skip to content

A remote-access concentrator lands its inside leg on the core VLAN — what filters the decrypted traffic?

level: juniorimportance: must knowfreq 68%

answer

  1. the tunnel is not the control
  2. where plaintext first exists
  3. the box you would have to own
  4. one policy, or two separately owned
  5. an extra hop has a licence

basics

~20 s

Nothing except the concentrator itself. ESP is decapsulated at its inside leg, so plaintext appears already on the core and no independent device sees it. Enforcement there means paying for a second filter and a second hop.

solid answer

~50 s

The decapsulation point is the enforcement point. When the head-end's inside leg sits on the core VLAN, the first place remote traffic exists as plaintext is already inside the estate, so the only policy applied to it is the head-end's own — the same box an adversary would have to own for any of this to matter. Land that leg in a screened tier instead and a separate device, ideally administered by a different team, stands between the tunnel's exit and everything else; that device is what still constrains an attacker who owns the head-end outright. The price is real and you should say it out loud at the design review: another throughput licence, a second rule base to keep in step with the first, an extra hop on both directions of every remote flow, and a change window that now touches two teams.

go deeper

for a junior

Be ready to say where a tunnel's traffic first becomes plaintext and that this is the first place any device can filter it. Knowing the inside leg's landing zone decides that is the whole point.

for a middle

Explain why the head-end's own policy is not a second layer — it shares the appliance's failure domain — and name what the second device costs in licence, configuration and hops.

for a senior

Demonstrate the judgment: which landing zone you would choose for a given estate, what an owned head-end reaches from each, and what evidence you would produce to prove the claim rather than assert it.

for a principal

Own the tradeoff between a purchase and a routing change, the failure posture of the extra hop, and the exception-review cadence that stops the second layer from being written away in a migration.

## What "terminating inside the boundary" actually means A remote-access tunnel carries encrypted payload — with IPsec, an ESP-encapsulated packet — from a client to a head-end appliance. The head-end decapsulates it. **The point of decapsulation is the first place in your estate where that traffic exists as plaintext, and therefore the first place any policy can be written about it.** Everything upstream of that point sees an opaque blob addressed to the head-end; everything downstream sees ordinary routed packets. So the physical question "which VLAN does the inside leg plug into?" is really the policy question "what is the first device other than the head-end that gets a vote on this traffic?" If the inside leg lands on the core VLAN, the answer is: **none**. Remote traffic is born inside, adjacent to whatever the core routes. ## "But the concentrator has a policy" It does, and it is a real control — per-user or per-group rules deciding which internal destinations a tunnel session may address. What it is not is a *second* layer, because it shares a failure domain with the tunnel termination itself. One box holds the outside leg exposed to the internet, the credential check, the policy, and the inside leg. An adversary who owns that box owns the policy that was supposed to bound them. A control cannot constrain the thing that can rewrite it. That is the whole argument for landing outside the estate: not that the appliance is bad, but that the blast radius of owning it should be decided by something the appliance's own compromise cannot reach. ## The two positions, side by side | Inside leg lands on | First device other than the head-end that sees plaintext | What a fully-owned head-end can originate unaided | | --- | --- | --- | | The core VLAN | none | anything the core will route for it | | A screened tier behind a second enforcement device | that device | only what its rule base permits from the head-end's own address | The second row is only true while the second device's rule base does not contain a broad allow for the head-end. The usual way this boundary is quietly voided is a management, backup or high-availability exception written as "any from the head-end" — after which the two rows are the same picture with an extra hop. ## What the outside position costs This is the half candidates skip, and interviewers are listening for it: - **Money.** A second enforcement device sized for peak remote-access load, not average — and licences are usually sold by throughput, so the peak is what you buy. - **A second configuration.** Two rule bases now describe the same intent, and they drift. Every new internal service a remote user needs is two changes in two systems, often owned by two teams. - **Latency and MTU.** An extra hop on both directions of every remote flow, on top of the tunnel's own encapsulation overhead. - **A new failure domain.** That device can take remote access down on its own. Somebody has to decide and sign the failure posture — for remote access, failing closed is usually the defensible answer, but it is a decision, not a default. - **Exception pressure.** The first "temporary any/any while we migrate" is the moment the second hop stops meaning anything, so it needs a review cadence with an owner. ## The cheap version of the right answer The outside position does not always mean buying a box. If the estate already has a screened tier with an enforcement point in front of it, moving the inside leg into that tier costs a routing change and an outage window rather than a purchase. That is frequently the design that actually gets built, and proposing it is a stronger answer than demanding new hardware. ## Proving it, rather than asserting it A diagram is not evidence. What demonstrates the position is traffic sourced from the head-end's inside address toward a destination the policy denies, and the corresponding deny record from the second device — repeated after each change window, because the claim decays every time either rule base is edited. ## What to say in an interview Name the decapsulation point as the enforcement point; say that the head-end's own policy shares a failure domain with the head-end; describe the two candidate landing zones and what an owned appliance reaches from each; and state the price of the outside position without being asked. Candidates who stop at "we terminate in the DMZ, it's best practice" have given a slogan; candidates who can say what the second hop costs and who signs for it have given an architecture.

  • Is the head-end's own per-user policy a second layer of enforcement?
    No. It is a real control, but it lives on the same box as the tunnel termination and the credential check, so it shares that box's failure domain. An adversary who owns the head-end can rewrite or ignore it. A second layer only counts if compromising the first does not deliver it — which in practice means a separate device with a separate administrative path.
  • What evidence would you produce to show the outside position actually constrains the head-end?
    Traffic sourced from the head-end's inside-leg address to a destination the second device's policy denies, plus that device's deny record for it — in both directions, since a filter that only sees one direction proves less than it looks. Re-run it after every change window on either rule base, because the claim expires whenever either is edited.
  • Does moving the inside leg outward always mean buying another appliance?
    No, and saying so is usually the winning answer. If a screened tier with an existing enforcement point already exists, relocating the inside leg into it costs a routing change and an outage window instead of a purchase. You still inherit the second rule base and the drift between them, but not the licence.

A tunnel under a city wall does not end at the wall — it ends wherever you dig the exit. Dig it in the town square and the gate guard never sees who came through.

saying these in an interview costs you the question

  • The tunnel is encrypted, so the traffic is already trusted
  • The concentrator's own rules count as a second enforcement layer
  • Putting the inside leg on its own VLAN is segmentation
  • Endpoint agents will catch anything the network misses
  • A second hop is free because we already own a firewall
  • Terminating in the DMZ is best practice, no further reasoning offered

context