Skip to content
Tech Interview Prep home
Technical interview guide

VPNs & Tunneling

Encapsulating traffic inside another protocol to create a private, often encrypted path across an untrusted network.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed
Relevant for
Network Engineer

Scope: Current IETF IPsec/IKEv2/NAT-T/GRE/L3VPN/VXLAN/PMTUD/UDP, NIST IPsec, WireGuard, OpenVPN 2.6, and TLS 1.3 references reviewed 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Compare IPsec transport and tunnel modes.

QA-2

Trace an IKEv2 negotiation failure.

QA-3

Choose a tunnel and protection mechanism for an overlay.

QA-4

Diagnose traffic that bypasses an apparently active IPsec tunnel.

QA-5

Walk me through how Phase 1 and Phase 2 negotiations differ in purpose, exchange structure, and security parameters across IKEv1 and IKEv2.

QA-6

Specify cryptographic proposals and rekey policy.

QA-7

Troubleshoot a VPN that fails only behind NAT.

QA-8

Calculate and validate VPN MTU.

QA-9

Diagnose a size-dependent VPN failure.

QA-10

Compare route-based and policy-based site-to-site VPNs.

QA-11

Deploy a full-tunnel default route without recursive failure.

QA-12

Threat-model full versus split remote-access VPN.

QA-13

Connect two sites with overlapping address space.

QA-14

Prevent a tenant route leak in an L3VPN.

QA-15

Secure a VXLAN overlay across an untrusted underlay.

QA-16

Design liveness and failover for a site-to-site VPN.

QA-17

Tune and troubleshoot anti-replay behavior.

QA-18

Validate VPN rekey under load.

QA-19

Design high availability for VPN gateways.

QA-20

Design leak-proof always-on remote access.

QA-21

Design zero-trust controls around a remote-access VPN.

QA-22

Design VPN observability and audit.

QA-23

Capacity-plan VPN gateways.

QA-24

Troubleshoot an established tunnel with no application connectivity.

QA-25

Review and validate a VPN deployment end to end.