SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Network · Live

Encryption and routing.

Reliably route and automatically protect network data from eavesdropping.

Overview

Secure, reliable by default.

Secure and reliable networks are the basis for smooth operations of all business-relevant applications. A virtual private network is required, with secure connections to every site across public and private networks (internet or MPLS), regardless of provider.

WAN Encryption and Routing by Open Systems enables secure site-to-site connections over the internet, MPLS, VSAT or other WAN transport layers, ensuring that all traffic between sites is automatically encrypted and authenticated, so business-critical data remains secure and the risk of internet eavesdropping is reduced. Routing traffic over direct paths ensures high performance and reliable connections, and consistent decryption and application visibility supports governance of applications that constantly compete for network resources.

Encrypted, reliably routed WAN traffic across the Open Systems network
Components

Three parts, one service.

Encryption

Encryption of all network traffic, whether sent via internet, MPLS or any other connectivity type, with automatic key renewals to protect information from eavesdropping.

Routing

Generic routing for direct path communication in the WAN, allowing interoperability with other networks via different protocols, and serving as the basis for Path Selection.

Application visibility

Decryption and filtering of all traffic with a single-pass architecture that provides an accurate and complete picture of the application landscape on the WAN.

How it works

From tunnels to application visibility.

Encryption

WAN traffic is protected through site-to-site IPSEC encryption. These VPN tunnels are built automatically, and their keys are rotated regularly. The topology of site interconnections is configurable and depends on the size of the network and its traffic patterns: full mesh for smaller networks or those with any-to-any communication, or partial mesh or star topologies for very large networks or when data is exchanged only occasionally.

Site-to-site IPSEC encryption topology across the WAN

Single-pass architecture

When traversing any Open Systems SD-WAN enforcement point, whether a physical deployment at a site or a cloud instance, traffic is decrypted for further analysis and filtering. Thanks to the single-pass architecture, decryption and traffic identification are done only once, ensuring performance and consistent traffic analysis. One of the most important insights comes from application visibility: which applications produce most of the transferred bits and bytes, and how much bandwidth they consume.

Single-pass architecture decrypting and analyzing traffic once

Routing

Basic routing in the WAN is dynamic, with optional static routes. Interoperability with other networks can be enabled by a set of static routes or dynamically. Routing information can also be propagated to the local LAN to enhance performance in and between site-to-site services. These routing protocols build the foundation for the application-based, smarter Path Selection routing that is part of SD-WAN.

Dynamic WAN routing with interoperability and LAN propagation
Benefits

What you get.

Automatic traffic encryption

Worry-free traffic encryption and authentication within the WAN, including regular IPSEC key renewals.

Flexible yet reliable routing

Stable routing within the WAN with flexible options for interoperability with LAN and other networks.

Single-pass architecture

Decrypt traffic only once for efficient analysis and processing, with consistent application visibility across your network.

Resources

Go deeper.

Leave complexity behind.

See how Open Systems runs encryption and routing as part of the full SASE Experience. Talk to a specialist.

Contact us
Already a customerEverything you use today keeps running.