A site-to-site VPN is usually best when two networks need ongoing communication, such as a branch, plant or remote cabinet connecting to a central office. The routers maintain the tunnel automatically and devices can communicate according to fixed firewall rules without each user starting a VPN client.
Individual remote-access accounts are better for people who need temporary or personal access from different locations. They allow user-level credentials and easier revocation, but may be cumbersome for machine-to-machine traffic. Many deployments use both: a site-to-site tunnel for core systems and individual access for support staff. The design should minimise what each tunnel can reach and account for changing cellular public IPs or carrier-grade NAT.
Public Q&A
When should a site use a site-to-site VPN rather than individual remote-access VPN accounts?
Useful next steps
Use this answer as a practical starting point. Current scope, specifications, compatibility, availability, pricing, timing and next steps should be confirmed directly with Comset where they affect a decision.
Related visual examples
A short visual sample connected to this answer or its topic.


