skip to content

VPN

Tunnels carry private traffic across a network you do not trust: plain GRE overlays, WireGuard's key-routed peers, TLS-keyed tunnels. Interviewers use it to test tunnelling, keys and routing at once.

on this pageshow

explore

questions

page 1 of 2

In a remote-access VPN, what is the difference between a full tunnel and a split tunnel, and what does each cost?

level: juniorimportance: must knowfreq 55%

answer

  1. where the default route points
  2. only corporate prefixes enter
  3. head-end capacity versus inspection
  4. resolver choice must follow the split

basics

~20 s

A full tunnel sends all the client's traffic through the VPN gateway; a split tunnel sends only corporate destinations there and lets the rest go direct. Split saves gateway capacity and latency; full keeps central visibility and control.

solid answer

~40 s

The difference is where the client's default route points. In a **full tunnel** every destination, internet included, goes into the tunnel, so SaaS, web and video traffic reach the internet through the corporate gateway: one egress, central inspection and logging, one DNS policy, but each internet-bound byte crosses the head-end's internet link twice and remote users pay the longer path. In a **split tunnel** only the corporate prefixes, usually RFC 1918 ranges, enter the tunnel and everything else leaves through the local network: far less head-end load and shorter paths to SaaS, but the organisation no longer sees or filters that direct traffic. The split also has to reach name resolution, or lookups for internal names go to the local resolver. It is a capacity-and-latency versus control trade-off, argued per traffic class.

go deeper

for a junior

Recall the one-line difference: full tunnel sends everything to the VPN gateway, split tunnel sends only corporate destinations there. Then name one gain and one loss of each.

for a middle

Explain it as a route-table decision: where the default route points, which prefixes go into the tunnel, and why internet traffic in a full tunnel crosses the head-end twice.

for a senior

Show that DNS has to follow the split, and that the local-subnet exemption leaks names even in a full tunnel. Argue which traffic classes deserve inspection and which can go direct.

for a principal

Frame it as a capacity and latency budget against central visibility, and say where control moves when traffic goes direct: to the endpoint, or nowhere.

## What the choice is about A **remote-access VPN** connects one device (a laptop or phone) to an organisation's network across networks nobody in the organisation controls: a home router, a hotel, a mobile carrier. Once the tunnel is up, the client has two ways out: the **tunnel interface**, which carries packets encrypted to the **VPN gateway** (the head-end), and the **local interface**, which reaches the internet directly. Every packet is sent one way or the other by the client's route table. Full and split tunnelling are the two answers to one question: *which destinations go into the tunnel?* ## Full tunnel In a **full tunnel** the default route points into the tunnel, so every destination, corporate or not, is sent to the gateway. Internet-bound traffic is decrypted there and leaves through the organisation's own internet edge. - **What it buys:** one egress point, so the same web filtering, data-loss controls, logging and DNS policy apply to a remote user as to someone in the office; the visited network sees only encrypted packets to the gateway. - **What it costs:** every internet-bound byte crosses the head-end's internet link twice, once in through the tunnel and once out to the destination, and the replies do the same in reverse. Video calls and SaaS traffic take a detour via the gateway, adding latency, and gateway capacity has to be sized for all remote traffic, not just corporate traffic. ## Split tunnel In a **split tunnel** only the organisation's own prefixes go into the tunnel and the default route stays on the local interface. RFC 8598 describes it plainly: split-tunnel configurations "only send packets with a specific destination IP range, usually chosen from [RFC1918], via the VPN", which lets an enterprise offer remote access "without needing to accept and forward all the non-enterprise-related network traffic" of its users. - **What it buys:** the gateway carries only corporate traffic, and SaaS and internet traffic take the shortest path. - **What it costs:** traffic that goes direct is outside every central control. The organisation cannot inspect, filter or log it, and the visited network sees its destinations. ## Side by side | Aspect | Full tunnel | Split tunnel | |---|---|---| | Default route | Into the tunnel | Local interface | | Internet and SaaS traffic | Via the gateway | Direct | | Head-end load | All remote traffic, internet traffic twice over the internet link | Corporate traffic only | | Latency to SaaS | Extra path via the gateway | Shortest path | | Central inspection and logging | Everything | Tunnelled traffic only | | What the visited network sees | Encrypted packets to the gateway | Destinations of direct traffic, and names if DNS stays local | | DNS | Gateway-supplied resolvers for every name | Must be split per domain, or internal names leak | ## The split has to include name resolution A route table splits packets by **destination address**, but a DNS query's destination is the resolver, not the name inside it. A split-tunnel client that keeps the local network's resolver for everything will ask it for internal names too. **Split DNS** fixes this by sending queries for internal domains to internal resolvers through the tunnel and the rest to the local resolver; RFC 8598 standardises how an IKEv2 gateway tells the client which domains are internal. The full tunnel is not automatically clean either: RFC 8598 notes that the local network "is often explicitly exempted from IPsec encryption", so a full-tunnel client that keeps using a resolver on that local subnet still sends every name in clear. ## How the decision is usually argued The choice is rarely all-or-nothing. Common positions are: 1. **Full tunnel with a local-subnet exception**, so the client can still reach devices on its own link while everything else is controlled centrally. 2. **Split tunnel with corporate prefixes in**, internet out, and split DNS, when inspection happens on the endpoint instead of the network. 3. **Full tunnel with a few heavy, trusted destinations sent direct**, when head-end capacity is the constraint. What an interviewer wants is the trade-off argued for a traffic class: what the organisation loses sight of, what it saves, and whether name resolution follows the same split.

  • Who sees a split-tunnel user's direct internet traffic, and who no longer does?
    The visited network and its ISP see the destinations of direct traffic, and the names too if lookups go to their resolver. The organisation sees none of it, since it never reaches the gateway. With a full tunnel the visited network sees only encrypted packets to the gateway and the organisation sees the browsing. RFC 8598 counts this as a privacy gain of split DNS: the enterprise "remains unaware of all non-enterprise (DNS) activity of the user".
  • Does a full tunnel mean no packet ever uses the local network?
    No. The tunnel's own encrypted packets travel to the gateway over the local network, address assignment and link-layer resolution stay local, and many deployments exempt the local subnet so the user can reach local devices. That exemption is why RFC 8598 tells full-tunnel deployments to use the gateway-supplied DNS servers for all queries, so lookups do not leak onto the exempted local network.

saying these in an interview costs you the question

  • Split tunnelling means the tunnel encrypts only part of each packet.
  • A split tunnel sends internet traffic into the tunnel and corporate traffic direct.
  • A full tunnel is always faster because the corporate internet link is bigger.
  • Splitting the routes is enough; DNS follows the split automatically.
  • A full tunnel guarantees that nothing ever touches the local network.
open as a page

What is the difference between a site-to-site VPN and a remote-access VPN, and who terminates each tunnel?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A site-to-site VPN joins two networks through gateways, so hosts need no VPN software; a remote-access VPN joins one device, running a client, to a gateway that authenticates the user and assigns an inner address.

open as a page

In WireGuard, what identifies a peer, and why do two WireGuard peers never negotiate a cipher suite?

level: juniorimportance: must knowfreq 42%

basics

~20 s

A WireGuard peer is identified only by its static Curve25519 public key, exchanged out of band. The cryptography is fixed by the protocol (Curve25519, ChaCha20-Poly1305, BLAKE2s), so there is nothing to negotiate and nothing to downgrade.

open as a page

Why do two branch routers pair GRE with IPsec to run OSPF over the internet, instead of using a policy-based IPsec tunnel alone?

level: middleimportance: must knowfreq 35%

basics

~20 s

GRE gives the routers a point-to-point link that carries OSPF's multicast hellos and any routed subnet; IPsec encrypts and authenticates that single GRE flow. Policy-based IPsec alone matches unicast subnet pairs and gives OSPF no interface to run on.

open as a page

How do IPsec, WireGuard and TLS-based VPNs each get through a NAT, and which of them still connects when a hotel network blocks UDP?

level: middleimportance: must knowfreq 35%

basics

~20 s

Tunnels answer a NAT three ways: ride UDP (IPsec wraps ESP in UDP 4500; WireGuard is UDP already), send keepalives so the mapping stays, or hide inside TCP or TLS on 443. Only the TCP rung survives dropped UDP.

open as a page

In a TLS-based VPN, what does the TLS control channel produce, and why does user traffic travel on a separate data channel?

level: middleimportance: must knowfreq 30%

basics

~20 s

The TLS control channel authenticates the peers and produces key material; user packets ride a separate datagram channel keyed from it, so each one is protected and replay-checked on its own, with no in-order stream to stall behind a loss.

open as a page

In a site-to-site VPN, how does store-to-store traffic flow in a hub-and-spoke topology versus a full mesh, and what does each cost?

level: middleimportance: must knowfreq 40%

basics

~20 s

In hub-and-spoke, store-to-store traffic detours through a hub, crossing two tunnels and being decrypted and re-encrypted there, but each store keeps only its hub tunnels; a full mesh sends it directly but needs n(n-1)/2 tunnels, 45,451 for 302 sites.

open as a page

In WireGuard, what is cryptokey routing, and how does one peer's allowed-IPs list govern both outgoing and incoming packets?

level: middleimportance: must knowfreq 36%

basics

~20 s

Cryptokey routing binds each peer's public key to its allowed IPs. Outbound, a packet's destination picks the peer whose session encrypts it. Inbound, the decrypted packet's source must map back to the peer that sent it, or the packet is dropped.

open as a page

A TLS-based VPN forced onto TCP 443 crawls over a lossy hotel link, while the same tunnel over UDP is fine — why, and what do you change?

level: seniorimportance: must knowfreq 35%

basics

~20 s

Over TCP the tunnel retransmits every loss itself, so inner TCP connections see long, bursty delays, fire their own retransmission timeouts and cut their rates: TCP-in-TCP meltdown. Carry the tunnel on UDP and keep TCP 443 only as a fallback.

open as a page

On a split-tunnel VPN, why do lookups for internal names leak to the hotel's DNS resolver, and what stops it?

level: seniorimportance: must knowfreq 30%

basics

~20 s

Routes split packets by destination address, but the client still sends every query to the resolver the hotel's DHCP gave it, so internal names leave in clear. Split DNS sends internal domains to internal resolvers through the tunnel.

open as a page

What does GRE, IP protocol 47, do to a packet, and why is a plain GRE tunnel across the internet not private?

level: juniorimportance: should knowfreq 30%

basics

~20 s

GRE wraps any packet, multicast and non-IP included, in a 4-byte GRE header and a new IPv4 header marked protocol 47. It adds no encryption or authentication, so anyone on the path can read or forge what it carries.

open as a page

A GRE tunnel over IPv4 carries the RFC 2890 Key field across 1,500-byte links; what tunnel MTU and TCP MSS follow, and why?

level: middleimportance: should knowfreq 25%

basics

~20 s

The tunnel adds 28 bytes: a 20-byte outer IPv4 header, the 4-byte GRE base header and the 4-byte Key. The inner IP MTU is 1,500 - 28 = 1,472 bytes, so the TCP MSS is 1,472 - 40 = 1,432.

open as a page

In a VPN tunnel behind a NAT, which peer must send the keepalives, and how should their interval relate to the translator's UDP mapping timer?

level: middleimportance: should knowfreq 25%

basics

~20 s

The peer behind the NAT must send them, because RFC 4787 only requires outbound packets to refresh a mapping. The interval must undercut the shortest UDP mapping timer on the path; RFC 3948 defaults to 20 seconds of idleness.

open as a page

In a TLS-based VPN, what changes between a routed (layer 3) tunnel interface and a bridged (layer 2) one, and when is bridging worth it?

level: middleimportance: should knowfreq 25%

basics

~20 s

A routed tunnel carries IP packets into its own subnet; a bridged tunnel carries Ethernet frames and drops the client into the LAN's broadcast domain, so ARP, DHCP and non-IP traffic cross too. Bridge only when something truly needs layer 2.

open as a page

In a split-tunnel VPN, how does an include-only route list differ from an exclude list, and where does an unlisted destination go?

level: middleimportance: should knowfreq 35%

basics

~20 s

An include list sends only the named prefixes through the tunnel and everything else direct; an exclude list sends everything through the tunnel except the named prefixes. So an unlisted destination goes direct under include and into the tunnel under exclude.

open as a page

In a remote-access VPN, why does the gateway give each client an inner address, and what must the internal network route back to it?

level: middleimportance: should knowfreq 24%

basics

~20 s

The inner address belongs to the corporate side, so servers' replies route to the VPN gateway and are tunnelled back; the client's own address belongs to someone else's network. Internal routing must carry each pool prefix to the gateway that owns it.

open as a page

Why is an idle WireGuard tunnel completely silent, and what do its passive keepalive and optional persistent keepalive each do?

level: middleimportance: should knowfreq 24%

basics

~20 s

WireGuard sends nothing without data to carry. The passive keepalive answers received data with an empty authenticated packet after 10 idle seconds; the optional persistent keepalive sends one periodically to hold NAT or firewall state open.

open as a page

In multipoint GRE with NHRP, how does one spoke learn another spoke's public address to build a direct tunnel, and what part does the hub play?

level: seniorimportance: should knowfreq 15%

basics

~20 s

Each spoke registers its tunnel and public addresses with the hub, an NHRP Next Hop Server. To reach another spoke it sends an NHRP Resolution Request; the Resolution Reply carries that spoke's public address, and a direct GRE tunnel follows.

open as a page

A GRE tunnel between two branches flaps every minute or so once OSPF over it starts advertising the WAN subnets; what is happening, and how do you stop it?

level: seniorimportance: should knowfreq 18%

basics

~20 s

This is recursive routing: OSPF over the tunnel advertises a route to the tunnel's own destination, so reaching the endpoint requires the tunnel. It drops, the route is withdrawn, it recovers, and repeats. Keep underlay addresses out of the overlay IGP.

open as a page

After a laptop's VPN tunnel through carrier-grade NAT sits idle, the gateway cannot reach the laptop until it sends traffic; why, and how do UDP and TCP tunnels recover?

level: seniorimportance: should knowfreq 18%

basics

~20 s

The translator's idle mapping expired, so the gateway's packets have nowhere to go until the laptop creates a new one. UDP tunnels recover on the laptop's next authenticated packet; TCP tunnels need the laptop to open a new connection.

open as a page

When an IPsec VPN client falls back to carrying IKE and ESP over TCP on a UDP-blocking network, what does the tunnel lose, and why does RFC 9329 make it a last resort?

level: seniorimportance: should knowfreq 20%

basics

~20 s

Over TCP, every Child SA shares one reliable connection: loss turns into delay for all flows, real-time traffic is retransmitted, and per-SA QoS and DF copying are lost. RFC 9329 therefore says to prefer direct or UDP-encapsulated ESP.

open as a page

Why does a TLS-based VPN put a pre-shared HMAC on every control-channel packet when the TLS handshake already authenticates both peers?

level: seniorimportance: should knowfreq 15%

basics

~20 s

The HMAC lets the server drop any control packet lacking a valid tag before it allocates TLS state or parses a certificate, so scans, floods and exploits aimed at the TLS stack never reach it. It is a filter, not an identity.

open as a page

On a remote-access VPN client, why can classless static routes from the local DHCPv4 server pull traffic out of the tunnel, and what prevents it?

level: seniorimportance: should knowfreq 15%

basics

~20 s

The split lives in the client's own route table, where the most specific route wins. Option 121 routes from the local DHCPv4 server, or a local administrator, can outrank the tunnel's routes; egress rules tied to the tunnel interface stop that.

open as a page

A site-to-site VPN joins an acquired warehouse whose LAN reuses the data centre's 10.1.0.0/16; why does the tunnel come up while traffic fails, and what fixes it?

level: seniorimportance: should knowfreq 18%

basics

~20 s

The tunnel forms between the gateways' public addresses, but the inner addresses collide: hosts treat 10.1.0.0/16 as local and never send to the gateway. Renumber one site, or translate so each side sees the other under an unused alias prefix.

open as a page

After moving 50 engineers onto a WireGuard gateway, two laptops both complete handshakes but only one passes traffic; what in cryptokey routing explains it?

level: seniorimportance: should knowfreq 22%

basics

~20 s

The two laptops' gateway entries share one tunnel address. Handshakes check only keys, so both succeed, but each address maps to one peer. Replies go to that owner, and the other laptop's packets fail the inbound source check.

open as a page

For a remote-access estate, how do you choose between a TLS-based VPN and IPsec, weighing user-space processing, firewall traversal and interoperability?

level: principalimportance: should knowfreq 18%

basics

~20 s

IPsec runs in the kernel and any standard gateway speaks it, but needs IKE's UDP ports and ESP to pass; a TLS-based VPN needs one UDP or TCP port, at the cost of user-space copies and one implementation at both ends.

open as a page

A retailer's dual-hub site-to-site VPN now carries heavy store-to-store video traffic; how do you choose between bigger hubs, regional hubs, a partial mesh and on-demand spoke-to-spoke tunnels?

level: principalimportance: should knowfreq 10%

basics

~20 s

Start from the traffic matrix: modest store-to-store volume means bigger hubs; regional clusters mean regional hubs or a partial mesh; unpredictable pairs mean on-demand spoke-to-spoke tunnels, and any flow that skips a hub needs its inspection moved to the stores.

open as a page

When a WireGuard gateway replaces IPsec remote access for 50 engineers, what does the protocol leave you to build, and when would you decline?

level: principalimportance: should knowfreq 18%

basics

~20 s

WireGuard authenticates device keys, not users, and pushes no configuration, so enrolment, key-to-person mapping, revocation, addressing and client settings are yours. Decline, or keep IPsec beside it, where policy demands certificate or EAP login or mandated algorithms.

open as a page

In WireGuard's Noise IKpsk2 handshake, what does each of the two messages carry, and how does one round trip authenticate both peers?

level: middleimportance: nice to knowfreq 15%

basics

~20 s

The initiator, already holding the responder's static key, sends an ephemeral key, its encrypted static key and an encrypted timestamp. The responder answers with its own ephemeral key. Chaining four Diffie-Hellman results proves both static keys in one round trip.

open as a page

Why does RFC 8598 make an IKEv2 client ignore split-DNS attributes on a full tunnel and accept DNSSEC trust anchors only for whitelisted domains?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

Split-DNS attributes let the VPN gateway choose who answers for a domain, and a trust anchor lets it vouch for signatures. RFC 8598 confines both to enterprise split tunnels and whitelisted domains so a VPN provider cannot override public DNS or DNSSEC.

open as a page

showing 1–30 of 31