What is a VPN? Site-to-Site VPN, Remote-Access VPN and Encryption Explained

What is a VPN? Site-to-Site VPN, Remote-Access VPN and Encryption Explained
Networking ATN Campus September 10, 2026 20 views

What is a VPN? Site-to-Site VPN, Remote-Access VPN and Encryption Explained

Modern organizations often need employees, offices, and remote locations to securely communicate over networks such as the Internet.

A Virtual Private Network (VPN) creates a protected communication path over an existing network, allowing authorized users or networks to communicate securely.

In this article, we will learn how VPNs work, encryption, site-to-site VPNs, remote-access VPNs, and common real-world use cases.


What is a VPN?

A Virtual Private Network is a technology that creates a secure logical connection over an underlying network.

VPN technologies commonly use authentication, encryption, and tunneling to protect communications between authorized endpoints.

    User / Network A
          |
          |
    +-------------+
    | VPN Endpoint|
    +-------------+
          |
          | Encrypted Tunnel
          |
      INTERNET
          |
          |
    +-------------+
    | VPN Endpoint|
    +-------------+
          |
          |
    User / Network B
    

Why Do Organizations Use VPNs?

VPNs are commonly used when communication needs to travel across networks that are not fully trusted or are outside the organization's private network.

  • Connect branch offices securely
  • Provide secure remote access for employees
  • Protect data while it travels across networks
  • Connect users to private organizational resources
  • Support secure communication between distributed locations

How Does a VPN Work?

```

Original Traffic
|
v
+----------------+
| Authentication |
+----------------+
|
v
+----------------+
|   Encryption   |
+----------------+
|
v
+----------------+
|    Tunnel      |
+----------------+
|
v
INTERNET
|
v
+----------------+
| Decryption     |
+----------------+
|
v
Destination 
```

A VPN endpoint establishes a secure tunnel with another VPN endpoint. Traffic sent through that tunnel is protected according to the VPN technology and configuration being used.

What is VPN Encryption?

Encryption transforms readable information into protected data so that unauthorized parties cannot easily understand the contents while it is being transported.

```

Readable Data
|
v
"Login Information"
|
v
+-------------+
| Encryption  |
+-------------+
|
v
Protected Data
|
v
"8F#k2@xL..." 
```

The receiving VPN endpoint uses the appropriate cryptographic mechanisms to process the protected traffic.

VPN Authentication

Encryption is only one part of a secure VPN. VPN solutions can also authenticate users, devices, or VPN endpoints before allowing communication.

Authentication can involve mechanisms such as:

  • Username and password
  • Digital certificates
  • Pre-shared keys
  • Multi-factor authentication
  • Identity-provider integration

Site-to-Site VPN

A Site-to-Site VPN connects two or more networks through a VPN tunnel.

Instead of individual users manually establishing a VPN connection, the network devices at each location establish and maintain the secure connection.

    Head Office
    192.168.10.0/24
          |
    +-------------+
    | VPN Router  |
    +-------------+
          |
          |
    ===== INTERNET =====
          |
          |
    +-------------+
    | VPN Router  |
    +-------------+
          |
    Branch Office
    192.168.20.0/24
    

Site-to-Site VPN Use Cases

  • Head office to branch office connectivity
  • Connecting geographically separated company networks
  • Connecting data centers
  • Connecting private cloud and on-premises networks
  • Secure communication between organizational sites

Remote-Access VPN

A Remote-Access VPN allows an individual user or device to securely connect to an organization's private network from a remote location.

         Remote Employee
               |
               |
          VPN Client
               |
               |
            INTERNET
               |
               |
         VPN Gateway
               |
               |
      +----------------+
      | Company Network|
      +----------------+
         |     |     |
        App  File  Server
    

Once authenticated and authorized, the user may be able to access resources permitted by the organization's security policies.

Site-to-Site vs Remote-Access VPN

Feature Site-to-Site VPN Remote-Access VPN
Connects Networks Individual users/devices to a network
Typical endpoint VPN gateways/routers User device and VPN gateway
User action Usually transparent to users User typically connects through VPN software or client
Common use Branch office connectivity Remote employee access

VPN Tunneling

VPN tunneling encapsulates traffic so that it can travel through the underlying network between VPN endpoints.

```

Original Packet
|
v
+------------------+
| VPN Encapsulation |
+------------------+
|
v
Protected Tunnel Traffic
|
v
Internet
|
v
+------------------+
| VPN Decapsulation|
+------------------+
|
v
Original Traffic 
```

Common VPN Technologies

  • IPsec VPN
  • SSL/TLS-based VPN technologies
  • WireGuard
  • OpenVPN

Different VPN technologies have different architectures, security properties, performance characteristics, and deployment models.

Real-World VPN Example

    Employee
       |
       | Remote Access VPN
       |
    INTERNET
       |
       v
  VPN Gateway
       |
  +----+----+
  |         |
```

Company   Internal
Apps     Services 
```

A remote employee can use an organization's VPN solution to securely access permitted internal applications from outside the corporate network.

Practical Networking Lab

In a network simulation or lab environment, you can study VPN concepts by creating two networks connected through a simulated Internet and configuring compatible VPN endpoints.

  1. Create a head-office network.
  2. Create a branch-office network.
  3. Place a routed Internet segment between them.
  4. Configure VPN-capable gateways.
  5. Configure authentication and encryption parameters.
  6. Establish the VPN tunnel.
  7. Test communication between the private networks.

Quiz

Question: Which type of VPN is commonly used to connect two company networks together?

Show Answer

Site-to-Site VPN.

Bonus Question: Which type of VPN is commonly used by a remote employee to access company resources?

Show Answer

Remote-Access VPN.

Key Takeaways

  • VPNs create secure logical connections over underlying networks.
  • VPN technologies can use authentication, encryption, and tunneling.
  • Site-to-Site VPNs connect networks to networks.
  • Remote-Access VPNs connect individual users or devices to private networks.
  • Encryption helps protect data while it travels through the tunnel.
  • VPNs are widely used for branch connectivity and remote access.

Start Your Networking Journey with ATN Campus

Want to learn VPNs, IPsec, network security, routing, switching, firewalls, cybersecurity, and cloud networking?

ATN Campus provides industry-focused networking and cybersecurity training that combines theory with practical hands-on experience.

Courses Available

  • CCNA – Cisco Certified Network Associate
  • CCNP – Cisco Certified Network Professional
  • CEH – Certified Ethical Hacker
  • Cisco CyberOps
  • Network Security
  • Cloud Networking
  • Python for Network Automation
  • Practical Networking Labs
  • Cybersecurity Fundamentals
  • Career Guidance & Certification Preparation

Whether you're starting from zero or preparing for a professional networking or cybersecurity certification, ATN Campus can help you build the practical knowledge and hands-on skills needed for today's IT industry.

???? Learn networking. ???? Secure communications. ???? Practice with real-world labs. ???? Prepare for certifications. ???? Build your IT career with ATN Campus.
Document ATN CAMPUS