30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

4.2.3. Secure Communication and Access

💡 First Principle: Every communication channel is a potential interception point. Securing communication means encrypting data in transit, authenticating both endpoints, and controlling who can access management interfaces.

VPN types:
  • Site-to-site VPN — connects two networks (e.g., headquarters to branch office) over an encrypted tunnel. Uses IPSec. Always-on, transparent to users.
  • Remote access VPN — connects individual users to the corporate network. Uses IPSec or SSL/TLS. Initiated by the user when needed.
  • Split tunnel vs. full tunnel — split tunnel only routes corporate traffic through the VPN (better performance, less security). Full tunnel routes ALL traffic through the VPN (more secure, slower). Full tunnel ensures all traffic is inspected by corporate security controls.
VPN and tunneling protocols:
  • IPsec — secures IP packets at the network layer: AH provides integrity and origin authentication, ESP adds encryption. IKEv2 negotiates the keys and, with its MOBIKE extension, keeps a tunnel up when a mobile user changes networks.
  • SSL/TLS VPN — tunnels over TLS on port 443, often clientless through a browser portal, so it passes through most firewalls.
  • WireGuard — a modern VPN protocol with a very small codebase and a fixed set of current algorithms (Curve25519, ChaCha20-Poly1305): strong security with low overhead.
  • L2TP — carries Layer 2 frames through a tunnel but does not encrypt them, which is why it is deployed as L2TP/IPsec. GRE — wraps one protocol's packets inside another (for example to carry routing protocols between sites) and likewise provides no confidentiality, so it is run inside IPsec when that matters.
  • PPTP — deprecated: its MS-CHAPv2 authentication and encryption are broken; do not use.
Secure protocols:
  • SSH — encrypted remote administration (replaces Telnet)
  • TLS/HTTPS — encrypted web communication
  • SFTP/SCP — encrypted file transfer (replaces FTP)
  • SNMPv3 — encrypted network management (replaces SNMPv1/v2)
  • LDAPS — encrypted directory queries

Out-of-band management — managing network devices through a separate, dedicated management network that's isolated from production traffic. If the production network is compromised, the management channel remains accessible. Requires separate physical or logical infrastructure.

Jump server (bastion host) — a hardened intermediary that administrators connect through to reach internal systems. Instead of exposing management interfaces directly, all administrative access routes through the jump server. This creates a single, auditable choke point: every admin session is logged, and the jump server can enforce MFA, session recording, and time-limited access. If the jump server is compromised, you disable one system rather than re-securing every device.

Port security on switches restricts which devices can connect to physical ports by limiting allowed MAC addresses. Port security prevents rogue devices from connecting to the network — if an unauthorized MAC appears, the port can be configured to shut down, restrict traffic, or alert administrators.

⚠️ Exam Trap: Split tunnel is faster but less secure because non-corporate traffic bypasses VPN inspection. If a question describes a security concern about remote users accessing both corporate resources and the internet, full tunnel is the more secure answer.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications