About this interactive
A VPN encrypts traffic at one end and decrypts it at the other, so it crosses the public internet unreadable. That path is the tunnel.
Site-to-site: two networks, say headquarters and a branch office, joined by a tunnel between their firewalls. Anyone on the branch network reaches headquarters' resources automatically; nobody starts a client.
Client-to-site (remote access): one device connects to the company's VPN concentrator, often the firewall. The user authenticates, and then the device acts as if it were on the network.
Client or clientless. Most client-to-site VPNs use client software, such as Cisco AnyConnect or OpenVPN, which gives the device a virtual network connection: it is like sitting on the network. A clientless VPN runs in the browser over TLS (the video says SSL, "technically TLS") and offers only what its portal publishes, such as web apps. Both are encrypted: AnyConnect and OpenVPN build their tunnels with TLS (or DTLS) too, so TLS does not mean "browser only".
Full or split tunnel. In a full tunnel, everything the device sends goes through the tunnel to the company, including ordinary web browsing, which then leaves through the company's internet connection (and its filtering). In a split tunnel, only traffic for the company's network uses the tunnel; everything else goes straight out from wherever the user is. That saves the company's bandwidth, but the direct traffic is not protected by the VPN and is not filtered by the company.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →