Replacing Your VPN: From Classic VPN to Zero Trust and Mesh VPN

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Want to replace your corporate VPN but the target model is not settled yet? WZ-IT's Secure Access Check assesses your current remote access and delivers target model, product choice, migration path and a fixed-price quote for the switch, from €1,490 excl. VAT. The amount is credited towards the switch. Book a free initial consultation
The classic corporate VPN comes from a time when staff, servers and applications sat in one shared network. A gateway at the network edge checks the sign-in and then opens access to an entire segment. Today staff work on the move, applications run in several data centres, and external service providers need access to individual systems. At the same time, the VPN gateways themselves are among the most frequently attacked systems.
This guide explains when replacing the VPN makes sense, which target models exist, how self-hosted and cloud solutions differ, and in which order the switch works without interrupting operations. As of October 2026.
Key points at a glance:
- Zero trust is an architecture principle, not a product. Access is granted per application or target and by identity, not by network location.
- VPN gateways from several major vendors have repeatedly appeared in CISA's catalogue of actively exploited vulnerabilities since 2023.
- There are four target models: cloud ZTNA, a self-hosted mesh VPN, plain WireGuard for sites, and publishing individual applications.
- The replacement runs group by group in parallel operation. The old gateway is switched off last.
- The inventory decides the outcome, not the product choice.
Table of Contents
- Why businesses replace their VPN
- Vulnerabilities in VPN gateways since 2023
- Zero trust: what the principle requires
- The four target models compared
- Product choice: self-hosted or cloud service
- Inventory: what must be clear before replacing
- Migration path: from parallel operation to switch-off
- NIS2 and access control
- Common misconceptions
- Our approach at WZ-IT
- Further guides
Why businesses replace their VPN
The reasons fall into four groups. Usually two or three come together.
| Trigger | What lies behind it |
|---|---|
| Attack surface | The gateway is reachable from the internet and must process data before sign-in. Vulnerabilities at this point lead straight into the internal network. |
| Flat network | After sign-in, a user often reaches an entire segment, not just the applications they need. A compromised account or device has correspondingly wide reach. |
| Vendor changes | Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 on all FortiGate models, and settings are not carried over during the upgrade (Fortinet, release notes 7.6.3). Microsoft deprecated DirectAccess in June 2024 (Microsoft Learn, deprecated features). |
| New requirements | Multi-factor sign-in, access for service providers to individual systems, NIS2 evidence, sites across several data centres. |
A vendor change forces a reconfiguration anyway. If you have to reconfigure, it makes sense to first check whether the current model is still the right one.
Vulnerabilities in VPN gateways since 2023
The following selection shows vulnerabilities in remote-access gateways that the US cybersecurity agency CISA added to its Known Exploited Vulnerabilities (KEV) catalogue. CVSS scores are from the NVD; differing vendor scores are noted.
| CVE | Product | Type | CVSS | In KEV since |
|---|---|---|---|---|
| CVE-2023-4966 | Citrix NetScaler ADC and Gateway | information disclosure ("Citrix Bleed") | 7.5 (Citrix: 9.4) | 18 Oct 2023 |
| CVE-2023-46805 | Ivanti Connect Secure, Policy Secure | authentication bypass | 8.2 | 10 Jan 2024 |
| CVE-2024-21887 | Ivanti Connect Secure, Policy Secure | command injection, chained with CVE-2023-46805 | 9.1 | 10 Jan 2024 |
| CVE-2024-21762 | Fortinet FortiOS SSL VPN | out-of-bounds write | 9.8 | 9 Feb 2024 |
| CVE-2024-3400 | Palo Alto PAN-OS GlobalProtect | command injection with root privileges | 10.0 | 12 Apr 2024 |
| CVE-2025-0282 | Ivanti Connect Secure before 22.7R2.5 | unauthenticated code execution | 9.0 | 8 Jan 2025 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | memory overread | 7.5 (Citrix, CVSS 4.0: 9.3) | 10 Jul 2025 |
| CVE-2025-20362 | Cisco Secure Firewall ASA and FTD | access to VPN endpoints without authentication | 8.6 (Cisco: 6.5) | 25 Sep 2025 |
| CVE-2025-20333 | Cisco Secure Firewall ASA and FTD | code execution in the VPN web server | 9.9 (Cisco) | 25 Sep 2025 |
For two of these cases CISA issued emergency directives to US federal agencies: ED 24-01 of 19 January 2024 on Ivanti and ED 25-03 of 25 September 2025 on Cisco. The Cisco campaign is described in Cisco ASA, ArcaneDoor and CVE-2025-20362, the Fortinet situation in FortiGate SSL VPN risk 2026.
The table is not a statement about any single vendor. It shows a pattern: a device at the internet edge that accepts connections before sign-in and processes complex protocols is a valuable target, regardless of vendor.
Zero trust: what the principle requires
The US standards institute NIST describes zero trust in SP 800-207 (August 2020) in one sentence: no implicit trust is granted based solely on physical or network location. Sitting in the company network does not automatically grant authorisation.
CISA's Zero Trust Maturity Model 2.0 (April 2023) structures implementation in five pillars: identity, devices, networks, applications and workloads, and data. The German BSI states in its zero trust position paper 2023 that zero trust approaches secure application access better preventively and reduce the impact of attacks.
For remote access this translates into four requirements:
- Identity before access: sign-in through a central identity service with multi-factor, such as Keycloak or authentik.
- Access per target: policies define which group reaches which application or system, not which network.
- Device posture: access only from devices that meet defined conditions, such as operating system version or active antivirus.
- Logging: a traceable record of who accessed what and when.
A detailed definition is in the knowledge article What is ZTNA?.
The four target models compared
| Criterion | Cloud ZTNA | Mesh VPN, self-hosted | WireGuard site-to-site | Publishing an application |
|---|---|---|---|---|
| Principle | connection through a vendor platform, access per application | devices connect directly with encryption, a control plane distributes keys and policies | fixed tunnels between sites or data centres | a single web application reachable through a reverse proxy with sign-in |
| Examples | Zscaler, Cloudflare, Twingate | NetBird, Headscale with Tailscale clients | WireGuard | NetBird reverse proxy, reverse proxy with identity service |
| Open port at the internet edge | no | only control plane and relay, no network access without sign-in | yes, one UDP port per gateway | yes, HTTPS |
| Where control and data run | at the vendor | with you or your operator | with you | with you |
| Fits | businesses without in-house operations that accept a cloud service | users, servers and sites with data sovereignty requirements | fixed connections between sites | a few web applications for external users |
| Limits | vendor dependency, per-user pricing | own operations or an operator needed | no user identity, no per-group policies | web applications only |
In practice the models are combined. A common setup is a mesh VPN for staff, administrators and service providers, complemented by WireGuard tunnels between data centres and individual published web applications. How internal services become reachable without a VPN client is described in NetBird reverse proxy.
Product choice: self-hosted or cloud service
The fundamental question is: where do the control plane and connection data live? With cloud ZTNA both are at the vendor; with self-hosted solutions they are on your own infrastructure or at an operator of your choice.
| Product | Licence | Self-hostable | Paid tier (example) | Notable |
|---|---|---|---|---|
| NetBird | client BSD-3-Clause, management, signal and relay AGPL-3.0 | yes, fully | Commercial Starter EUR 2,000 per year for up to 50 users and 500 devices | identity service integration, policies, device posture and logging in the free edition |
| Headscale | BSD-3-Clause | yes | none | control plane for Tailscale clients, a single tailnet |
| Tailscale | vendor cloud service | control plane only via Headscale | Standard USD 8, Premium USD 18 per user per month | Personal free for up to 6 users |
| WireGuard | GPLv2 (kernel) | yes | none | in the Linux kernel since 5.6, no user management |
| OpenVPN Access Server | commercial licence | yes | billed per connection | free for up to 2 connections |
Sources: GitHub, NetBird, NetBird pricing, self-hosted, GitHub, Headscale, Tailscale pricing, WireGuard, WireGuard 1.0.0 for Linux 5.6, OpenVPN Access Server pricing. As of October 2026.
Some points that often get lost in comparisons:
- NetBird Community Edition can be used without limits on users and devices, according to the vendor. Commercial Starter adds high availability, SCIM provisioning, device approvals and email support. What that means in numbers is covered in NetBird self-hosting licence. The current release is NetBird v0.80.0 of 1 October 2026.
- Headscale covers a single tailnet according to its README and targets personal use or small open-source organisations. The current release is v0.29.4 of 23 September 2026.
- Per-user pricing grows with every person and every service provider. At which size a fixed price pays off is shown in Tailscale pricing 2026.
Six mesh VPN solutions with architecture, licence and pricing are compared in Mesh VPN comparison 2026.
Inventory: what must be clear before replacing
Most problems in a VPN replacement do not come from the new product but from access paths nobody had on the list. The inventory therefore first clarifies what today's VPN actually does.
| Area | Questions |
|---|---|
| User groups | Who connects today: staff, administrators, service providers, machine vendors? With which devices and operating systems? |
| Targets | Which applications, servers and networks does each group reach? Which of them does it really need? |
| Protocols | Web applications, RDP, SSH, SMB shares, databases, industrial protocols? Are there applications that expect fixed IP addresses? |
| Sites | Which sites, data centres and cloud environments are connected site-to-site? |
| Identity | Is there a central identity service (Entra ID, Active Directory, Keycloak), and is multi-factor set up? |
| Devices | Are devices centrally managed? Which conditions should a device meet for access? |
| Logging | Which evidence is needed, and where should the logs be stored? |
| Dependencies | Which systems rely on the VPN, such as printing, telephony, licence servers or monitoring? |
The inventory produces an access matrix: group, target, protocol, condition. It is the template for the policies in the new system and, at the same time, the documentation for evidence.
Migration path: from parallel operation to switch-off
The switch follows a fixed sequence. The old VPN and the new model run in parallel until the last group has moved.
- Prepare the identity service. Create groups or take them over from the directory, enable multi-factor for all groups.
- Build the control plane. Self-hosted on your own infrastructure or at the operator, with backups and monitoring. Highly available if required.
- Transfer policies from the access matrix. Grant each group only the targets it needs. Add device conditions.
- Switch the pilot group. Usually IT itself. Experience with clients, name resolution and applications feeds into the guide for everyone.
- Move groups one after another. Staff, administrators, service providers, each with a short guide. If problems occur, the old VPN remains the fallback.
- Connect sites. Switch site-to-site tunnels to WireGuard or to the mesh VPN; the knowledge article on WireGuard site connectivity covers the details.
- Switch off the old gateway. Once the logs show no more connections, access is deactivated, the port forwards at the internet edge are closed and the licences are cancelled.
Step-by-step guides exist for the most common starting points: migrate OpenVPN to NetBird and migrate FortiGate SSL VPN to NetBird.
NIS2 and access control
The NIS2 directive requires in Article 21(2), among other things, access control policies (point i) and "the use of multi-factor authentication or continuous authentication solutions" (point j). In Germany, the NIS2 implementation act of 2 December 2025 entered into force on 6 December 2025 (BGBl. 2025 I No. 301); the requirement from point j is in section 30(2) no. 10 BSIG.
NIS2 does not prescribe a product or an access model. An identity-based model with per-group policies, multi-factor and logging does, however, deliver exactly the evidence that is asked for: who has access, on what basis, and who accessed what and when.
Not legal advice. Whether and how NIS2 applies to your business should be clarified with your legal or compliance advisers. Trademarks belong to their owners.
Common misconceptions
| Misconception | Correct is |
|---|---|
| "Zero trust is something you buy as a product." | Zero trust is an architecture principle. Products implement parts of it; the target model and policies come from the inventory. |
| "A mesh VPN is automatically zero trust." | Only with an identity service, per-target policies, device posture and logging. |
| "WireGuard replaces the corporate VPN." | WireGuard is the tunnel protocol. User management, key distribution and policies are needed on top. |
| "Self-hosting NetBird requires licence fees." | The Community Edition is free and unlimited. Commercial Starter adds functions such as high availability and SCIM. |
| "After the next patch the gateway is secure." | Patches close known vulnerabilities. The gateway remains an internet-facing entry point into the network. |
| "The switch needs one cut-over date for everyone." | The old and new models run in parallel, and groups move one at a time. |
| "NIS2 bans classic VPNs." | NIS2 requires access control and multi-factor, not a specific product. |
Our approach at WZ-IT
WZ-IT supports the replacement from inventory to operation. Every step has a defined result.
- Secure Access Check. The Secure Access Check costs from EUR 1,490 net. The result is the inventory with access matrix, the target model, the product choice with reasoning, the migration path and a fixed-price quote for the VPN migration sprint. If a cloud service or another product fits better, the recommendation says so. The amount is credited towards the switch if you commission it within 6 months on the same topic.
- VPN migration sprint. In the VPN migration sprint from EUR 2,490 net we implement identity integration, control plane and policies, move the pilot group, groups, service providers and sites, and switch off the old gateway.
- Operation. With Managed NetBird from EUR 349.90 net per month we take care of updates, backups, monitoring and support for the control plane. All remote access services are listed under VPN services.
WZ-IT is an official NetBird reseller. You can obtain Commercial Starter and Enterprise licences through WZ-IT. When WZ-IT operates NetBird, support beyond the vendor's email support is included.
Further guides
- FortiGate SSL VPN risk 2026, why exposed VPN appliances become a liability.
- Cisco ASA, ArcaneDoor and CVE-2025-20362, how a campaign against VPN gateways unfolded.
- Mesh VPN comparison 2026, six solutions with architecture, licence and pricing.
- NetBird self-hosting licence, what Commercial Starter unlocks.
- Tailscale pricing 2026, when self-hosting is cheaper.
- What is ZTNA?, the terms in the knowledge section.
- VPN services, all WZ-IT remote access services.
Replace your VPN without interrupting operations. We assess your remote access, recommend target model and product, and move group by group until the old gateway is switched off. Book a free initial consultation
Sources
- NIST SP 800-207, Zero Trust Architecture
- CISA, Zero Trust Maturity Model
- BSI, Zero Trust (German)
- NVD, CVE-2023-4966
- NVD, CVE-2023-46805
- NVD, CVE-2024-21887
- NVD, CVE-2024-21762
- NVD, CVE-2024-3400
- NVD, CVE-2025-0282
- NVD, CVE-2025-5777
- NVD, CVE-2025-20362
- NVD, CVE-2025-20333
- CISA, Advisory AA23-325A
- CISA, Emergency Directive 24-01
- CISA, Emergency Directive 25-03
- Fortinet, FortiOS 7.6.3 release notes: SSL VPN tunnel mode replaced with IPsec VPN
- Microsoft Learn, Deprecated features for Windows client
- GitHub, NetBird
- NetBird pricing, self-hosted
- GitHub, Headscale
- Tailscale pricing
- WireGuard
- WireGuard 1.0.0 for Linux 5.6
- OpenVPN Access Server pricing
- Directive (EU) 2022/2555 (NIS2)
- BGBl. 2025 I No. 301, German NIS2 implementation act
Replace your corporate VPN, with a target model and migration path
We assess your current remote access, recommend a target model and a product, and move user groups over step by step without interrupting day-to-day operations.
Frequently Asked Questions
Answers to important questions about this topic
A classic remote-access VPN gives users access to a network segment after sign-in. Replacing it means moving to a model that grants access per application or target and based on identity, such as zero trust network access (ZTNA) or a mesh VPN with access policies. The old gateway keeps running in parallel until all user groups have moved, and is then switched off.
No. Zero trust is an architecture principle. NIST SP 800-207 (August 2020) describes it as granting no implicit trust based solely on network location. It can be implemented with cloud services or with self-hosted software such as NetBird combined with an identity service.
Not automatically. A mesh VPN connects devices directly through encrypted tunnels, usually based on WireGuard. It becomes a zero trust implementation only with sign-in through an identity service, policies per group and target, device posture checks and logging. NetBird includes these functions in its free Community Edition.
Because they are reachable from the internet and can be attackable before sign-in. Since 2023, the US agency CISA has added several vulnerabilities in VPN gateways from Fortinet, Ivanti, Palo Alto Networks, Citrix and Cisco to its catalogue of actively exploited vulnerabilities, including CVE-2024-3400 with CVSS 10.0. For Ivanti and Cisco, CISA issued emergency directives (ED 24-01, ED 25-03).
The Community Edition is free with no limit on users or devices. Commercial Starter costs EUR 2,000 per year for up to 50 users and 500 devices and adds high availability, SCIM provisioning, device approvals and email support. Enterprise for 50+ users is available on request (as of October 2026). WZ-IT is an official NetBird reseller.
For fixed connections between sites, often yes. WireGuard has been part of the Linux kernel since 5.6 and is lean. For many users, however, it lacks sign-in through an identity service, policies per group, key distribution and logging. A control plane such as NetBird or Headscale takes over these tasks.
Only to a limited extent. Headscale is an open-source implementation of the Tailscale control server under BSD-3-Clause and, according to its README, covers a single tailnet, intended for personal use or small open-source organisations. For businesses with several groups, tenants or support needs, NetBird or Tailscale itself is usually the better fit.
No. The old VPN and the new model run in parallel. Groups are moved one after another, starting with a pilot group. The gateway is switched off only once all groups, sites and service providers have moved and it no longer shows connections.
No. NIS2 does not prescribe a product. Article 21(2) of the directive requires, among other things, access control policies (point i) and multi-factor authentication solutions (point j). In Germany, the NIS2 implementation act has applied since 6 December 2025. An identity-based access model makes evidence easier but is not the only option. Not legal advice.
Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 on all FortiGate models and replaced it with IPsec VPN, which can also run over TCP port 443. Existing settings are not carried over during the upgrade. For businesses using SSL VPN this is a reconfiguration anyway, and therefore a good moment to review the target model.
DirectAccess has been deprecated since June 2024 and will be removed in a future Windows release. Microsoft recommends migrating to Always On VPN. Anyone still using DirectAccess faces a replacement in any case.
Older applications, machine controllers or RDP servers can be included as well. Access is then granted at network level per target and group, and multi-factor sign-in happens when the client connects through the identity service. The application itself does not need to change.
With an inventory: which user groups access what, which sites are connected, which service providers have access and which identity service exists. WZ-IT's Secure Access Check delivers the inventory, target model, product choice, migration path and a fixed-price quote for the switch, from EUR 1,490 net.

Written by
Timo Wevelsiep
Co-Founder & CEO
Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.
LinkedInLet's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





