WZ-IT records the existing access paths, builds an appropriate secure-access environment in parallel and migrates a limited pilot group. The wider rollout is planned only after the new path has been tested.
Companies worldwide trust WZ-IT
The sprint ends with a working target environment for the agreed pilot group. Identities, networks and access policies are tested in practice while the existing VPN remains available as a defined fallback.
NetBird, WireGuard or a suitable combination is selected around users, sites, identities and the systems that need to be reached.
A limited user group accesses the agreed networks and services through the new path.
Tests, deviations, rollback and the next migration waves are documented for implementation.
The fixed price covers a technically implemented pilot migration. Clear limits for users, networks and identity integration keep the work predictable and leave production access untouched until the new path has been tested.
The current VPN, user groups, devices, networks, administrative access and known dependencies are captured.
Control plane, data paths, routing, DNS, identity integration and operating location are designed for the agreed scope.
The standard environment is installed on agreed infrastructure, hardened and prepared for the pilot.
One suitable identity provider, groups and initial access policies are configured within the package limits.
Clients, routes and approved targets are configured for the agreed group and tested in parallel operation.
WZ-IT records test cases, findings, rollback and the recommended rollout for further users or sites.
Clear boundary
Source and target environments use separate address and access paths. The pilot group can therefore move without migrating every user at the same time.
Source system, users, networks, identity provider and critical access paths are clearly scoped.
WZ-IT configures the platform, identity integration, groups, policies and routes for the pilot.
The pilot group uses the new path; reachability, DNS, policies and rollback are tested.
Results, corrections, further waves and the later shutdown of legacy access are documented.
Clearly defined packages
Before work starts, we confirm the source system, identity provider, networks and user group. The wider rollout can then build on the tested target environment.
Migration Pilot
€2,490
excluding VAT, one-off
For controlled replacement of one existing access path with a limited pilot group.
Multi-Site Migration
€4,900
excluding VAT, one-off
For multiple networks or sites and a larger first migration wave.
OIDC integration requires a suitable and technically reachable interface and the necessary product edition. Vendor licences and runtime infrastructure are itemised separately before commissioning.
The pilot environment remains usable. It can support migration of additional users and sites, vendor licensing, and transition of monitoring, updates and support into ongoing operations.
Have WZ-IT take responsibility for the control plane, relays, monitoring, updates, backups and agreed response.
Configure operationsAssess self-hosting, edition, SSO, policies, routing and technical integration in detail.
View NetBird expertiseBring further cloud, Proxmox, Kubernetes or on-premises networks into the access model in a controlled way.
View secure accessRequest a migration sprint
Tell us the current VPN, approximate number of users and the most important target systems. We confirm the package and technical prerequisites before commissioning.
Source systems, parallel operation, licensing and wider rollout
Common starting points include OpenVPN, firewall SSL VPNs, manually managed WireGuard profiles, Tailscale and inherited administrative access. Before work starts, we review clients, authentication, networks and required protocols because not every exception can be transferred unchanged into a mesh or zero-trust model.
No. The sprint is designed around parallel operation. Source and target access use separate paths so the pilot group can test and fall back to the agreed legacy connection if required. Shutdown only happens after separate approval.
No. NetBird is often appropriate where central identity, groups, policies and network routes are needed. WireGuard or a combination can be a better fit for clearly scoped site tunnels or specialist networks. The target model is selected around the existing environment.
No. The fixed price covers assessment, standard setup, integration and pilot migration within the selected package. Required NetBird vendor licences and cloud, gateway or relay infrastructure are itemised separately before commissioning.
You receive the documented tests, deviations, rollback path and plan for further migration waves. WZ-IT can deliver the remaining rollout separately or hand the documentation to your internal IT team.
Yes. WZ-IT can operate the control plane, relays, monitoring, updates, backups and support as Managed Secure Access. Scope, product edition, infrastructure and service level are agreed separately from the one-off migration sprint.
The fixed-price packages cover a controlled pilot and a limited first wave. Environments with several identity providers, complex MDM, many countries or hundreds of users are planned as a custom rollout project after the initial assessment.