Alta Help Center

AltaConnect and Auto-VPN

Permanently deleted user
Permanently deleted user
  • Updated

AltaConnect and Auto-VPN are WireGuard-based VPN deployment features available within Alta Control for Alta Labs routers. AltaConnect creates managed VPN groups, while Auto-VPN creates individual point-to-point VPN tunnels.

Requirements

  • You must have administrator access to the sites containing the routers you want to use in a VPN group or Site-to-Site (S2S) Auto-VPN tunnel.
  • A minimum of two routers is required to create an AltaConnect VPN group.
  • A minimum of three routers is required to use a failover hub: a primary hub, a failover hub, and at least one spoke.
  • Multi-hub AltaConnect is available with Route10 firmware 1.5f or later.

AltaConnect

AltaConnect creates secure site-to-site VPN groups between Alta Labs routers using either Mesh or Star topology. AltaConnect automatically generates and manages the required WireGuard configuration.

VPN connectivity between group members is maintained dynamically within the selected topology and is designed to recover following device reboots or temporary interruptions.

For a multi-hub Star group, one router is assigned as the primary hub and a second router is assigned as the failover hub. AltaConnect automatically configures BGP for multi-hub operation.

The redundant hubs connect between each other, as well as to all of the spokes. Routing automatically changes to provide failover. If a spoke loses internet connectivity only to the primary hub, for example, then that spoke can still reach all the other spokes and the primary hub via the secondary hub.

 

Choose a topology

Use this comparison to choose the topology that best fits your deployment.

Topology Connection model Use it when
Mesh All routers act as peers. No primary or failover hub is assigned. The member sites are peers and no single site should act as the central hub.
Star One router acts as the primary hub. Optionally, enable Failover Hub and assign a second router as the failover hub. One site should act as the central hub for the other sites, such as a headquarters or data-center site. Use Failover Hub to enable a secondary hub site for redundancy.

Route Internet options

For Star topology, Route Internet controls how Internet traffic from spokes is routed. This setting is separate from the topology and from the primary-hub and failover-hub role assignments.

Route Internet option Behavior
Off Route Internet traffic from spokes over the standard WAN connection. Only traffic between VPN Group VLANs is routed over the AltaConnect connection.
AltaConnect Only Route all Internet traffic from spokes over the AltaConnect VPN Group, and drop traffic if the AltaConnect connection is down.
WAN Fallback Route all Internet traffic from spokes over the AltaConnect VPN Group, and use the standard WAN connection if the AltaConnect connection is down.

In short, Off keeps spoke Internet traffic on the standard WAN, AltaConnect Only uses AltaConnect and fails closed, and WAN Fallback uses AltaConnect with the standard WAN as a fallback.

Accessing AltaConnect

  1. Navigate to Alta Control.
  2. Select the site menu near the top-right corner of the page.
  3. Select Site Manager.
  4. In the top-right corner, select AltaConnect.

Creating a VPN group

  1. In AltaConnect, select New VPN Group.
  2. Enter a name for the VPN group.
  3. Select the desired topology:
    • Mesh (default)
    • Star
  4. For a multi-hub Star group, turn on Failover Hub.
  5. Under Route Internet, select Off, AltaConnect Only, or WAN Fallback.
  6. Beside Routers, select Add.
  7. In the Add Routers window, select the sites and Route10 routers to add to the VPN group. You can select routers from multiple sites.
  8. For each selected router, select which subnets should be routed through the VPN group.
  9. Select Add selected.
  10. For Star topology, use the green role indicator to assign the primary hub.
  11. If Failover Hub is enabled, use the orange role indicator to assign the failover hub.
  12. Select Save.

The VPN group automatically generates and configures the required WireGuard connections between the selected routers. For a multi-hub Star group, AltaConnect also automatically configures BGP.

screenshot-2026-09-02_10-44-12.png
Example multi-hub Star configuration with Failover Hub enabled. Green identifies the primary hub, and orange identifies the failover hub.

Viewing Existing VPN Groups

From the main AltaConnect page, select a VPN group to display its assigned routers.

Each router entry displays its hostname/DDNS address and shared-subnet count. Only routers from sites you have permission to access are visible. The updated group view also shows the router name, site, and connection status.

For a multi-hub Star group, the green role indicator identifies the primary hub and the orange role indicator identifies the failover hub.

screenshot-2026-09-02_10-45-05.png

Example multi-hub VPN group showing three connected routers. Green identifies the primary hub, and orange identifies the failover hub.

Migrating from Existing Site-to-Site VPN Configurations

Existing site-to-site VPN tunnels must be removed or disabled before adding the routers to an AltaConnect VPN group. Leaving existing tunnels active may result in routing conflicts between overlapping VPN configurations.

You can either:

  • Delete the existing tunnels
  • Disable them temporarily

Existing site-to-site VPN tunnels must be removed or disabled before adding routers to an AltaConnect VPN group. Leaving existing tunnels active may result in routing conflicts between overlapping VPN configurations.

Disabling the existing tunnels is recommended during migration because it allows the previous configuration to be re-enabled if needed.

Auto-VPN (Auto-Connect)

Auto-VPN simplifies the creation of individual site-to-site VPN tunnels between Alta Labs Route10 routers using WireGuard.

Unlike AltaConnect, which creates managed VPN groups using mesh or star topology, Auto-VPN is designed for creating individual point-to-point VPN tunnels between two routers.

Accessing Auto-VPN

  1. Navigate to Alta Control.
  2. Open the target site for one side of the site-to-site tunnel.
  3. Navigate to the Network page.
  4. Open the router configuration panel by either selecting the icon on the left, or tapping on the entry in the list. 
  5. Select the VPN tab.
  6. Beside Client/S2S, select the + button to create a new VPN tunnel profile.

Creating an Auto-VPN Tunnel

  1. Under Auto-Connect, select the remote site.
  2. Select the preferred Remote Router, if needed.
    1. Multiple Route10 routers may exist within a single site, allowing a different router to be selected specifically for VPN connectivity.
  1. Adjust the selected subnets for both the local and remote sides. 
  2. For most deployments, only the subnet selections need to be changed before saving, though additional options are available if needed.
  3. Select Save Both Routers.

The generated VPN tunnel configuration will be applied to both routers automatically.

Video Tutorial:

Auto VPN & Alta Connect Tutorial | Alta Labs


 

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Article is closed for comments.