The two kinds, and what goes wrong with each
Site-to-site connects your offices to each other permanently, so a branch or warehouse can reach head office systems as though it were in the same building. What goes wrong: it is built as a single tunnel with no failover, so when the link drops the site is simply cut off. Where sites need to behave as one network reliably, SD-WAN is usually the better answer and we will say so.
Remote access lets staff connect from home or the road. What goes wrong: shared credentials, no multi-factor authentication, no certificate expiry management, and no process for removing access when somebody leaves. We regularly find working accounts belonging to people who left the business years earlier.
What we do
- Design and configuration on the firewall you already own - Sophos, Fortinet or WatchGuard - rather than adding another product.
- Multi-factor authentication on remote access, which is the single change that most reduces risk here.
- Certificate and user lifecycle: issuing, renewing before expiry, and revoking promptly when someone leaves.
- Split-tunnel and access policy so remote users reach what they need and nothing else.
- Documentation and handover, so the next person to touch it is not starting from nothing.
- Ongoing management as part of managed services, including the joiner and leaver process.
What it costs
Quoted per engagement after a short scoping call, based on the number of sites and users, and fixed before any work starts. VPN work is most often scoped as part of a firewall project or an SD-WAN rollout, which usually works out cheaper than commissioning it on its own.