Related Ingenix tool
Build and validate a vendor-neutral VPN baseline in your browser.
In this guide
Key terminology
| Term | Meaning |
|---|---|
| VPN | Virtual Private Network: a protected logical connection carried across another network, normally the Internet. |
| Tunnel | The logical path through which selected traffic is carried. |
| Gateway | The firewall, router or VPN appliance that terminates the tunnel. |
| IKE | Internet Key Exchange, used by IPsec peers to authenticate and negotiate security associations. |
| Child SA | The IPsec security association that protects actual traffic after IKE negotiation. |
| Traffic selector | The source/destination traffic definition associated with an IPsec Child SA. |
| Full tunnel | All or nearly all client traffic is sent through the VPN gateway. |
| Split tunnel | Only selected destinations use the VPN; other traffic breaks out locally. |
VPN types
Site-to-site VPNs connect networks, normally between security gateways. Remote-access VPNs connect individual users or devices to a gateway. Host-to-host VPNs can protect traffic directly between individual systems.
| Type | Typical use | Main design concern |
|---|---|---|
| Site-to-site | Branch, data-centre or partner connectivity. | Routing, addressing, selectors and redundancy. |
| Remote access | Users accessing internal services from untrusted networks. | Identity, MFA, endpoint posture and least privilege. |
| Host-to-host | Direct protection between specific systems. | Endpoint management and key lifecycle. |
How tunnelling works
A VPN does not normally make the original packet magically private from end to end. Instead, the VPN endpoint receives selected traffic, encapsulates and protects it, sends the protected traffic across the transport network, then decapsulates it at the remote endpoint.
With IPsec, IKE negotiates the security relationship and ESP commonly carries the protected user traffic. The Internet or WAN between gateways only needs to provide IP reachability between the VPN peers.
Encapsulation matters
Adding VPN headers increases packet size. This can affect MTU, fragmentation and TCP performance. A tunnel can therefore establish successfully while applications still fail because larger packets cannot traverse the complete path.
Encryption and authentication
VPN security has several separate jobs: authenticate the peers, establish shared keying material, provide confidentiality where required, and provide integrity/authentication for protected packets.
- Authentication: proves the peer or user is authorised.
- Encryption: prevents unauthorised parties reading protected traffic.
- Integrity: detects modification of protected traffic.
- Key exchange: establishes cryptographic material without sending the resulting session key directly.
For IPsec, prefer IKEv2 and modern authenticated encryption such as AES-GCM where both peers support it. See the IPsec VPN Engineering Guide and VPN Encryption & Cryptography Guide for deeper treatment.
Routing and selectors
A VPN can be up while traffic is still unable to cross it. The route table must send the traffic toward the VPN, security policy must permit it, and the VPN must consider the traffic part of an appropriate Child SA.
Route-based designs commonly use a tunnel interface and routing table. Policy-based designs commonly use explicit local and remote traffic selectors. Overlapping address space makes both approaches harder to operate and can prevent the intended route or selector from being unique.
Full vs split tunnel
| Design | Behaviour | Trade-off |
|---|---|---|
| Full | Client traffic uses the VPN gateway. | Centralises inspection but consumes gateway/WAN capacity and may add latency. |
| Split | Only selected destinations use VPN. | Efficient, but local breakout needs its own security controls. |
Split tunnelling is a routing decision as much as a VPN decision. Document which prefixes use the tunnel and what happens to DNS, Internet traffic and private SaaS services.
Design principles
- Define exactly which networks, users and applications need connectivity.
- Avoid overlapping address ranges between connected networks.
- Prefer IKEv2 and modern cryptography.
- Use MFA and device controls for remote access.
- Make routing, firewall policy and NAT behaviour explicit.
- Account for DNS, MTU, MSS and asymmetric routing.
- Design redundancy and define how failure is detected.
- Document peers, subnets, proposals, selectors and failover behaviour.
What to capture when troubleshooting
Start with a precise test: source, destination, protocol, port and timestamp. Capture the VPN status, IKE and Child SA state, route table, security-policy decision and NAT/session information. If the result is still unclear, take a short packet capture at the appropriate points and compare what the client, gateway and remote side actually see.
Useful evidence includes firewall/VPN logs, authentication logs, routing information, tunnel counters and packet captures. Preserve the evidence before changing configuration so you can compare before and after. Do not collect private keys or credentials.
For a deeper troubleshooting workflow, see the VPN Troubleshooting Guide.