
Before we begin, let's establish the basic definitions so as not to confuse concepts like proxy and VPN.
VPN (Virtual Private Network) — is a technology that allows you to create secure tunnels over a public network, the internet. The concept itself is quite broad, as it encompasses various implementations. It can be a VPN network, a VPN application, or a proxy server.
As for the proxy server — that's clear. We covered it in more detail in a separate article «What Is a Proxy Server and How to Set It Up». In this context, a VPN refers to a technology that allows you to establish a connection between server A and B through an intermediary machine C. But what is the difference between a VPN network and a VPN application? In fact, you have already encountered these concepts.
A VPN network — is a network within which you can organize a secure connection between a user's device and a remote server. The network is configured at the OS level or on networking equipment, which allows encryption of all traffic.
In turn, a VPN application — is software that allows you to use a VPN network. As a rule, it provides the user with a simpler way to connect and configure connection parameters with a remote server. In other words, VPN networks and applications are related to each other. But in IT conversations, you may hear not only these definitions.
Another component of a VPN is a virtual network. This term refers to a network created by software or hardware-software means that operates on top of physical infrastructure. It can be deployed on a publicly accessible network, allowing remote devices to be combined into a single local pool. Do not confuse a virtual network with a VPN network. A virtual network can be a component of a VPN, but not the other way around.
Another component of a VPN is a private network. This term refers to a network that can only be used by specific individuals or organizations. Unlike public VPNs, a private network is created for the specific needs of companies. For example, using it, an organization can set up remote access to office applications and services for its employees.
Great — we've sorted out the basic definitions. Now let's break down a VPN and see what lies at its core. Several "blocks" can be identified here: authentication, encryption, proxying, and tunneling. Let's examine each process in more detail.
If you take any VPN apart, inside there will be "logical blocks" responsible for these four processes. However, their implementation depends on the choice of connection type and the protocol used to transmit data.
This type of VPN allows individual users and devices to securely connect to a company's private network over a public network. Remote access is achieved by establishing a connection between the user and a VPN server located within the organization's network. Special protocols are used for this, including IPSec, OpenVPN, SSL/TLS, and others.
This is a type of VPN connection used to link two networks together. In this case, an encrypted tunnel is used between the local networks where hosts A and B are located, respectively. Site-to-Site VPN allows them to operate as if they were connected to the same switch.
Setting up this type of connection is straightforward. It is sufficient to install a VPN gateway at the site boundary — for example, a firewall. It will handle key exchange, data encryption and decryption, as well as negotiation of VPN tunnel parameters.
This type of connection allows a single VPN gateway to be linked to multiple remote gateways. At the same time, all of the latter can exchange data with each other, not just with the initial device. This technology can be useful when creating a virtual network between various branches of an organization.
There are many types of VPN connections, but what protocols can be used for encrypting and transmitting data at the network level? Let's briefly review popular solutions and those most optimal in terms of speed and security.
The concept of a "VPN chain," or DoubleVPN, is used when traffic is routed through multiple servers linked together. This adds an extra layer of security and anonymity. The principle of operation is simple.
This technology leads to increased network latency due to additional encryption and decryption cycles, but it enhances the security of the transmitted data. However, these are not the only features of using a VPN.
There are several reasons why people use VPNs. Let's look at them in more detail.
But that's not all. VPNs are actively used by companies to organize access to closed corporate networks. Let's consider this point separately.
In addition to regular users, employees of various organizations work with VPNs. After all, this technology is especially relevant for the corporate sector. But why is that? There are several reasons.
If you are planning to create a secure network for working with corporate systems, it is especially important to approach the choice of provider responsibly. At Selectel, we offer a GOST VPN service that can be used to organize a secure connection between your local infrastructure and infrastructure hosted in our data centers. The service will allow you to comply with Russian legislation requirements, securely exchange information, and control access to resources for your employees.