ENGINEERING GUIDE · SECURITY

VPN Fundamentals

A practical foundation for understanding VPN types, tunnelling, encryption, authentication, routing, split tunnelling and the operational evidence needed to design and troubleshoot them.

Engineering referenceVPN · Tunnelling

Related Ingenix tool

Build and validate a vendor-neutral VPN baseline in your browser.

VPN Configuration Designer →
The important bit: A VPN creates an authenticated protected path; it does not automatically make every endpoint, route or application inside that path trustworthy.

Key terminology

TermMeaning
VPNVirtual Private Network: a protected logical connection carried across another network, normally the Internet.
TunnelThe logical path through which selected traffic is carried.
GatewayThe firewall, router or VPN appliance that terminates the tunnel.
IKEInternet Key Exchange, used by IPsec peers to authenticate and negotiate security associations.
Child SAThe IPsec security association that protects actual traffic after IKE negotiation.
Traffic selectorThe source/destination traffic definition associated with an IPsec Child SA.
Full tunnelAll or nearly all client traffic is sent through the VPN gateway.
Split tunnelOnly selected destinations use the VPN; other traffic breaks out locally.

VPN types

Site-to-site VPNs connect networks, normally between security gateways. Remote-access VPNs connect individual users or devices to a gateway. Host-to-host VPNs can protect traffic directly between individual systems.

TypeTypical useMain design concern
Site-to-siteBranch, data-centre or partner connectivity.Routing, addressing, selectors and redundancy.
Remote accessUsers accessing internal services from untrusted networks.Identity, MFA, endpoint posture and least privilege.
Host-to-hostDirect protection between specific systems.Endpoint management and key lifecycle.

How tunnelling works

A VPN does not normally make the original packet magically private from end to end. Instead, the VPN endpoint receives selected traffic, encapsulates and protects it, sends the protected traffic across the transport network, then decapsulates it at the remote endpoint.

With IPsec, IKE negotiates the security relationship and ESP commonly carries the protected user traffic. The Internet or WAN between gateways only needs to provide IP reachability between the VPN peers.

Encapsulation matters

Adding VPN headers increases packet size. This can affect MTU, fragmentation and TCP performance. A tunnel can therefore establish successfully while applications still fail because larger packets cannot traverse the complete path.

Encryption and authentication

VPN security has several separate jobs: authenticate the peers, establish shared keying material, provide confidentiality where required, and provide integrity/authentication for protected packets.

  • Authentication: proves the peer or user is authorised.
  • Encryption: prevents unauthorised parties reading protected traffic.
  • Integrity: detects modification of protected traffic.
  • Key exchange: establishes cryptographic material without sending the resulting session key directly.

For IPsec, prefer IKEv2 and modern authenticated encryption such as AES-GCM where both peers support it. See the IPsec VPN Engineering Guide and VPN Encryption & Cryptography Guide for deeper treatment.

Routing and selectors

A VPN can be up while traffic is still unable to cross it. The route table must send the traffic toward the VPN, security policy must permit it, and the VPN must consider the traffic part of an appropriate Child SA.

Route-based designs commonly use a tunnel interface and routing table. Policy-based designs commonly use explicit local and remote traffic selectors. Overlapping address space makes both approaches harder to operate and can prevent the intended route or selector from being unique.

Full vs split tunnel

DesignBehaviourTrade-off
FullClient traffic uses the VPN gateway.Centralises inspection but consumes gateway/WAN capacity and may add latency.
SplitOnly selected destinations use VPN.Efficient, but local breakout needs its own security controls.

Split tunnelling is a routing decision as much as a VPN decision. Document which prefixes use the tunnel and what happens to DNS, Internet traffic and private SaaS services.

Design principles

  1. Define exactly which networks, users and applications need connectivity.
  2. Avoid overlapping address ranges between connected networks.
  3. Prefer IKEv2 and modern cryptography.
  4. Use MFA and device controls for remote access.
  5. Make routing, firewall policy and NAT behaviour explicit.
  6. Account for DNS, MTU, MSS and asymmetric routing.
  7. Design redundancy and define how failure is detected.
  8. Document peers, subnets, proposals, selectors and failover behaviour.

What to capture when troubleshooting

Start with a precise test: source, destination, protocol, port and timestamp. Capture the VPN status, IKE and Child SA state, route table, security-policy decision and NAT/session information. If the result is still unclear, take a short packet capture at the appropriate points and compare what the client, gateway and remote side actually see.

Useful evidence includes firewall/VPN logs, authentication logs, routing information, tunnel counters and packet captures. Preserve the evidence before changing configuration so you can compare before and after. Do not collect private keys or credentials.

For a deeper troubleshooting workflow, see the VPN Troubleshooting Guide.