After authenticating the user, device, or both, the system creates a protected path for authorized traffic. Access may cover selected applications and subnets or provide broader network connectivity.
The client may use installed software or, for some web-oriented services, a browser. A full-tunnel configuration sends general network traffic through the organization or provider; split tunneling sends only selected traffic through the VPN. These choices affect bandwidth, inspection, name resolution, privacy, local-network exposure, and which controls can observe a session.
Key points
Authentication and enrollmentBind access to managed accounts and devices, use phishing-resistant multi-factor authentication where appropriate, and secure initial setup and recovery.
Least-privilege accessLimit routes, applications, ports, and administrative functions by role and context; enforce policy again after traffic reaches the gateway.
Endpoint and gateway securityPatch exposed services and clients, protect keys and tokens, assess device risk, log important activity, and revoke access promptly when conditions change.
Important limitationAn encrypted tunnel protects traffic between its endpoints but does not make the remote device trustworthy. Malware, stolen sessions, unsafe local networks, excessive authorization, and vulnerable internal services remain risks.