In this 8-minute demonstration, Sales Engineer Flavio Carrasco presents NetFoundry's identity-first, site-to-site (S2S) connectivity platform. He outlines common challenges with traditional VPN deployments—such as overlapping IPs, vendor interoperability, complex firewall rule management, and the security risks of opening inbound ports.

thumb-s2s-demo-v1a

The demo showcases how administrators can easily spin up a virtual edge router and share a registration key, allowing a partner or customer to connect securely via their existing hardware using a single command. Once authenticated, administrators can instantly grant or revoke granular, least privileged access to remote services (like those hosted on Azure and AWS) entirely through a centralized portal, while also monitoring network telemetry and continuous posture compliance.

Key Takeaways

  • Rapid and Simplified Deployment: Administrators can establish secure connectivity in minutes rather than weeks by simply sharing an auto-generated registration key that deploys a container on the customer's hardware.

  • Granular Control and Enhanced Security: Access is managed dynamically through a centralized portal via one-click assignments, enforcing least privilege access and continuous posture checks without opening any inbound firewall ports (only outbound port 443 is required).

  • Elimination of Complex Configurations: The platform inherently handles complex networking burdens, actively supporting overlapping IP ranges without route advertisement configurations and automatically rotating certificates to reduce ongoing operational overhead.

Experience Identity-First S2S Connectivity

 Operational Comparison: S2S VPNs 

3 Ops Slides 19April2026-HS