Layer 2 Tunnel

XLOG Mini Tunnel

A virtual ethernet cable between the branch and the central site.

A network device that connects your edge networks to your central network over an encrypted Layer 2 tunnel. It links your multi-branch setup to the central site regardless of location or service provider, as if there were a real cable between them and the XLOG Firewall.

XLOG Mini Tunnel device
What It Does

Turns separate branch networks into a single network

Your branches may be in different cities, on different internet providers, with networks separate from one another. The XLOG Mini Tunnel removes that separation: the mini box installed at the branch joins the branch network to your central network at Layer 2. It works as if there were a real ethernet cable between the central site and the branch.

Traffic is encrypted with 256-bit ChaCha20 and carried over your existing internet line; location and service provider make no difference. This lets you build your own closed-circuit branch networks and manage them from one place.

For multi-branch setups

A precise fit for multi-branch organizations and businesses. Its ethernet ports connect your branch to the central site at Layer 2, easily.

Layer 2 instead of MPLS

The Mini Tunnel device working at Layer 2 is advantageous over MPLS networks in terms of security, cost and logging.

Plug and play

The device is plug and play. It is configured through the XLOG Firewall and the customer portal.

Models

The XLOG Mini Tunnel comes in two models

Both models use the same tunnel architecture, the same encryption and the same central management through the XLOG Firewall. The difference comes down to one thing: the wireless radio. Both models gather five Gbit ethernet ends at the branch; the Mini Wifi broadcasts Wi-Fi on top of that.

MODEL 01

XLOG Mini 5 Port

Gathers five Gbit ethernet ends on the branch side.

Tunnel Ports
5
Ethernet Ports
5x Gbit Ethernet
Throughput
100 Mbps
Hardware
Mini Box
Details of the 5 Port model
MODEL 02

XLOG Mini Wifi

The wireless version of the five-port model; it broadcasts Wi-Fi in addition to the same ports.

Tunnel Ports
5
Ethernet Ports
5x Gbit Ethernet
Wireless
Wi-Fi Dual Band 2.4 / 5 GHz
Throughput
100 Mbps
Details of the Mini Wifi model

Shared by both models

Encryption
256-bit ChaCha20
Layer 2 Tunnel
Yes
Central Management
Yes
Central Logging
Yes
Full Traffic Redirection
Yes
Fiber Ports
None

XLOG Mini Wifi: the wireless model of the same device

The XLOG Mini Wifi is the wireless version of the 5-port model. Its job of connecting edge networks to the central network over an encrypted Layer 2 tunnel, its topology and its XLOG Firewall integration are identical to the 5 Port model; the only difference is that the Mini Wifi additionally offers Wi-Fi Dual Band 2.4/5 GHz support. Technical specifications of the Mini Wifi model »

XLOG Firewall Integration

The tunnel terminates on the XLOG Firewall at the central site

The Mini Tunnel is not a device designed to stand alone; it works integrated with the XLOG Firewall. The device at the branch is brought online plug and play, and the central end of the tunnel terminates on the XLOG Firewall. Configuration is also done through the XLOG Firewall and the customer portal rather than on the device — there is no interface to configure at the branch.

BRANCH / EDGE SITE Branch network switch, access point, users XLOG Mini Tunnel 5 Gbit ethernet ports mini box, plug and play internet · any provider Layer 2 tunnel encrypted with 256-bit ChaCha20 CENTRAL SITE XLOG Firewall the tunnel terminates here central network and servers The link works at Layer 2, as if there were a real ethernet cable in between.
01

Branch network

The switch, access points and end users at the branch are connected to the device's ethernet ports.

02

XLOG Mini Tunnel

The mini-box device is brought online in the field plug and play. Configuration is done through the XLOG Firewall and the customer portal, not on the device.

03

Encrypted tunnel

Traffic is encrypted with 256-bit ChaCha20 and carried over the existing internet line regardless of location or service provider.

04

XLOG Firewall at the central site

The tunnel terminates on the XLOG Firewall at the central site; the branch network joins the central site at Layer 2.

Tunnel Modes

How much of the traffic should enter the tunnel?

The Mini Tunnel works in two different modes. The difference comes down to one question: will the users at the branch reach the internet through the central site or through their own line? That choice determines where the DHCP server and the default gateway sit, and which traffic can be filtered and logged centrally.

MODE 01

Full Tunnel Mode

Branch network tunnel XLOG Firewall DHCP + gateway Internet The entire edge network passes through the tunnel.

The Mini Tunnel device tunnels the entire edge network to the XLOG Firewall at the central site. It is as if a virtual ethernet cable were plugged between the firewall and the edge switch.

The DHCP server and the default gateway become the XLOG Firewall; the XLOG Firewall manages all edge traffic.

MODE 02

Transparent / Split Tunnel Mode

Branch network Router DHCP + gateway Internet tunnel XLOG Firewall

In this mode users reach the internet through their own router; at the edge site the DHCP server and the default gateway are the edge router. The Mini Tunnel device engages only when users want to reach networks that exist solely on the central network (marked as split networks).

For that reason, only the traffic entering the tunnel can be filtered and logged by the firewall in this mode.

Services provided from the central site in full tunnel mode

Because the XLOG Firewall manages all of the edge traffic, the services below are provided without installing a separate device at the branch.

Signed logging and log reporting Hotspot (Captive Portal Login) MAC-based allow/block and bandwidth definition 802.1x MAC authentication Firewall policy definition NAT Web filtering, IPS/IDS, application filter Live per-user bandwidth monitoring

These and similar services are provided to the branch network from the central site.

Assess your network with XLOG

Let us map out your branch topology together and decide which tunnel mode and which model fit.