Case study · Logistics · 500+ employees

90% fewer internal support requests

A logistics operator with warehouses on three continents gave 500+ staff one network that "just works" — and watched the VPN ticket queue evaporate.

Bluefin Logistics — warehouse routes converging on a hub

The networks were hostile; the VPN was worse

Logistics staff connect from wherever freight happens: carrier-grade NAT, captive portals at customer sites, warehouse wifi that only allows port 443. The legacy VPN needed exactly the ports those networks block — so the mesh that dials out on any available path won by default.

  • ✓Connections find a path through NAT, portals, and port filters
  • ✓500+ scanners enrolled with device tags, sync-only
  • ✓Offboarding follows HR's SCIM feed, not a memory
why the old VPN failed here
carrier NATnat behind nat—TIMEOUT
captive portalsport 443 only—BLOCKED
warehouse wifiudp dropped—DROPPED
openvlan meshdials out, any path—CONNECTED
scannerstagged, sync-only500+ONLINE

The DMZ shrank to zero

The security team's favorite metric isn't the ticket drop — it's the endpoint count. Every dashboard that used to sit on a public IP behind a fragile allowlist now answers only to authenticated mesh members. The most-scanned asset they owned simply stopped existing.

# before: public-facing assets
vpn-gw.bluefin.example exposed · most-scanned
ops-dash.bluefin.example dmz · ip-allowlisted
scan-api.bluefin.example public · "temporary", 2 yrs
 
# after: same apps, private path
public endpoints: 0
every session carries identity + device + audit row

The challenge

Bluefin's staff move between warehouses, offices, and customer sites, often on locked-down networks that block traditional VPN protocols. Their legacy VPN generated a steady drumbeat of "can't connect", "works yesterday but not today", and "the scanner app times out" — hundreds of tickets a month landing on a four-person helpdesk.

The switch

OpenVLAN's mesh tolerates the hostile networks logistics workers actually use: NAT behind NAT, captive portals, blocked UDP — connections find a path. Handheld scanners and warehouse gateways joined as tagged devices, and the ops dashboards they sync with were published privately instead of sitting on a DMZ IP.

The results

Internal support requests fell 90% within a quarter. The remaining tickets are almost all hardware failures. The helpdesk reclaimed its afternoons, and the security team retired the VPN's public endpoint — the single most-scanned asset they owned.

90%

reduction in internal support requests

0

public endpoints left to scan

3

continents, one consistent network

"Our helpdesk used to open the day with the VPN queue. Now they open it with actual hardware problems."
— IT operations manager, Bluefin Logistics

What's next

Bluefin plans to extend the same mesh to cold-chain IoT sensors, replacing a stack of per-vendor SIM VPN plans with one network and one audit log.

This case study is an illustrative example with fictional data for demonstration purposes.

Bluefin FAQs

What networks does it actually work on?
The ones logistics staff actually meet: carrier-grade NAT, captive portals at customer sites, locked-down warehouse wifi, LTE dongles. The node dials out on whatever path the network permits — if HTTPS works, the mesh works.
How do handheld scanners connect?
They enroll as tagged devices with a sync-only policy — a scanner can reach the inventory API and nothing else. If one falls off a forklift, its access dies with it and the replacement inherits the same profile.
What about seasonal and temporary staff?
Access is driven by HR's SCIM feed, so a seasonal worker's network access ends the same hour their employment does. Nobody sweeps stale accounts at quarter end anymore.
Were warehouses offline during the rollout?
No. Each site got one subnet router alongside the existing gear, and scanners moved over per-site as they came in for charging. The old VPN stayed reachable until a site reported zero fallback usage for two weeks.
What's left in the ticket queue?
Hardware, almost entirely: cracked screens, dead batteries, one forklift incident per quarter. Network connectivity tickets — the entire reason the old queue existed — are effectively gone.

Make the VPN ticket queue history