Concept and mechanism
An encrypted connection protects channel properties but does not determine every resource a person may use. For vendor access, record identity, purpose, destinations, services, duration, and approver. Use individual identity, suitable authentication, and limited permissions. Test both the required flow and access that should be denied. A VPN does not itself authorize the whole management network. An SSID matching the corporate name does not authenticate an AP either. Managed profiles and suitable service-identity validation reduce reliance on names that can be copied. Scenarios describe fictional requirements, not a particular bank’s internal rules.
Guided application
Also distinguish control behavior along the path. AWS security groups are stateful: the corresponding response to an allowed connection is handled using that state. This neither permits arbitrary new inbound connections nor guarantees routes or other filters permit the flow. In a volumetric attack saturating the link before the local firewall, a rule on that firewall may not recover capacity already consumed. Coordinate the contracted upstream mitigation process, communicate impact, and validate legitimate traffic. For every change, retain evidence of applied scope and expiry. Operational handover should define who revokes temporary access, where records are kept, and how removal is confirmed.
The vendor reaches the correct bastion and three unauthorized consoles: the positive test passed, but restriction failed.
Common pitfalls
VPN as complete trust; shared account as traceability; SSID as identity; local rule as a solution for every saturation.
Related topics: Diagnosis using counters, DNS, and captures · MTU, capacity, and service validation
Authentication, authorization, encryption, and availability each need their own evidence.
Reference: Zero Trust Architecture · N10-009 V9