SECURE LAYER 2 NETWORK BRIDGING

Extend Ethernet securely across sites, clouds and edge locations.

Create one centrally managed Layer 2 fabric across distributed agents. Connect local bridges through encrypted, resilient relay paths—without configuring a separate tunnel or TAP adapter for every remote location.

Start with two locations and extend the authorised fabric when ready.

IDEAL USE CASES

Where distributed systems still need to share Ethernet.

Use the fabric when applications, devices or operational constraints require Layer 2 adjacency across locations—but traditional VPN tunnel sprawl is difficult to secure and operate.

SITES & INDUSTRY

Extend established local networks

Connect branch, industrial and manufacturing Ethernet environments while keeping local devices on familiar network interfaces.

  • Branch-office Ethernet networks
  • Industrial and manufacturing Layer 2
  • Legacy discovery and broadcast-based systems
  • Resilient Layer 2 access across remote sites
CLOUD & EDGE

Join distributed workloads

Bridge hosted and local compute without building a separate point-to-point tunnel for every participating location.

  • Edge and cloud-hosted workloads
  • Virtual machines across distributed hosts
  • Isolated customer or project fabrics
  • Containers, appliances and existing Linux bridges

HOW IT WORKS

From local bridge to authorised remote network.

Central establishes who may participate. The approved agents then forward Ethernet across protected data-plane sessions and resilient relay infrastructure.

  1. 01 / ATTACH

    Connect each location

    Install an Ethernet attachment on each agent and connect its TAP adapter to the appropriate local bridge.

  2. 02 / AUTHORISE

    Approve network identities

    Central validates agents and MAC addresses, prevents duplicate ownership and establishes secure connectivity.

  3. 03 / FORWARD

    Send frames intelligently

    Known unicast goes only to the destination MAC owner. Broadcast and multicast replicate across authorised connections.

ONE MANAGEMENT EXPERIENCE

Operate a fabric, not a collection of tunnels.

Add locations, review identity, choose resilience and investigate events from one solution. Low-level infrastructure hashes, process IDs and session identifiers remain available for diagnostics without dominating everyday operations.

Discuss fabric management
  • 01Add or remove locationsControl which agents and local networks participate.
  • 02Review discovered MAC addressesAuthorise new identities before they can send traffic.
  • 03Detect duplicate or moved MACsResolve ownership conflicts and unexpected location changes.
  • 04Monitor agent-to-agent connectivitySee data-plane health independently from Central-control health.
  • 05Select resilience policiesApply the right relay, failover, striping or redundancy behaviour.
  • 06Revoke and investigateRemove access immediately and review security or operational events.

SECURITY BY DESIGN

Authority at the control plane. Enforcement at every agent.

Membership, source identity and session state are explicit. Unauthorised traffic fails closed, replayed frames are rejected and unavailable peers cannot consume unbounded resources.

FRAME POLICY

Identity-bound traffic

  • Authorised source-MAC enforcement
  • Network and agent identity binding
  • Duplicate MAC ownership prevention
FAILURE CONTROL

Bounded, fail-closed behaviour

  • Replay protection
  • Unknown-unicast fail-closed behaviour
  • Bounded queues for slow or unavailable peers
OUTAGE CONTINUITYPreviously authorised MAC mappings and active sessions can remain available in agent memory during a temporary Central outage. New devices and new connectivity remain blocked until Central authority is restored.

Check the local network before extending it.

Use Layer 2 only where the application or appliance needs Ethernet adjacency. Confirm addressing, VLAN placement, broadcast behaviour, latency and capacity across the intended sites. Local switching, cabling, endpoint security and building-system safety remain part of the site design.

Each participating agent uses one TAP attachment to an existing Linux bridge or an agent-provisioned bridge. DC Core can also supply a preconfigured bridge appliance for an agreed site, with fabric onboarding and remote path validation.

Use the building-systems deployment guide · Review security controls

BUILD ONE SECURE ETHERNET FABRIC

Build one secure Ethernet fabric across every location.

Connect distributed networks through centrally authorised identities, encrypted agent-to-agent sessions and resilient relay infrastructure.

Deploy Your First Fabric