STACKIT focuses on the combination of flexibility and security. VPN operation does not take place as an isolated service, but is part of a closed, private network within the STACKIT Cloud.
In concrete terms, this means
- No direct Internet access required - connection via STACKIT Private Networking
- Integration into dedicated virtual private clouds (VPCs) with firewall rules
- Use of VPN gateways to connect external networks to the STACKIT infrastructure
- Support for IP whitelisting, role-based access control and detailed logging
- Optional use of own VPN solutions (e.g. OpenVPN or IPsec) on STACKIT VMs
This architecture protects not only the data, but also the communication and the systems themselves - regardless of whether they are used by internal employees, external partners or machines.
VPN: Best practices
A VPN can make your network communication considerably more secure - provided it is set up carefully. Below you will find practical recommendations for successful VPN operation with STACKIT:
Secure VPN access: Use strong authentication mechanisms - such as certificates or two-factor authentication. This provides additional protection for your connection.
Update the VPN server regularly: Whether OpenVPN or IPsec - always keep your software up to date to avoid known security vulnerabilities.
Use network segmentation: Limit access rights for individual devices, users or services. This prevents individual attack vectors from jeopardizing the entire network.
Enable monitoring & logging: Keep an eye on important metrics such as connection duration, data traffic or suspicious activities - for example via STACKIT Monitoring.
Design mobile use consciously: Make sure that Android and Apple apps also use the VPN tunnel correctly. Many VPN clients offer an always-on mode - for continuous protection, even when switching networks.