Skip to main content
Cloud / STACKIT / Products / STACKIT VPN - Managed IPsec Site-to-Site

STACKIT VPN - Managed IPsec Site-to-Site

STACKIT VPN: managed IPsec gateway for encrypted site-to-site tunnels between on-premise and STACKIT Cloud with an active-active architecture.

Network
Pricing Model Plan/SKU-based per VPN gateway by bandwidth tier
Availability STACKIT regions eu01 (Germany) and eu02 (Austria)
Data Sovereignty EU-sovereign cloud of the Schwarz Group, operated in Europe
Reliability SLA as published by the provider SLA

What is STACKIT VPN?

STACKIT VPN is a managed VPN gateway service that establishes encrypted IPsec site-to-site tunnels between on-premise networks and the STACKIT Cloud. The service uses the standard IPsec protocol with IKEv2 and connects external networks to your cloud resources through a STACKIT Network Area (SNA). STACKIT VPN solves the problem of connecting local data centers and branch sites to a sovereign EU cloud securely and without dedicated hardware appliances. STACKIT documentation does not state an official GA or beta status for the service: the API runs under the /v1beta1/ path, and Portal, CLI and Terraform integration are announced as “will be available soon”. Currently the service can be used via the STACKIT API and the Go SDK.

The service consists of two components: the VPN gateway as the access point into the SNA, and the VPN connections, which are the actual encrypted tunnels. The gateway is built internally as an active-active architecture with two instances that provide parallel, resilient tunnels. A separate tunnel interface is created per availability zone, so the connection stays available even if one zone fails.

Core features

  • IPsec tunnels with IKEv2: Encrypted, industry-standard site-to-site connections between on-premise and the STACKIT Cloud.
  • Active-active high availability: The gateway internally consists of two instances that provide parallel tunnels; a separate tunnel interface is created per availability zone.
  • Three routing modes: policy-based (with local and remote subnets), static route-based via a Virtual Tunnel Interface, and BGP route-based for dynamic routing.
  • Bandwidth by plan: Select guaranteed bandwidth via plan or SKU, ranging from 100 Mbit/s to 1,000 Mbit/s per the release notes, with configurable IKE rekey times.
  • Site-to-site and site-to-multisite: Connect one or several sites to the same STACKIT Network Area.

Typical use cases

Hybrid cloud connectivity: Connect an existing data center to the STACKIT Cloud over encrypted tunnels and run workloads across sites without routing traffic over the open internet.

Multi-site connectivity: Use BGP route-based routing to connect several branch sites dynamically to the STACKIT Network Area and exchange routes automatically.

Multi-cloud networking: Establish IPsec tunnels between STACKIT and other environments to connect distributed architectures in a sovereign, encrypted way.

Benefits

  • Managed service without your own VPN hardware or manual appliance operation
  • Resilient active-active architecture with one tunnel interface per availability zone
  • EU-sovereign operation in the Schwarz Group cloud (regions eu01 and eu02)
  • Fully controllable via the STACKIT API

Integration with innFactory

As an official STACKIT Partner, innFactory supports you with the adoption and operation of this service.

Typical Use Cases

Hybrid connectivity from data centers to the STACKIT Cloud
Encrypted site-to-site link between on-premise and a STACKIT Network Area
Dynamic routing via BGP across multiple sites
Multi-cloud networking over IPsec tunnels

Frequently Asked Questions

What is STACKIT VPN?

STACKIT VPN is a managed IPsec gateway service that establishes encrypted site-to-site tunnels between on-premise networks and the STACKIT Cloud. The service uses IKEv2 and connects external sites to a STACKIT Network Area (SNA). An active-active architecture provides parallel, resilient tunnels.

When should I use STACKIT VPN?

Use STACKIT VPN when you need to connect data centers or branch sites securely to the STACKIT Cloud, for example for hybrid architectures, data migration, or accessing cloud workloads from your own network. For multiple sites or dynamic topologies, the service supports routing via BGP.

How much does STACKIT VPN cost?

Billing is plan- or SKU-based per VPN gateway and tiered by bandwidth. The exact bandwidth and the number of included connections depend on the selected plan. For binding prices, refer to the official STACKIT pricing overview.

Which routing modes and limits does STACKIT VPN support?

The service supports three routing modes: policy-based (with local and remote subnets), static route-based via a Virtual Tunnel Interface (VTI), and BGP route-based for dynamic routing. IKE rekey times are configurable: Phase 1 between 900 and 28800 seconds, Phase 2 between 900 and 3600 seconds. Per the release notes, bandwidth ranges from 100 Mbit/s to 1,000 Mbit/s. STACKIT VPN requires an existing STACKIT Network Area.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

70 comparable products found across other clouds.

Ready to start with STACKIT VPN - Managed IPsec Site-to-Site?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation