Assume all your machines have Internet access, which they probably do these days. Instead of having to create firewall rules and routes and that whole mess in order to connect to a machine on "the inside" somewhere, the machine reaches out to the Internet and creates a tunnel, and you connect to the machine through that tunnel.