---
title: "STACKIT VPN"
description: "Managed IPSec site-to-site VPN gateway providing encrypted hybrid cloud connections and dynamic BGP routing."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["VPN", "IPSec", "BGP", "Hybrid Cloud", "Encrypted"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-vpn/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-vpn.mdx"
---

STACKIT VPN establishes encrypted IPSec site-to-site tunnels connecting on-premises data centers to STACKIT.

## Service Overview
- **Encrypted Hybrid Link**: Securely bridges private corporate networks with STACKIT VPC instances.
- **High Availability**: Active-active gateway configurations built across distinct availability zones.
- **No Egress Costs**: Included tunnel bandwidth without separate ingress or egress data volume charges.

## Technical Details
- **Protocols**: IPSec with IKEv2 and Pre-Shared Keys (PSK).
- **Routing**: Policy-based, route-based, and dynamic BGP route propagation (up to 100 advertised routes).

## Limitations & Constraints
- **Site-to-Site Only**: Designed strictly for gateway site-to-site connections (point-to-site user VPN unsupported).
- **Gateway Quota**: Projects are limited to a maximum of 6 VPN gateway instances.
- **Phase 2 SAs**: Using identical remote addresses for both tunnels of a policy based vpn is not recommended.

<LinkCard title="STACKIT VPN Documentation" href="https://docs.stackit.cloud" />
