VPN Detection

This page provides information on the VPN Detection in Netify's Network Intelligence Engine. To learn more about our full suite of intelligence drivers, see our intelligence capabilities page.

Risk Overview

While VPN technology is a staple for secure remote access, its ability to encapsulate and encrypt traffic makes it a primary vector for stealthy data exfiltration. By tunneling sensitive information through an encrypted VPN session, an insider or malicious actor can move data off-site without triggering traditional firewall alerts.


Indicator Drivers

Business VPN Application Driver

Much like consumer VPN services, business VPNs like Zscaler and ZeroTier play an essential role in protecting enterprise networks. However, these VPNs can still create compliance and control issues if this traffic is not managed properly.

The Business VPN indicator driver is triggered when a business VPN application is detected on the network.

Business VPN Application
Tag
vpn_application_business
Score
Medium Risk - 45
Version
1.2.9

Consumer VPN Application Driver

Consumer VPNs like ExpressVPN and Mullvad VPN play an essential role in protecting users' privacy. On the other hand, businesses need to protect their networks to maintain security, compliance, and control over their environments.

The Consumer VPN indicator driver is triggered when a consumer VPN application is detected on the network. You can find a list of supported VPNs on our VPN Resources page.

Consumer VPN Application
Tag
vpn_application_consumer
Score
High Risk - 70
Version
1.2.9

VPN Protocol Driver

The VPN Protocol indicator driver is triggered when a supported VPN protocol is detected by the Netify DPI engine.

WiFi Calling is a popular feature that allows mobile phones to use local WiFi for mobile connectivity. This application uses the IPsec VPN protocol, so you may want to make an exception in the configuration for this type of traffic.

VPN Protocol
Tag
vpn_protocol
Score
High Risk - 60
Version
1.2.9

Consumer VPN Server Driver

The Consumer VPN Server indicator driver activates when a connection is made to any of thousands of known VPN servers across the Internet. It complements the Consumer VPN Application indicator driver by broadening detection to include more obfuscated and less easily identifiable VPN services.

Consumer VPN Server
Tag
vpn_server_consumer
Score
High Risk - 70
Version
1.2.9