Raff Site-to-Site VPN connects your office, data center or another cloud to your Raff VPC over WireGuard or IPsec (IKEv2). Up to 10 tunnels per gateway, multiple remote subnets per tunnel, and the traffic through the tunnel is never metered.
No appliances to license, no bandwidth calculator, no sales call. Enable the gateway on your VPC and add tunnels.
Pick per tunnel: WireGuard for modern peers, IPsec with IKEv2 and a preshared key for classic firewalls.
Branch offices, a second cloud, a partner network. Each tunnel has its own peer and its own subnets.
Standard IKEv2 means UniFi, pfSense, OPNsense, MikroTik and friends connect with their built-in VPN settings.
Sync backups, mirror databases, push builds. Data through the tunnel is never counted or billed.
The same gateway serves up to 10 WireGuard peer configs for laptops, downloadable from the dashboard.
Route several office networks through one tunnel. Routes push to the gateway automatically.
The gateway and each tunnel bill by the hour. Spin one up for a migration weekend, delete it Monday.
Tunnel creates, changes and deletes land in your account audit log with actor and result.
Billed by the hour, so a weekend migration costs a weekend, not a month. The big clouds charge comparable tunnel fees and then meter every byte through them; the tunnel traffic here is unmetered.
Office to VPC, all in: about $34.96/month. AWS charges $36.50/month per VPN connection and then $0.09/GB for the data leaving through it. Rates verified against our pricing system, Jul 2026.
If you have configured a VPN on your firewall once, this will feel familiar. The Raff side is a form, not a config file.
One toggle on your VPC. The gateway comes up with WireGuard and IPsec ready.
Pick WireGuard or IPsec, enter your office endpoint, subnets and preshared key. Routes push automatically.
Enter the same peer details in UniFi, pfSense or any IKEv2 firewall. Handshake, done.
A tunnel into your VPC makes everything on Raff feel like part of your LAN. Everything below is reachable through it.
A site-to-site VPN links two whole networks over an encrypted tunnel, so machines on each side reach each other by private IP. On Raff it connects your office, data center or another cloud to your VPC using WireGuard or IPsec.
The VPN gateway is about $14.97/month and each site tunnel about $20.00/month, both billed by the hour. The data through the tunnel is unmetered and never charged per gigabyte.
Yes. Each tunnel can be WireGuard or IPsec (IKEv2 with a preshared key). You choose per tunnel, so modern peers and classic firewalls both work on the same gateway.
Any device that speaks standard IKEv2 or WireGuard: UniFi, pfSense, OPNsense, MikroTik, Fortinet and others. You enter matching peer settings on both sides and the tunnel comes up.
Up to 10 site-to-site tunnels per VPN gateway, each with its own remote endpoint and one or more remote subnets. The same gateway also serves up to 10 WireGuard remote-access peers for laptops.
AWS charges about $36.50/month per VPN connection and then $0.09/GB for data leaving through it. Raff's gateway plus a tunnel is roughly $35/month total and the tunnel traffic is unmetered.
A Raff VPC with the VPN gateway enabled, and a firewall or router on your side that supports IKEv2 or WireGuard. You configure the tunnel from the VPC's VPN tab in the dashboard.
WireGuard or IPsec tunnels with unmetered traffic, billed by the hour. 15,000+ builders run on Raff in our us-east region, backed by a 99.9% uptime SLA in writing.