ENGINEERING GUIDE · SECURITY

Remote Access VPN Design

Design secure remote-access VPN services with identity, MFA, client addressing, split tunnelling, DNS, device posture, least privilege, monitoring and operational controls.

Engineering referenceRemote access · Identity

Related Ingenix tool

Build and validate a vendor-neutral VPN baseline in your browser.

VPN Configuration Designer →
Security principle: A successful VPN login should not automatically grant unrestricted internal access.

Requirements

Define who needs remote access, what devices are permitted, which applications are required, where users are connecting from, and what happens when the identity provider, VPN gateway or WAN is unavailable.

AreaDesign question
IdentityWho is allowed to connect and how is identity verified?
DeviceAre unmanaged or non-compliant devices permitted?
AccessWhich subnets, hosts and applications are actually required?
RoutingWhich destinations use the VPN?
OperationsWhat is logged and how are failed connections investigated?

Authentication and MFA

Use central identity and MFA where possible. RADIUS, certificates and identity-provider integrations can be appropriate depending on the platform. Avoid shared credentials because they make attribution, revocation and incident response difficult.

Separate VPN authentication from application authorisation. A user proving their identity should not by itself determine which internal systems they can reach.

Network access and least privilege

Assign clients to controlled address pools and restrict access with firewall policy. Separate administrative access from ordinary user access and use distinct rules for sensitive services.

Prefer explicit destination groups and application requirements over broad “internal network” access. Record the business reason for privileged access and review it periodically.

Split tunnelling

ModelBenefitRisk / consideration
Full tunnelCentralises Internet and internal traffic inspection.Uses more WAN/gateway capacity and may add latency.
Split tunnelReduces VPN bandwidth and improves local Internet performance.Local breakout bypasses central inspection controls.

Choose deliberately. Document the destination prefixes that enter the tunnel, what DNS traffic does, and whether security controls exist for local breakout.

DNS and name resolution

Define which DNS servers remote clients receive and which suffixes/search domains they use. Internal names should resolve through the intended security path without exposing unnecessary internal DNS services to untrusted networks.

When troubleshooting, test by IP first, then test DNS resolution, then test the application. This separates routing and policy problems from name-resolution problems.

Device posture

Consider supported operating-system versions, patch level, endpoint protection, device management and certificates. Where the VPN platform supports posture checks, define what happens when a device fails them.

  • Prefer managed devices for privileged access.
  • Use certificates where they materially improve device identity.
  • Define session timeout and reauthentication behaviour.
  • Have a clear process for lost or compromised devices.

Monitoring and logs

Log authentication successes and failures, tunnel establishment, assigned client addresses, policy decisions and disconnects. Correlate VPN events with identity-provider, firewall and endpoint logs when investigating an incident.

Useful troubleshooting evidence includes the user's source network, exact timestamp, VPN gateway, assigned VPN address, destination tested, authentication result, security-policy decision and any relevant packet capture. Do not collect passwords, private keys or reusable MFA material.

Testing and troubleshooting

  1. Test authentication with a known account and known-good client.
  2. Confirm the client receives the expected VPN address and routes.
  3. Test an internal IP address.
  4. Test internal DNS.
  5. Test the required application and port.
  6. Test access to a permitted resource and an explicitly denied resource.
  7. Test reconnect, roaming and sleep/wake behaviour.
  8. Test expiry, reauthentication and gateway failure where practical.

If a connection fails, inspect VPN authentication logs first, then client routes, firewall policy and DNS. For protocol-level failures, take a short controlled packet capture and correlate it with the VPN gateway logs. See the VPN Troubleshooting Guide.