CompTIA Network+ (N10-009)Network OperationsMedium
A network administrator needs to establish a secure, encrypted connection from a remote office to the main data center over the public internet. The connection must allow all traffic between the two sites to be protected without requiring individual users to initiate a VPN client. Which type of VPN should the administrator implement?
- AClient-to-site VPN
- BPPTP VPN
- CSSL VPN
- DSite-to-site VPN
Show answer & explanationAnswer & explanation
Correct answer: D. Site-to-site VPN
A site-to-site VPN creates a permanent, encrypted tunnel between two networks (e.g., a remote office and a data center). This allows all traffic between the sites to be secured automatically without client-side software on individual user devices.
Why the other options are wrong
- A. A client-to-site VPN (or remote access VPN) requires individual users to initiate a VPN client for their device to connect to the corporate network.
- B. PPTP VPNs are considered insecure and are generally not recommended for new deployments requiring strong encryption.
- C. SSL VPNs can be client-to-site or clientless, but the primary requirement here is for a full network-to-network connection without individual client initiation.
Site-to-Site VPN
A type of VPN that establishes a secure, encrypted connection between two separate networks (e.g., two offices or an office and a data center) over an untrusted network like the internet, making the connection appear as a single, private network.
- Connects entire networks, not individual users.
- Typically always-on and transparent to end-users.
- Often uses IPsec for authentication and encryption.
Memory trick: VPNs connect sites or clients, securely tunneling through.