Encrypted tunnels between sites and for remote staff, terminated on managed hardware with MFA where it matters.
A VPN does one of two jobs and they need different designs. Site-to-site joins networks permanently. Remote access lets individuals in from anywhere. Building both on the same box is fine; specifying them as if they were the same thing is not.
Remote access is where the risk sits. A VPN with a shared password and no second factor is a credential-stuffing target, so we deploy certificate or MFA-backed authentication and scope what each group can reach once inside.
Throughput is the other thing people get wrong. Encryption is expensive, and a router rated for 1 Gbps of routing may manage a fraction of that with IPsec enabled — we size on the encrypted figure.
Publishing exclusions is deliberate. Nobody in this market does it, and it's the fastest way to avoid a variation conversation later.
If yours isn't here, ask — we'd rather answer it before you buy than after.
For a handful of sites where occasional latency variation is tolerable, VPN over internet is often the sensible answer. If performance is contractual or voice quality matters across many sites, MPLS or SD-WAN is the better fit.
Usually the terminating hardware, not the circuit. Encryption throughput is frequently a small fraction of routed throughput, and it's the specification people forget to check.
Free site survey first. You keep the findings whether or not you buy.