How CloudConnexa Delivers the SASE Framework

Share
How CloudConnexa Delivers the SASE Networking Layer
8:29

The networking layer of SASE, done simply: mesh site-to-site connectivity over the internet, with built-in Zero Trust — sized for SMBs.

The short answer: CloudConnexa delivers SASE's networking half by meshing every site, cloud network, and remote user into one software-defined overlay called a Wide-area Private Cloud (WPC) — connected over the internet via IPsec or OpenVPN tunnels, not MPLS. Zero Trust access, segment-level Access Groups, and Cyber Shield IDS/IPS layer onto that same mesh, so networking and security converge in one service built for SMBs and mid-market teams.

 

SASE is the union of two halves: security (Gartner's SSE stack) and networking (traditionally SD-WAN). We've covered how CloudConnexa handles the SSE security side. This article focuses on the networking layer — how CloudConnexa connects your sites — and where it fits best.

CloudConnexa's networking layer: software-defined connectivity over the internet

The core of CloudConnexa is the Wide-area Private Cloud (WPC) — a virtual private overlay network that spans OpenVPN's worldwide points of presence, called Regions. You connect each location to the WPC, and CloudConnexa stitches them into one cohesive private network. This is software-defined connectivity delivered as a cloud service — the spirit of the SASE networking model.

How sites connect

Each site runs a Connector that establishes an always-on tunnel into its nearest CloudConnexa Region.

Tunnels use IPsec or OpenVPN protocols — IPsec offers broad compatibility with existing routers and cloud platforms (AWS, Azure, etc.).

Application Domain-based Routing works across the mesh, so traffic is steered intelligently and server IPs stay cloaked.

openvpn_ztna-research-report_email_800x200

An honest note on transport: best-effort internet, not MPLS

It's important to set expectations clearly. CloudConnexa builds its site-to-site connectivity on best-effort public internet, encrypted with IPsec and OpenVPN tunnels. It does not use dedicated MPLS circuits, and it doesn't promise the carrier-grade SLAs of a traditional managed SD-WAN with private links.

For most organizations, that's a feature, not a limitation:

  • No expensive circuits. You use the internet connections you already pay for — no MPLS contracts or long provisioning lead times.
  • Fast to deploy. Spin up a new site in minutes by connecting a Connector, instead of waiting weeks for a circuit.
  • Flexible and cloud-native. Cloud VPCs, branch offices, and remote workers all join the same overlay the same way.

The strength: full-mesh connectivity, simply managed

Where CloudConnexa shines is its full-mesh model. Regions interconnect in a full mesh, and a new WPC defaults to a Full Mesh topology — so every connected site, cloud network, and user can reach each other through one private fabric. You don't hand-build and maintain a tangle of point-to-point tunnels between every office; the WPC handles interconnection for you.

Layer on CloudConnexa's built-in Zero Trust access — switch the topology to Custom for deny-by-default, identity-based control — and you get a converged networking-plus-security posture that reflects the heart of the SASE vision, without enterprise SD-WAN complexity.

Segment-level access control between sites

A mesh shouldn't mean "everything can reach everything." CloudConnexa lets you define Access Groups for sites and even for specific source IP subnets within a site, so policy is enforced per network segment rather than per location only. For example, you can:

  • Allow a branch office network to reach only specific Applications at HQ — not the entire HQ network.
  • Permit just one subnet of a branch (say, point-of-sale devices or a finance VLAN) to reach a particular application at another site, while the rest of that branch cannot.

Because the source can be scoped down to a subnet, access policy becomes specific to a segment of a site — bringing least-privilege Zero Trust principles to site-to-site traffic, not just remote users.

IDS/IPS on traffic flowing between sites

Security follows that inter-site traffic too. CloudConnexa's Cyber Shield IDS/IPS inspects traffic flowing between connected sites over the WPC, classifying threats by priority (Critical, High, Medium) across categories like malware, intrusion attempts, and exploits — alerting on them as an IDS or actively dropping malicious packets as an IPS. So a compromised host at one branch is far less able to use the mesh to attack systems at HQ or another site.

The right fit: CloudConnexa is adequate, secure, and refreshingly simple mesh connectivity for SMB and mid-market organizations. With connection-based pricing, a free tier for small teams, and quick setup, it gives distributed small businesses enterprise-style mesh networking and Zero Trust access — without enterprise budgets, hardware, or specialists.

Where CloudConnexa fits in your SASE journey

If your organization needs guaranteed-bandwidth MPLS for latency-sensitive, mission-critical traffic across dozens of large branches, a heavyweight managed SD-WAN may be warranted. But if you're a small or mid-sized business that wants to connect offices, cloud resources, and remote workers securely — with Zero Trust access baked in and minimal overhead — CloudConnexa's mesh connectivity covers the SASE networking layer effectively and affordably.

 

Ready to see how OpenVPN can help protect your organization from attacks?

Try the self-hosted Access Server solution or the managed CloudConnexa service for free, no credit card required.

See Which One is Right for You

Frequently asked questions

Does CloudConnexa replace SD-WAN?

It delivers the networking outcomes SMBs need from SD-WAN — connecting sites into one secure, mesh overlay — using IPsec and OpenVPN tunnels over the internet rather than MPLS or proprietary appliances.

Why no MPLS?

MPLS circuits are costly and slow to provision. CloudConnexa uses encrypted tunnels over the internet you already have, trading carrier SLAs for flexibility, speed of deployment, and lower cost — a worthwhile trade for most SMBs.

How many sites can I connect?

You can connect multiple sites, cloud networks, and hosts into the same full-mesh WPC, all reachable through one private overlay.

Can I restrict which sites or subnets reach specific applications?

Yes. Access Groups can target whole sites or specific source IP subnets within a site — for example, letting a branch reach only certain HQ applications, or letting just one subnet of a branch reach an app at another site. Policy becomes specific to a segment of a site.

Does site connectivity include security?

Yes. The same platform provides Zero Trust access controls and Cyber Shield, whose IDS/IPS also inspects traffic flowing between sites over the mesh using Critical, High, and Medium severity tiers — so networking and security converge in one service.

Is CloudConnexa a complete SASE solution?

It covers both SASE halves through one platform: this article's mesh, full-mesh WPC, and site-level Access Groups deliver the networking layer, while CloudConnexa's SSE side — ZTNA, identity, Cyber Shield content filtering, and CASB-style visibility — delivers the security layer. See What Is SASE? for how the two halves fit together as a framework.

How much does CloudConnexa cost?

CloudConnexa uses connection-based pricing rather than per-seat licensing, with a free tier (up to 2 connections) for small teams to get started with no card required.

Connect your sites the simple way: Try CloudConnexa free and build a secure, full-mesh network across your offices and cloud in an afternoon.

Further reading

Sources: OpenVPN CloudConnexa documentation (Wide-area Private Cloud, Site-to-Site connectivity, IPsec, Regions/Connectors, mesh topology, Access Groups, Cyber Shield IDS/IPS); Gartner's SASE definition. Feature availability may vary; verify current capabilities in official CloudConnexa docs.

Related posts from OpenVPN

Subscribe for Blog Updates