VPN connections between branch offices

Two offices may need access to the same server, business application or shared data. We plan a VPN connection between locations, allow the required traffic and check how applications behave over the actual internet connections.

Request a connection plan
Conceptual illustration of a connection between two offices

When a site-to-site VPN is appropriate

A branch connection is useful when two local networks need to exchange selected business traffic. This may mean accessing a central application or a particular server. Before recommending it, we check whether the application vendor supports this arrangement and whether the available internet service meets its needs.

A site-to-site connection differs from an employee signing in from home. If the requirement is only email or cloud documents, linking entire networks may be unnecessary. We plan projects for businesses in Belgrade and New Belgrade, with working arrangements agreed for each remote location.

What we check first

  • Routers, firewalls, VPN capabilities and administrator access.
  • Internet connections, public-address availability and provider restrictions.
  • Address ranges at each site and possible overlap.
  • Servers, ports and users that require connectivity.
  • Bandwidth, latency and an acceptable configuration window.

If both offices use the same IP range, addressing changes or another supported approach need additional planning. Required hardware or provider services are identified in the proposal before implementation.

Connecting sites with limited access

Plan and configuration

We agree which networks communicate, document the existing settings and prepare a configuration rollback. The method must be supported by the equipment; routing and firewall rules are then aligned.

Testing business work

An active tunnel is not the whole acceptance test. With a user, we check the agreed application, file access or another real task, including behaviour after the connection is re-established.

Limits and handover

A VPN cannot increase your internet plan’s capacity or eliminate latency between sites. Large transfers, provider outages and application design affect the user experience. Backup internet connectivity or ongoing monitoring must be defined separately if required.

Your business receives an overview of connected networks, permitted traffic and maintenance responsibilities. One application needing access is not a reason to open the entire network. To separate guests, employees and servers, the project can include VLAN segmentation.

Getting a proposal

The number of sites, equipment compatibility, routing complexity and testing requirements determine the scope. Send an equipment overview and describe the work that needs to function across locations. We then identify prerequisites, labour costs and any hardware or provider charges.

For the wider service, see network infrastructure. Our IT services pricing page explains billing; the scope of this project is confirmed in a proposal.

Questions about this service

Is a static public IP address essential?
That depends on equipment, topology and provider conditions. We check public reachability, dynamic addresses and CGNAT before selecting a solution; not every connection supports the same setup.
Can a branch access only a specific server?
Where the equipment and addressing plan support it, routing and firewall rules can restrict access to agreed resources. We test permitted connections and confirm that prohibited ones are blocked.
Is ongoing VPN maintenance included?
Handover and agreed initial checks form part of the defined project. Continuous monitoring, later changes and interventions need a separate support agreement.