# Overlay Networks

## Intro

Sometimes you need to securely connect devices on L4. This may be a link between your app and reverse proxy, Modbus TCP connection, or anything else lacks built-in secured transport. This is where Overlay Networking comes to play. You may think of it as a just fancier name for VPN :)

There are three kinds of overlay networking we use:


1. Sporadic WireGuard tunnels.
2. [Nebula](https://nebula.defined.net/docs/)
3. [Tailscale](https://tailscale.com) with [Headscale](https://headscale.net).

## WireGuard

There is nothing much to say about. You just set up point-to-point or hub-and-spoke tunnels between nodes you’d like to connect. There is no centralised infrastructure for maintaining such tunnels.

## Nebula

Nebula is a simple overlay network which intentionally lacks control nodes or planes, which makes it resilient to partial network outages. We use Nebula in our LAN for Critical Infrastructure to withstand potential gateway outages.


:::tip
Read more about Nebula [in the dedicated wiki article](/doc/nebula-yhHeLjxWdg).

:::

## Tailscale


:::info
WIP

:::



:::tip
Read more about Tailscale [in the dedicated wiki article](/doc/tailscale-9PsQGP0Zvf).

:::

---

**Documents**

- [BKSP 101](https://wiki.bksp.in/s/public/doc/bksp-101-HvrtlzB32F)
- [Проекты](https://wiki.bksp.in/s/public/doc/proekty-yjWZscgTvo)
- [Infrastructure](https://wiki.bksp.in/s/public/doc/infrastructure-VPKsJwVSVh)
- [Пространство](https://wiki.bksp.in/s/public/doc/prostranstvo-UF1eSbQDi5)
- [Equipment](https://wiki.bksp.in/s/public/doc/equipment-t5MYAVJ8l0)
- [Other](https://wiki.bksp.in/s/public/doc/other-uPW1YJQaRt)