Run OpenVLAN alongside whatever you have today, move team by team, then decommission on your schedule.
Connect your identity provider, enable a pilot tailnet, and install clients for one friendly team. Nothing existing changes.
Deploy subnet routers in each VPC and office. Publish internal apps with MagicDNS names. Keep the old VPN running.
Move departments in waves. Each wave: enroll devices, verify access, update bookmarks to MagicDNS names, then disable their VPN group.
When VPN usage hits zero, switch off concentrators, reclaim IPs, delete the shared VPN accounts. Celebrate visibly.
Replaced by the mesh itself — clients connect from anywhere, no appliance to babysit.
Replaced by OpenVLAN SSH with SSO, recording, and ACLs per host. Delete the bastion.
SSH details →Replaced by identity-based grants and session recording. Keep the vault for secrets if you like.
Privileged access →Gone entirely — the mesh only carries tailnet traffic by default.
Close them. Clients need only outbound 443.
Create your tailnet, connect your IdP, enroll two devices. That's the whole kickoff.