skip to content

Tunneling Models

Site-to-site joins two networks through gateways; remote access connects a single client into one. Interviewers push on hub-and-spoke versus mesh, because that decides how branch traffic flows.

on this pageshow

questions

5

What is the difference between a site-to-site VPN and a remote-access VPN, and who terminates each tunnel?

level: juniorimportance: must knowfreq 58%

answer

  1. who sits at each end
  2. whole networks versus one device
  3. gateway to gateway
  4. client, user, assigned inner address

basics

~20 s

A site-to-site VPN joins two networks through gateways, so hosts need no VPN software; a remote-access VPN joins one device, running a client, to a gateway that authenticates the user and assigns an inner address.

solid answer

~40 s

A **site-to-site** VPN runs between two gateways, routers or firewalls at each site, and joins whole networks: each gateway announces the prefixes behind it, and hosts send ordinary traffic that routing steers into the tunnel, with no VPN software of their own. A **remote-access** VPN runs between a client on one device and a gateway: the gateway authenticates the user, assigns an inner address so replies route back to it, and the tunnel lives only as long as the session. RFC 7296 describes both, as its gateway-to-gateway and endpoint-to-gateway scenarios. In both, protection ends at the gateway, not at the server. A retailer typically runs both: stores and data centres site-to-site, home and travelling staff remote access.

go deeper

for a junior

Recall the two shapes: gateway to gateway joins networks, client to gateway joins one device. Say who runs VPN software in each, and that protection stops at the gateway.

for a middle

Explain the mechanics: site-to-site gateways announce the prefixes behind them and routing steers traffic in; a remote-access gateway authenticates a user and assigns an inner address so replies come back to it.

for a senior

Show operating judgment: which population gets which model, why joined sites must not overlap, and how a gateway serving thousands of short sessions is sized differently from one holding a few permanent tunnels.

for a principal

Frame the trade-off between company-built tunnels over the internet and a provider's layer 2 or layer 3 VPN service, and which parts of the estate each leaves the company to run and secure.

## Two shapes of tunnel A **virtual private network** carries private traffic across a network it shares with others, usually the public internet, inside a tunnel whose ends are authenticated and whose contents are usually encrypted. RFC 4110 defines a VPN as a set of sites whose communication with outsiders is restricted while their own traffic crosses infrastructure that others also use. Two architectures cover most deployments, and they differ in **who terminates the tunnel** and **what sits behind each end**. | | Site-to-site | Remote access | |---|---|---| | Ends of the tunnel | gateway to gateway | client device to gateway | | What each end stands for | a whole network, a set of prefixes | one device and the person using it | | Who runs VPN software | only the two gateways | every laptop or phone, plus the gateway | | What is authenticated | the two gateways | the gateway, and the user or device | | Inner addresses | the sites' own subnets, routed | one address the gateway assigns for the session | | Lifetime | usually up continuously | comes and goes with the user's session | ## Site-to-site: two networks joined by gateways RFC 7296, the IKEv2 specification, draws this as its first usage scenario, a **security gateway to security gateway** tunnel: - **Neither host implements the VPN.** A point-of-sale terminal sends to its ordinary default router; routing at the store's gateway steers packets for the data-centre prefixes into the tunnel. - **Each gateway announces the addresses behind it**, so one tunnel carries traffic for many hosts at once. - **Protection covers part of the way**, between the gateways. On each site's LAN the traffic is ordinary, unencrypted traffic. - **The sites route to each other**, so their address ranges must not collide; two sites that both use the same private range cannot simply be joined. ## Remote access: one device joined to a network The same RFC's third scenario is an **endpoint to security gateway** tunnel, typically a roaming laptop connecting back to its corporate network: - The device runs **VPN client software**, and the gateway authenticates a user or device rather than a site. - The client needs an address that belongs to the corporate side, so that replies come back to the gateway and are tunnelled to it. The gateway hands one out for the session, from its own pool or from a DHCP server; in IKEv2 this is done with the **configuration payload**. - Each packet therefore carries two source addresses: the **outer** header holds the address of wherever the laptop is right now, the **inner** header the address the gateway assigned. - The tunnel exists only while the user is connected, so the gateway serves many short-lived sessions rather than a few permanent tunnels. ## One retailer, both models A retailer with 300 stores, two data centres and 2,000 remote staff uses both architectures side by side: 1. Each store's gateway builds site-to-site tunnels to the data centres; every till, scanner and camera reaches the data centres without any VPN setting of its own. 2. The two data centres join each other with a site-to-site tunnel of their own, or a private circuit. 3. The 2,000 staff run a remote-access client that lands on a gateway in either data centre and receives an inner address from that gateway's pool. 4. One gateway platform can serve both roles. What differs is the peer at the far end and whether the tunnel stands for a network or for a person. ## Not the same thing as a provider's VPN service Both models above are tunnels the company builds itself across the internet. RFC 4026, an Informational terminology document, names the other family, **provider-provisioned VPNs**. In a **CE-based** VPN the customer's edge devices do all the VPN work and the provider does not know the traffic is VPN traffic; in a **PE-based** VPN the provider's edge devices keep per-VPN state. A provider service is either a **layer 3 VPN**, which forwards on the customer's IP addresses, or a **layer 2 VPN**, such as a point-to-point virtual wire (VPWS) or an emulated LAN (VPLS). In that vocabulary a company-built site-to-site tunnel is a CE-based layer 3 design in which the company acts as its own provider. ## Common confusions - **A VPN is not end-to-end encryption.** In both models protection ends at the gateway; the hop from the gateway to the server is protected only if something else protects it. - **A remote-access client is not just a site with one host.** The gateway assigns its inner address and authenticates a person, which changes how addresses are planned and how sessions are logged. - **Site-to-site does not need matching subnets.** It needs non-overlapping ones, because the two sides route to each other. - **The two models are not tied to one protocol.** IPsec, TLS-based designs and others can build either; the architecture is a choice about the ends of the tunnel, not about the cipher.

  • Does a host behind a site-to-site VPN gateway need any VPN configuration?
    No. The host sends to its usual default router, and the gateway's routing decides which destinations go into the tunnel and protects them on the way. That transparency is why the model suits tills, printers and cameras that could never run a client. The cost is that the host cannot tell whether its traffic was protected, and nothing protects it on the local LAN.
  • How does a provider-provisioned VPN differ from a site-to-site VPN a company builds itself?
    RFC 4026 separates CE-based designs, where only customer equipment knows about the VPN, from PE-based ones, where the provider's edge keeps per-VPN state, and splits provider services into layer 3 VPNs that forward on customer IP addresses and layer 2 VPNs such as a virtual wire or an emulated LAN. A company-built site-to-site tunnel is CE-based, with the company as its own provider.
  • Can one gateway terminate site-to-site and remote-access tunnels at the same time?
    Yes, and it is common. What changes is the peer: a site-to-site peer is another gateway announcing a set of prefixes and staying up continuously, while a remote-access peer is a client that authenticates a user and receives one assigned address for a session. Capacity planning differs too, a few permanent tunnels against thousands of short-lived sessions.

saying these in an interview costs you the question

  • Every host behind a site-to-site VPN gateway needs a VPN client installed
  • A VPN protects traffic all the way to the destination server
  • A remote-access client keeps its home or hotel address inside the tunnel
  • A site-to-site VPN needs both sites to use the same subnet
  • Site-to-site and remote-access VPNs need different gateway hardware
open as a page

In a site-to-site VPN, how does store-to-store traffic flow in a hub-and-spoke topology versus a full mesh, and what does each cost?

level: middleimportance: must knowfreq 40%

basics

~20 s

In hub-and-spoke, store-to-store traffic detours through a hub, crossing two tunnels and being decrypted and re-encrypted there, but each store keeps only its hub tunnels; a full mesh sends it directly but needs n(n-1)/2 tunnels, 45,451 for 302 sites.

open as a page

In a remote-access VPN, why does the gateway give each client an inner address, and what must the internal network route back to it?

level: middleimportance: should knowfreq 24%

basics

~20 s

The inner address belongs to the corporate side, so servers' replies route to the VPN gateway and are tunnelled back; the client's own address belongs to someone else's network. Internal routing must carry each pool prefix to the gateway that owns it.

open as a page

A site-to-site VPN joins an acquired warehouse whose LAN reuses the data centre's 10.1.0.0/16; why does the tunnel come up while traffic fails, and what fixes it?

level: seniorimportance: should knowfreq 18%

basics

~20 s

The tunnel forms between the gateways' public addresses, but the inner addresses collide: hosts treat 10.1.0.0/16 as local and never send to the gateway. Renumber one site, or translate so each side sees the other under an unused alias prefix.

open as a page

A retailer's dual-hub site-to-site VPN now carries heavy store-to-store video traffic; how do you choose between bigger hubs, regional hubs, a partial mesh and on-demand spoke-to-spoke tunnels?

level: principalimportance: should knowfreq 10%

basics

~20 s

Start from the traffic matrix: modest store-to-store volume means bigger hubs; regional clusters mean regional hubs or a partial mesh; unpredictable pairs mean on-demand spoke-to-spoke tunnels, and any flow that skips a hub needs its inspection moved to the stores.

open as a page