
VPN Architecture & Diagnostics Assistant
Diagnose VPN issues, optimize configs & validate security posture
What You Can Do
You'll receive structured troubleshooting workflows that systematically diagnose VPN connectivity failures, identify performance bottlenecks, and evaluate your architecture against security best practices. Claude generates detailed diagnostic trees, configuration validation reports, and actionable remediation steps tailored to your specific VPN setup and observed symptoms.
Features
Systematically isolate VPN failures through layered troubleshooting (authentication, tunneling, routing, DNS) to pinpoint root causes
Analyze latency, throughput, and handshake timing to recommend protocol choices, MTU adjustments, and encryption tuning
Evaluate cipher suites, key rotation policies, certificate chains, and access controls against industry standards
Parse VPN configs and verify alignment with security policies, redundancy requirements, and compliance frameworks
Generate runbooks for common failure modes (tunnel drops, DNS leaks, authentication timeouts) with escalation paths
Assess split-tunnel vs full-tunnel design, multi-hop strategies, failover logic, and geographic distribution for your use case
Cross-reference configurations against SOC 2, PCI-DSS, HIPAA, and FedRAMP requirements with gap analysis
Provide templates for parsing VPN gateway logs, client logs, and firewall events to extract diagnostic signals
Example Output
Example 1: Connectivity Diagnosis Report
PROBLEM: VPN drops after 15 minutes of idle time
LIKELY CAUSES (ranked by probability):
1. Keepalive timeout (60%) — Gateway sends keepalives; client doesn't respond
2. Firewall stateful timeout (25%) — NAT state expires before keepalive trigger
3. MTU fragmentation (10%) — Oversized packets fail silently
4. DNS resolution timeout (5%) — Split-tunnel DNS causes tunnel recreation
DIAGNOSTIC STEPS:
☐ Enable debug logging: `ovpn-client --log-level 9`
☐ Check keepalive setting: grep 'keepalive' client.ovpn
☐ Measure ICMP round-trip: ping -s 1472 vpn-gateway.example.com
☐ Monitor TCP state: netstat -nt | grep :1194
RECOMMENDED FIX:
Set keepalive 10 120 in server.conf
Example 2: Security Posture Snapshot
CIPHER SUITE AUDIT
✓ PASS: TLS 1.3 (required)
✗ FAIL: AES-128-CBC still enabled (remove immediately)
⚠ WARN: ECDHE key reuse >7 days (rotate weekly)
KEY MANAGEMENT
✓ PASS: 4096-bit root CA
✓ PASS: Client certs rotate quarterly
✗ FAIL: No key escrow policy documented
COMPLIANCE: SOC 2 Type II
⚠ 2 findings: audit logging incomplete, MFA not enforced for admin access
Example 3: Configuration Optimization
PERFORMANCE BOTTLENECK IDENTIFIED
Observed: 145ms latency, 8 Mbps throughput (expected 50 Mbps)
ROOT CAUSE: ChaCha20 cipher + AES GCM encryption overhead
RECOMMENDATION: Switch to AES-NI hardware acceleration
CONFIG CHANGE:
- cipher AES-256-GCM (hardware accelerated)
- fast-io
- sndbuf 512000
- rcvbuf 512000
EXPECTED IMPROVEMENT: 35–45ms latency, 45+ Mbps throughput
What's Included
- SKILL.md: Structured VPN diagnostic methodology with multi-layer troubleshooting flowcharts
- Connectivity Diagnosis Checklist: Layered troubleshooting template (auth → tunnel → routing → DNS)
- Configuration Audit Template: Security policy cross-reference, cipher validation, key rotation verification
- Performance Analysis Worksheet: Latency profiling, throughput benchmarking, MTU discovery workflow
- Incident Response Runbooks: Pre-built playbooks for tunnel drops, DNS leaks, authentication failures, split-tunnel issues
- Log Parsing Guide: Extract diagnostic signals from OpenVPN, WireGuard, Cisco ASA, Palo Alto, and cloud provider VPN logs
- Compliance Mapping Table: SOC 2, PCI-DSS, HIPAA, FedRAMP requirements linked to VPN configuration controls
- Security Posture Scorecard: Cipher suite audit, certificate lifecycle review, key management validation checklist
Who It's For
- Network and security engineers — Diagnose VPN outages and optimize gateway configurations
- DevOps and cloud architects — Validate site-to-site and remote access VPN design for production workloads
- Security and compliance teams — Audit VPN configurations against SOC 2, PCI-DSS, HIPAA, and FedRAMP frameworks
- IT operations and support — Troubleshoot remote access issues and build incident response playbooks
- Penetration testers — Assess VPN architecture and protocol implementation for security gaps
Best For
- Diagnosing VPN connectivity failures and performance degradation
- Optimizing VPN configurations for throughput, latency, and encryption overhead
- Auditing security posture against industry standards and compliance requirements
- Building incident response playbooks for common VPN failure modes
- Reviewing VPN architecture (split-tunnel, multi-hop, failover) for a specific use case






