Migration

Switch without the big-bang cutover

Run OpenVLAN alongside whatever you have today, move team by team, then decommission on your schedule.

Bridge leading from a gray legacy island to a bright mesh island

The phased playbook

Week 1 — Parallel run

Connect your identity provider, enable a pilot tailnet, and install clients for one friendly team. Nothing existing changes.

Week 2–3 — Anchor the infrastructure

Deploy subnet routers in each VPC and office. Publish internal apps with MagicDNS names. Keep the old VPN running.

Week 3–6 — Migrate teams

Move departments in waves. Each wave: enroll devices, verify access, update bookmarks to MagicDNS names, then disable their VPN group.

Week 6+ — Decommission

When VPN usage hits zero, switch off concentrators, reclaim IPs, delete the shared VPN accounts. Celebrate visibly.

Replacing each legacy piece

VPN concentrator

Replaced by the mesh itself — clients connect from anywhere, no appliance to babysit.

Bastion / jump hosts

Replaced by OpenVLAN SSH with SSO, recording, and ACLs per host. Delete the bastion.

SSH details →

PAM vault (for access)

Replaced by identity-based grants and session recording. Keep the vault for secrets if you like.

Privileged access →

Site-to-site IPsec

Replaced by subnet routers advertising each site into the tailnet.

Site-to-site →

Split-tunnel exceptions

Gone entirely — the mesh only carries tailnet traffic by default.

Firewall "VPN ports"

Close them. Clients need only outbound 443.

Migration FAQs

Can both systems run at once?
Yes — the standard approach. Users on either system reach the same resources while you migrate wave by wave.
What about our existing IP ranges?
Subnet routers advertise your real ranges into the tailnet; clients keep using existing addresses and hostnames.
How long does a typical mid-size company take?
Six weeks end-to-end is typical for a 200–1,000 person org, mostly waiting on human scheduling rather than technology.
Do we need professional services?
No — the playbook above is what our solutions engineers walk customers through on regular plans.

Day one of the switch starts here

Create your tailnet, connect your IdP, enroll two devices. That's the whole kickoff.