Full tunnel
All eligible traffic is carried through the VPN interface. Simpler to reason about, and usually the default expectation for a consumer-facing connectivity product.
Southwest Network Corporation
We design and develop VPN and network-connectivity products across client applications, tunnel integration, routing policy, control-plane systems, multi-platform delivery, and ongoing network product engineering.
From tunnel integration and routing policy to multi-platform clients, control-plane systems, deployment, and ongoing product engineering.
Illustrative topology
abstract · no live data
Illustrative architecture · conceptual only · no live data
Engineering scope
A VPN product is a client application on every target platform, a tunnel integration layer, a routing policy, a control plane the clients depend on, gateway integration, and a release process that keeps all of it shippable.
Client applications for Windows, macOS, iOS, Android, Linux, and router environments where the target firmware allows it. Includes the interface work around connect and disconnect, connection state, region or route choices, and update handling.
Integration of a tunnel protocol behind an adapter layer, so session establishment, reconnect behaviour, and platform networking integration are handled consistently across targets. WireGuard, OpenVPN, and IKEv2 appear here only as common integration options.
Design and implementation of which traffic uses the tunnel: full tunnel or split tunnel, included and excluded routes, and per-app or destination-based rules where the operating system exposes them. DNS and routing configuration are part of the platform integration work.
The product backend that clients depend on: authentication and account lifecycle, device registration, configuration delivery, a directory of available regions and resources, plan or subscription state integration, and client version and configuration management.
Integration work at the gateway and service-endpoint layer: how endpoints are registered and organised by region, how health and status signals are collected, how configuration is rolled out, and how traffic paths are designed.
Connection state and error telemetry, log and diagnostic design, automated build and release pipelines, cross-platform compatibility testing, crash and error review, and a repeatable update workflow.
Platforms
Every operating system exposes VPN functionality differently. The matrix below sets out the engineering context per platform, referencing each vendor's own documentation.
Android VpnService
Android exposes VpnService, which lets an application establish a virtual network interface, configure addresses and routes, receive outgoing IP packets, and inject received packets back into the networking stack. App-level allow and deny routing is configured through VpnService.Builder.
Network Extension
Apple platforms provide Personal VPN for the built-in IPsec/IKEv2 configurations and Packet Tunnel Provider for packet-oriented custom protocols. A packet tunnel provider works through a virtual interface and can set included and excluded routes, DNS, a virtual IP, and MTU, including per-app VPN contexts.
Routing policy & profiles
On Windows, an important design choice is split tunnel versus force tunnel. Routing policy decides which traffic uses the VPN interface and which stays on the physical interface, and profile configuration determines how that behaviour is applied.
Tunnel & service integration
Linux work covers tunnel and protocol integration alongside routing table and DNS handling, service lifecycle under the init system in use, and packaging for the distributions a project needs to target.
Configuration-oriented integration
Router work is configuration-oriented rather than application-oriented, and depends on what the target firmware supports. It is scoped per project against the specific device and firmware requirements.
This describes company development capability and engineering scope. It does not state which platform APIs or implementations are used inside Rabbit Fast.
Tunnel & protocol
Protocol choice is a project decision with trade-offs in transport, platform fit, and long-term maintenance. Integration sits behind an adapter layer so the client does not have to be rewritten when that decision changes.
A modern VPN tunnel protocol using Cryptokey Routing over UDP transport. Frequently considered where a compact, UDP-oriented tunnel suits the deployment.
wireguard.comA mature open-source VPN platform and protocol family built on SSL/TLS, with flexible client/server deployment and both TCP and UDP tunnelling.
openvpn.netRelevant where using the operating system's built-in VPN configuration is the right fit, for example Apple's Personal VPN path or managed profiles on Windows.
developer.apple.comAn existing protocol or tunnel architecture supplied by the customer can be evaluated and integrated behind the client adapter layer. We do not claim to have authored a proprietary VPN protocol.
Protocol examples describe common VPN engineering options and do not state which protocol Rabbit Fast uses. Protocol selection depends on project requirements, target platforms, deployment environment, and maintenance constraints.
Routing
Which traffic uses the tunnel is one of the defining behaviours of a VPN product — and one of the most common sources of inconsistency between platforms.
All eligible traffic is carried through the VPN interface. Simpler to reason about, and usually the default expectation for a consumer-facing connectivity product.
Selected traffic is carried through the VPN interface while everything else stays on the physical interface. Requires a clear rule set and predictable behaviour when rules do not match.
Route sets decide which destinations are inside the tunnel. Apple's packet tunnel configuration and Windows routing policy both express this as included and excluded routes.
Where the operating system exposes it — for example app allow and deny lists on Android — routing can be scoped per application rather than per destination alone.
Control plane
Behind the client sits the product backend: who the user is, which devices are registered, what configuration each client receives, which regions and resources exist, and what plan state applies.
Desktop, mobile, and router clients that authenticate, fetch configuration, present connection options, and report state.
User, account, and session lifecycle, plus device and client-version registration.
Distribution of client configuration and metadata about available regions and resources, together with plan or subscription state integration.
The data-path layer the client connects to, integrated by region with health metadata and staged configuration rollout.
Connection state and error signals, service health metadata, diagnostics, and update or configuration rollout workflows.
Illustrative architecture · no live data
This is a conceptual VPN product architecture used to explain development scope. It does not disclose Rabbit Fast's internal architecture.
Reference product
Rabbit Fast / 兔快VPN is a multi-platform VPN and connectivity product operated by Southwest Network Corporation. It is published here as a practical example of taking a connectivity product from architecture to multi-platform productization — not as a client engagement.
One product published across Windows, macOS, iOS, Android, Linux, and router environments.
A consistent connection workflow: install, sign in, choose a connection option, connect.
Route and connection options surfaced to the user rather than hidden behind a single fixed path.
A product website, client distribution, plan structure, and an ongoing customer-support channel.
One account is used across the platforms the product supports, so the same connection approach applies whether the device is a desktop, a phone, or a router.
Protocol internals, network topology, provider relationships, node counts, security configuration, and other operational details are not published on this corporate website.
Lifecycle
Requirements, architecture, implementation, integration and QA, release, then iteration. Each stage produces a written record so the product stays maintainable after handover.
Target platforms, routing behaviour, protocol constraints, and product expectations are recorded in writing.
Client, tunnel, control-plane, and gateway responsibilities are defined before implementation begins.
Client applications, adapter layers, routing policy, and backend services are built in agreed stages.
Cross-platform behaviour, reconnect handling, and routing rules are tested against the defined requirements.
Builds are produced through an automated pipeline and distributed through the channels each platform requires.
Telemetry, error review, and change records feed the next round of product engineering work.
Services
Alongside product development, the company performs scoped network engineering work: how systems are connected, how traffic is routed, and how environments are built, documented, and maintained.
Client applications, tunnel integration, routing policy, and control-plane systems built as one product across the platforms a project targets.
Routing policy, path selection, and split-tunnel behaviour designed, implemented, and measured rather than left at defaults.
Topology planning, device configuration, segmentation, and infrastructure documentation in environments under client control.
Network-related software, automation, monitoring configuration, tooling, and ongoing engineering support.
Resources
Short original notes on the topics that come up most in VPN product engineering, with links to the official platform and protocol documentation.
Company
Southwest Network Corporation develops VPN and network-connectivity products and provides network technology engineering. Rabbit Fast is a company-operated reference product demonstrating multi-platform productization.
The company describes its work conservatively: it builds and operates connectivity software and performs engineering work under written scope. It does not claim licences, carrier status, owned network infrastructure, or a proprietary VPN protocol.
Development & product model
Corporate Filing Address: 30 N Gould St Ste N, Sheridan, WY 82801, United States · This information reflects the company's Wyoming formation filing.
Company Information