TechKnowSurge
ISC2 CC 4.1 NIST 800-53 AC-17 CompTIA Network+ 3.5 Cisco CCST Cybersecurity 2.5 NIST 800-53 SC-8 CompTIA Security+ 3.2 CompTIA A+ Core 2 4.9
InteractiveSecurityFree

Where Does the VPN Traffic Go?

Through the tunnel or straight out? Predict where each remote user's traffic goes and what they can reach.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

A VPN encrypts traffic at one end and decrypts it at the other, so it crosses the public internet unreadable. That path is the tunnel. Site-to-site: two networks, say headquarters and a branch office, joined by a tunnel between their firewalls. Anyone on the branch network reaches headquarters' resources automatically; nobody starts a client. Client-to-site (remote access): one device connects to the company's VPN concentrator, often the firewall. The user authenticates, and then the device acts as if it were on the network. Client or clientless. Most client-to-site VPNs use client software, such as Cisco AnyConnect or OpenVPN, which gives the device a virtual network connection: it is like sitting on the network. A clientless VPN runs in the browser over TLS (the video says SSL, "technically TLS") and offers only what its portal publishes, such as web apps. Both are encrypted: AnyConnect and OpenVPN build their tunnels with TLS (or DTLS) too, so TLS does not mean "browser only". Full or split tunnel. In a full tunnel, everything the device sends goes through the tunnel to the company, including ordinary web browsing, which then leaves through the company's internet connection (and its filtering). In a split tunnel, only traffic for the company's network uses the tunnel; everything else goes straight out from wherever the user is. That saves the company's bandwidth, but the direct traffic is not protected by the VPN and is not filtered by the company.

What you'll learn

Aligned to

ISC2 CC
4.1 Understand network security
NIST 800-53
AC-17 Remote Access
SC-8 Transmission Confidentiality and Integrity
CompTIA Network+
3.5 Compare and contrast network access and management methods.
Cisco CCST Cybersecurity
2.5 Implement secure access technologies
CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
CompTIA A+ Core 2
4.9 Given a scenario, use remote access technologies.

Key terms

Virtual Private Network
VPN
A technology that creates a secure, encrypted tunnel over a public network to protect data in transit.
Site-to-Site VPN
A VPN configuration that connects two fixed network locations through an encrypted tunnel over the internet, allowing them to communicate as a single network.
Remote Access VPN
A VPN configuration that allows individual users to securely connect to a private network from a remote location.
Split Tunnel
A VPN configuration that routes only traffic destined for the private network through the VPN tunnel, while other traffic takes a direct internet path.
Tunnel
A secure, encapsulated communication path established over a public network to carry private network traffic between endpoints.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.

Topics

Virtual Private Network Site To Site Vpn Split Tunnel Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →