Use case · Layer 2
Stretch one network between sites
Some devices cannot be re-addressed: a building controller, a legacy application, a migration halfway done. Weft carries the same layer-2 segment to every site that needs it.
How Weft does it
- VXLAN inside WireGuard. The segment is carried as VXLAN between sites, and every frame is encrypted by WireGuard on the way.
- No flood-and-learn across the WAN. Sites learn where each device is from BGP EVPN rather than flooding unknown traffic over the internet.
- Joined to your routed network. Hosts on the stretched segment can reach your routed subnets, and back, through a gateway the fabric provides.
- A site port is all it takes. Choose the port on the site that faces the segment from a list in the console; the site can also serve it on Wi-Fi.
- Policy still applies. Segmentation is enforced on bridged traffic as well as routed traffic.