Most Vouchio accounts never need to think about networking: you point your backup software at a public, encrypted endpoint and you're done. But once continuous replication is involved, especially on Recovery Ready, some businesses want traffic to travel over a private or dedicated path instead of the open internet. Here's how the options compare.

Option 1: Public endpoint (HTTPS / S3-compatible)

This is the default for every plan and the right choice for most SMBs. All traffic is encrypted in transit over TLS to a standard, internet-reachable endpoint, the same way you'd talk to any S3-compatible service. No firewall changes, no networking team required. If you're not sure which option you need, this is almost always it.

Option 2: Site-to-site VPN

A VPN tunnel connects your office or datacenter network directly to your Vouchio replication endpoint, so traffic never traverses the public internet as plain routed traffic (it's still encrypted, but now it's also confined to a private tunnel). This is a common choice once continuous replication is running around the clock and a business wants that traffic isolated from general internet egress, or wants storage traffic to appear as part of its own private network for firewall and routing purposes.

Good fit if You already run site-to-site VPNs to other locations or vendors, and want Vouchio to look like just another private network hop rather than an internet destination.

Option 3: GRE tunnel

GRE (Generic Routing Encapsulation) wraps traffic in its own tunnel headers so it can carry protocols or routing setups that don't travel cleanly over a standard connection, often paired with IPsec for encryption. It's more common in networks that already use GRE elsewhere, for example to link multiple office locations through a hub-and-spoke topology that also needs to reach Vouchio.

Good fit if Your network team already manages GRE tunnels between sites and wants Vouchio reachable through the same routing setup, rather than adding a separate connection type.

Option 4: IPsec tunnel

A standalone IPsec tunnel, without GRE, is a straightforward way to get authenticated, encrypted point-to-point connectivity between your network and Vouchio. It's a good middle ground for businesses that want a private, encrypted path but don't have an existing GRE setup to extend.

Option 5: Direct / cross-connect

For the highest and most predictable throughput, a direct or cross-connect is a private physical or virtual circuit between your infrastructure and Vouchio's, bypassing the public internet entirely. This is typically relevant for larger data volumes, colocated infrastructure, or businesses with strict requirements around where replication traffic travels. It usually involves coordinating with your datacenter or network provider, so lead times are longer than the other options.

OptionSetup effortBest for
Public endpointMinutesMost SMBs, standard backup software
Site-to-site VPNHoursIsolating replication traffic on your own network
GRE tunnelHours to a dayNetworks already using GRE across sites
IPsec tunnelHoursPrivate, encrypted point-to-point without GRE
Direct / cross-connectDays to weeksLarge volumes, colocated infrastructure, strict routing requirements

How to request one

Tell us your preferred connection method in the recovery-plan questionnaire, along with how many sites or locations need to connect. A specialist will confirm what's supported for your setup and, for VPN, GRE, IPsec, or direct connect, coordinate the technical details with whoever manages your network.

Not sure which option fits your setup?

Select "not sure, recommend for me" in the questionnaire and we'll suggest one based on your volume and sites.

Get your quote