VPNGeek
Purchase
IPSEC GATEWAYS · FEATURES

Every capability, documented

The full technical and operational feature set — for the engineers doing the evaluating.

Gateway & tunnel management

Self-serve provisioning

Gateways in 6 regions, live in minutes, via UI or CLI.

Tunnel lifecycle

Create, edit, pause, and rekey tunnels without downtime windows.

Environments & naming

Production/staging separation, tags, and clean naming.

Routing & traffic controls

Subnet definitions

Any CIDR per side; overlap checks before deploy.

Traffic selectors

Route exactly the networks you intend — nothing else.

Static routes

Push routes to spokes for hub-and-spoke topologies.

Security & authentication

Modern crypto

IKEv2, AES-256-GCM, SHA-2, PFS groups 14–21.

PSK or certificates

Your keys, rotated on your schedule.

Access controls

Roles, enforced 2FA, and per-gateway permissions.

Secure defaults

Weak ciphers and IKEv1 disabled unless you opt in.

Availability & resilience

99.99% uptime SLA

Backed by redundant gateway infrastructure per region.

DPD & auto-failover

Dead Peer Detection restarts tunnels before users notice.

Zero-downtime maintenance

Rolling updates; rekeys never drop established traffic.

Monitoring & diagnostics

Live tunnel status: phase 1/2, throughput, peersFull event log — every rekey, DPD probe, and config changeAlerts on tunnel drop, latency, and renegotiation loopsPer-event JSON export for your SIEM

Scalability

Unlimited tunnels

No per-tunnel fees; mesh or hub-and-spoke as you grow.

6 regions

EU, US, and APAC gateways close to your sites.

Bandwidth headroom

10 Gbps ports; scale gateways horizontally per site.

Technical specifications

IKE versions
IKEv2 (recommended) · IKEv1 (legacy opt-in)
Ciphers
AES-256-GCM · AES-128-GCM · ChaCha20-Poly1305
Integrity / PRF
SHA-256 · SHA-384 · SHA-512
DH / PFS groups
14 (MODP-2048) · 19 (ECP-256) · 20 (ECP-384) · 21 (ECP-521)
NAT traversal
NAT-T (UDP 4500) · UDP 500 for IKE
Authentication
Pre-shared keys · X.509 certificates
Tunnel modes
Site-to-site (route-based) · Remote access

Evaluate it against your network

Check compatibility Check all plans Talk to a specialist