CompTIA Network+ (N10-009)Network OperationsHard
Two branch offices require a permanent, always-on encrypted connection so that all users and servers on both networks can communicate transparently without installing individual VPN client software on each device. Which solution best meets this requirement?
- ASite-to-site VPN
- BSSH port forwarding
- CClient-to-site VPN
- DSplit-tunnel VPN
Show answer & explanationAnswer & explanation
Correct answer: A. Site-to-site VPN
A site-to-site VPN establishes a persistent encrypted tunnel between two gateway devices (routers/firewalls), allowing entire networks to communicate securely without requiring client software on individual endpoints. Client-to-site and split-tunnel VPNs are per-user solutions requiring client configuration, and SSH port forwarding only tunnels specific application traffic, not whole-network communication.
Why the other options are wrong
- B. SSH port forwarding tunnels individual application sessions, not whole-network traffic.
- C. Client-to-site VPN requires individual client software on each user's device, which contradicts the requirement.
- D. Split-tunnel is a client VPN configuration choice, not a network-to-network solution.
Site-to-Site VPN
A VPN tunnel established between two network gateways (e.g., routers or firewalls) that transparently connects two networks over an encrypted channel, without requiring client software on individual devices.
- Configured between gateway/firewall devices, not end-user clients
- Provides always-on, transparent connectivity between branch networks
- Contrasts with client-to-site VPN, which connects individual remote users
Memory trick: Site-to-site links whole buildings, not just people.