Use case · Branch networking
Connect branch offices over any internet link
Replace leased lines and hand-built VPN tunnels with one encrypted fabric that runs over whatever connections each office already has.
The problem
Site-to-site VPNs are configured by hand, one pair at a time. Every new office means another set of tunnels on every other device, and a failed broadband line is noticed when someone phones to say the file server is gone.
How Weft does it
- Every site reaches every other site over WireGuard. Adding an office is one enrolment; nothing on the existing sites is edited by hand.
- Two uplinks per site. Weft builds a tunnel over each and watches them with BFD at 300 ms intervals, so a dead line is detected in under a second and traffic moves to the other.
- Sites behind NAT work. A site with no public address reaches the fabric through a hub, which is simply another of your sites. If the active hub goes silent, its duties move to the next one automatically.
- Every path is measured. The console shows the latency and loss between every pair of sites, worst first, with a history for each.
- Your existing routers stay. A site can exchange routes with them over OSPF or eBGP, or hand off a routed network on a dedicated port.
What you need
At each office, a machine running Ubuntu 24.04 (x86-64 or ARM64) with one or two internet connections. It becomes the office's gateway into the fabric.