Site-to-site VPN mistakes we still walk into
Overlapping subnets, stale tunnels, and a second office that was never documented.
ITSIGN Administrator · April 2, 2025 · 2 min read
Two offices, both using 192.168.1.0/24, and a tunnel that "worked until the new copier." Or a tunnel left up after the warehouse closed.
Draw the subnets. NAT if you must. Kill unused tunnels. Write down who owns the far end.
We run this as part of server and network management for firms with Toronto and Vancouver (or any second site) on the same estate.
Related reading
Do you still need a perimeter firewall?
Yes, if you have an office. No, it is not your only control. Identity is the new edge, and both still matter.
2 min read
Firewall change control that people will actually follow
If the process takes a week, someone will bypass it on a Friday. Make it short and recorded.
2 min read
Guest Wi-Fi that can see finance is not guest Wi-Fi
Cameras, visitors and the shop floor do not belong on the same VLAN as the accounting share.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
