Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Vpn Architect

ASecurity

Design secure remote-access VPN architecture — protocol choice, authentication, segmentation, and migration to zero-trust access.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgosecurityperformance

Works with

cli

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill vpn-architect --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vpn Architect?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Vpn Architect
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-vpn-architect/badge)](https://www.skillsdirectory.com/skills/aicodedecode-vpn-architect)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: vpn-architect
description: Design secure remote-access VPN architecture — protocol choice, authentication, segmentation, and migration to zero-trust access.
category: security
---

## Overview

VPNs extend the trusted network to remote users and sites — which is exactly why their security posture matters so much: a VPN concentrator is one of the most attacked assets in any estate, and a compromised VPN credential historically meant broad network access. Modern practice hardens traditional VPNs while migrating toward zero-trust network access (ZTNA) where it fits.

This skill covers defensive VPN architecture: protocol and product selection, strong authentication, segmentation, logging, and the pragmatic path toward ZTNA.

VPN architecture sits at an awkward transition: still essential for many use cases, increasingly supplemented by zero-trust access. The pragmatic stance is to harden what you have while deliberately migrating what you can — running a neglected VPN 'until we do zero trust someday' is how appliances become the initial-access vector in someone else's incident report.

## When to use

- Designing or replacing remote-access VPN for a hybrid/remote workforce.
- Hardening an existing VPN (patches, MFA, config review) after incidents or audit findings.
- Segmenting VPN users so a compromised endpoint does not mean the whole network.
- Evaluating ZTNA as a VPN complement or replacement.

## Core concepts

- **The VPN is a high-value target:** internet-facing, authentication-bearing, and historically vulnerability-prone. Patch aggressively, monitor auth logs, and treat it as crown-jewel infrastructure.
- **Protocols:** WireGuard and IKEv2/IPsec are the modern defaults (strong crypto, good performance); OpenVPN remains solid; avoid PPTP/L2TP-with-PSK and SSL-VPN products with poor patch histories unless risk-accepted.
- **Authentication:** MFA mandatory, ideally phishing-resistant; machine certificates plus user auth for managed devices; no split-tunnel exceptions without justification.
- **Least-privilege network access:** VPN users should reach only what their role needs — per-group ACLs, segmented zones — not "the whole corporate LAN." Full-tunnel by default for managed devices.
- **Logging:** authentication attempts, session start/stop, bytes transferred, and endpoint posture — shipped to the SIEM with alerts on anomalies (impossible travel, off-hours admin access).
- **ZTNA direction:** identity- and device-aware per-application access instead of network-level tunnels. Evaluate for new deployments; migrate high-risk use cases first.

- **Always-on VPN for managed devices.** Removes the user decision entirely — the device is either connected and protected or it is not on the network. Pair with device compliance checks.
- **Endpoint posture before access.** Require disk encryption, OS patch level, and EDR presence as VPN admission criteria — a compromised endpoint should not get a tunnel.
- **Split tunneling governance.** Every split-tunnel exception needs a documented business reason and periodic review; default-deny the bypass, not the tunnel.

## Practical workflow

1. **Define access requirements:** who connects (employees, contractors, admins), from what devices, to which resources. This drives segmentation and auth design.
2. **Select and harden the platform:** current, supported software; hardened config (strong ciphers, no legacy protocols); management interface not internet-exposed; tested backup/failover.
3. **Enforce strong auth:** MFA for all users; certificates for managed devices; lockout and rate-limiting on auth; disable or tightly control any legacy auth methods.
4. **Segment:** role-based access groups mapped to firewall zones; admins get a separate, more restricted path; contractors get time-boxed, resource-scoped access.
5. **Monitor:** SIEM alerts for brute force, impossible travel, concurrent sessions, and new-device enrollments; quarterly access reviews of VPN entitlements.
6. **Plan the ZTNA path:** pilot ZTNA for a high-risk app or contractor population; measure user experience and security outcomes; expand where it wins, keep VPN where tunnels are genuinely needed (site-to-site, legacy).

### VPN hardening checklist

- [ ] Patched to current; management interface not internet-facing
- [ ] MFA enforced for all users; weak auth methods disabled
- [ ] Strong protocols/ciphers only; legacy protocols removed
- [ ] Role-based segmentation; no flat "VPN = LAN" access
- [ ] Full-tunnel default for managed devices; split-tunnel justified and reviewed
- [ ] Auth and session logging to SIEM with anomaly alerts
- [ ] Quarterly entitlement reviews; contractor access time-boxed

### Sustaining the practice

- Review VPN access entitlements quarterly alongside all privileged access
- Track appliance vulnerabilities as P1 patch items with dedicated SLAs
- Measure ZTNA pilot outcomes to build the migration business case
- Audit split-tunnel exceptions annually — they accumulate silently

### Metrics that prove it works

- Patch latency on VPN appliances (days from vendor release)
- MFA enforcement coverage % of VPN users
- Authentication-anomaly alerts triaged within SLA
- % of remote access migrated to ZTNA (where targeted)

## Common pitfalls

- **Unpatched VPN appliances.** VPN vulnerabilities are routinely exploited within days of disclosure. Patch like your network depends on it — it does.
- **Flat access.** VPN into the whole LAN turns one phished credential into a network-wide incident. Segment by role.
- **MFA gaps.** "MFA except for these legacy clients" is the hole attackers find. Close it or document and mitigate the risk explicitly.
- **Split-tunnel sprawl.** Convenience split tunneling exposes the endpoint to the open internet while connected. Default to full tunnel; exception with justification.
- **No session monitoring.** Authentication without anomaly detection misses credential-reuse and session-hijack patterns.
- **Treating VPN as the forever answer.** For app-level remote access, ZTNA usually offers better least-privilege and UX. Reassess periodically.
- **Site-to-site VPNs forgotten in reviews.** Everyone hardens remote-access VPN; the decade-old site-to-site tunnels with static PSKs get ignored. Inventory them too.
- **Vendor-default credentials on appliances.** Still found in real estates. Change them during deployment and verify in audits.
- **Contractor VPN accounts that never expire.** Time-box every non-employee account at creation; expiry should be automatic, renewal deliberate.
- **No bandwidth or session anomaly monitoring.** Data exfiltration over VPN looks like normal traffic without baselines. Monitor session patterns, not just logins.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →