virtual private network
Enable an AI agent to recognise a virtual private network, assess the connectivity and protection it actually provides, and determine which connection, routing and access changes are authorised.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
recalled by Codex without web access - no source was read
Researched by: Codex
Purpose and description
Enable an AI agent to recognise a virtual private network, assess the connectivity and protection it actually provides, and determine which connection, routing and access changes are authorised.
A virtual private network (VPN) is a logical network that provides selected users or sites with private connectivity over shared infrastructure through mechanisms such as tunnelling, traffic isolation and, in cryptographic VPNs, authentication and encryption.
It can be Classify a proposed or observed VPN and identify evidence missing from its privacy or security claims.; Trace whether a specified flow uses the VPN, bypasses it or is blocked.; Assess whether a participant may join and which resources it should reach.; Establish, revoke or change a connection within recorded administrative authority.; Diagnose reachability, DNS, MTU and performance failures using scoped observations.; Check failure behaviour and verify that an authorised configuration change preserves required traffic protection..
Distinguishing features
Identify an explicit logical membership or attachment boundary and forwarding behaviour that connects members across shared infrastructure; a product label alone does not establish that it is a VPN.
Determine whether the mechanism supplies network connectivity or only relays selected application requests; an application proxy is not automatically a VPN.
Test traffic separation and cryptographic protection independently: a provider-provisioned VPN may isolate forwarding without encrypting payloads.
Locate the endpoints of protection and the onward path after termination; reaching a VPN gateway does not establish protection all the way to an application.
Distinguish private network participation from anonymity: changing the visible egress address does not by itself establish unlinkability or eliminate operator visibility.
Scope
+ VPN membership, participating endpoints, gateways and connected address spaces
+ Remote-access and site-to-site arrangements, including provider-provisioned private networks
+ Tunnelling, forwarding separation and any cryptographic protection
+ Authentication, authorisation and routes that determine effective reachability
+ Connection lifecycle, failure behaviour and evidence of delivered protection
- The general architecture and operation of the underlying Internet or carrier network
- Endpoint operating-system security beyond requirements for VPN participation
- Application security and application-level access controls beyond their interaction with VPN reachability
- Proxy services, Tor and encrypted application sessions that do not establish a private network
- The complete commercial or organisational model of a VPN service provider
Characteristics
- VPN classification
- Remote access, site to site, provider-provisioned, hybrid, or unresolved; categories may overlap Determines which participants, attachments and operational responsibilities must be represented.
- Membership and attachment
- Users, devices, sites or tenant networks linked to VPN endpoints and admission authorities Makes the private network boundary explicit.
- Forwarding and encapsulation mechanism
- Named mechanism and version, forwarding context, and encapsulation where applicable Supports assessment of interoperability, isolation and configuration constraints.
- Protection properties
- Isolation, peer authentication, confidentiality, integrity and replay protection, each recorded as evidenced, absent, unknown or not applicable Prevents the word private from standing in for verified security properties.
- Effective traffic coverage
- Source, destination, address family, application and DNS traffic mapped to VPN, direct or blocked paths Shows which traffic actually receives the intended treatment.
- Operational connection state
- Disabled, negotiating, established, degraded, failed or disconnecting, with observation time Separates configured intent from present connectivity.
- Effective reachability
- Participant-to-resource paths with routing, filtering and authorisation evidence A connected VPN does not imply permission or ability to reach every private resource.
- Path performance
- Latency in ms, throughput in Mbit/s, loss in percent and effective MTU in bytes, with test path and time Determines whether the VPN can support the intended workload.
- Failure traffic policy
- Block, bypass, reroute or mixed, specified by traffic class Determines what happens to traffic when a connection or protection mechanism fails.
Also called
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 6 bundles · 11 layers · 18 findings · 28 questions.
VPN identity and boundaries Establishes what qualifies as this VPN and which entities form its private network.
VPN terminology spans cryptographic tunnels and provider-managed isolation, so recognition requires an explicit interpretation.
Classification and instance
Records the definition being applied and the concrete arrangement it describes.
VPN qualification
Record the criteria under which the arrangement counts as a VPN, including whether privacy means forwarding isolation, cryptographic protection or both.
- Which definition and authority classify this arrangement as a VPN, and what observable criteria do they require? definition
- What distinguishes this instance from an application proxy, a local virtual network or an ordinary encrypted session? boundary
Participants and attachments
Identifies VPN members, connection endpoints and attached networks.
Private network membership
Record participating users, devices, sites or tenants and distinguish them from gateways and infrastructure that transport their traffic.
- Which entities are members, which terminate VPN connections, and which only provide transport? boundary
- Which configuration or control-plane evidence establishes each attachment and its owning authority? provenance
Isolation, protection and trust Separates logical traffic isolation from cryptographic guarantees and operator trust.
An agent must assess the mechanisms and endpoints of protection rather than infer them from the VPN label.
Separation and cryptography
Records how traffic is separated and which security properties are implemented.
Evidenced protection
Record forwarding separation, encapsulation and negotiated cryptographic properties as separate claims with supporting evidence.
- What mechanism prevents traffic from entering another tenant's or participant group's forwarding context? boundary
- Which peer authentication, encryption, integrity and replay protections are actually active on each protected segment? measurement
Termination and observation
Maps where protection ends and what intermediaries can observe.
Trust and visibility boundary
Record protection termination points, operator control and visibility into payloads or metadata, accounting for separate application encryption.
- Where does each VPN protection terminate, and which onward segments rely on different protection? boundary
- What evidence supports claims about operator visibility, logging and retention, and what remains unverified? provenance
Traffic selection and reachability Determines which traffic traverses the VPN and which destinations become reachable.
Tunnel establishment alone cannot establish coverage, prevent bypass or explain access failures.
Routes and traffic selection
Captures effective routing and selection across traffic classes and address families.
Effective VPN coverage
Record actual VPN, direct and blocked paths rather than relying only on full-tunnel or split-tunnel labels.
- Which IPv4, IPv6, application and local-network flows traverse the VPN under the effective routing and policy rules? measurement
- Which bypasses are intended exceptions, and which violate the stated traffic-coverage requirement? boundary
DNS and destination access
Connects name resolution, addressing and filtering to usable destination paths.
Resolved and permitted paths
Record DNS resolver selection, overlapping address spaces, translation and access filters that affect private or external destinations.
- Which resolver handles each relevant namespace, and do its requests follow the intended VPN or direct path? measurement
- For a target resource, which route, address overlap, translation or filter determines reachability? boundary
Admission and authorised control Connects VPN participation and administrative changes to identifiable authority.
Network membership, peer authentication and permission to access resources are distinct decisions.
Identity and admission
Records how peers or attachments are recognised and admitted.
Admission evidence
Record credentials, certificates, device requirements or provider provisioning that establish participation, without assuming every VPN authenticates individual users.
- What authenticates or authoritatively provisions each peer or attachment, and which identity does that establish? provenance
- How can an authorised operator revoke membership, and what happens to existing sessions or forwarding state? action
Access and change authority
Separates access permissions from permission to administer VPN behaviour.
Bounded VPN actions
Record who may reach resources and who may change peers, routes, protection settings or bypass exceptions.
- Which resources may each admitted participant access, and where is that permission enforced? boundary
- Which VPN changes may the agent perform, under whose authority, and with what verification and rollback conditions? action
Operation and failure behaviour Assesses live service state, workload suitability and behaviour when connectivity or protection changes.
A VPN can appear connected while traffic is unusable, bypassing protection or retaining obsolete access.
Live state and path quality
Distinguishes control-plane success from working data paths.
Usable connectivity
Record negotiation or provisioning state alongside representative end-to-end traffic tests and path constraints.
- What evidence shows that representative permitted flows work beyond a connected status indicator? measurement
- What latency, throughput, loss and effective MTU are observed for the intended workload and path? measurement
Failure and recovery
Captures traffic handling during outages, transitions and restoration.
Protection through transitions
Record whether traffic blocks, bypasses or reroutes during relevant failures and whether recovery restores the intended access boundary.
- During tunnel loss, gateway failure, rekeying or device network changes, which traffic blocks, bypasses or uses an alternate path? measurement
- Which authorised recovery action restores service, and how will the agent verify routes, DNS handling and revoked access afterward? action
Evidence and external alignment What the world already says about this thing, gathered so the model can be checked against it.
A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.
Reported evidence
Findings from the breadth pass, kept separate from the structural claims.
Check these first
Recalled without web access and unsourced; every item is a lead to verify.
- This describes the networking concept, including enterprise and provider VPNs, rather than only commercial consumer VPN services.
- Privacy can mean traffic isolation rather than encryption: provider-provisioned VPNs do not inherently encrypt customer traffic.
- The listed kinds use overlapping classification axes; deployment topology and network service layer are separate distinctions.
- Which of these check these first hold for the sense of virtual private network this model covers, and on what evidence? provenance
Kinds and varieties
Recalled without web access and unsourced; every item is a lead to verify.
- Remote-access VPN
- Site-to-site VPN
- Provider-provisioned Layer 2 VPN
- Provider-provisioned Layer 3 VPN
- Which of these kinds and varieties hold for the sense of virtual private network this model covers, and on what evidence? provenance
Identifiers and schemes
Recalled without web access and unsourced; every item is a lead to verify.
- BGP/MPLS VPN route distinguisher - 8-byte value commonly represented as administrator:assigned-number - Distinguishes otherwise overlapping address prefixes in BGP/MPLS VPN routing; it is not a universal VPN identifier.
- BGP route target extended community - Commonly represented as autonomous-system-number:assigned-number or IPv4-address:assigned-number - Controls route import and export in provider VPNs; multiple VPN routing instances may share a route target.
- Which of these identifiers and schemes hold for the sense of virtual private network this model covers, and on what evidence? provenance
Standards and regulation
Recalled without web access and unsourced; every item is a lead to verify.
- IETF RFC 4301, Security Architecture for the Internet Protocol: architecture for IPsec protection.
- IETF RFC 7296, Internet Key Exchange Protocol Version 2 (IKEv2): authentication and security association establishment for IPsec.
- IETF RFC 4364, BGP/MPLS IP Virtual Private Networks (VPNs): provider-provisioned IP VPN architecture.
- IETF RFC 4026, Provider Provisioned Virtual Private Network (VPN) Terminology: terminology for provider VPN services.
- Which of these standards and regulation hold for the sense of virtual private network this model covers, and on what evidence? provenance
Real-world use
Recalled without web access and unsourced; every item is a lead to verify.
- Giving remote workers access to organisational networks.
- Connecting branch offices and data centres across shared transport networks.
- Connecting private networks to cloud environments.
- Providing separate customer routing environments on telecommunications infrastructure.
- Protecting traffic between a user device and a VPN gateway when using untrusted access networks.
- Which of these real-world use hold for the sense of virtual private network this model covers, and on what evidence? provenance
Typical measurements
Recalled without web access and unsourced; every item is a lead to verify.
- Tunnel throughput - Deployment-dependent; constrained by underlying links, processing capacity and encapsulation overhead. - bit/s
- Added round-trip latency - No universal range; depends on gateway location, routing, congestion and processing. - ms
- Effective tunnel MTU - Usually below the underlying path MTU because encapsulation consumes packet space. - bytes
- Which of these typical measurements hold for the sense of virtual private network this model covers, and on what evidence? provenance
Failure modes and hazards
Recalled without web access and unsourced; every item is a lead to verify.
- Routing or DNS configuration errors can send traffic outside the intended tunnel.
- Compromised credentials, endpoints or gateways can permit unauthorised access.
- MTU mismatches and failed path MTU discovery can cause fragmentation or stalled connections.
- Overlapping addresses or incorrect route import and export policies can disrupt connectivity or breach isolation.
- Protection may end at the VPN gateway; a VPN does not inherently provide anonymity, trustworthy endpoints or encryption to the final destination.
- Which of these failure modes and hazards hold for the sense of virtual private network this model covers, and on what evidence? provenance
Neighbouring kinds and how to tell them apart
Recalled without web access and unsourced; every item is a lead to verify.
- Proxy server - A proxy intermediates selected application connections; a VPN provides logical network connectivity and routing or forwarding for participating endpoints.
- VLAN - A VLAN partitions a Layer 2 network into logical broadcast domains; it does not by itself establish VPN connectivity across an intervening network.
- IPsec - IPsec is a suite of network-layer security mechanisms that can implement a VPN; VPNs can also use other mechanisms.
- Tor - Tor uses multiple relays to limit linkage between origin and destination; a conventional VPN ordinarily concentrates trust in its gateway or provider.
- Which of these neighbouring kinds and how to tell them apart hold for the sense of virtual private network this model covers, and on what evidence? provenance
What the second pass must settle
- Which reference definitions should govern this registry entry, particularly the inclusion of provider-provisioned VPNs without payload encryption?
- Should an instance denote a complete private network, a service configuration or an individual connection, and how should those levels relate?
- Where should this entry draw its boundary with application-scoped VPN products, zero-trust network access and other selective access services?
- What evidence and observation periods are sufficient to substantiate isolation, traffic-coverage and operator logging claims?
- Which deployment-specific failure tests are required before an agent can judge that the VPN preserves its intended protection during transitions?