Skip to content
Notifications
Clear all

Is NordLayer any good for a multi-cloud environment? 6-month report

1 Posts
1 Users
0 Reactions
27 Views
(@chrisb)
Reputable Member
Joined: 3 months ago
Posts: 319
Topic starter   [#21174]

We rolled out NordLayer across our team six months ago to solve a specific pain point: secure, audited access to resources spread across AWS, GCP, and a couple of on-prem VMs. We needed something simpler than a full mesh VPN and more centralized than individual cloud VPNs. Here’s the blunt breakdown after half a year.

**The Good (Why We Keep It):**
* **Setup was trivial.** Getting a gateway configured in each cloud (AWS VPC, GCP VPC) took minutes. The client is dead simple for the team, which cuts down on support tickets.
* **Access controls are solid.** Being able to segment teams (dev, ops, finance) and tie access to specific cloud networks works as advertised. The activity logs are detailed enough for our compliance needs.
* **It’s reliable.** Uptime has been 100% for our gateways. No noticeable latency spikes impacting daily work.

**The Not-So-Good (Where it Gets Iffy):**
* **Cost creeps up.** The per-user pricing is fine at first, but for a larger team with contractors, it adds up fast. It’s a pure operational expense, unlike some cloud-native solutions that can be tucked into committed spend.
* **It’s another layer.** For purely AWS-to-AWS workflows, we’ve started moving some things to AWS Client VPN or SSM Session Manager because it’s cheaper and native. NordLayer becomes an unnecessary hop.
* **Limited cloud integration.** It can’t leverage IAM roles or service principals. All access is at the network level. For some scenarios, that’s a pro. For others, it feels like a blunt instrument.

**Verdict:**
It’s “good” if your priority is a unified, no-fuss network overlay for hybrid/multi-cloud with clear user management. It works. But if your environment is heavily shifting towards a single cloud or you need deep integration with cloud-specific IAM, you might outgrow it. We’re keeping it for now, but actively reviewing the bill and moving eligible workflows to native tools.

cb



   
Quote