Layer 2 Tunnel

Porsuk

Secure. Fast. Layer 2.

A Layer 2 tunnel that can carry tagged/untagged VLANs. It brings the internet traffic of branches in different locations to the central site with their VLANs.

Porsuk device
What It Does

A tunnel that carries branches to the central site with their VLANs

Porsuk carries the branches of geographically dispersed businesses to the central location as tagged/untagged VLANs. It lets multi-branch businesses bring the internet traffic of branches in different locations to the central site with their VLANs intact.

01

Connects the branch to the central site at Layer 2

It brings your edge sites to your central firewall as Layer 2 tagged/untagged VLANs. The branch network works like a part of the central network.

02

Network and security policies stay central

Whatever the firewall brand, the edge sites are carried to the central site. That way you can manage your network and your security policies easily from one place.

03

A cost-effective alternative to MPLS

An existing MPLS service or other edge-site solutions put a financial burden on businesses. Porsuk is both cost-effective and supports features the other solutions do not.

4,096
Maximum number of VLANs that can be carried from an edge site to the central site
256-bit
End-to-end encryption per the RFC 8439 standard
Unlimited
Number of branches that can connect
24/7
Call center support
Porsuk Features

Six core features

Works independently of the firewall

You can bring your edge sites to your central firewall as Layer 2 tagged/untagged VLANs.

Tagged/untagged VLAN transport

You can carry the VLANs created on the central firewall/switch to your remote branch, and the VLANs created at your remote branch to your central site.

Cloud management

Cloud or on-premises management can be selected from the tunneling system interface. You can use whichever suits your business best.

Encrypted connection

In the tunneling solution, traffic between branches is encrypted end to end with 256 bits per the RFC 8439 standard.

Price advantage

An existing MPLS service or other edge-site solutions put a financial burden on businesses. Porsuk is both cost-effective and supports features the other solutions do not.

Easy management

You can manage the configuration settings and the status of every device in your business from a single panel.

How It Works

Installation completes in 5 minutes

Installing the Porsuk Layer 2 Tunnel is very easy. You can set up the Porsuk Layer 2 Tunnel within 5 minutes. You can also do the installation with help from the support team.

Setup 1: the internet uplink connects to the Porsuk device, Porsuk to the switch, and the switch to the end user computer.
Setup 1 — Porsuk sits between the direct internet connection and the local switch.
Setup 2: the internet uplink connects to the firewall, the firewall to the Porsuk device, Porsuk to the switch, and the switch to the end user computer.
Setup 2 — Porsuk sits behind the existing firewall and in front of the switch.
Port Modes

Four different port configurations

Porsuk's ports can be configured in four different ways to suit your needs. Each configuration determines how the VLANs between the central site and the remote office are handled.

DEFAULT – DEFAULT

Merge office networks into a single local network

You can use the default–default setup to merge your office networks in separate locations into a single local network.

For example, this lets you bring your offices into one 192.168.1.0/24 network.

Default–default diagram: the Porsuk devices in two offices connect to each other over the internet, and both offices sit on the same 192.168.1.0/24 network.
TAGGED – ACCESS

Distribute central VLANs as access ports at the branch

You can carry the VLANs on the central core switch, router or firewall to remote offices through Porsuk as tagged, and broadcast those VLANs as access on the switches or access points at the offices.

For example, say you have VLAN100-STAFF, VLAN200-GuestWiFi and VLAN300-StaffWiFi at the central site; you can terminate those VLANs on the ports of the Porsuk devices at your remote offices, plug your switches or access points into those ports and join the central network.

Tagged–access diagram: tagged VLAN 100 from the central switch enters the Porsuk at the first office; it is carried over the internet to the Porsuk at the second office and handed to the client there as access VLAN 100.
TAGGED – TAGGED

Carry tagged VLANs end to end

You can terminate the tagged VLANs at your central and remote offices between one another as tagged, or carry tagged VLANs from the central site to remote offices.

For example, if you have tagged VLAN100, VLAN200 and VLAN300 at both your central and remote offices, you can place a Porsuk at each site to merge and centralize those networks, terminating the VLANs as tagged over the internet.

Tagged–tagged diagram: at both offices the link between the switch and Porsuk is configured as a tagged VLAN; the VLANs are carried tagged over the internet.
ACCESS – ACCESS

Carry access ports end to end as separate networks

By plugging the ports configured as access VLANs on devices such as the firewall, core switch or router at the central or remote office into separate ports on Porsuk, you can carry the networks on those ports to remote offices as they are.

Access–access diagram: the access ports of the central device are plugged into separate Porsuk ports and each network is carried as-is to the corresponding port at the remote office.
Management Panel

Tunnel and VLAN mapping from the panel

The devices at the branches, the ports of the master device and the VLAN mappings are all managed from a single panel. Management runs in the cloud or in your own data center; the interface is the same either way.

Highlights

Encryption, management, speed and support

All of your traffic is encrypted

Internet traffic from the edge sites is encrypted with 256 bits per the RFC 8439 standard on its way to your central firewall. So even if the traffic is captured by bad actors, it cannot be decrypted.

Cloud management, easy to use

Porsuk was designed and built entirely around cloud management. You do not need to be at a fixed location to manage your devices; wherever you are in the world, you can manage all of them.

Fast connection

Porsuk uses advanced tunneling technology. The link between your remote branches and your central site is therefore delivered at maximum speed and performance.

24/7 call center support

The Porsuk support team, made up of people experienced in the industry, is a phone call away 24/7.

On-Premises

Run the management in your own data center

Your company policy may require the Porsuk central management software to be installed on a server in your own data center. Porsuk offers that flexibility; you can run the Layer 2 tunnel system as a closed circuit on your own IT resources.

The management model is selected as cloud or on-premises from the tunneling system interface.

Advantages of in-house use
More secure
Everything under your business's control
Connection signalling runs entirely on your own servers
Models

Porsuk models

All four models support tagged/untagged VLAN transport. The differences are the port layout, the interface type and the throughput.

Porsuk A105 front panel: 12V/2A power input, RST, PWR and ACT LEDs, WAN and LAN1–LAN4 ports.
Small businesses

Porsuk A105

Layer 2 Tunnel Device
Ports
5x Gigabit Ports
Throughput
100 Mbps
VLAN Transport
Yes
Model details
Porsuk E1006 front panel: ON/OFF button, CONSOLE and USB inputs, PWR LED, WAN and LAN1–LAN5 ports.
Medium-sized businesses

Porsuk E1006

Layer 2 Tunnel Device
Ports
6x Gigabit Ports
Throughput
800 Mbps
VLAN Transport
Yes
Model details
Porsuk E1008 front panel: ON/OFF button, CONSOLE and USB inputs, PWR LED, WAN and LAN1–LAN5 ports plus SFP1 and SFP2 slots.
Large businesses

Porsuk E1008

Layer 2 Tunnel Device
Ports
6x Gigabit Ports + 2x 1 Gbit (SFP)
Throughput
800 Mbps
VLAN Transport
Yes
Model details
Porsuk P10008 product image: rack-type Porsuk chassis, six gigabit ports and two SFP slots.
Enterprise edition

Porsuk P10008

Layer 2 Tunnel Device
Ports
6x Gigabit Ports + 2x 10 Gbit (SFP+)
Throughput
5000 Mbps
VLAN Transport
Yes
Model details
Technical Specifications

Model comparison

Model Target Scale Ports Throughput VLAN Transport Details
Porsuk A105 Small businesses 5x Gigabit Ports 100 Mbps Yes Details
Porsuk E1006 Medium-sized businesses 6x Gigabit Ports 800 Mbps Yes Details
Porsuk E1008 Large businesses 6x Gigabit Ports + 2x 1 Gbit (SFP) 800 Mbps Yes Details
Porsuk P10008 Enterprise edition 6x Gigabit Ports + 2x 10 Gbit (SFP+) 5000 Mbps Yes Details

Shared by every model

VLAN capacity
Transport of up to 4,096 VLANs from the edge sites to the central location
VLAN mode
Tagged and untagged VLAN transport
Encryption
End to end, 256-bit per the RFC 8439 standard
Management
Cloud or on-premises; selected from the tunneling system interface
Number of branches
Unlimited connections
Compatibility
All internet service providers and all firewall brands
Port modes
Default–default, tagged–access, tagged–tagged, access–access
Installation
Can be completed within 5 minutes
Frequently Asked Questions

Common questions about Porsuk

Porsuk carries the branches of geographically dispersed businesses to the central location as tagged/untagged VLANs.

See Porsuk on your own network

Let us review your branch topology and your VLAN plan together, and recommend the model that fits your needs.

Request a demo