Operational consequence
One compromised account or endpoint can discover and reach more infrastructure than the user needs, while troubleshooting and revocation span several consoles.
REPLACE LEGACY VPN
Move from broad, location-based reachability to resource-scoped access that keeps user identity, device evidence, policy, path, and enforcement outcome connected.
System role: Customer solution owner + Oten solution architecture
Evaluation depends on: Requires a bounded component, platform, protocol, integration, migration, rollback, and evidence scope.
Network, security, and IT teams reducing subnet-level remote access without interrupting critical application and infrastructure workflows.
A legacy VPN authenticates once, assigns network reachability, and leaves segmentation, device risk, and active-session response to separate systems.
One compromised account or endpoint can discover and reach more infrastructure than the user needs, while troubleshooting and revocation span several consoles.
Users discover only authorized resources, connect by direct or encrypted relay path after policy, and receive resource-specific denial and remediation.
Define the subject, device, resource, protocol, policy version, enforcement points, confirmation requirement, and recovery owner.
Map users, devices, applications, routes, protocols, DNS, dependencies, and exception paths from the existing VPN.
Establish separate user and device identity with qualified posture evidence.
Define named resources and exact routes before retaining bounded subnet access where migration requires it.
Evaluate policy, select a direct or encrypted relay path, and enforce at the Endpoint and resource boundary.
Correlate decision, path, policy generation, and required enforcement acknowledgement.
Oten Endpoint, Access Control Plane, connectivity services, Oten Gateway where resource-side policy is required, and approved identity integration.
Identity provider, endpoint management, DNS, network routing, protected applications, SIEM, and the existing VPN during staged migration.
Direct path, relay fallback, DNS, route, platform, headless-node, and active-session behavior must be verified for each network and protocol mode.
Collect resource and route usage without changing access.
Move a low-risk user and application cohort while retaining the old path.
Reduce broad subnet access only after dependency and denial evidence is complete.
Remove VPN authority after resource, failure, and rollback tests pass.
Next in Oten Access
Define success, limitation, failure, recovery, and rollback evidence before changing the production access boundary.