---
tags:
- networking
- l1
- flashcard-deck
- vpn
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [VPN & Tunneling](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
vpn/a6a8828f0a11	vpn	easy	vpn, wireguard, basics	What is WireGuard and why is it considered the modern VPN standard?	"WireGuard is a VPN protocol built into the Linux kernel (5.6+) with only ~4000 lines of code. It uses UDP, identifies peers by public keys (not certificates), uses ChaCha20 + Poly1305 encryption, and is silent by design (does not respond to unauthenticated packets). Its simplicity and performance make it the modern default.\n\nRemember: ""VPN = encrypted tunnel over untrusted network."" Two types: site-to-site (connect offices) and remote access (connect users).\n\nWho made it: Jason Donenfeld created WireGuard. It was merged into Linux kernel 5.6 in March 2020.\n\nNumber anchor: ~4000 lines of code vs OpenVPN\'s ~100,000. Smaller codebase = easier to audit for security."	training/library/topics/vpn-tunneling/primer.md
vpn/2a8e1703de25	vpn	easy	vpn, tunnels, layers	What is the difference between a Layer 2 (TAP) and Layer 3 (TUN) VPN tunnel?	"Layer 2 tunnels carry Ethernet frames, making both sides appear on the same LAN (broadcasts and ARP work). Layer 3 tunnels carry IP packets, with each side on its own subnet (no broadcasts). Most VPNs are Layer 3. Layer 2 is used for bridging sites or legacy protocols requiring broadcast traffic.\n\nName origin: TUN = ""tunnel"" (L3 IP packets), TAP = ""network tap"" (L2 Ethernet frames). The device names /dev/tunX and /dev/tapX reflect this."	training/library/topics/vpn-tunneling/primer.md
vpn/a5ab01f78521	vpn	easy	vpn, ssh, tunneling	What is SSH local port forwarding and when would you use it?	ssh -L 5432:db.internal:5432 bastion.example.com forwards local port 5432 through the bastion to reach db.internal:5432. Use it for quick access to services behind firewalls without setting up a full VPN. It is not meant for production use but is invaluable for ad-hoc database or service access.\n\nExample: `ssh -L 3000:grafana.internal:3000 bastion` lets you access Grafana at localhost:3000 through the bastion.	training/library/topics/vpn-tunneling/primer.md
vpn/52afd05e7e56	vpn	medium	vpn, wireguard, allowedips	What does AllowedIPs do in WireGuard and why does it confuse people?	AllowedIPs serves two purposes: for outgoing traffic, it determines which destination IPs are routed through the peer; for incoming traffic, it determines which source IPs are accepted from the peer. Setting 0.0.0.0/0 creates a full tunnel (all traffic), while 10.0.0.0/24 creates a split tunnel (only VPN subnet traffic).\n\nAnalogy: AllowedIPs is like a routing table and firewall rule combined — it controls both where traffic goes and what\'s accepted.	training/library/topics/vpn-tunneling/primer.md
vpn/65d1079e0f75	vpn	medium	vpn, openvpn, protocol	Why should you prefer UDP over TCP for OpenVPN, and when is TCP necessary?	UDP has lower latency and avoids TCP-over-TCP meltdown (where retransmissions on both the tunnel and inner connection cause exponential delays). TCP is only needed when UDP is blocked by firewalls, and can run on port 443 to look like HTTPS traffic. Always try UDP first.\n\nName origin: TCP-over-TCP meltdown was described by Olaf Titz (2001). Both layers try to retransmit lost packets, causing exponential delays.	training/library/topics/vpn-tunneling/primer.md
vpn/1eb3e1d31793	vpn	medium	vpn, ipsec, phases	What are the two phases of IPSec tunnel establishment?	"Phase 1 (IKE SA): peers authenticate, negotiate encryption algorithms, and establish a secure management channel. Phase 2 (IPSec SA / Child SA): peers negotiate data encryption parameters, define what traffic to protect via selectors, and create the actual tunnel for data transfer using ESP.\n\nRemember: ""Phase 1 = management tunnel (IKE SA), Phase 2 = data tunnel (IPSec SA)."" Think: handshake first, then data."	training/library/topics/vpn-tunneling/primer.md
vpn/5c62823cdfd8	vpn	medium	vpn, split-tunnel, full-tunnel	What is the difference between split tunneling and full tunneling, and when should you use each?	"Full tunnel routes all traffic through the VPN (WireGuard AllowedIPs = 0.0.0.0/0) — simpler but slower for internet. Split tunnel routes only specific subnets (AllowedIPs = 10.0.0.0/24) — faster but some traffic is unprotected. Use split for developer access to internal resources; use full for compliance requirements or untrusted networks.\n\nRemember: ""Full tunnel = everything through VPN (secure but slow). Split tunnel = only internal traffic through VPN (fast but some traffic unprotected)."""	training/library/topics/vpn-tunneling/primer.md
vpn/24d11a545273	vpn	hard	vpn, ipsec, modes	What is the difference between IPSec transport mode and tunnel mode?	"Transport mode preserves the original IP header and encrypts only the payload — used for host-to-host communication. Tunnel mode encrypts the entire original packet and wraps it in a new IP header — used for site-to-site VPN (most common). Tunnel mode hides the original source and destination from observers on the transit network.\n\nRemember: ""Transport = host-to-host (encrypts payload). Tunnel = site-to-site (encrypts entire packet + new header)."" Tunnel mode is far more common."	training/library/topics/vpn-tunneling/primer.md
vpn/6bb8b87588ee	vpn	hard	vpn, ssh, advanced	How does SSH dynamic port forwarding (SOCKS proxy) work and how does autossh improve SSH tunnels?	ssh -D 1080 bastion.example.com creates a SOCKS5 proxy on localhost:1080 that routes all configured traffic through the bastion. autossh wraps SSH with auto-reconnect on failure (autossh -M 0 -o ServerAliveInterval=60 -fN -L ...), monitoring the connection and restarting it if it drops.\n\nUnder the hood: SOCKS5 proxy supports both TCP and UDP. Configure browsers or curl with `--proxy socks5h://localhost:1080` (the h means DNS goes through the proxy too).	training/library/topics/vpn-tunneling/primer.md
vpn/56154eddb55d	vpn	hard	vpn, comparison, protocols	Compare WireGuard, OpenVPN, IPSec, and SSH tunnels across performance, complexity, and use cases.	WireGuard: excellent performance, very simple, ~4000 LOC, UDP only — best for general VPN. OpenVPN: good performance, moderate complexity, UDP or TCP — best for enterprise with PKI/LDAP. IPSec: good performance, complex, in-kernel — best for site-to-site with hardware routers. SSH tunnels: fair performance, simple, TCP only — best for quick access to individual services.\n\nInterview tip: WireGuard for greenfield, OpenVPN for legacy PKI environments, IPSec for site-to-site with hardware routers, SSH tunnels for ad-hoc access.	training/library/topics/vpn-tunneling/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Tailscale & Zero Trust Networking](../../../../library/topics/tailscale/index.md) (Topic Pack, L2) — VPN & Tunneling
- [VPN & Tunneling](../../../../library/topics/vpn-tunneling/index.md) (Topic Pack, L2) — VPN & Tunneling

<!-- wiki:related:end -->
