Blog

Networking articles

Business VPNs Explained: Remote Access and Site-to-Site

A business VPN explained: remote access vs site-to-site, IPsec, WireGuard and SSL VPN protocols, split tunnelling, and how to set one up securely.

4 min read Networking

The VPN apps advertised to consumers promise privacy and the ability to appear in another country. A business VPN does a different job: it extends your private company network securely across the internet, so staff at home can reach office systems and branch offices can share resources as if they were in the same building. There are two main kinds, remote access and site-to-site, and choosing between them (or using both) depends on who needs to connect to what.

What a VPN does

A Virtual Private Network creates an encrypted tunnel between two points across the public internet. Traffic inside the tunnel is unreadable to anyone in between, such as a café's Wi-Fi operator, and it arrives at the other end with an address on your internal network. To your file server, a laptop connected over VPN from home looks much like a laptop plugged in at the office.

Remote access VPN

A remote access VPN connects individual devices to the company network. Each user runs a VPN client on their laptop or phone and signs in. The VPN gateway, usually your office firewall or a server in the cloud, checks their credentials and admits them.

Typical uses:

  • Staff working from home who need internal file shares, an on-premises accounting system or printers.
  • Administrators who need secure access to servers, instead of exposing SSH or Remote Desktop to the internet.
  • Contractors who need temporary, limited access.

Site-to-site VPN

A site-to-site VPN connects whole networks, router to router. Users do nothing; the gateways at each location keep a permanent tunnel up and route traffic between networks automatically.

Typical uses:

  • A head office and branch offices sharing an ERP or file server.
  • Connecting your office network to a cloud virtual network, so servers in the cloud can be reached on private addresses. All major cloud providers offer managed VPN gateways for this.
  • Linking with a partner's network for a specific integration, limited by firewall rules to only the systems involved.
Head office 10.1.0.0/16  ⇄  encrypted tunnel  ⇄  Branch 10.2.0.0/16

One requirement is easy to overlook: the networks on each side must use different, non-overlapping private ranges. If both offices use 192.168.1.0/24, routing between them breaks. Plan address ranges with a subnet calculator before you build the tunnel.

Remote access vs site-to-site at a glance

Remote accessSite-to-site
ConnectsA device to a networkA network to a network
User actionInstall client and sign inNone; always on
EndpointsLaptops and phones anywhereRouters or firewalls at fixed sites
AuthenticationPer user, ideally with MFABetween gateways, using keys or certificates
Best forRemote and travelling staffBranches, cloud networks, partners

The main VPN protocols

  • IPsec: the long-standing standard for site-to-site VPNs and supported by virtually every firewall and cloud provider. It uses IKE for key exchange on UDP port 500 and UDP 4500 when NAT is in the path. It is powerful but has many options, which makes configurations between different vendors fiddly.
  • WireGuard: a modern protocol with a small codebase and a deliberately limited set of modern cryptographic choices. It is fast, simple to configure and runs over a single UDP port (51820 by default). It is increasingly used for both remote access and site-to-site, though it leaves user management and authentication workflows to the surrounding product.
  • OpenVPN: a widely used open-source option, running over UDP or TCP (port 1194 by default), and able to use TCP 443 to pass restrictive networks.
  • SSL/TLS VPNs: commercial remote access products from firewall vendors, often running over TCP 443. These integrate with company directories and MFA but have been frequent targets for attackers, so prompt patching is essential.

Avoid PPTP entirely; its security is broken. L2TP on its own provides no encryption and is only acceptable when combined with IPsec.

Split tunnelling or full tunnel?

With a full tunnel, all of a remote user's internet traffic goes through the company network, so it passes your security filtering, but it also consumes office bandwidth and can make video calls slower. With split tunnelling, only traffic for company networks goes through the VPN; everything else goes directly to the internet. Split tunnelling is common now that many applications are cloud-hosted anyway, but it means remote devices need their own protection, such as endpoint security and DNS filtering.

Setting up a business VPN securely

  1. Require multi-factor authentication for every remote access user. A VPN account protected by only a password is a prime target.
  2. Give least-privilege access. A VPN connection should not automatically grant access to the entire network. Use firewall rules or groups so sales staff reach the CRM, not the server management interfaces.
  3. Patch the VPN gateway promptly. VPN appliances sit on the internet edge and are actively targeted when vulnerabilities are published.
  4. Expose only the VPN. Once it is in place, close direct inbound access to RDP, SSH and databases. Confirm from outside with a port checker.
  5. Use certificates or strong pre-shared keys for site-to-site tunnels, and modern algorithms (AES-GCM, SHA-256 or better).
  6. Log and review connections, and remove accounts promptly when people leave.
  7. Get a stable address for the gateway. Site-to-site tunnels are much easier with a static public IP at each end.

Is a VPN still the right model?

Many organizations now combine VPNs with or move towards zero-trust network access (ZTNA), where users connect to individual applications after identity and device checks, rather than joining the whole network. If most of your systems are already cloud applications with single sign-on, you may need a VPN only for a few remaining internal systems. For site-to-site links to the cloud, VPNs remain a standard, cost-effective choice; a cloud networking review can help decide what fits.

Key takeaways

  • Remote access VPNs connect individual users; site-to-site VPNs connect whole networks.
  • IPsec dominates site-to-site; WireGuard is a fast, simple modern option; avoid PPTP.
  • Require MFA, restrict what VPN users can reach, and patch gateways quickly.
  • Plan non-overlapping address ranges before linking networks.

Need help with this?

Netifi helps businesses around the world with Networking. Tell us what you are working on.