skip to content

The Tunnel's End

Where a tunnel lands, and what it lets past unexamined, decides what one credential or one compromised appliance reaches. Interviewers probe it because placement outlives every appliance you buy.

on this pageshow

explore

questions

16

Malware runs on a laptop whose VPN exempts one SaaS range to save head-end capacity - what does network inspection see?

level: juniorimportance: must knowfreq 62%

answer

  1. ask where the sensor physically sits
  2. packets never cross the head-end
  3. not thinner visibility - absent visibility
  4. only the endpoint and the destination still record
  5. capacity was bought with visibility

basics

~10 s

Nothing. Exempted traffic never enters the tunnel, so it never reaches the head-end or anything behind it. An exemption removes the vantage point entirely rather than reducing what gets logged.

solid answer

~40 s

Under full tunnelling every packet goes up the tunnel and out through the corporate stack, so the firewall, proxy and sensors sit behind the concentrator. An exemption is a routing decision made on the client: those destinations leave the laptop's local interface directly. A device only records traffic it carries, so for exempt destinations there is no flow record, no TLS metadata, no proxy entry - not a thinner view, no view. The only records left are on the endpoint itself and at the destination, and the endpoint is exactly the asset you are assuming is compromised. That gap was bought deliberately: the exemption exists because concentrator sessions, egress bandwidth and inspection licensing cost money. Malware on that laptop inherits a lane the policy already permits and nothing on the network watches.

go deeper

for a junior

Be ready to say where each control physically sits and to follow one packet. If it never crosses the head-end, no device behind the head-end can log it.

for a middle

Explain the client route set that produces the split, and be precise that a flow record is written by the forwarding device - so exemption means no record at all, not a coarser one.

for a senior

Show that you can state the bounded claim out loud: this path is unobserved, so no assertion about activity on it is available. Then name what you would rebuild a vantage with and what it costs.

for a principal

Own the framing that visibility was traded for capacity without appearing on any budget line, and that an untracked exemption is a permanent liability created by a temporary shortfall.

## What an exemption actually is A remote-access client installs a route set when it connects. Under **full tunnelling** the client claims the default route, so every destination - corporate and public alike - is encapsulated and delivered to the concentrator, which forwards it out through whatever the organisation has built: a filtering firewall, a web proxy, a decryption tier, flow exporters, DNS controls. Under **selective tunnelling** the client keeps a list of destinations that are *not* claimed, and those packets go straight out of the laptop's own interface to the local network and its internet path. That is the whole mechanism, and everything else follows from it. ## The stack is behind the concentrator, so exempt traffic is not near it A network control can only see what physically traverses it. Every corporate control in this design sits at or behind the head-end. Traffic that never reaches the head-end is not partially inspected, sampled or logged at a lower fidelity - it is simply not present at any device you own. | Position | Sees tunnelled traffic | Sees exempt traffic | |---|---|---| | VPN concentrator | five-tuple, volume, session | nothing | | Egress firewall / proxy | destination, TLS metadata, policy verdict | nothing | | Flow exporter behind it | five-tuple, bytes, packets, timestamps | nothing | | Endpoint agent on the laptop | process and connection events | process and connection events | | Destination service's own trail | tenant activity | tenant activity, if you are the tenant | The common wrong answer is that flow data still shows *something*, because flow feels like a passive, always-on fact of the network. It is not: a flow record is written by the device forwarding the packets, and no device you administer forwards these. ## What the absence of a record means, and what it does not This is where the direction of the claim matters. The absence of a flow record on this path proves nothing about what moved. It does not mean the volume was small, the destination was benign, or that nothing happened. It only means the path is unobserved. The strongest honest sentence a defender can say about an exempt destination is *"we do not observe this path"* - never *"we saw no activity there"*. ## Why anyone agreed to it Exemptions are rarely made for elegance. In an estate where every employee's only route to work is the tunnel, the head-end pair carries the entire workforce's internet traffic. Session counts, egress bandwidth and per-seat inspection licensing all scale with headcount, and real-time media in particular is a large, continuous, latency-sensitive byte stream. When the capacity line is refused or arrives late, exempting a destination is the fix that costs nothing today. The bill is paid in visibility rather than in currency, which is precisely why it does not appear on any budget. ## The adversary's side of the same fact An implant on the laptop is a process on the same host, subject to the same route set. It does not need to defeat a control, tunnel inside another protocol, or find a misconfiguration; it addresses a destination the organisation has already decided to permit and to not watch. Two properties compound this: the exempt list lives on the device, readable by anything running there, so the uninspected path is discoverable rather than guessed at; and modern exemptions are keyed to large cloud or CDN address blocks that host far more than the one vendor you intended. ## What is left to work with Endpoint telemetry still records process and connection activity, but it lives on the machine you are assuming is compromised, and its coverage is a licensing and rollout question rather than a given. The destination's own audit trail records what happened inside *your* tenant - useful, and blind to anything that used your uninspected lane to reach somebody else's account at the same address range. Neither is a substitute for a control in the path; both are what you have left after removing one.

  • Doesn't the concentrator's flow data at least show that the laptop contacted the exempt destination?
    No. A flow record is produced by the device that forwards the packets. Exempt packets leave the laptop's local interface and never reach the head-end, so nothing there can write a record for them. And the missing record proves nothing on its own - it is evidence about your sensor placement, not about the traffic.
  • If the exemption covers only real-time media over UDP, is the visibility loss proportionally smaller?
    The share of bytes you stop inspecting is large, but exposure is not proportional to bytes. Any process on the host can address the exempt destination range over the same permitted path. Narrowing an exemption by destination and by transport shrinks the reachable surface, but on whatever remains your vantage is zero, not reduced.
  • Does enrolling the laptop in the corporate proxy client change the answer?
    Only if the proxy path is on the packets' route. If the exemption bypasses the client's forwarding for those destinations, enrolment is bookkeeping: the device is managed, the traffic is still unseen. Enrolment tells you which laptop should be sending you records, not that this traffic produced any.

Adding a camera to the loading dock tells you nothing about the side door, and no amount of camera tuning will. The exemption is a side door you cut on purpose.

saying these in an interview costs you the question

  • Claims flow records still exist for exempt destinations
  • Says visibility is reduced rather than absent
  • Assumes the proxy sees it because the device is enrolled
  • Treats an endpoint agent as an equivalent replacement for a path control
  • Reads the missing record as evidence nothing happened

context

open as a page

A remote-access VPN authenticates a user with MFA and hands out a pool address - what does that session then reach?

level: juniorimportance: must knowfreq 78%

basics

~20 s

A tunnel session reaches whatever the routing table and the filters behind the address pool allow, which by default is everything the concentrator can route to. Authentication decides who gets an address; it never decides which destinations that address may open.

open as a page

An intruder inside a partner's network arrives over their site-to-site tunnel — what did that tunnel's authentication prove, and what must you run behind it?

level: juniorimportance: must knowfreq 66%

basics

~20 s

It proves only that the far-end device held the agreed key or certificate — nothing about the hosts behind it. Traffic leaving the tunnel is ordinary unauthenticated traffic, so your side needs its own default-deny filter on the extranet zone.

open as a page

A remote-access concentrator lands its inside leg on the core VLAN — what filters the decrypted traffic?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Nothing except the concentrator itself. ESP is decapsulated at its inside leg, so plaintext appears already on the core and no independent device sees it. Enforcement there means paying for a second filter and a second hop.

open as a page

A managed-service provider reports a breach and their tunnel into your extranet is still up — what do you do first, and what can you establish?

level: seniorimportance: must knowfreq 54%

basics

~20 s

Cutting the tunnel stops the service the provider runs for you, so the business owner decides. Narrow the policy, revoke the accounts they hold inside your estate, and expect your records to show that bytes moved, not what they were.

open as a page

A VPN exempt list keyed to a SaaS vendor's published IP ranges is reviewed quarterly - what can an adversary reach through it?

level: middleimportance: should knowfreq 47%

basics

~20 s

Anything reachable at an address inside those blocks. The exemption is keyed to addresses, not to the vendor's identity, so shared cloud space and blocks the vendor has released stay exempt until someone reviews the list.

open as a page

Internal logs show a VPN pool address, not a user - how do you bind a flow to an account?

level: middleimportance: should knowfreq 55%

basics

~20 s

Join the flow to the concentrator's address-assignment record using the flow's own timestamp: that record says which account held which pool address, and when. Pool addresses are reassigned, so a join without time attributes the flow to the wrong person.

open as a page

A partner announces prefixes over your site-to-site tunnel that the contract annex never listed — what limits their reach, and what does holding that limit cost?

level: middleimportance: should knowfreq 45%

basics

~20 s

The accepted-route filter and the zone policy limit reach; the annex is paper and enforces nothing. Cost: someone must own an inbound prefix list and a source-address filter per partner, and every legitimate change becomes a ticket with an outage risk.

open as a page

Why might the filter behind your VPN head-end see only the forward direction of decrypted traffic?

level: middleimportance: should knowfreq 46%

basics

~20 s

Routing decides the path, not the diagram. If the core reaches the VPN client pool over an adjacency that skips the filter, return packets never traverse it — and flows still work, so the gap stays silent.

open as a page

VPN head-end capacity runs out next quarter and the cheapest fix is exempting the two heaviest SaaS destinations - which traffic do you hand an adversary?

level: seniorimportance: should knowfreq 54%

basics

~20 s

Rank candidates by exposure, not by bytes. Real-time media over UDP is the defensible first exemption: huge volume, narrow and stable destinations, almost no inspection yield. A general-purpose file or web SaaS is the opposite on every axis.

open as a page

An adversary owns your VPN head-end outright — how does the inside leg's position change what they originate?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Owning the box deletes its own policy as a control: the adversary now originates traffic and chooses source addresses. From a core-VLAN landing they reach whatever the core routes; from a screened tier, only what a device they cannot administer permits.

open as a page

Shrinking VPN pool reach needs app-by-app discovery nobody will staff - what do you deliver and who signs?

level: principalimportance: should knowfreq 41%

basics

~20 s

Stop enumerating what remote users need and start removing what they never need, in tranches ordered by consequence. Deliver a falling reachable-destination count per pool, and have a named risk owner accept the remainder with an expiry.

open as a page

Three destinations are exempt from your VPN tunnel - how do you prove an implant is not using that uninspected path?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

You cannot, from the network - there is no vantage there by construction. You either rebuild one deliberately, fall back to endpoint and destination-side records with their limits stated, or say plainly that the path is unobserved.

open as a page

One remote-access VPN lands into two merged estates using overlapping RFC1918 space - how do you scope reach?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Give each population its own pool, keep the two overlapping address plans in separate routing tables, and translate only the few flows that must cross. One shared pool routed into both estates lets the unassessed directory's accounts reach your core.

open as a page

A business-critical supplier refuses a security audit and refuses an offboarding clause with teardown evidence — what do you require, and what do you build anyway?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Require what a supplier will actually sign: breach notification to a tested contact, declared flows, and the right to disable. Build default-deny and a tunnel expiry that fails closed. Escalate the residual risk for named acceptance.

open as a page

How do you justify a second enforcement hop behind the VPN head-end when cost and a peer argue for one box?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Stop arguing defence in depth. Write what a fully-owned head-end could originate from each candidate position, have a risk owner sign it, price the second hop honestly, and offer the variant that needs no purchase.

open as a page