A business VPN serves one specific purpose: reaching your network from outside, without exposing it to the internet.
The word covers two very different things, and the confusion is common. The consumer VPNs advertised everywhere are for hiding your browsing and appearing to be in another country. That is not what this is about. A business VPN creates an encrypted tunnel between someone outside and the company network, as though they were on site.
Many businesses have, at some point, opened remote desktop directly to the internet. Often in a hurry, to help someone out. And then it stayed.
That kind of access is swept and attacked constantly by automated programs trying thousands of combinations. It is one of the most exploited ways into small organizations. A VPN solves the problem at the root: there is nothing exposed any more, only an authenticated tunnel gets you in.
It protects the link, not the machines. An infected computer connecting over a VPN brings its infection onto the company network, encrypted tunnel or not. So the remote machine has to be kept up to date and protected like the others: a point we deal with at the same time, never afterwards.
The VPN in the router. Many recent devices include one. It is the simplest and cheapest solution for one or two people working from home occasionally.
The VPN on the NAS. If you have one, it often acts as a VPN server, with proper user management. See NAS installation.
A dedicated router. For several simultaneous users or a permanent link between two sites, with better performance and finer administration.
We choose according to the number of users, how often it will be used and what is already there - not from a catalog. It often turns out that the existing equipment is enough.
Two points determine whether it is feasible and deserve looking at before any promise is made.
Your connection's upload speed. A VPN sends data out from your premises: it is the upload speed that counts, often far lower than the download speed. Opening a large file remotely can be slow, and it is better to know beforehand.
The type of address your operator provides. Some configurations simply prevent incoming access. That is checked in a few minutes and determines which solution is chosen.
We always put it in place where the solution allows. Otherwise a stolen username and password are enough to get onto your network from anywhere. With a second proof required at sign-in, the password alone is no longer enough - it is the measure that brings the most for the least effort.
Worth clarifying, the question always comes up. They encrypt your browsing as far as their server, which is genuinely useful on a public network you do not control. They protect against neither viruses, nor phishing, nor a stolen password - contrary to what their advertising implies. And they give no access at all to your company network. They are two different tools for two different needs.
It is not always the right answer, and we would rather say so. If the need is limited to consulting documents, an online sharing space is simpler and quicker to use. If the need is to fix a machine occasionally, an on-demand remote-control tool does the job and leaves no door open. And if the business software exists as a hosted version, the question of remote access disappears by itself.
A VPN is called for when you need to reach resources that stay on your premises: a file server, a database, an application installed in-house. That is what we check before proposing anything.
Feasibility check, choice of solution, configuration of the remote machines, two-factor authentication and documentation. See also securing the network and remote support.
It adds some encryption, but the limiting factor is almost always the upload speed of the premises' connection. That is what we measure before committing.
Usually yes, a light VPN client, sometimes built into the system. It is configured once, after which connecting takes one click.
No. It secures the link, not the machines. An infected remote machine remains a danger to the network it joins, which is why we deal with both together.
It depends on the equipment and the available speed. Two or three occasional users work on most routers; beyond that, dedicated equipment is needed.
Can't find your question? It may be in our full FAQ.
Everything worth knowing before you hand over your equipment.
278 questions on breakdowns, security, networking and backup.
What the households and businesses we work with have to say.
Lyon, Villeurbanne, Caluire, Tassin, Écully and the whole Rhône.
Describe your problem: we reply with an initial assessment.
A feasibility check first: not everything is up to us, but you will know where you stand.
Automatic assistant: it can make mistakes. Never share a password or a card number.