Z+

L48

Client-to-site, site-to-site and split/full tunnels

Cram this first — memory hook

Client-to-site = one person enters; site-to-site = two offices connect. Split/full = which traffic uses the path.

Exam trap

Full tunnel is not the same term as Internet Protocol Security tunnel mode. One concerns traffic selection; the other packet encapsulation.

The slide facts

Client-to-site connects an individual remote device; site-to-site connects networks through gateways. The client diagram contrasts split and full tunneling.

Close the book — check

Does site-to-site normally mean every employee manually connects their own Virtual Private Network client to the other office?

Scenario

A student working remotely should reach the school file server through the Virtual Private Network while personal streaming stays on the home connection. Which routing approach fits?

Retrieve it

Authored for this desk. Not claimed to be CompTIA exam questions. Options shuffle; the correct choice stays correct.

Does site-to-site normally mean every employee manually runs a Virtual Private Network client to the other office?

If you have time — extra

A client-to-site Virtual Private Network lets one remote device connect to an organization's gateway. A site-to-site links networks, such as Cape Town and Johannesburg offices, through their gateways; ordinary users may not run a separate client for each cross-site connection. Full tunneling routes the configured general traffic through the organization's path, enabling centralized controls but increasing gateway/link load. Split tunneling sends only selected destinations through the while other traffic uses another path, such as the local internet connection. This can improve efficiency but needs deliberate security and routing policy. Neither label alone tells you that all devices are authorized or all Domain Name System behavior is correct. The split/full distinction is separate from transport/tunnel mode: they answer different questions.

Walkthrough

Identify whether the endpoint is a user device or network gateway, decide which destinations should use the , apply routes//access policy, and test both protected and intentionally unprotected paths.

Supporting video

Watch after the notes. Watching does not mark the topic practiced.

VPNs— Client-to-site, clientless, split and full tunnels.

Z+ · the last-lap desk · N10-009

Search

Lessons, ports, glossary