WZ-IT Logo

Replacing Your VPN: From Classic VPN to Zero Trust and Mesh VPN

Timo Wevelsiep
Timo Wevelsiep
•
#VPN #ZeroTrust #ZTNA #MeshVPN #NetBird #WireGuard #NIS2

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Replacing Your VPN: From Classic VPN to Zero Trust and Mesh VPN

Want to replace your corporate VPN but the target model is not settled yet? WZ-IT's Secure Access Check assesses your current remote access and delivers target model, product choice, migration path and a fixed-price quote for the switch, from €1,490 excl. VAT. The amount is credited towards the switch. Book a free initial consultation

The classic corporate VPN comes from a time when staff, servers and applications sat in one shared network. A gateway at the network edge checks the sign-in and then opens access to an entire segment. Today staff work on the move, applications run in several data centres, and external service providers need access to individual systems. At the same time, the VPN gateways themselves are among the most frequently attacked systems.

This guide explains when replacing the VPN makes sense, which target models exist, how self-hosted and cloud solutions differ, and in which order the switch works without interrupting operations. As of October 2026.

Key points at a glance:

  1. Zero trust is an architecture principle, not a product. Access is granted per application or target and by identity, not by network location.
  2. VPN gateways from several major vendors have repeatedly appeared in CISA's catalogue of actively exploited vulnerabilities since 2023.
  3. There are four target models: cloud ZTNA, a self-hosted mesh VPN, plain WireGuard for sites, and publishing individual applications.
  4. The replacement runs group by group in parallel operation. The old gateway is switched off last.
  5. The inventory decides the outcome, not the product choice.

Table of Contents

  1. Why businesses replace their VPN
  2. Vulnerabilities in VPN gateways since 2023
  3. Zero trust: what the principle requires
  4. The four target models compared
  5. Product choice: self-hosted or cloud service
  6. Inventory: what must be clear before replacing
  7. Migration path: from parallel operation to switch-off
  8. NIS2 and access control
  9. Common misconceptions
  10. Our approach at WZ-IT
  11. Further guides

Why businesses replace their VPN

The reasons fall into four groups. Usually two or three come together.

Trigger What lies behind it
Attack surface The gateway is reachable from the internet and must process data before sign-in. Vulnerabilities at this point lead straight into the internal network.
Flat network After sign-in, a user often reaches an entire segment, not just the applications they need. A compromised account or device has correspondingly wide reach.
Vendor changes Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 on all FortiGate models, and settings are not carried over during the upgrade (Fortinet, release notes 7.6.3). Microsoft deprecated DirectAccess in June 2024 (Microsoft Learn, deprecated features).
New requirements Multi-factor sign-in, access for service providers to individual systems, NIS2 evidence, sites across several data centres.

A vendor change forces a reconfiguration anyway. If you have to reconfigure, it makes sense to first check whether the current model is still the right one.

Vulnerabilities in VPN gateways since 2023

The following selection shows vulnerabilities in remote-access gateways that the US cybersecurity agency CISA added to its Known Exploited Vulnerabilities (KEV) catalogue. CVSS scores are from the NVD; differing vendor scores are noted.

CVE Product Type CVSS In KEV since
CVE-2023-4966 Citrix NetScaler ADC and Gateway information disclosure ("Citrix Bleed") 7.5 (Citrix: 9.4) 18 Oct 2023
CVE-2023-46805 Ivanti Connect Secure, Policy Secure authentication bypass 8.2 10 Jan 2024
CVE-2024-21887 Ivanti Connect Secure, Policy Secure command injection, chained with CVE-2023-46805 9.1 10 Jan 2024
CVE-2024-21762 Fortinet FortiOS SSL VPN out-of-bounds write 9.8 9 Feb 2024
CVE-2024-3400 Palo Alto PAN-OS GlobalProtect command injection with root privileges 10.0 12 Apr 2024
CVE-2025-0282 Ivanti Connect Secure before 22.7R2.5 unauthenticated code execution 9.0 8 Jan 2025
CVE-2025-5777 Citrix NetScaler ADC and Gateway memory overread 7.5 (Citrix, CVSS 4.0: 9.3) 10 Jul 2025
CVE-2025-20362 Cisco Secure Firewall ASA and FTD access to VPN endpoints without authentication 8.6 (Cisco: 6.5) 25 Sep 2025
CVE-2025-20333 Cisco Secure Firewall ASA and FTD code execution in the VPN web server 9.9 (Cisco) 25 Sep 2025

For two of these cases CISA issued emergency directives to US federal agencies: ED 24-01 of 19 January 2024 on Ivanti and ED 25-03 of 25 September 2025 on Cisco. The Cisco campaign is described in Cisco ASA, ArcaneDoor and CVE-2025-20362, the Fortinet situation in FortiGate SSL VPN risk 2026.

The table is not a statement about any single vendor. It shows a pattern: a device at the internet edge that accepts connections before sign-in and processes complex protocols is a valuable target, regardless of vendor.

Zero trust: what the principle requires

The US standards institute NIST describes zero trust in SP 800-207 (August 2020) in one sentence: no implicit trust is granted based solely on physical or network location. Sitting in the company network does not automatically grant authorisation.

CISA's Zero Trust Maturity Model 2.0 (April 2023) structures implementation in five pillars: identity, devices, networks, applications and workloads, and data. The German BSI states in its zero trust position paper 2023 that zero trust approaches secure application access better preventively and reduce the impact of attacks.

For remote access this translates into four requirements:

  • Identity before access: sign-in through a central identity service with multi-factor, such as Keycloak or authentik.
  • Access per target: policies define which group reaches which application or system, not which network.
  • Device posture: access only from devices that meet defined conditions, such as operating system version or active antivirus.
  • Logging: a traceable record of who accessed what and when.

A detailed definition is in the knowledge article What is ZTNA?.

The four target models compared

Criterion Cloud ZTNA Mesh VPN, self-hosted WireGuard site-to-site Publishing an application
Principle connection through a vendor platform, access per application devices connect directly with encryption, a control plane distributes keys and policies fixed tunnels between sites or data centres a single web application reachable through a reverse proxy with sign-in
Examples Zscaler, Cloudflare, Twingate NetBird, Headscale with Tailscale clients WireGuard NetBird reverse proxy, reverse proxy with identity service
Open port at the internet edge no only control plane and relay, no network access without sign-in yes, one UDP port per gateway yes, HTTPS
Where control and data run at the vendor with you or your operator with you with you
Fits businesses without in-house operations that accept a cloud service users, servers and sites with data sovereignty requirements fixed connections between sites a few web applications for external users
Limits vendor dependency, per-user pricing own operations or an operator needed no user identity, no per-group policies web applications only

In practice the models are combined. A common setup is a mesh VPN for staff, administrators and service providers, complemented by WireGuard tunnels between data centres and individual published web applications. How internal services become reachable without a VPN client is described in NetBird reverse proxy.

Product choice: self-hosted or cloud service

The fundamental question is: where do the control plane and connection data live? With cloud ZTNA both are at the vendor; with self-hosted solutions they are on your own infrastructure or at an operator of your choice.

Product Licence Self-hostable Paid tier (example) Notable
NetBird client BSD-3-Clause, management, signal and relay AGPL-3.0 yes, fully Commercial Starter EUR 2,000 per year for up to 50 users and 500 devices identity service integration, policies, device posture and logging in the free edition
Headscale BSD-3-Clause yes none control plane for Tailscale clients, a single tailnet
Tailscale vendor cloud service control plane only via Headscale Standard USD 8, Premium USD 18 per user per month Personal free for up to 6 users
WireGuard GPLv2 (kernel) yes none in the Linux kernel since 5.6, no user management
OpenVPN Access Server commercial licence yes billed per connection free for up to 2 connections

Sources: GitHub, NetBird, NetBird pricing, self-hosted, GitHub, Headscale, Tailscale pricing, WireGuard, WireGuard 1.0.0 for Linux 5.6, OpenVPN Access Server pricing. As of October 2026.

Some points that often get lost in comparisons:

  • NetBird Community Edition can be used without limits on users and devices, according to the vendor. Commercial Starter adds high availability, SCIM provisioning, device approvals and email support. What that means in numbers is covered in NetBird self-hosting licence. The current release is NetBird v0.80.0 of 1 October 2026.
  • Headscale covers a single tailnet according to its README and targets personal use or small open-source organisations. The current release is v0.29.4 of 23 September 2026.
  • Per-user pricing grows with every person and every service provider. At which size a fixed price pays off is shown in Tailscale pricing 2026.

Six mesh VPN solutions with architecture, licence and pricing are compared in Mesh VPN comparison 2026.

Inventory: what must be clear before replacing

Most problems in a VPN replacement do not come from the new product but from access paths nobody had on the list. The inventory therefore first clarifies what today's VPN actually does.

Area Questions
User groups Who connects today: staff, administrators, service providers, machine vendors? With which devices and operating systems?
Targets Which applications, servers and networks does each group reach? Which of them does it really need?
Protocols Web applications, RDP, SSH, SMB shares, databases, industrial protocols? Are there applications that expect fixed IP addresses?
Sites Which sites, data centres and cloud environments are connected site-to-site?
Identity Is there a central identity service (Entra ID, Active Directory, Keycloak), and is multi-factor set up?
Devices Are devices centrally managed? Which conditions should a device meet for access?
Logging Which evidence is needed, and where should the logs be stored?
Dependencies Which systems rely on the VPN, such as printing, telephony, licence servers or monitoring?

The inventory produces an access matrix: group, target, protocol, condition. It is the template for the policies in the new system and, at the same time, the documentation for evidence.

Migration path: from parallel operation to switch-off

The switch follows a fixed sequence. The old VPN and the new model run in parallel until the last group has moved.

  1. Prepare the identity service. Create groups or take them over from the directory, enable multi-factor for all groups.
  2. Build the control plane. Self-hosted on your own infrastructure or at the operator, with backups and monitoring. Highly available if required.
  3. Transfer policies from the access matrix. Grant each group only the targets it needs. Add device conditions.
  4. Switch the pilot group. Usually IT itself. Experience with clients, name resolution and applications feeds into the guide for everyone.
  5. Move groups one after another. Staff, administrators, service providers, each with a short guide. If problems occur, the old VPN remains the fallback.
  6. Connect sites. Switch site-to-site tunnels to WireGuard or to the mesh VPN; the knowledge article on WireGuard site connectivity covers the details.
  7. Switch off the old gateway. Once the logs show no more connections, access is deactivated, the port forwards at the internet edge are closed and the licences are cancelled.

Step-by-step guides exist for the most common starting points: migrate OpenVPN to NetBird and migrate FortiGate SSL VPN to NetBird.

NIS2 and access control

The NIS2 directive requires in Article 21(2), among other things, access control policies (point i) and "the use of multi-factor authentication or continuous authentication solutions" (point j). In Germany, the NIS2 implementation act of 2 December 2025 entered into force on 6 December 2025 (BGBl. 2025 I No. 301); the requirement from point j is in section 30(2) no. 10 BSIG.

NIS2 does not prescribe a product or an access model. An identity-based model with per-group policies, multi-factor and logging does, however, deliver exactly the evidence that is asked for: who has access, on what basis, and who accessed what and when.

Not legal advice. Whether and how NIS2 applies to your business should be clarified with your legal or compliance advisers. Trademarks belong to their owners.

Common misconceptions

Misconception Correct is
"Zero trust is something you buy as a product." Zero trust is an architecture principle. Products implement parts of it; the target model and policies come from the inventory.
"A mesh VPN is automatically zero trust." Only with an identity service, per-target policies, device posture and logging.
"WireGuard replaces the corporate VPN." WireGuard is the tunnel protocol. User management, key distribution and policies are needed on top.
"Self-hosting NetBird requires licence fees." The Community Edition is free and unlimited. Commercial Starter adds functions such as high availability and SCIM.
"After the next patch the gateway is secure." Patches close known vulnerabilities. The gateway remains an internet-facing entry point into the network.
"The switch needs one cut-over date for everyone." The old and new models run in parallel, and groups move one at a time.
"NIS2 bans classic VPNs." NIS2 requires access control and multi-factor, not a specific product.

Our approach at WZ-IT

WZ-IT supports the replacement from inventory to operation. Every step has a defined result.

  1. Secure Access Check. The Secure Access Check costs from EUR 1,490 net. The result is the inventory with access matrix, the target model, the product choice with reasoning, the migration path and a fixed-price quote for the VPN migration sprint. If a cloud service or another product fits better, the recommendation says so. The amount is credited towards the switch if you commission it within 6 months on the same topic.
  2. VPN migration sprint. In the VPN migration sprint from EUR 2,490 net we implement identity integration, control plane and policies, move the pilot group, groups, service providers and sites, and switch off the old gateway.
  3. Operation. With Managed NetBird from EUR 349.90 net per month we take care of updates, backups, monitoring and support for the control plane. All remote access services are listed under VPN services.

WZ-IT is an official NetBird reseller. You can obtain Commercial Starter and Enterprise licences through WZ-IT. When WZ-IT operates NetBird, support beyond the vendor's email support is included.

Further guides

Replace your VPN without interrupting operations. We assess your remote access, recommend target model and product, and move group by group until the old gateway is switched off. Book a free initial consultation

Sources

Enquiry

Replace your corporate VPN, with a target model and migration path

We assess your current remote access, recommend a target model and a product, and move user groups over step by step without interrupting day-to-day operations.

Where are you with the replacement?

How should we get back to you?

Frequently Asked Questions

Answers to important questions about this topic

A classic remote-access VPN gives users access to a network segment after sign-in. Replacing it means moving to a model that grants access per application or target and based on identity, such as zero trust network access (ZTNA) or a mesh VPN with access policies. The old gateway keeps running in parallel until all user groups have moved, and is then switched off.

No. Zero trust is an architecture principle. NIST SP 800-207 (August 2020) describes it as granting no implicit trust based solely on network location. It can be implemented with cloud services or with self-hosted software such as NetBird combined with an identity service.

Not automatically. A mesh VPN connects devices directly through encrypted tunnels, usually based on WireGuard. It becomes a zero trust implementation only with sign-in through an identity service, policies per group and target, device posture checks and logging. NetBird includes these functions in its free Community Edition.

Because they are reachable from the internet and can be attackable before sign-in. Since 2023, the US agency CISA has added several vulnerabilities in VPN gateways from Fortinet, Ivanti, Palo Alto Networks, Citrix and Cisco to its catalogue of actively exploited vulnerabilities, including CVE-2024-3400 with CVSS 10.0. For Ivanti and Cisco, CISA issued emergency directives (ED 24-01, ED 25-03).

The Community Edition is free with no limit on users or devices. Commercial Starter costs EUR 2,000 per year for up to 50 users and 500 devices and adds high availability, SCIM provisioning, device approvals and email support. Enterprise for 50+ users is available on request (as of October 2026). WZ-IT is an official NetBird reseller.

For fixed connections between sites, often yes. WireGuard has been part of the Linux kernel since 5.6 and is lean. For many users, however, it lacks sign-in through an identity service, policies per group, key distribution and logging. A control plane such as NetBird or Headscale takes over these tasks.

Only to a limited extent. Headscale is an open-source implementation of the Tailscale control server under BSD-3-Clause and, according to its README, covers a single tailnet, intended for personal use or small open-source organisations. For businesses with several groups, tenants or support needs, NetBird or Tailscale itself is usually the better fit.

No. The old VPN and the new model run in parallel. Groups are moved one after another, starting with a pilot group. The gateway is switched off only once all groups, sites and service providers have moved and it no longer shows connections.

No. NIS2 does not prescribe a product. Article 21(2) of the directive requires, among other things, access control policies (point i) and multi-factor authentication solutions (point j). In Germany, the NIS2 implementation act has applied since 6 December 2025. An identity-based access model makes evidence easier but is not the only option. Not legal advice.

Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 on all FortiGate models and replaced it with IPsec VPN, which can also run over TCP port 443. Existing settings are not carried over during the upgrade. For businesses using SSL VPN this is a reconfiguration anyway, and therefore a good moment to review the target model.

DirectAccess has been deprecated since June 2024 and will be removed in a future Windows release. Microsoft recommends migrating to Always On VPN. Anyone still using DirectAccess faces a replacement in any case.

Older applications, machine controllers or RDP servers can be included as well. Access is then granted at network level per target and group, and multi-factor sign-in happens when the client connects through the identity service. The application itself does not need to change.

With an inventory: which user groups access what, which sites are connected, which service providers have access and which identity service exists. WZ-IT's Secure Access Check delivers the inventory, target model, product choice, migration path and a fixed-price quote for the switch, from EUR 1,490 net.

Timo Wevelsiep

Written by

Timo Wevelsiep

Co-Founder & CEO

Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.

LinkedIn

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back by the next business day at the latest.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • SweetConnect GmbH
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.