale

WIP


Read more about Tailscale in the dedicated wiki article.