Skip to main content
Cloud / STACKIT / Products / STACKIT VPN - Managed IPsec Site-to-Site

STACKIT VPN - Managed IPsec Site-to-Site

STACKIT VPN: managed IPsec gateway for encrypted site-to-site tunnels between on-premise and STACKIT Cloud with an active-active architecture.

Network
Pricing Model Plan/SKU-based per VPN gateway by bandwidth tier
Availability STACKIT regions eu01 (Germany) and eu02 (Austria)
Data Sovereignty EU-sovereign cloud of the Schwarz Group, operated in Europe
Reliability SLA as published by the provider SLA

What is STACKIT VPN?

STACKIT VPN is a managed VPN gateway service that establishes encrypted IPsec site-to-site tunnels between on-premise networks and the STACKIT Cloud. The service uses the standard IPsec protocol with IKEv2 and connects external networks to your cloud resources through a STACKIT Network Area (SNA). STACKIT VPN solves the problem of connecting local data centers and branch sites to a sovereign EU cloud securely and without dedicated hardware appliances. The service is generally available (GA) as a managed service and can be used via the STACKIT API.

The service consists of two components: the VPN gateway as the access point into the SNA, and the VPN connections, which are the actual encrypted tunnels. The gateway is built internally as an active-active architecture with two instances that provide parallel, resilient tunnels. A separate tunnel interface is created per availability zone, so the connection stays available even if one zone fails.

Core features

  • IPsec tunnels with IKEv2: Encrypted, industry-standard site-to-site connections between on-premise and the STACKIT Cloud.
  • Active-active high availability: The gateway internally consists of two instances that provide parallel tunnels; a separate tunnel interface is created per availability zone.
  • Three routing modes: policy-based (with local and remote subnets), static route-based via a Virtual Tunnel Interface, and BGP route-based for dynamic routing.
  • Bandwidth by plan: Select guaranteed bandwidth via plan or SKU, ranging from 100 Mbit/s to 1,000 Mbit/s per the release notes, with configurable IKE rekey times.
  • Site-to-site and site-to-multisite: Connect one or several sites to the same STACKIT Network Area.

Typical use cases

Hybrid cloud connectivity: Connect an existing data center to the STACKIT Cloud over encrypted tunnels and run workloads across sites without routing traffic over the open internet.

Multi-site connectivity: Use BGP route-based routing to connect several branch sites dynamically to the STACKIT Network Area and exchange routes automatically.

Multi-cloud networking: Establish IPsec tunnels between STACKIT and other environments to connect distributed architectures in a sovereign, encrypted way.

Benefits

  • Managed service without your own VPN hardware or manual appliance operation
  • Resilient active-active architecture with one tunnel interface per availability zone
  • EU-sovereign operation in the Schwarz Group cloud (regions eu01 and eu02)
  • Fully controllable via the STACKIT API

Integration with innFactory

As an official STACKIT Partner, innFactory supports you with the adoption and operation of this service.

Typical Use Cases

Hybrid connectivity from data centers to the STACKIT Cloud
Encrypted site-to-site link between on-premise and a STACKIT Network Area
Dynamic routing via BGP across multiple sites
Multi-cloud networking over IPsec tunnels

Frequently Asked Questions

What is STACKIT VPN?

STACKIT VPN is a managed IPsec gateway service that establishes encrypted site-to-site tunnels between on-premise networks and the STACKIT Cloud. The service uses IKEv2 and connects external sites to a STACKIT Network Area (SNA). An active-active architecture provides parallel, resilient tunnels.

When should I use STACKIT VPN?

Use STACKIT VPN when you need to connect data centers or branch sites securely to the STACKIT Cloud, for example for hybrid architectures, data migration, or accessing cloud workloads from your own network. For multiple sites or dynamic topologies, the service supports routing via BGP.

How much does STACKIT VPN cost?

Billing is plan- or SKU-based per VPN gateway and tiered by bandwidth. The exact bandwidth and the number of included connections depend on the selected plan. For binding prices, refer to the official STACKIT pricing overview.

Which routing modes and limits does STACKIT VPN support?

The service supports three routing modes: policy-based (with local and remote subnets), static route-based via a Virtual Tunnel Interface (VTI), and BGP route-based for dynamic routing. IKE rekey times are configurable: Phase 1 between 900 and 28800 seconds, Phase 2 between 900 and 3600 seconds. Per the release notes, bandwidth ranges from 100 Mbit/s to 1,000 Mbit/s. STACKIT VPN requires an existing STACKIT Network Area.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

AWS

Amazon API Gateway - Managed API Platform

Amazon API Gateway is a fully managed service for creating, publishing, and managing REST, HTTP, and WebSocket APIs.

Pricing Pay per request (tiered by volume), plus …
SLA SLA as published by the provider
Compare →
AWS

Amazon CloudFront: Content Delivery Network

Amazon CloudFront is AWS's global CDN with 750+ Points of Presence for fast content delivery worldwide.

Pricing Pay-as-you-go (data transfer and …
SLA 99.9% Monthly Uptime Percentage per official SLA
Compare →
AWS

Amazon Route 53 - DNS and Domain Registration

Amazon Route 53 is AWS' scalable DNS service for domain registration, routing, and health checks.

Pricing Pay per hosted zone and per DNS query, …
SLA SLA as published by the provider: tiered service credits when monthly availability falls below 99.99% (see official SLA page)
Compare →
AWS

Amazon Route 53 Global Resolver - Hybrid DNS

Amazon Route 53 Global Resolver: internet-reachable anycast DNS resolver for secure DNS resolution across branch, remote …

Pricing Hourly per-region fee + pay-per-query
SLA N/A
Compare →
AWS

Amazon VPC - AWS Networking & Content Delivery Service

Amazon VPC is an AWS service for Network isolation and Multi-tier web applications. GDPR-compliant in EU regions.

Pricing No charge for the VPC itself, pay only …
SLA N/A (free base service; components like NAT Gateway have their own SLAs)
Compare →
AWS

Amazon VPC Lattice - Application Networking

Amazon VPC Lattice simplifies service-to-service communication. Consistent application networking across VPCs and …

Pricing Pay-per-use: hourly per service plus per …
SLA SLA as published by the provider
Compare →

57 comparable products found across other clouds.

Ready to start with STACKIT VPN - Managed IPsec Site-to-Site?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation