Bg illustration

Instant Extranet

Onboard partners through a repeatable, governed control plane with built-in segmentation and policy for private, high-reach connectivity

03 Business Partner Connectivity graphic

Ready for Instant Connectivity?

Extend controlled access into networks you don’t own. Alkira replaces manual VPN tunnels and firewall rules with a repeatable, governed control plane.

Business Partner Connectivity2 illustration

What’s the Difference Between a Site-to-Site VPN, a Traditional Extranet, and Instant Extranet?

Site-to-Site VPN icon

What Is a Site-to-Site VPN?

A site-to-site VPN establishes an encrypted tunnel between two networks, typically configured manually per partner. It works for a single connection, but each additional partner means another tunnel, another set of firewall rules, and another point of failure to maintain.


Alkira replaces one-off VPN tunnels with a repeatable, policy-driven connection model that scales to any number of partners.

Traditional Extranet icon

What Is a Traditional Extranet?

A traditional extranet is a hardware-anchored hub, firewalls, routers, and dedicated circuits, built to let external partners reach specific internal resources. Segmentation and access control are hand-configured device by device, which slows onboarding and complicates change.


Alkira collapses the hardware stack into an on-demand fabric, with segmentation and access policy defined once and enforced everywhere.

Instant Extranet icon

What Is Instant Extranet?

Instant Extranet is the joint Lumen and Alkira approach to partner connectivity: Alkira's cloud-native control plane applies segmentation and policy automatically at its Cloud Exchange Point, while Lumen's SLA-backed underlay carries the traffic that needs deterministic performance, so every new partner is onboarded the same well-governed way, without new hardware or manual tunnel builds.


Lumen and Alkira onboard partners up to 91% faster, with policy and segmentation applied automatically from day one.

Use Cases

3D concept illustration of partner onboarding

Partner Onboarding

Connect business partners in 91% less time1 secure segmentation, ensuring users access only what they need.

3D illustration of mergers and acquisitions

Mergers & Acquisitions

Streamline your merger or acquisition with segmented, secure and isolated access to network resources.

3D concept illustration of private connectivity

Private Connectivity

Enable partner connectivity over a private network using Alkira’s private exchange.

1Nemertes, Alkira Real Economic Value Report, October 2024.

Whitepaper

Modernizing Business Partner Connectivity

Modernizing business partner connectivity white paper cover

Solution Highlights

3D illustration of automated partner connectivity

Automated Partner Connectivity

Streamline all processes related to partner connectivity using a single, user-friendly interface.

3D illustration of overlapping IP addresses

Address Overlapping IP Addresses

Use Alkira’s advanced NAT policies to resolve IP conflicts across business partners.

3D illustration of policy framework

Advanced Policy Framework

Define and enforce policies to restrict partner access to specific applications.

3D illustration of network traffic visibility

Traffic Visibility

Inspect and monitor traffic to ensure secure operations.

Featured Testimonial

Michaels Improved
Store Connectivity

“We deployed 1400 stores nationwide and Canada in three weeks.
We would not hesitate to recommend Alkira.”

Wei Dong,
VP & Chief Information Security Officer
Michaels’

Wei Dong Michaels VP & CISO

How Does Instant Extranet Compare to Traditional Partner Connectivity?

Capability Alkira Instant Extranet Traditional Extranet / Site-to-Site VPN
Onboarding Speed Up to 91% faster, provisioned through a portal Manual tunnel and firewall configuration per partner
Segmentation Built in and enforced by default, per partner Bolted on, often inconsistent across sites
Overlapping IP Addresses Resolved automatically with advanced NAT policy Requires manual re-addressing or workaround design
Connectivity Path Production traffic on Lumen's SLA-backed NaaS underlay; partners connect over IPsec, no circuit to provision Dedicated circuits or best-effort internet per partner, provisioned and managed independently
Policy Enforcement Centralized, application-level policy framework Distributed across individual firewalls and devices
Traffic Visibility Continuous inspection and monitoring across all segments Limited to per-device logs, hard to correlate

Better Together

Alkira and Lumen: Powering the Programmable Network

Alkira and Lumen have come together to deliver the programmable, secure, and AI-ready network enterprises need to connect applications, clouds, data centers, users, and AI workloads, with greater agility, visibility, and control.

One network. Every cloud. Total Control. Globally.

FAQ


What is Instant Extranet?
+
Instant Extranet is a joint Lumen and Alkira solution for onboarding business partners, suppliers, and acquired networks through a repeatable, governed control plane. Alkira’s cloud-native overlay applies segmentation and policy automatically, so every partner, vendor, or third party gets access only to the applications and resources they need.


How is Instant Extranet different from a traditional extranet or site-to-site VPN?
+
A traditional extranet or site-to-site VPN is built one tunnel, one firewall rule, and often one piece of hardware at a time. Instant Extranet replaces that with a cloud-delivered control plane: each partner or acquired entity lands in its own isolated segment at Alkira’s Cloud Exchange Point, and explicit, least-privilege policy exposes only the shared applications, provisioned automatically rather than tunnel by tunnel.


How long does it take to onboard a business partner with Alkira?
+
Enterprises using Instant Extranet onboard partners in up to 91% less time than manual, hardware-based approaches, because routing, segmentation, and access policy are automated rather than configured connection by connection.


Can Instant Extranet resolve overlapping IP addresses between partners?
+
Yes. Alkira applies advanced NAT policies and connector groups automatically to resolve overlapping and conflicting IP address ranges across business partners, so duplicate address space is no longer a blocker to onboarding.


Does Instant Extranet support mergers and acquisitions?
+
Yes. During M&A, Alkira segments and connects the acquired organization’s network resources on a defined timeline, giving both sides controlled, isolated access without extending full trust between networks on day one.


Does the partner traffic run over the public internet?
+
Partners typically connect to Alkira through an IPsec connector over their own broadband, or over Lumen’s Internet On-Demand for SLA-backed performance, so there’s nothing to provision at the partner site. Production and data-center traffic rides Lumen’s private, SLA-backed NaaS underlay rather than best-effort links, keeping performance-sensitive traffic deterministic end to end.


How is Instant Extranet different from SD-WAN?
+
SD-WAN optimizes branch WAN transport for a single organization. Instant Extranet is purpose-built for connecting external business partners, vendors, and acquired networks, with segmentation and policy designed around limited, defined trust rather than full internal access.

Additional Resources

Extranet as a Service Transforming Business Partner Connectivity diagram

Extranet-as-a-Service: Transforming Business Partner Connectivity for the Modern Age

Traditional approaches to extranet connectivity—characterized by hardware-dependent architectures, manual processes, and siloed implementations—are increasingly inadequate for modern business requirements. This blog post explores how Extranet-as-a-Service delivers a transformative solution to these challenges, enabling organizations to connect with partners securely and efficiently in the cloud era. The Evolution of Business Partner Connectivity Business partner ecosystems are…
Global backbone blog feature featured graphic

Revolutionizing WAN: How Alkira Cloud Backbone as-a-Service Transforms Enterprise Connectivity

Enterprise networking is at a critical turning point in the era of cloud computing, generative AI, and distributed workforces. Traditional WAN architectures—rooted in MPLS, SD-WAN, and colocation facilities—struggle to keep up. They’re complex, expensive, and often too slow to deploy to support the fast-paced needs of modern organizations. Alkira Cloud Backbone as-a-Service is changing the…
David Klebanov
Connecting Healthcare Applications using Alkira Cloud Area Networking

Connecting Healthcare Applications using Alkira Network Infrastructure-as-a-Service

Typically, medium and large-size Healthcare providers manage many medical facilities across multiple regions. These providers deal with massive amounts of patients’ sensitive information that must be stored securely. They also provide secure access to local and remote users from various locations to access the patient’s information. Based on the above information, we can see what…
Ahmed Abeer | Deepesh Kumar