Related Ingenix tool
Build and validate a vendor-neutral VPN baseline in your browser.
In this guide
Requirements
Define who needs remote access, what devices are permitted, which applications are required, where users are connecting from, and what happens when the identity provider, VPN gateway or WAN is unavailable.
| Area | Design question |
|---|---|
| Identity | Who is allowed to connect and how is identity verified? |
| Device | Are unmanaged or non-compliant devices permitted? |
| Access | Which subnets, hosts and applications are actually required? |
| Routing | Which destinations use the VPN? |
| Operations | What is logged and how are failed connections investigated? |
Authentication and MFA
Use central identity and MFA where possible. RADIUS, certificates and identity-provider integrations can be appropriate depending on the platform. Avoid shared credentials because they make attribution, revocation and incident response difficult.
Separate VPN authentication from application authorisation. A user proving their identity should not by itself determine which internal systems they can reach.
Network access and least privilege
Assign clients to controlled address pools and restrict access with firewall policy. Separate administrative access from ordinary user access and use distinct rules for sensitive services.
Prefer explicit destination groups and application requirements over broad “internal network” access. Record the business reason for privileged access and review it periodically.
Split tunnelling
| Model | Benefit | Risk / consideration |
|---|---|---|
| Full tunnel | Centralises Internet and internal traffic inspection. | Uses more WAN/gateway capacity and may add latency. |
| Split tunnel | Reduces VPN bandwidth and improves local Internet performance. | Local breakout bypasses central inspection controls. |
Choose deliberately. Document the destination prefixes that enter the tunnel, what DNS traffic does, and whether security controls exist for local breakout.
DNS and name resolution
Define which DNS servers remote clients receive and which suffixes/search domains they use. Internal names should resolve through the intended security path without exposing unnecessary internal DNS services to untrusted networks.
When troubleshooting, test by IP first, then test DNS resolution, then test the application. This separates routing and policy problems from name-resolution problems.
Device posture
Consider supported operating-system versions, patch level, endpoint protection, device management and certificates. Where the VPN platform supports posture checks, define what happens when a device fails them.
- Prefer managed devices for privileged access.
- Use certificates where they materially improve device identity.
- Define session timeout and reauthentication behaviour.
- Have a clear process for lost or compromised devices.
Monitoring and logs
Log authentication successes and failures, tunnel establishment, assigned client addresses, policy decisions and disconnects. Correlate VPN events with identity-provider, firewall and endpoint logs when investigating an incident.
Useful troubleshooting evidence includes the user's source network, exact timestamp, VPN gateway, assigned VPN address, destination tested, authentication result, security-policy decision and any relevant packet capture. Do not collect passwords, private keys or reusable MFA material.
Testing and troubleshooting
- Test authentication with a known account and known-good client.
- Confirm the client receives the expected VPN address and routes.
- Test an internal IP address.
- Test internal DNS.
- Test the required application and port.
- Test access to a permitted resource and an explicitly denied resource.
- Test reconnect, roaming and sleep/wake behaviour.
- Test expiry, reauthentication and gateway failure where practical.
If a connection fails, inspect VPN authentication logs first, then client routes, firewall policy and DNS. For protocol-level failures, take a short controlled packet capture and correlate it with the VPN gateway logs. See the VPN Troubleshooting Guide.