Your internal tools feed your indicators. Installed in an hour, secure end to end.
GLPI, vCenter, Active Directory, SCCM, Nessus: the data that matters sits behind your firewall. OutPost is a virtual machine you deploy in your DMZ. The encrypted WireGuard tunnel is built in: the VM opens it outbound itself, nothing comes in, and it relays only the APIs you allow, one firewall rule per API.
- Encrypted WireGuard tunnel, opened by the VM
- No inbound flow from the Internet
- One firewall rule per API, nothing else
- Why it is safe ↓
THEY DID IT
Clésence connected AD, GLPI, EDR and monitoring without rebuilding its inventory
A social housing company in the Action Logement group, multi-site estate, outsourced CISO. Data was captured through the APIs of the existing repositories, and their CMDB is now fed back automatically with consolidated data.
Read the case study →
Alexandre Demol
Infrastructure Manager — Clésence

« For every incident, we spent 2 to 3 hours rebuilding what happened. With OverView, the information is right there — we went from reactive to preventive. »
THE PROBLEM
Your most useful data sits behind your firewall
One VPN per vendor
Every SaaS tool that wants to read your GLPI, your vCenter or your Active Directory asks for a site-to-site VPN, a security review and weeks of network tickets. The indicators project waits for the network project.
Open ports you end up regretting
Exposing an internal API to the Internet, even IP-filtered, is one more attack surface to justify at every audit.
Agents everywhere
Installing an agent on every server to collect data means rollout, updates and exceptions to manage forever.
HOW IT WORKS
An outpost, not a front door
An outpost is a small forward position, set at the edge of the territory, that observes and reports back to base. It commands nothing, stores nothing, and can be withdrawn without affecting the main position.
- 01
Deploy the VM
Import the provided image (OVA, VHDX or QCOW2) into your hypervisor, in a DMZ or isolated VLAN. A lightweight VM, about 15 minutes.
- 02
Allow outbound traffic
The VM initiates a WireGuard tunnel to OverView itself. On your firewall: outbound HTTPS and UDP, no inbound rule, no NAT.
- 03
Open only what is needed
By default OutPost sees nothing on your network. You add one rule per API to query: the GLPI IP on 443, the vCenter IP, nothing else.
- 04
Plug in your connectors
OutPost shows up in OverView as a connectivity point. You configure your internal sources exactly like a cloud connector, and indicators compute on the next synchronization.
WHICH ROUTE FOR WHICH TOOL
Three routes, one inventory
Cloud, on-prem, file: every source has a path into OverView. Most customers combine two of them.
| Your situation | Recommended route |
|---|---|
| SaaS tool with a public API (EDR, Entra ID, Intune, ServiceNow) | Cloud API |
| Internal tool with an API (GLPI, vCenter, Active Directory, Nessus, Centreon) | OverView OutPost |
| Several internal tools behind the same firewall | OutPost, one VM for all of them |
| Tool with no API, or that only produces exports (scanner report, antivirus console, home-grown CMDB) | OverView DropPoint |
| Isolated site or a network you do not open | DropPoint, a file goes out, nothing comes in |
| Both cases in the same estate | OutPost + DropPoint, same inventory |
The answers your security review will ask for
Outbound only, NAT traversed
The VM initiates every connection and crosses your NAT like a workstation would. No public IP, no bastion, no reverse proxy, no internal API exposed.
End-to-end encrypted
WireGuard (ChaCha20-Poly1305) with automatic key rotation. Any relay only ever sees encrypted traffic.
Zero trust by default
At install time OutPost has access to nothing. Every internal API must be explicitly allowed by your firewall, IP and port included.
Dedicated private network
OutPost joins OverView’s private network only. The platform alone can reach it, never another customer or the Internet.
Bounded blast radius
If the VM were compromised, an attacker would only see the APIs you allowed, read-only. Its access is revoked in under 30 seconds.
Hardened base, self-updating
Hardened OS with automatic security updates. Nothing for you to maintain.
Recommended reading before your security review
HAND THIS TO YOUR NETWORK TEAM
What the firewall must let out, and nothing else
Paste this block into the ticket. The deployment guide details the rules for FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower and pfSense / OPNsense.
- 01Outbound TCP 443 and UDP 3478 from the VM to the control plane and relays (*.tailscale.com)
- 02Outbound high-port UDP from the VM to the OverView egress IP, for the direct WireGuard connection
- 03Outbound TCP 80 / 443 to the Ubuntu and Tailscale repositories (updates), UDP 123 to ntp.ubuntu.com
- 04Internal: VM IP to each target API on its port (e.g. 443), everything else denied by default
- 05Stateful firewall, no SSL inspection on these flows, no inbound rule
TECH SHEET
What to plan for
- Sizing
- 2 vCPU · 2 GB RAM · 10 GB disk
- Hypervisors
- VMware vSphere / ESXi (OVA), Microsoft Hyper-V (VHDX), Nutanix AHV, Proxmox VE, KVM (QCOW2)
- OS
- Hardened Ubuntu 24.04 LTS, automatic security updates
- Network
- DHCP by default or static IP, internal DNS resolution supported
- Outbound flows
- TCP 443 and UDP 3478 to the control plane, high-port UDP to OverView
- Inbound flows
- None
- Placement
- DMZ or isolated VLAN, behind a stateful firewall
- Documented firewalls
- FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower, pfSense / OPNsense
WHAT YOU UNLOCK
Your internal tools become OverView sources
CMDB, hypervisors, scanners, directories, monitoring, backup: as soon as a tool exposes an API on your network, OutPost makes it readable by OverView. One VM covers every tool behind the same firewall, added one at a time, with nothing installed on them. And every source unlocks indicators.
Examples of indicators unlocked
- EDR coverage of servers, against the real inventorySources: vCenter + EDR
- Devices active in AD but unknown to the ITSMSources: Active Directory + GLPI
- Obsolete servers with High vulnerabilitiesSources: Nessus + vCenter
- Share of VMs that are backed upSources: vCenter + Veeam
- Active / inactive AD accountsSources: Active Directory
FREQUENTLY ASKED
What your CISO will ask
Ready to regain control?
Plug in your sources, see the value in 14 days. Free access, no commitment, 45-minute setup.
Try for free