Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
WireGuard typically outperforms OpenVPN/IPsec substantially — strong answers give measured per-protocol figures on their own infrastructure, not generic protocol comparisons.
Look for granular (app/domain/subnet), group-scoped split tunneling with an auditable policy trail — all-or-nothing tunneling forces bad tradeoffs between performance and coverage.
Modern VPN access should be identity-first: SSO + SCIM + posture checks before connection, not a shared secret or standalone credential store.
Most buyers are on a VPN→ZTNA trajectory; a credible vendor offers a coexistence path under unified policy rather than pretending traditional VPN is the end state.
For enterprise: structured SIEM export of connection events. For privacy products: an independent no-logs audit with named auditor and date — self-asserted no-logs claims are not evidence.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for stated failover behavior (session survival vs. reconnect) and horizontal scaling, plus PoP geography matching your workforce.
VPN gateways are heavily targeted (multiple mass-exploited CVEs industry-wide in recent years) — strong answers show fast historical time-to-patch and a real disclosure process, not silence about their own CVE history.
Look for per-platform parity on the enforcement features (always-on, kill switch) — these often exist on Windows but silently missing on macOS/mobile.
Look for transparent, separately-itemized pricing for remote-access versus site-to-site use cases, since they scale on different dimensions (user count versus site count/bandwidth).
Posture-checking on unmanaged/BYOD devices is a materially harder and more valuable capability than assuming every connecting device is company-managed — ask for a concrete answer on BYOD-specific enforcement.
Ask directly for a real incident-response track record, not just a generic support-tier promise — a compromised VPN gateway is a severe, fast-moving incident class given its network position.
Remote-access and site-to-site VPN are related but distinct capabilities — a vendor should clarify this scope boundary explicitly rather than implying comprehensive coverage.
Lab-tested throughput on a low-latency local connection often doesn't reflect real remote-worker experience — press for a customer-validated figure on a realistic long-distance connection.
A VPN provider sitting inline on all customer traffic is itself significant infrastructure — insist on the real audit report, not just a logo or unqualified 'compliant' claim.
VPN traffic that bypasses the customer's other security controls (rather than being subject to the same inspection) is a real, sometimes-overlooked policy gap — ask for an explicit answer on how the two integrate.
Strong answers give a concrete, contractual outage-response SLA; a workforce fully dependent on VPN connectivity for remote work needs fast, guaranteed support, not best-effort self-service documentation.