we_are_coded.by CODE · The world, decoded
БГ
Concept

VPN, air-gap, and how a network is guarded

The BasicsUpdated on 16 August 2026we are coded

The tunnel, the moat, and the bridge - three ways to guard what shouldn't be reached from outside.

Checked on16 August 2026
In short: a VPN is an encrypted tunnel between your computer and a company's internal network - go through it, and you look as if you're physically sitting in the office. Air-gapped is a system cut off from the internet entirely - reachable only on site, hands on the keyboard. Jump host is the single controlled door everyone must pass through before reaching what matters most inside. Together the three build degrees of access - from an open field to a locked vault with no door at all.

A VPN (virtual private network) sounds boring, but the idea is elegant: you dig an encrypted tunnel through the open internet, and on the other side you come out inside the network, as if you'd never been outside. For remote work it's convenient - you sit at home, and the system treats you like an employee at a desk. The problem is that the tunnel doesn't ask who's actually going through it. It only asks whether you have the key.

And that's exactly why a VPN is attackers' favorite door. They don't have to break a wall - it's enough to steal login credentials leaked from some other site and try them here, hoping the password is the same. Once they're through the tunnel, the system inside sees only legitimate traffic - the thief stays invisible to it. That's why good networks no longer trust the tunnel alone - they demand a second proof: a device they recognize, behavior that fits.

Air-gap is the other extreme - a moat with no bridge at all. The machine has no cable to the internet, no Wi-Fi chip, it's physically cut off. It's used where the cost of a breach is catastrophic: industrial control systems, backups, the most important encryption keys. The inconvenience is brutal - every update walks in on foot, on a USB stick, through a person who carries the risk literally in his pocket. But that inconvenience is exactly the protection. No network - no way to hack it remotely.

A jump host is the compromise between the two - a narrow bridge across the moat, instead of ten open doors. Anyone who wants to reach the internal systems passes through it first, and from there every one of his moves is logged. The good part is that instead of guarding a hundred entrances, you guard one, tightly. The bad part is the mirror image - if that one bridge falls, the attacker inherits all the traffic that passed over it. That's why good teams don't stop there - they watch the bridge itself as closely as the moat behind it.

A moat with no bridge can't be crossed - and that's the only truly secure thing we've ever invented.

This one holds up

My first instinct at home was to open a VPN to everything - it's convenient, you work from anywhere. Then I thought about who else has that same key if my laptop leaks or my password shows up in some old breach. Now the most sensitive things have no network path out at all - literally an air-gap on a small machine, reachable only in person. It's not convenient. That's exactly why it works.

I keep a VPN only for the things I need to reach remotely, and through a narrow jump host, not an open door to everything. The difference is philosophical: you accept that convenience and security pull in different directions, and you decide consciously what each one is worth, instead of letting inertia decide for you.

The visual is generated code art. No third-party images.
Official primary sources
→NIST CSRC glossary: air gap→NIST CSRC glossary: virtual private network (VPN)