📖 What is Site-to-Site VPN?

A Site-to-Site VPN is a permanent encrypted connection between two separate networks, typically connecting a branch office to a central corporate headquarters. It uses a VPN gateway at each site to tunnel traffic securely over the public internet.

🥋 Sensei Says:

"Ensure you distinguish this from Remote Access VPNs. Site-to-Site is for office-to-office; Remote Access is for user-to-office."

📚 Certification: CompTIA Network+ Certification Exam (N10-009)

🔑 What are the Key Concepts of Site-to-Site VPN?

  • IPsec is the primary protocol suite used, providing authentication, integrity, and confidentiality through encryption and tunneling mechanisms.
  • VPN Gateways, such as firewalls or routers, manage the encryption process, making the connection transparent to the end-user devices.
  • Tunneling encapsulates the original data packet inside a new IP packet, allowing private network traffic to traverse the public internet.
  • These connections are typically 'always-on,' providing a permanent bridge between two fixed locations rather than a session-based user connection.
  • Routing configurations, including static routes or BGP, are essential to direct traffic from the local subnet into the VPN tunnel.

🎯 How does Site-to-Site VPN appear on the N10-009 Exam?

You may be asked to recommend a connectivity solution for a company that needs to securely link a new branch office to the headquarters over the public internet while ensuring all traffic is encrypted.

A scenario might describe a need to connect two entire corporate subnets without requiring individual users to launch client software. You must distinguish this from a remote access VPN and select site-to-site.

Expect questions where you must identify the correct device for tunnel termination, such as a firewall or router, acting as the VPN gateway to handle encryption for the entire local network.

❓ Frequently Asked Questions

What is the main difference between a Site-to-Site VPN and a Remote Access VPN?

Site-to-Site connects two entire networks via hardware gateways, making it transparent to users. Remote Access connects a single device to a network using a software client, typically for remote workers.


Does a Site-to-Site VPN provide the same performance as a dedicated leased line?

No, because it relies on the public internet, performance can vary. A leased line provides guaranteed bandwidth and lower latency, whereas a VPN is more cost-effective but subject to internet congestion.

Related Terms from CompTIA Network+ Certification Exam

📝 Related Study Guides

Exam Tips 8 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ N10-009 exam contains up to 90 questions in 90 minutes, requiring 720 out of 900 to pass. It covers five domains: Networking Fundamentals (23%), Network Implementation (20%), Network Operations (18%), Network Security (19%), and Network Troubleshooting (20%). Expect multiple choice, multiple select, and performance-based questions testing hands-on networking skills.

Exam Tips 10 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. To pass, you must master five core domains: Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting, focusing heavily on real-world scenario application.

Exam Tips 10 min read

CompTIA Network+ (N10-009): What to Expect on the Exam

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. You must master five core domains—Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting—to achieve a passing score of 720 on a scale of 100-900.

🧠

Test Your Knowledge

Think you understand Site-to-Site VPN? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium