Topic 6.7
VPNs & Tunnels: WireGuard, IPsec & SSH Tunnels
In one line
A tunnel wraps packets inside other packets so they can cross a network that wouldn't carry them directly, and a VPN is an encrypted tunnel. WireGuard is a small, modern VPN using public keys. IPsec is the long-standing standard for site-to-site links, including cloud VPN gateways. SSH tunnels forward single ports for quick, ad-hoc access. Tunnels add headers, so they lower the MTU (Topic 4.6).
Think of it like this
Posting a letter inside a sealed courier pouch. The courier only sees the pouch's address (the tunnel endpoints), not the letter inside or who it's really for.
Words you'll meet
New words in this topic, in plain English. Come back here whenever one feels fuzzy.
- Tunnel
- Carrying packets inside other packets between two endpoints.
- VPN
- Virtual Private Network: an encrypted tunnel connecting networks or devices.
- WireGuard
- A modern, minimal VPN protocol using public-key peers over UDP.
- IPsec
- A suite of protocols for encrypted IP tunnels, common for site-to-site links.
- AllowedIPs
- In WireGuard, the address ranges routed to a peer and accepted from it.
- SSH local forwarding
- Using
ssh -Lto send a local port's traffic through an SSH server to another host. - Split tunnel
- Sending only some traffic (private ranges) through the VPN and the rest directly.
Step by step
01A WireGuard link to the kitchen partner
Tiffin needs a private link from its Mumbai VPC to a partner kitchen's network (10.20.0.0/16). Each side generates a key pair and puts the other's public key in its config. Only traffic to the listed AllowedIPs goes through the tunnel.
[Interface]
Address = 10.99.0.1/30
ListenPort = 51820
PrivateKey = <contents of /etc/wireguard/private.key> # never commit this
MTU = 1420
[Peer]
# partner kitchen gateway
PublicKey = 9mQ2...partner-public-key...=
Endpoint = 198.51.100.24:51820
AllowedIPs = 10.99.0.2/32, 10.20.0.0/16 # tunnel address + partner network
PersistentKeepalive = 25 # keeps NAT mappings open02Site-to-site IPsec with a cloud VPN gateway
For the head office, Tiffin uses AWS Site-to-Site VPN: AWS runs two IPsec tunnels (for redundancy) to the office router, with BGP exchanging routes. The office router config comes from AWS's downloadable template, and both tunnels should show UP.
03A quick SSH tunnel
Priya needs to run one query against the private database from her laptop. Instead of opening the database to the internet, she forwards a local port through the bastion host. The connection exists only while the SSH session runs.
Break it on purpose
Errors are the best teachers. Make each change, read the error, guess what went wrong, then reveal the answer.
Break #1
The tunnel that swallowed the internet
Arjun sets AllowedIPs = 0.0.0.0/0 on his laptop's WireGuard peer to 'make sure everything works'.
Myth vs fact
Myth
A VPN makes everything behind it trusted.
Fact
Once connected, a compromised laptop can reach the whole network. Limit what VPN users can reach and authenticate services individually (zero-trust access).
Pro corner
Extra depth for experienced readers. New to this? Skip it for now and come back later.
- ▸
WireGuard is quiet by design: it doesn't answer unauthenticated packets, so port scans can't even tell it's there. For debugging,
wg show(handshake times and transfer counters) andtcpdump -ni eth0 udp port 51820tell you whether encrypted packets flow at all.
Remember this
- 1
Tunnel = encapsulation: the original packet becomes the payload of an outer packet between two tunnel endpoints. VPN = a tunnel that also encrypts and authenticates.
- 2
WireGuard: peers identified by public keys, a few lines of config, runs over UDP (default port 51820), built into the Linux kernel.
AllowedIPssays which destination addresses go through each peer. - 3
IPsec: the standard for site-to-site VPNs and cloud VPN gateways (AWS Site-to-Site VPN). Uses IKE to negotiate keys and ESP to carry encrypted traffic, with UDP 500/4500 for setup and NAT traversal.
- 4
Remote-access VPNs (WireGuard, OpenVPN, commercial ones) connect laptops to private networks. Many teams now use identity-aware proxies or 'zero trust' access instead, which check user and device per request rather than trusting the whole network.
- 5
SSH tunnels:
ssh -L 5433:db.internal:5432 bastionforwards a local port through a server you can SSH to. Handy for one-off database access, but not a replacement for a proper VPN or access proxy. - 6
Every tunnel adds overhead (around 60–80 bytes), so set the tunnel MTU (WireGuard defaults to 1420) or clamp MSS.
Explain it without notes
What does WireGuard's AllowedIPs do?
When is an SSH tunnel the right tool, and when isn't it?
Practice
Forward a remote web service on port 8080 to your laptop through a bastion.
Check whether a WireGuard tunnel is actually passing traffic.
Trade-offs
- ↔
WireGuard is simple and fast but has fewer enterprise features (no built-in user management). IPsec is interoperable with every vendor and cloud but complex to configure. VPNs grant broad network access, while zero-trust proxies grant per-application access at the cost of more setup.
Done when you can
I can explain tunnels and VPNs.
I can configure a WireGuard peer with sensible AllowedIPs.
I can use an SSH tunnel for one-off access.