A little learning. A little more confidence.Your next step starts here

Network foundations · Lesson 5 of 5

Know where your VPN tunnel ends

A virtual private network, or VPN, can protect traffic between your device and a VPN gateway. That tunnel has endpoints and a scope. It does not make every destination trustworthy.

SEE THE IDEA

Notice where the tunnel ends

A simplified VPN route for traffic configured to use the tunnel.

  1. Your device

    Starts the protected VPN connection.

  2. VPN gateway

    The VPN tunnel ends here.

  3. Destination

    Traffic continues beyond the gateway; keep HTTPS and other protections.

Split tunneling sends some traffic outside the VPN route. The gateway and the destination are separate trust decisions.
Read the visualDoes the VPN make an attachment from an unknown sender safe?

No. A protected route does not establish that a downloaded file or destination is harmless.

Ask which traffic uses it

Some configurations route all traffic through the tunnel. Split tunneling sends only selected traffic through it. Follow the organization’s approved configuration.

Keep other protections

A VPN does not replace HTTPS, careful sign-in decisions, or device updates. A protected route can still carry a request to a deceptive page.

Use the approved service

The gateway is part of your trust decision. For work, use the supplied client and contact support if the expected connection fails.

Put it in context

At a conference, a fictional employee connects to the company VPN and opens a message claiming to be payroll. The tunnel protects the configured connection to the company gateway. It does not prove that the message or the page asking for a password came from payroll.

A tunnel protects a route. You still need to verify the request.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE