What is a VPN concentrator?
A VPN concentrator is a hardware device that creates and manages a large number of remote VPN connections. Like a standard VPN, it encrypts network traffic and routes it through an intermediary server, but on a much larger scale.
Enterprise organizations use VPN concentrators to connect remote employees with their central corporate network securely. Unlike a standard VPN router, you can manage hundreds or even thousands of connections with a VPN concentrator, and network performance doesn’t degrade as you scale. VPN concentrators also authenticate each user and maintain the same security standards across the entire organization.
The VPN concentrator definition encompasses two forms of the solution — a dedicated VPN hardware and a high-capacity virtual instance that works the same way.
How does a VPN concentrator work?
A VPN concentrator connects remote employees to a corporate network through an encrypted VPN tunnel. This remote-access VPN handles many connections at once, and employees across the organization can use it no matter where they’re located.
- 1.A remote user (or device) initiates a connection.
- 2.The VPN concentrator authenticates the user (or device).
- 3.The VPN concentrator uses encryption to create a tunnel around the user’s network traffic.
- 4.The VPN concentrator assigns the user a virtual IP address and network settings.
- 5.The VPN concentrator continuously performs encryption, decryption, and key management for the session.
- 6.The VPN concentrator routes traffic between the remote user (or device) and the corporate network.
The VPN concentrator can also use load balancing to spread the traffic across different servers and prevent downtime. When a user disconnects from the VPN concentrator, it turns off the encrypted tunnel and removes the connection to the corporate network.
What is the main purpose of a VPN concentrator?
The main purpose of VPN concentrators is to allow remote access to a central corporate system and encrypt remote connections at scale.
Many enterprise organizations have large teams spread across multiple cities, states, and even countries. Many of these teams also use remote or hybrid work models, which means employees aren’t always in the office. With a VPN concentrator, these employees can work using a secure internet connection and access company resources even if they’re at home or in public, which helps protect valuable company data.
What does a VPN concentrator do?
A VPN concentrator handles the following functions centrally, so individual endpoints don’t need to manage their own encryption or authentication:
- Creating multiple encrypted VPN tunnels simultaneously within a single network
- Authenticating users who want to access the centralized system
- Encrypting and decrypting data passing between the corporate network and remote clients
- Assigning IP addresses to connected users
Pros and cons of a VPN concentrator
VPN concentrators are powerful tools for large businesses that need secure remote access to their systems. However, they have some potential drawbacks to be aware of. Keep in mind the following pros and cons if you’re considering a VPN concentrator.
Pros
The benefits of using a VPN concentrator for your business include:
All employee connections to the corporate network are encrypted, no matter where they’re working. This encryption helps keep sensitive company data safe from prying eyes on public or home networks.
A VPN concentrator can handle a large number of simultaneous connections.
Connections are encrypted automatically, without manual configuration by the user.
VPN concentrators help large teams maintain the same authentication and security standards across their entire organization with centralized control.
Cons
The drawbacks of using a VPN concentrator for your business include:
VPN concentrators require a significant upfront investment.
VPN concentrators require specialized IT skills to configure and maintain.
VPN concentrators are often too complex for small businesses, even if they have remote teams or are scaling quickly.
If a VPN concentrator fails, it could significantly disrupt business operations for your entire team.
Where is a VPN concentrator on the network?
Within the network, VPN concentrators are positioned between the firewall and the internal router, often inside a demilitarized zone (DMZ), which is the buffer zone between your external services and your sensitive internal servers.
Types of VPN concentrator encryption protocols
VPN concentrators can use several possible encryption protocols, so you’ll need to decide which one makes sense for your organization.
- IPsec is an efficient VPN protocol suite that is compatible with a wide range of devices. This protocol has both tunnel and transport modes, with tunnel mode as the standard for VPN concentrators.
- SSL/TLS protocols support browser-based and client-based VPN access. SSL is a legacy term, while TLS is today’s standard.
- L2TP is a legacy tunneling protocol usually combined with IPsec. It’s dated but still supported natively on many devices.
- OpenVPN is a protocol currently valued for its security and flexibility. It is commonly supported on VPN concentrators.
- WireGuard is a widely deployed VPN protocol valued for its speed. It’s supported by an increasing number of enterprise concentrators.
One VPN protocol that shouldn’t be considered for VPN concentrators (or any other VPN connections) is PPTP. It’s an outdated protocol that is insecure and could put your network at risk.
VPN concentrator vs. VPN router vs. business VPN
A VPN concentrator isn’t your only option for securing your business operations. Depending on your business’s size and security needs, a VPN router or a business VPN might be a better fit.
If your business is small and everyone works in the same office, a VPN router may be a better option. It’s much cheaper and easier to maintain than a VPN concentrator, but it can only accommodate a small number of users.
If you need a VPN for remote workers, a business VPN might be a better fit. It grants remote access and secure connections for companies of any size.
Take a look at the comparison table for more differences between VPN concentrators, VPN routers, and business VPNs:
| | VPN concentrator | VPN router | Business VPN |
|---|---|---|---|
Best for | Enterprises with 500+ remote users | Small offices with up to 50 users | Teams of any size |
Connection limit | Thousands of simultaneous connections | Dozens of simultaneous connections | Depends on subscription plan |
Setup complexity | High (requires specialist configuration) | Moderate | Low (simple software-based setup) |
Hardware required | Yes, dedicated appliance | Yes, physical router | No |
Cost | High, requires ongoing maintenance | Moderate | Depends on subscription plan |
Encryption | Usually AES-256 | Depends on the router | Usually AES-256 |
Example | Cisco Meraki, Aruba | Juniper Networks, Fortinet | NordLayer |
The trademarks displayed are for illustration purposes only. NordVPN is not affiliated with, sponsored by, or endorsed by their owners. NordVPN and NordLayer are developed by related entities, both part of the same corporate group.
Which solution is right for your business?
The right VPN solution depends on the size of your business, your security needs, and your budget. If you run a large enterprise with hundreds of remote connections happening simultaneously, a VPN concentrator is likely the right fit. For smaller businesses, a cloud-based network security solution that includes business VPN capabilities — like NordLayer — usually makes more sense. NordLayer offers some of the same benefits as VPN concentrators but without the high hardware and installation costs.
VPN concentrator vs. other solutions
A VPN concentrator is one of many solutions for secure remote work access. Here’s how it stacks up against other connection methods.
VPN concentrator vs. site-to-site VPN
A site-to-site VPN connects businesses with multiple offices in fixed locations, while a VPN concentrator is designed for remote access. Both site-to-site and remote access VPNs are helpful solutions for enterprise organizations, but they serve different purposes. Many enterprise organizations use both types of VPNs at the same time.
VPN concentrator vs. VPN client
A VPN client is a software program on a single device that connects the user to a server using an encrypted tunnel. A VPN concentrator is a centralized server-side device that manages thousands of VPN clients simultaneously. For remote users to access a VPN concentrator, they’ll need to have the right VPN client installed on their device.
VPN concentrator vs. firewall
A firewall is a security software or hardware that filters incoming network traffic and blocks suspicious activity. A VPN concentrator manages a large volume of encrypted VPN tunnels connecting to a single network.
Large organizations should have both a firewall and a VPN solution for security. The two tools complement each other, with the VPN concentrator usually placed behind the firewall.
Cloud and virtual VPN concentrators
Rather than buying expensive hardware, some organizations set up a cloud VPN concentrator. A virtual VPN concentrator serves the same purpose as the traditional hardware-based version.
In many cases, virtual VPN concentrators are more affordable because they require no upfront hardware. They’re also easier to scale as your business grows. They still need ongoing maintenance, but troubleshooting is usually easier. Furthermore, no single piece of hardware can bring everything down.
Modern alternatives to a VPN concentrator
While VPN concentrators work well for enterprise organizations with on-premises systems, other solutions may be more flexible for small businesses. Consider these alternatives to a VPN concentrator:
- ZTNA. A zero-trust network access (ZTNA) model only grants users access to the specific applications they are authorized to use and requires ongoing identification for added security.
- SASE. A secure access service edge (SASE) is a cloud architecture that moves the network edge closer to remote users, helping organizations maintain security.
- SDP. A software-defined perimeter (SDP) hides a remote network from the public and requires strict multi-factor authentication for remote access.
- Business VPN. A business VPN provides cloud-based secure remote access for small remote teams.
NordLayer opens in a new tab combines the business VPN benefits with several of these solutions. It’s a cloud-based network security solution that includes secure access to every app, on any device, with a ZTNA framework.