Solutions · Hybrid Connectivity

Connect sites, services, and workloads across hybrid environments.

Bring cloud VPCs, on-premise IDCs, office networks, and edge nodes under one access overlay — without collapsing them into a single flat network.

One overlay. Every environment type.

NetSeed connects sites across deployment boundaries using WireGuard tunnels between NSN nodes and NSGW ingress points. Each environment keeps its own network boundary — they are joined at the service level, not flattened at the network level.

  • Cloud VPC connectivity Connect AWS, GCP, Azure, or private cloud VPCs into the overlay. Services are reachable by name across region and provider boundaries.
  • On-premise IDC integration NSN runs alongside existing on-premise workloads without requiring network topology changes. The tunnel reaches out; nothing needs to be opened inbound.
  • Office and branch networks Office sites join the overlay through a site node. Users at the office get the same access boundaries as remote users — policy follows identity, not location.
  • Edge and embedded environments Edge deployments with constrained networking join through the same NSN binary — same policy model, same audit record format.
HYBRID CONNECTIVITY

Service-level joining, not network flattening

Each environment retains its own network boundary. A workload in the cloud VPC and a workload in the on-premise IDC can communicate at the service level — but neither gets flat access to the other's surrounding network.

Architecture

Sites connect through gateway ingress points and site nodes.

NSGW provides multi-region ingress. NSN runs at each site. Policy flows from NSD. Every environment participates in the same access model regardless of deployment type.

Cloud VPC
NSGW POP
On-Prem IDC
Key capabilities

Designed for environments that do not simplify.

INGRESS

Multi-region NSGW ingress

Deploy NSGW ingress points in multiple regions. Clients connect to the nearest ingress point — latency is reduced without replicating policy configuration per-region.

ACCESS

Cross-environment service access

A workload in one environment can reach a named service in another environment through the overlay — authenticated, authorized, and audited at every hop.

MODELS

Mixed deployment models

Cloud-managed control plane alongside self-hosted site nodes. Fully self-hosted. Cloud for one region, self-hosted for another. Deployment models coexist in the same policy domain.

Policy follows identity. Not environment boundaries.

A developer with access to a staging database has that access whether they are in the office, at home, in the cloud environment, or connected through the IDC. The policy is the same. The enforcement is at the site, close to the resource.

+Identity-based policy applies across all environments
+NSN enforces locally — control plane outage does not break access
+Per-flow audit records from every site, normalized format
+No special rules for cross-environment traffic
CONSISTENCY

Same access model everywhere

The NSN binary runs the same policy evaluation logic at every site — cloud, IDC, office, or edge. There is no separate "inter-site" policy layer to manage.

Get started

Connect your environments without flattening them.

Hybrid connectivity is part of the standard NetSeed deployment — no additional licensing tier or separate product needed.