In short
VPN server setup is building the infrastructure that links branches to each other (site-to-site) and remote staff to the company network (remote access) through encrypted tunnels. It is for companies with more than one location or with people working remotely. CybUp chooses IPsec, WireGuard or OpenVPN to fit the need, sets up the VPN on a firewall, Windows or Linux, adds MFA and access restrictions, and hands it over documented.
What is a VPN server setup, and what types of VPN are there?
A VPN server setup covers two different jobs. A site-to-site VPN joins the networks of two locations with a permanent tunnel, so a user at the branch reaches the file server or ERP at head office without doing anything. A remote access VPN connects a single user’s laptop or phone to the company network; the user signs in through a client app.
Both can run on the same device, but the design questions are different. For site-to-site, the address plan and routing decide everything; for remote access, it is authentication, MFA and what each user is allowed to reach. We write up the two requirements separately first, then bring them together on one platform.
How do you set up a site-to-site VPN between offices?
A site-to-site VPN is usually built as an IPsec (IKEv2) tunnel between the firewalls or routers at each end. IKEv2 is the standard key exchange protocol defined by the IETF in RFC 7296 (RFC 7296), which is why devices from different vendors can share a tunnel. The encryption and integrity algorithms, the Diffie-Hellman group and the networks allowed into the tunnel must be defined identically at both ends.
The problem we run into most often is not technical but a planning one: both locations using the same internal address range. If head office and the branch both use 192.168.1.0/24, a leftover from a home router, traffic will not reach the right place even with the tunnel up. In that case we move the branch to a new address block or set up a NAT tunnel as a temporary fix. With more than two branches and dual lines, managing the tunnels on FortiGate SD-WAN makes line outages far easier to handle.
“This document describes version 2 of the Internet Key Exchange (IKE) protocol. IKE is a component of IPsec used for performing mutual authentication and establishing and maintaining Security Associations (SAs).”
Which VPN protocol is best for remote access?
The number of users, the client devices and the authentication requirements decide the protocol. The general picture is below.
A word of warning: if you use FortiGate, FortiOS 7.6.3 removed SSL VPN tunnel mode, and remote access has to move to IPsec VPN (Fortinet release note). We split that migration into user groups and start with a pilot group. On OpenVPN we apply hardening steps such as certificate keys of at least 2048 bits and extra protection layers like tls-auth (OpenVPN: Hardening).
- IPsec (IKEv2): standard and built into most firewalls and operating systems; the default choice for business remote access
- WireGuard: fast and lean; it works with key pairs rather than user authentication, so it suits a small number of administrators and devices (WireGuard)
- OpenVPN: TLS-based and flexible; easy to integrate with Active Directory and MFA
- SSL VPN / browser-based access: for cases where no client can be installed, with a limited scope
How do you add MFA to a VPN?
A VPN protected only by a username and password can be opened with a single leaked password, so we treat MFA as the default for remote access. How it is done depends on the platform: FortiToken, or SAML with Microsoft Entra ID, on FortiGate; TOTP-based authentication over RADIUS on pfSense and OpenVPN; and on Windows, NPS integrated with Microsoft Entra MFA.
Alongside MFA, tying users to Active Directory groups means a leaver’s VPN access ends the moment their account is disabled. For group-based access we work hand in hand with Active Directory setup. The accounts team, for example, reaches only the accounting server and the software team only the test environment; we never write one broad rule along the lines of “VPN users → entire internal network”.
“When combined with Remote Authentication Dial-In User Service (RADIUS) services and the Network Policy Server (NPS) extension for Microsoft Entra multifactor authentication, VPN authentication can use strong MFA.”
Split tunnel or full tunnel: which should you use?
With split tunnelling only traffic bound for the company network goes through the VPN, and the rest of the user’s internet traffic leaves over their own connection; with full tunnelling everything goes through the company firewall. Split tunnelling takes load off the head office internet line and the VPN server, and sends cloud traffic such as Microsoft 365 and video calls to the user by the shortest route.
Full tunnelling, on the other hand, keeps web filtering and company security policies in force while the user works from home. We decide according to the company’s security policy. Most of the time a mix works best: split tunnelling for company resources, full tunnelling for high-risk roles or for laptops connecting from networks outside the company.
Should the VPN server run on Windows, Linux or the firewall?
In most companies the best place for the VPN is the firewall that already faces the internet: FortiGate, pfSense or MikroTik. VPN users’ traffic then passes through the same rule set, and there is no separate server to maintain. For setup details, see pfSense installation and MikroTik configuration.
On Windows Server, Microsoft’s Always On VPN connects the device automatically, even before the user signs in; profiles are deployed with Intune or PowerShell, and it supports domain-joined, Microsoft Entra joined and workgroup devices (Microsoft: Always On VPN). On Linux, a WireGuard or OpenVPN server on Ubuntu is a sensible option for reaching cloud servers or for small teams.
What you receive
- Location and address plan, with overlapping networks resolved
- Site-to-site IPsec tunnels and routing
- Remote access VPN with client profiles and setup instructions
- MFA and access rules based on Active Directory groups
- Split or full tunnel design
- VPN logs, test results and a handover document
How we work
- 1
Free review
We map out your locations, address plans, user numbers and the applications people need to reach.
- 2
Design
We settle the protocol, the device that will run the VPN, the MFA method and the access matrix, and put them to you for sign-off.
- 3
Build
We configure the tunnels and the remote access server and prepare the client profiles.
- 4
Pilot
We trial it with a small group of users, fix whatever comes up, then roll it out to everyone.
- 5
Handover
We hand over the user guide and the technical documentation, and watch the connection logs over the first few days.
Frequently asked questions
How long does a VPN server setup take?
A tunnel between two locations plus remote access for 20–30 users is usually finished within a few working days. Overlapping address plans, many branches or a migration away from SSL VPN take longer.
How much does a VPN setup cost?
We give a written quote after reviewing the scope, and the review is free. The number of locations and users, MFA and your existing devices determine the scope.
Is our current firewall good enough for VPN?
In most cases, yes. We check the device’s VPN throughput and concurrent user limit against your user count, and if it falls short we tell you so in writing.
Can staff connect from their phones?
Yes. IPsec, WireGuard and OpenVPN all have iOS and Android clients. We recommend separately limiting which resources phones can reach.
If someone’s home broadband is slow, will the VPN be slow too?
Yes; a VPN cannot be faster than the user’s own connection. Split tunnelling, and using remote desktop instead of opening files over the VPN, make a noticeable difference in that case.
How should VPN logs be kept under KVKK?
Logs showing who connected, when and from which address should be kept for both security and accountability under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698). We set the retention period and access rights according to your company policy; the framework is on our KVKK technical measures page.
How do we cut off VPN access when someone leaves?
If the VPN is tied to Active Directory or Entra ID groups, disabling the account is enough. With key-based setups such as WireGuard, that user’s key has to be removed from the server, and we add this step to your offboarding process.
Do you set up VPNs remotely?
Yes. Most VPN work can be done remotely. At locations in Istanbul we work on-site when needed.