Network service

Business VPN Setup & Management

In short: Most business VPNs we inherit were set up once, in a hurry, and never revisited - which means people who left years ago can often still connect.

The two kinds, and what goes wrong with each

Site-to-site connects your offices to each other permanently, so a branch or warehouse can reach head office systems as though it were in the same building. What goes wrong: it is built as a single tunnel with no failover, so when the link drops the site is simply cut off. Where sites need to behave as one network reliably, SD-WAN is usually the better answer and we will say so.

Remote access lets staff connect from home or the road. What goes wrong: shared credentials, no multi-factor authentication, no certificate expiry management, and no process for removing access when somebody leaves. We regularly find working accounts belonging to people who left the business years earlier.

What we do

VPN work rarely stands alone. It normally comes up during a firewall replacement, an SD-WAN rollout or after a security assessment finds stale accounts. If you are considering one of those, mention the VPN in the same conversation and we will scope it together.

What it costs

Quoted per engagement after a short scoping call, based on the number of sites and users, and fixed before any work starts. VPN work is most often scoped as part of a firewall project or an SD-WAN rollout, which usually works out cheaper than commissioning it on its own.

Frequently asked questions

Should we use a VPN or SD-WAN between our offices?

If you have two sites and modest traffic, a well-configured site-to-site VPN is usually enough. If you have three or more sites, or if a dropped link stops work, SD-WAN is normally the better answer because failover and traffic prioritisation are built in. We will tell you which applies to you rather than defaulting to the larger project.

Can you use the firewall we already have?

In most cases yes. Sophos, Fortinet and WatchGuard firewalls all handle site-to-site and remote-access VPN natively. Adding a separate VPN product is rarely necessary and usually just adds something else to maintain.

How do we stop ex-employees still having access?

A defined joiner and leaver process, certificate-based authentication with proper revocation, and multi-factor authentication so a leaked password alone is not enough. We set this up as part of the work and can run it for you afterwards.

Is a consumer VPN service the same thing?

No. Consumer VPN products hide your browsing from your internet provider. A business VPN connects your staff or your sites to your own systems securely. They solve completely different problems and one is not a substitute for the other.

Inherited a VPN nobody understands?

We will review what is configured, tell you who can currently connect, and what it would take to put it right.

Book a free consultation