Most Vouchio accounts never need to think about networking: you point your backup software at a public, encrypted endpoint and you're done. But once continuous replication is involved, especially on Recovery Ready, some businesses want traffic to travel over a private or dedicated path instead of the open internet. Here's how the options compare.
Option 1: Public endpoint (HTTPS / S3-compatible)
This is the default for every plan and the right choice for most SMBs. All traffic is encrypted in transit over TLS to a standard, internet-reachable endpoint, the same way you'd talk to any S3-compatible service. No firewall changes, no networking team required. If you're not sure which option you need, this is almost always it.
- Fastest to set up: works with any S3-compatible backup or NAS software out of the box
- No dedicated hardware or ISP coordination required
- Encrypted in transit by default, on every plan tier
Option 2: Site-to-site VPN
A VPN tunnel connects your office or datacenter network directly to your Vouchio replication endpoint, so traffic never traverses the public internet as plain routed traffic (it's still encrypted, but now it's also confined to a private tunnel). This is a common choice once continuous replication is running around the clock and a business wants that traffic isolated from general internet egress, or wants storage traffic to appear as part of its own private network for firewall and routing purposes.
Option 3: GRE tunnel
GRE (Generic Routing Encapsulation) wraps traffic in its own tunnel headers so it can carry protocols or routing setups that don't travel cleanly over a standard connection, often paired with IPsec for encryption. It's more common in networks that already use GRE elsewhere, for example to link multiple office locations through a hub-and-spoke topology that also needs to reach Vouchio.
Option 4: IPsec tunnel
A standalone IPsec tunnel, without GRE, is a straightforward way to get authenticated, encrypted point-to-point connectivity between your network and Vouchio. It's a good middle ground for businesses that want a private, encrypted path but don't have an existing GRE setup to extend.
Option 5: Direct / cross-connect
For the highest and most predictable throughput, a direct or cross-connect is a private physical or virtual circuit between your infrastructure and Vouchio's, bypassing the public internet entirely. This is typically relevant for larger data volumes, colocated infrastructure, or businesses with strict requirements around where replication traffic travels. It usually involves coordinating with your datacenter or network provider, so lead times are longer than the other options.
| Option | Setup effort | Best for |
|---|---|---|
| Public endpoint | Minutes | Most SMBs, standard backup software |
| Site-to-site VPN | Hours | Isolating replication traffic on your own network |
| GRE tunnel | Hours to a day | Networks already using GRE across sites |
| IPsec tunnel | Hours | Private, encrypted point-to-point without GRE |
| Direct / cross-connect | Days to weeks | Large volumes, colocated infrastructure, strict routing requirements |
How to request one
Tell us your preferred connection method in the recovery-plan questionnaire, along with how many sites or locations need to connect. A specialist will confirm what's supported for your setup and, for VPN, GRE, IPsec, or direct connect, coordinate the technical details with whoever manages your network.
Not sure which option fits your setup?
Select "not sure, recommend for me" in the questionnaire and we'll suggest one based on your volume and sites.
Get your quote