Back to Solutions
ENGINEERING & STANDARDS · ACCESS AND NETWORK

Who may go where — and by which path.

Overlay networks across grown infrastructure, privileged access through a PAM path instead of permanent tunnels, separation at the protocol layer instead of a firewall rule that passes a network along. We have built this and we operate it — with open standards, not a product licence.
Overlay · WireGuard · IPsec · mTLS PAM instead of standing tunnels Separation at the protocol layer

Why this page does not describe a product

We once had a product name for this. It did not sell, and in hindsight rightly so: nobody buys a network product from an operator. What customers want from us is the decision about what access looks like — and someone who keeps it that way afterwards.

Overlay instead of rebuild

Grown estates can rarely be re-cut in one move. An overlay lays a dedicated, encrypted transport layer over what is already there: sites, installations and services connect across it without mixing the networks underneath. That makes the rebuild plannable, because it runs in stages — and it makes access describable, because every connection carries an identity rather than just an address.

Technically we work with what is open and inspectable: WireGuard and IPsec for transport, mutually authenticated TLS for services, X.509 and SSH certificates instead of scattered key files, identities from one leading source over OIDC or SAML, 802.1X and RADIUS where the port itself is the boundary.

Privileged access

Administrator and vendor access runs through a PAM path: approval per session, a fixed time window, session recording, and no credentials sitting permanently with a contractor. The practical difference does not show in normal operation but afterwards — when somebody has to reconstruct who changed what, and when.

That includes an honest emergency path. Access that does not work during an incident gets bypassed, and then the whole construction stops meaning anything. So the exception path is built, documented and rehearsed rather than left unmentioned.

Separation that holds

Between zones we terminate. Crossings run through proxies, jump points and protocol-aware handover points that inspect the protocol and pass on only what is permitted — not through a rule that simply passes a network along. In process and plant networks this is the only variant that works without agents on the devices.

Concrete offerings

What we do in this area

  • Build and operate an overlay network

    An encrypted transport layer over the existing infrastructure, bound to identity, introduced in stages rather than as one rebuild.

  • PAM for privileged access

    Approval per session, time window, session recording, no standing credentials — including a rehearsed emergency path.

  • Zone and crossing analysis

    What talks to what today, over which protocol, and who approved it. The output is an ordered list, not an architecture picture with no consequence.

  • Terminating crossings

    Proxies, jump points and protocol-aware gateways between office IT, process and plant networks.

  • Certificates instead of key files

    Short-lived SSH and X.509 certificates from your own issuing authority, so access expires rather than being forgotten.

  • One leading identity source

    Accounts, roles and permissions from a single source that supplies network, servers, endpoints and applications.

What we work with

As of 2026-09 · Source: dynexo Operations
TransportWireGuard · IPsec/IKEv2 · mutually authenticated TLS
IdentityOIDC · SAML · X.509 · SSH certificates · RADIUS · 802.1X
Privileged accessPer-session approval · time window · session recording · no standing access
CrossingsTerminating: proxy, jump point, protocol-aware gateway
Operating modelIn your infrastructure or with us · handover to your team planned for
What it is notNo licence product, no appliance, no price table
Asked often

What comes up about this

  • Is this a VPN replacement?
    In effect often yes, in model no. A classic VPN connects a device to a network. An overlay connects an identity to a service. The difference matters when a device is compromised: it then reaches what was assigned to it, not a network segment.
  • Do we have to buy a particular product for this?
    No. We work with open standards and will keep operating products you already have. Where we use our own implementations, we say so and describe what they do.
  • How do you keep this current in day-to-day operations?
    Rule sets, crossings and access definitions exist as code and are rolled out with Ansible and Terraform. A state is therefore reproducible and reversible — and does not depend on who was on shift.
  • Does this work in process and plant networks?
    Yes, and there it is usually the only workable path. Telecontrol and substation-level devices run no agents. Control sits at the crossing: terminate, inspect, pass on or refuse.
Next step

How many standing access paths does your network have that nobody can justify any more?

We walk through your zones, crossings and privileged access and set an order — starting with what stands open today and can be closed without a rebuild.