Hey everyone, I'm still pretty new to setting up secure data infrastructure, so I need some advice from people who've actually done this in production.
We're a team of about 150 people, and our setup is getting complicated. We have:
* Most of our analytics workloads in Azure (Synapse, VMs for some legacy apps).
* A physical on-prem server room for some sensitive ETL processes and our main Postgres database.
* Data engineers and analysts who need to access both, from everywhere.
Our current "solution" is a mess of individual consumer VPNs and some clunky RDP setups. It's not scalable, and I'm pretty sure it's not secure. We need one managed solution.
**Main requirement:** A VPN (or something better?) that can seamlessly connect our Azure VNet and our on-prem network, with all our users (under 200) able to access resources in both places. Our budget isn't huge.
I've been looking at NordLayer because it pops up a lot, but I'm worried:
* Is it really built for this hybrid cloud/on-prem setup, or is it more for internet browsing security?
* How does it handle the "always-on" connection for our data pipelines? If a pipeline running on-prem needs to write to Azure, the tunnel can't just drop.
* We sometimes need to whitelist IPs in Azure SQL and other services. Does NordLayer provide stable gateway IPs for that?
I tried setting up a test with OpenVPN, but my pipeline runs started failing randomly 😅. The logs just showed timeouts.
Has anyone successfully used NordLayer or something else (Pritunl? Tailscale? A direct Azure VPN Gateway?) for a similar data-heavy, hybrid environment? What were the pitfalls?
Any guidance would be a lifesaver. I'm tasked with picking a solution, and I don't want to build on a shaky foundation.
null