Skip to main content

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

What is Virtual Private Network (VPN)?

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks. A VPN protects traffic between tunnel endpoints, but access policy still determines what the endpoint can reach after it enters the private network. Compare VPN and ZTNA by access scope, client needs, trust boundaries, routing, failure modes, and application support.

Why it matters

A VPN can protect traffic over an untrusted network and can connect remote users or sites. Its tunnel scope and private-network routes determine how much access a connected endpoint receives.

How it works

  1. The VPN peers authenticate and negotiate a tunnel protocol and traffic keys.
  2. The sender encrypts and encapsulates selected packets for transport across another network.
  3. The receiving peer decrypts the packets and routes them toward the permitted private destinations.

Example

A remote administrator connects a laptop to a corporate VPN, receives routes to an administration subnet, and then depends on firewall and application policy for access inside that subnet.

Pomerium boundary

Pomerium provides identity-aware access to specific private applications and services without giving a requester a broad private-network route. It is not a site-to-site VPN and does not replace every layer-3 connectivity use case.

Limits and non-claims

  • A remote-access VPN can expose a broad network scope after the tunnel connects.
  • A compromised tunnel endpoint can use the access granted to that endpoint.
  • Site-to-site encryption does not replace identity and authorization controls in each application.

Evaluation checklist

  • Which client or gateway identity, routes, addresses, and traffic enter the tunnel?
  • Which resource and action permissions remain after the VPN grants network reachability?
  • Can split tunneling, shared subnets, stale sessions, direct endpoints, or lateral movement bypass controls?

Sources and further reading

Keep learning

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo