Your internal tools feed your metrics. OutPost installs in an hour, with no inbound port to open.
GLPI, vCenter, Active Directory, SCCM, Nessus: the data that matters sits behind your firewall. OutPost is a virtual machine you deploy in your DMZ. The encrypted WireGuard tunnel is built in: the VM opens it outbound on its own, and nothing comes back in, and it relays only the APIs you allow, one firewall rule per API.
- Encrypted WireGuard tunnel, opened by the VM
- No inbound connections from the internet
- One firewall rule per API, nothing else
- Why it is safe ↓
THEY DID IT
Clésence connected AD, GLPI, EDR and monitoring without rebuilding its inventory
A social housing company in the Action Logement group, multi-site infrastructure, outsourced CISO. OverView read the existing inventories through their APIs, and their CMDB is now fed back automatically with consolidated data.
Read the case study →
Alexandre Demol
Infrastructure Manager — Clésence

“For every incident, we spent 2 to 3 hours rebuilding what happened. With OverView, the information is right there — we went from reactive to preventive.”
THE PROBLEM
Your most useful data sits behind your firewall
One VPN per vendor
Every SaaS tool that wants to read your GLPI, your vCenter or your Active Directory asks for a site-to-site VPN, a security review and weeks of network tickets. Your reporting project waits on the network project.
Open ports you end up regretting
Exposing an internal API to the Internet, even behind an IP filter, is one more attack surface to justify at every audit.
Agents everywhere
Installing an agent on every server to collect data means rollout, updates and exceptions to manage forever.
HOW IT WORKS
An outpost, not a front door
An outpost is a small forward position, set at the edge of the territory, that observes and reports back to base. It commands nothing, stores nothing, and can be withdrawn without affecting the main position.
- 01
Deploy the VM
Import the provided image (OVA, VHDX or QCOW2) into your hypervisor, in a DMZ or isolated VLAN. A lightweight VM, about 15 minutes.
- 02
Allow outbound traffic
The VM initiates a WireGuard tunnel to OverView itself. On your firewall: outbound HTTPS and UDP, no inbound rule, no port forwarding.
- 03
Open only what is needed
By default OutPost sees nothing on your network. You add one rule per API to query: the GLPI IP on 443, the vCenter IP, nothing else.
- 04
Plug in your connectors
OutPost appears in OverView as a connection route. You configure your internal sources exactly like a cloud connector, and your metrics are recomputed on the next sync.
WHICH ROUTE FOR WHICH TOOL
Three routes, one inventory
Cloud, on-prem, file: every source has a route into OverView. Most customers combine two of them.
| Your situation | Recommended route |
|---|---|
| SaaS tool with a public API (EDR, Entra ID, Intune, ServiceNow) | Cloud API |
| Internal tool with an API (GLPI, vCenter, Active Directory, Nessus, Centreon) | OverView OutPost |
| Several internal tools behind the same firewall | OutPost, one VM for all of them |
| Tool with no API, or that only produces exports (scanner report, antivirus console, home-grown CMDB) | OverView DropPoint |
| Isolated site or a network you do not open | DropPoint, a file goes out, nothing comes in |
| Both cases in the same infrastructure | OutPost + DropPoint, same inventory |
The answers your security review will need
Outbound connections only
The VM initiates every connection and crosses your NAT like a workstation would. No public IP, no bastion, no reverse proxy, no internal API exposed.
End-to-end encrypted
WireGuard (ChaCha20-Poly1305) with automatic key rotation. Any relay only ever sees encrypted traffic.
Zero trust by default
At install time OutPost has access to nothing. Every internal API must be explicitly allowed by your firewall, IP and port included.
Dedicated private network
OutPost joins OverView’s private network only. The platform alone can reach it, never another customer or the Internet.
Limited impact if compromised
If the VM were compromised, an attacker would only see the APIs you allowed, read-only. Its access is revoked in under 30 seconds.
Hardened base, self-updating
Hardened OS with automatic security updates. Nothing for you to maintain.
Recommended reading before your security review
HAND THIS TO YOUR NETWORK TEAM
What the firewall must let out, and nothing else
Paste this block into the ticket. The deployment guide details the rules for FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower and pfSense / OPNsense.
- 01Outbound TCP 443 and UDP 3478 from the VM to the control plane and relays (*.tailscale.com)
- 02Outbound high-port UDP from the VM to the OverView egress IP, for the direct WireGuard connection
- 03Outbound TCP 80 / 443 to the Ubuntu and Tailscale repositories (updates), UDP 123 to ntp.ubuntu.com
- 04Internal: VM IP to each target API on its port (e.g. 443), everything else denied by default
- 05Stateful firewall, no SSL inspection on this traffic, no inbound rule
TECH SHEET
What to plan for
- Sizing
- 2 vCPU · 2 GB RAM · 10 GB disk
- Hypervisors
- VMware vSphere / ESXi (OVA), Microsoft Hyper-V (VHDX), Nutanix AHV, Proxmox VE, KVM (QCOW2)
- OS
- Hardened Ubuntu 24.04 LTS, automatic security updates
- Network
- DHCP by default or static IP, internal DNS resolution supported
- Outbound traffic
- TCP 443 and UDP 3478 to the control plane, high-port UDP to OverView
- Inbound traffic
- None
- Placement
- DMZ or isolated VLAN, behind a stateful firewall
- Documented firewalls
- FortiGate, Palo Alto, Check Point, Cisco ASA / Firepower, pfSense / OPNsense
WHAT YOU UNLOCK
Your internal tools become OverView sources
CMDB, hypervisors, scanners, directories, monitoring, backup: as soon as a tool exposes an API on your network, OutPost lets OverView read it. One VM covers every tool behind the same firewall, added one at a time, with nothing installed on them. And every source unlocks metrics.
Examples of metrics unlocked
- EDR coverage of servers, against the real inventorySources: vCenter + EDR
- Devices active in AD but unknown to your ITSMSources: Active Directory + GLPI
- Obsolete servers with High vulnerabilitiesSources: Nessus + vCenter
- Percentage of VMs backed upSources: vCenter + Veeam
- Active / inactive AD accountsSources: Active Directory
FREQUENTLY ASKED
What your CISO will ask
Ready to take back control?
Plug in your sources, see for yourself in 14 days. Free access, no commitment, 45-minute setup.
Start for free