Tech Bytes: Why Beaver Excavating Tapped Firezone for WireGuard-Powered VPN (Sponsored) artwork

Tech Bytes: Why Beaver Excavating Tapped Firezone for WireGuard-Powered VPN (Sponsored)

The Fat Pipe - All Packet Pushers Pods

September 21, 2026

Today on the Tech Bytes podcast we talk VPNs. But instead of just hearing from Firezone, we talk with a customer. Our guest is Daniel Caruso, IT Network and Systems Administrator at Beaver Excavating, a construction firm headquartered in Canton, OH....

Speakers Daniel Caruso, Jamil Boukir

TopicsTechnology

SPEAKER_1 (0:04)

Today on the Tech Bytes Podcast, we're talking VPNs. Our sponsor is Firezone. They offer a secure remote access solution built on Wireguard. But instead of just hearing from Firezone, we're going to talk to a customer. Our guest is Daniel Caruso. He's IT Network and Systems Administrator at Beaver Excavating. They are a construction firm and ordered in Canton, Ohio.

Daniel looked at VPN options to help protect the company's remote desktop infrastructure. He's here to talk about what he looked at, why he chose Firezone, what day-to-day operations look like and more. We're also joined by Firezone's co-founder Jamil Boukir. So, Daniel and Jamil, welcome to the podcast. And Daniel, can you just get us started with a quick overview of Beaver Excavating, what the company does?

Daniel Caruso (0:43)

Yes, absolutely.

The Beaver Companies is a collection of three companies that do different things in different areas. Beaver Excavating is our big one. We do heavy excavating and major like with moving projects and stuff across a variety of states. We have Beaver Constructors that does construction based projects, and then we have Stone Products that does mining and aggregate solutions. So, we have kind of a niche in all the different areas.

SPEAKER_1 (1:16)

Okay. So, and this sounds like then it's a multi-state, multi-site business, lots of offices, lots of probably remote offices and work sites where you need to have connectivity?

Daniel Caruso (1:25)

Absolutely. We have a couple of actual office buildings, but a lot of our work is done out of job trailers that are scattered across a bunch of states.

SPEAKER_1 (1:34)

Okay. So, then prior to Firezone, how were your employees and workers connecting to remote resources and what kinds of applications and services are they accessing?

Daniel Caruso (1:45)

So, most of our employees utilize remote desktop, because unfortunately in the construction industry, a lot of the construction-specific software that we use is from the Stone Age. So, a lot of it is on-premise applications that still have to be housed on-premise. It makes cloud migrations a little difficult.

Previous to using Firezone, we used a remote desktop gateway, which just allowed access to the server open to the Internet, which was not very secure. So, we moved to Firezone to put all that traffic behind encryption.

SPEAKER_1 (2:26)

Okay. So, before Firezone, it was essentially, I'm opening up a web connection or an Internet connection, probably doing a username and password at the gateway and then getting access to resources?

Daniel Caruso (2:37)

Correct.

SPEAKER_1 (2:38)

Okay. How are employees connecting? I assume you've got some permanent offices, but also lots of work sites where there might not be Internet access at the site.

Daniel Caruso (2:50)

So, we use three different avenues there. Our actual physical offices, obviously, they have fiber connections. Our job trailers, most of them utilize the Starlink. We've migrated most of them over to Starlink, and obviously, for the guys in the field, they just use phone hotspots.

But mainly, the job trailers are connected via Starlink. Okay.

SPEAKER_1 (3:18)

When you were looking to get a VPN solution, what did you look at anything besides Firezone?

Daniel Caruso (3:24)

We looked at one other option. We looked at OpenVPN Connect, just because that was a pretty simple solution to set up. It was, you spin up the server, you create the accounts, and people can just connect.

It was very user-friendly and it was easy to manage. However, the connection quality wasn't that great. Getting into a remote desktop was okay, but there was a little bit of lag, and we also allow access to file shares and stuff like that over the VPN, and that's where OpenVPN was very limiting. We were getting super slow connection speeds, even though we have a gigabit connection here, it's just the overhead of the SSL VPN wasn't ideal.

SPEAKER_1 (4:06)

Okay. How did you find Firezone?

Daniel Caruso (4:11)

Well, when I was starting to get frustrated with OpenVPN, I just started looking at other options, and I just happened to know that Wireguard is a superior connection. And when I came across Firezone and realized that that's based on a Wireguard connection, I was interested, so we gave them a try.

SPEAKER_1 (4:27)

Okay. Jamila, since you're here, can you maybe give us a quick briefing on why you picked Wireguard as the basis for the product?

Jamil Boukir (4:36)

Yeah.

So, Wireguard is a UDP-based protocol. The internal module is really quick, as everyone knows. But it was also just the most modern protocol at the time. The cryptography was simple to audit. And it was very easy to get started with. And most of all, we had some engineering friends out here. I guess this is going back way in the early days of Firezone now. But some friends out here in the Bay Area, they had wanted to use Wireguard mainly for the speed and the latency.

8 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Fetch the whole transcript

The demo key returns a sample episode in full, no card needed:

request
curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

request
curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000790980543