Skip to content
Notifications
Clear all

Guide: Replacing our old VPN concentrator with P81 in a weekend

1 Posts
1 Users
0 Reactions
3 Views
(@auditor_abby)
Estimable Member
Joined: 4 months ago
Posts: 111
Topic starter   [#12855]

We ran a Check Point VPN concentrator for seven years. It was stable, but the client management was a nightmare and the logs were useless for anything beyond basic troubleshooting. Our compliance audit last quarter flagged several gaps in user access reporting. That was the final push.

I was tasked with finding a replacement that could be deployed over a weekend with minimal user disruption. Perimeter 81 was on the shortlist. Here's the blunt breakdown of how it went, focusing on the security and operational controls.

**Pre-migration (Friday PM)**
* Exported our existing user list and mapped groups to P81's "Networks" (their equivalent of VLANs/segments).
* The identity provider integration (Azure AD) was straightforward. We pushed the connector via our MDM and configured SAML SSO. This was critical for eliminating shared credentials.
* Built three networks: Corporate, Production Infrastructure, and Guest. The policy logic (user/group -> network -> resource) is more intuitive than traditional firewall rules.

**Cutover (Saturday)**
* User enrollment was self-service via email invite. We had about 85% adoption by Sunday evening without help desk tickets.
* The logging was the immediate win. Every connection event (user, device, location, network accessed) is timestamped and searchable in the dashboard. This alone satisfied two of our SOC 2 common criteria on access monitoring.
* We decommissioned the old VPN concentrator IPs on the firewall by Sunday afternoon.

**Post-migration (Monday & Compliance)**
* The real test was generating reports. I could pull a CSV of all authentication events for the last 30 days in under two minutes. Try that with a legacy appliance.
* We're using the "Always On" rule for company-issued devices. It's effectively a zero-trust network agent, which our auditor liked.
* One gap: The internal DNS logging is not as granular as I'd like. You can see queries, but tying them directly to the user session requires cross-referencing connection logs.

**Verdict**
It works as advertised for a straightforward site-to-user VPN replacement. The security advantage is in the centralized policy management and actionable audit logs. It's not a full SASE platform yet, but for closing those access review audit findings and getting rid of hardware, it was a successful weekend project.


Where is your SOC 2?


   
Quote