Skip to content

ON-PREM GATEWAY · OVERVIEW OUTPOST

Your internal tools feed your indicators. Installed in an hour, secure end to end.

GLPI, vCenter, Active Directory, SCCM, Nessus: the data that matters sits behind your firewall. OutPost is a virtual machine you deploy in your DMZ. The encrypted WireGuard tunnel is built in: the VM opens it outbound itself, nothing comes in, and it relays only the APIs you allow, one firewall rule per API.

YOUR NETWORKINTERNAL NETWORKGLPI · CMDBvCenter · VMsActive DirectoryINTERNAL FIREWALL · 1 RULE PER APIREAD ONLYDMZOutPostVM in your DMZStores nothingFIREWALLINTERNETOUTBOUND ONLYENCRYPTED WIREGUARDNO INBOUND FLOWOverView98 %EDR1 204ASSETS37HIGH
  • Encrypted WireGuard tunnel, opened by the VM
  • No inbound flow from the Internet
  • One firewall rule per API, nothing else
  • Why it is safe ↓

WHAT CHANGES

0VPN to build, 0 NAT, 0 agent
≈ 1 hfrom importing the VM to the first API read
1 ruleper allowed API on your firewall, nothing else
< 30 sto revoke the VM’s access

THEY DID IT

Clésence connected AD, GLPI, EDR and monitoring without rebuilding its inventory

A social housing company in the Action Logement group, multi-site estate, outsourced CISO. Data was captured through the APIs of the existing repositories, and their CMDB is now fed back automatically with consolidated data.

Read the case study →
Alexandre Demol, Infrastructure Manager — Clésence

Alexandre Demol

Infrastructure Manager — Clésence

Clésence

« For every incident, we spent 2 to 3 hours rebuilding what happened. With OverView, the information is right there — we went from reactive to preventive. »

THE PROBLEM

Your most useful data sits behind your firewall

1

One VPN per vendor

Every SaaS tool that wants to read your GLPI, your vCenter or your Active Directory asks for a site-to-site VPN, a security review and weeks of network tickets. The indicators project waits for the network project.

2

Open ports you end up regretting

Exposing an internal API to the Internet, even IP-filtered, is one more attack surface to justify at every audit.

3

Agents everywhere

Installing an agent on every server to collect data means rollout, updates and exceptions to manage forever.

HOW IT WORKS

An outpost, not a front door

An outpost is a small forward position, set at the edge of the territory, that observes and reports back to base. It commands nothing, stores nothing, and can be withdrawn without affecting the main position.

  1. 01

    Deploy the VM

    Import the provided image (OVA, VHDX or QCOW2) into your hypervisor, in a DMZ or isolated VLAN. A lightweight VM, about 15 minutes.

  2. 02

    Allow outbound traffic

    The VM initiates a WireGuard tunnel to OverView itself. On your firewall: outbound HTTPS and UDP, no inbound rule, no NAT.

  3. 03

    Open only what is needed

    By default OutPost sees nothing on your network. You add one rule per API to query: the GLPI IP on 443, the vCenter IP, nothing else.

  4. 04

    Plug in your connectors

    OutPost shows up in OverView as a connectivity point. You configure your internal sources exactly like a cloud connector, and indicators compute on the next synchronization.

WHICH ROUTE FOR WHICH TOOL

Three routes, one inventory

Cloud, on-prem, file: every source has a path into OverView. Most customers combine two of them.

Your situationRecommended route
SaaS tool with a public API (EDR, Entra ID, Intune, ServiceNow)Cloud API
Internal tool with an API (GLPI, vCenter, Active Directory, Nessus, Centreon)OverView OutPost
Several internal tools behind the same firewallOutPost, one VM for all of them
Tool with no API, or that only produces exports (scanner report, antivirus console, home-grown CMDB)OverView DropPoint
Isolated site or a network you do not openDropPoint, a file goes out, nothing comes in
Both cases in the same estateOutPost + DropPoint, same inventory
SECURITY

The answers your security review will ask for

Outbound only, NAT traversed

The VM initiates every connection and crosses your NAT like a workstation would. No public IP, no bastion, no reverse proxy, no internal API exposed.

End-to-end encrypted

WireGuard (ChaCha20-Poly1305) with automatic key rotation. Any relay only ever sees encrypted traffic.

Zero trust by default

At install time OutPost has access to nothing. Every internal API must be explicitly allowed by your firewall, IP and port included.

Dedicated private network

OutPost joins OverView’s private network only. The platform alone can reach it, never another customer or the Internet.

Bounded blast radius

If the VM were compromised, an attacker would only see the APIs you allowed, read-only. Its access is revoked in under 30 seconds.

Hardened base, self-updating

Hardened OS with automatic security updates. Nothing for you to maintain.

HAND THIS TO YOUR NETWORK TEAM

What the firewall must let out, and nothing else

Paste this block into the ticket. The deployment guide details the rules for FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower and pfSense / OPNsense.

  1. 01Outbound TCP 443 and UDP 3478 from the VM to the control plane and relays (*.tailscale.com)
  2. 02Outbound high-port UDP from the VM to the OverView egress IP, for the direct WireGuard connection
  3. 03Outbound TCP 80 / 443 to the Ubuntu and Tailscale repositories (updates), UDP 123 to ntp.ubuntu.com
  4. 04Internal: VM IP to each target API on its port (e.g. 443), everything else denied by default
  5. 05Stateful firewall, no SSL inspection on these flows, no inbound rule

TECH SHEET

What to plan for

Sizing
2 vCPU · 2 GB RAM · 10 GB disk
Hypervisors
VMware vSphere / ESXi (OVA), Microsoft Hyper-V (VHDX), Nutanix AHV, Proxmox VE, KVM (QCOW2)
OS
Hardened Ubuntu 24.04 LTS, automatic security updates
Network
DHCP by default or static IP, internal DNS resolution supported
Outbound flows
TCP 443 and UDP 3478 to the control plane, high-port UDP to OverView
Inbound flows
None
Placement
DMZ or isolated VLAN, behind a stateful firewall
Documented firewalls
FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower, pfSense / OPNsense

WHAT YOU UNLOCK

Your internal tools become OverView sources

CMDB, hypervisors, scanners, directories, monitoring, backup: as soon as a tool exposes an API on your network, OutPost makes it readable by OverView. One VM covers every tool behind the same firewall, added one at a time, with nothing installed on them. And every source unlocks indicators.

GLPIGLPI
iTopiTop
EasyVistaEasyVista
VMware vCenterVMware vCenter
NutanixNutanix
Tenable NessusTenable Nessus
Tenable Security CenterTenable Security Center
OpenVASOpenVAS
CyberwatchCyberwatch
Active DirectoryActive Directory
WallixWallix
CentreonCentreon
ZabbixZabbix
PRTG Network MonitorPRTG Network Monitor
LibreNMSLibreNMS
VeeamVeeam
SCCM / MECMSCCM / MECM
WSUSWSUS
LansweeperLansweeper
NetBoxNetBox
EfficientIP SOLIDserverEfficientIP SOLIDserver

Examples of indicators unlocked

  • EDR coverage of servers, against the real inventorySources: vCenter + EDR
  • Devices active in AD but unknown to the ITSMSources: Active Directory + GLPI
  • Obsolete servers with High vulnerabilitiesSources: Nessus + vCenter
  • Share of VMs that are backed upSources: vCenter + Veeam
  • Active / inactive AD accountsSources: Active Directory

FREQUENTLY ASKED

What your CISO will ask

Technically yes: OutPost ships with a WireGuard tunnel (Tailscale mesh network), pre-configured and operated by OverSOC. What you avoid is the site-to-site VPN project: no concentrator to configure, no routes to advertise, no keys to manage. The VM dials out, authenticates, done.

Ready to regain control?

Plug in your sources, see the value in 14 days. Free access, no commitment, 45-minute setup.

Try for free