Networking
Part 5 of 6 · Private NetworkingTunneling — VPN, WireGuard, SSH tunnels, Cloudflare Tunnel / ngrok patterns
Tunnels connect people, CI, and datacenters to private networks without publishing every service. Site-to-site routes CIDRs. Client VPN and WireGuard attach users. Reverse tunnels and SSH remote forwards invert the firewall and need an identity gate.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
What are you connecting?
Prefer
Match the tunnel to the principal
Offices and datacenters get site-to-site or a private circuit. People get Client VPN, WireGuard with an IdP, or an identity-aware reverse tunnel. A laptop debug session stays on SSM port-forward.
- Site-to-site is IPsec to a virtual private gateway or transit gateway.
- Cloudflare Tunnel or ngrok publishes an app without a public origin IP.
- You still own routes, identity, and the failure domain.
Alternative
One SSH reverse tunnel for everything
Fine for break-glass. Poor as an access plane. A remote forward on a shared host is an accidental publish. Client VPN for CI burns licenses. Full tunnel without capacity sends the internet through the cloud.
- Split tunnel can bypass egress controls.
- Stolen laptop plus no MFA is a foothold.
- Provider dependency is the trade for an outbound-only edge.
Overview
Tunnels connect humans, CI, and datacenters to private networks without publishing every service. The classic trade-off is identity, scale, protocol support, and threat model: site-to-site versus client VPN versus WireGuard versus reverse tunnels versus SSH local, remote, and dynamic forwards.
You should be able to:
- Pick a mode from "whole CIDR?", "how many users?", "HTTP only?", "must be IPsec?".
- Draw browser, identity edge, outbound connector, internal service.
- Say what breaks when the tunnel is trusted because it is encrypted.
Modes
- AWS Site-to-Site VPN. IPsec to a virtual private gateway or transit gateway. Office and datacenter CIDRs. BGP optional.
- AWS Client VPN. Managed OpenVPN-compatible access. AD or SAML. Per-user routes.
- WireGuard. Modern cryptography. You operate keys and the control plane, or you buy Tailscale or run Headscale.
- SSH tunnels. Fine for break-glass. Poor as the org-wide access plane.
- Cloudflare Tunnel / ngrok. Outbound-only connector. Put an IdP at the edge.
- Direct Connect / ExpressRoute. Private circuits when VPN throughput or jitter is not enough.
Zero-trust reverse tunnel
The private connector dials out. The user authenticates at the edge. The established tunnel is the only path back. Protect connector identity and the IdP. The relay is a high-value control point.
Flow
- 1
1 Browser or kubectl
- next2 Tunnel edge plus IdP
- 2
2 Tunnel edge plus IdP
- next3 Connector outbound
- 3
3 Connector outbound
- next4 Internal HTTP or SSH
- 4
4 Internal HTTP or SSH
Lesson map
Tunneling — VPN, WireGuard, SSH tunnels, Cloudflare Tunnel / ngrok patterns
Tunnels connect people, CI, and datacenters to private networks without publishing every service. Site-to-site routes CIDRs. Client VPN and WireGuard attach users. Reverse tunnels and SSH remote forwards invert the firewall and need an identity gate.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB office["Office CIDR"] vgw["VGW or TGW"] vpc["VPC subnets"] office -->|IPsec| vgw vgw -->|Private CIDR| vpc
Site-to-site versus client versus reverse
Site-to-site moves packets between CIDRs. Client VPN attaches a user and then routes. A reverse tunnel is application-centric: the connector exposes a service, not a whole network.
Sequence
- 1
Office CIDR
Site-to-Site IPsec
- 2
Office CIDR → VGW or TGW
IPsec
- 3
VGW or TGW → VPC subnets
Private CIDR routes
- 4
Office CIDR
Client VPN is per user
- 5
Office CIDR
Reverse tunnel is an app
Pattern stories
- Hybrid ERP in a datacenter. Site-to-site to a transit gateway, with prefix propagation. Not a laptop VPN.
- Eighty remote engineers need kubectl. Client VPN or Tailscale plus an IdP. Not a wide-open API on the internet.
- Partner demo. Cloudflare Tunnel plus access OTP. Tear it down after.
- Laptop debug of an admin UI. SSM port-forward. No persistent tunnel. That path is the SSM lesson.
Threat notes
Reverse tunnels invert firewall assumptions. SSH remote forward on a shared bastion is close to an unintended public publish. Split-tunnel Client VPN can bypass the egress controls you built with NAT and endpoints. WireGuard key distribution is the real product. Treat it like a PKI.
Publishing an HTTP app to the world with a load balancer is the next lesson, not a tunnel. North-south ALB and Ingress stay in ingress.
Sandbox: pick a tunnel (Python)
Press Run. Snippets must be self-contained — no network, files, or native modules.
Sandbox: SSH forward labels (TypeScript)
Press Run. Snippets must be self-contained — no network, files, or native modules.
Local forward (-L) reaches a remote host through a jump. Remote forward (-R) exposes a local service on the far side. Dynamic (-D) is a SOCKS proxy for ad-hoc tools. None of these is an org access plane.
GCP and Azure
Cloud VPN and Cloud Interconnect, Azure VPN Gateway and ExpressRoute, play the site-to-site and private-circuit roles. IAP and private relay patterns are the reverse-tunnel analogues: identity at the edge, outbound from the private side.
Pitfalls
For an on-prem ERP, a contractor kubectl session, a two-day partner demo, and a one-hour database debug, name the tunnel and what you tear down when the story ends.
Interview Q&A
Site-to-site versus Client VPN?
Answer
Site-to-site connects network ranges with CIDR routing. Client VPN connects users: an endpoint plus authentication, then routes. Different identity model and blast radius.
Why Cloudflare Tunnel instead of opening 443 to an ALB?
Answer
The connector is outbound-only. You can put DDoS protection and an IdP at the edge and avoid a public origin IP. The trade-off is provider dependency. If you do want a public load balancer, that is north-south ingress, not this page.
Is WireGuard a site-to-site replacement?
Answer
Technically yes. Operationally you must build HA, routing, and identity, or buy a control plane such as Tailscale or run Headscale. The paper is the crypto. Key distribution is the system.
When is Direct Connect worth it?
Answer
Stable high throughput, consistent latency, and hybrid compliance needs that VPN jitter or the internet path cannot meet. It is not the first answer for five engineers.
What is dangerous about SSH -R?
Answer
It publishes a local service onto the remote host. On a shared bastion that is an accidental public entry. Use it as break-glass, with a person accountable for tearing it down.
How is a reverse tunnel different from NAT?
Answer
NAT lets private workloads start outbound flows to the internet. A reverse tunnel keeps an outbound session so an authorized party can reach back to a specific service. The relay becomes part of your trust boundary.
Why is split tunnel a security decision?
Answer
Only some prefixes use the tunnel. The rest of the laptop traffic uses the local network and can bypass the egress controls you set in the VPC.
When is SSM port-forward enough?
Answer
One operator, one private port, no standing tunnel, AWS-native target. Do not scale that into a workforce VPN. See Session Manager.
What does BGP change on site-to-site?
Answer
Optional dynamic prefix exchange instead of only static routes. You still design overlap-free CIDRs. Overlap is the VPC lesson.
Who authenticates on a zero-trust tunnel?
Answer
The user at the IdP on the edge, and the connector with its own credential. Network location is not the permission.
What fails if CI uses the human Client VPN?
Answer
License count, device posture, and a shared profile that outlives the job. Give CI a narrower identity.
What would you say no to?
Answer
A full-tunnel VPN with no capacity plan, WireGuard peers with no revocation, and an SSH remote forward documented as the production API.