Home/Services/Remote Access & VPN Penetration Testing
security service

Remote Access & VPN Penetration Testing

Remote access VPN penetration testing against SSL VPN, IPsec and Citrix gateways. We test the edge attackers hit first, fixed price with a full report.

Manual, expert-ledEvidence-based findingsFree remediation retest

Remote access VPN penetration testing puts your remote-work edge under the same pressure a real attacker applies: the SSL VPN portal, the IPsec tunnels, the Citrix and RDP gateways that let staff in from anywhere. These devices sit at the boundary between the internet and everything you care about, and a single flaw here often means the whole network.

What remote access and VPN penetration testing covers

The remote-access appliance is the most attacked box on many corporate networks, and for good reason. It is exposed to the entire internet by design, it terminates trusted sessions, and the vendors behind it have shipped a steady run of critical vulnerabilities. When one of those appliances falls, the attacker is already inside, past the firewall, holding a foothold that looks like a legitimate user.

Our testing covers the full remote-access stack rather than just running a version scanner against the portal. We examine the gateway software and its known weaknesses, the authentication and MFA flow, session handling after login, and what a user can actually reach once the tunnel is up. The goal is to find the path from an anonymous internet client to sensitive internal systems, then help you close it.

SSL VPN and IPsec/IKE gateway testing across major vendor appliances
Citrix and RDP gateway assessment, including published-app breakout
Checks for known Fortinet, Ivanti, Citrix and Pulse appliance CVEs
MFA bypass, credential stuffing and password-spray resistance testing
Split-tunnel and network-segmentation review of what the tunnel can reach
Session-handling, token and re-authentication weaknesses after login

How we test your remote-access edge

We work in phases that mirror a real intrusion, starting from an anonymous position on the internet and building access as far as your controls allow.

Reconnaissance and fingerprinting

First we identify exactly what is exposed: the vendor and model of each gateway, the software version, the authentication methods on offer, and any secondary services the appliance exposes. Version detection matters here because the remote-access space has seen so many critical bugs. An out-of-date Fortinet, Ivanti or Citrix box is often exploitable before login even happens.

Authentication attacks

Next we pressure the login. We test resistance to credential stuffing using breach data tied to your domains, run controlled password-spray checks that respect lockout thresholds, and probe the MFA implementation for bypasses. Weak second factors, tokens that can be replayed, and portals that reveal valid usernames all get flagged. This is where many real breaches actually begin.

Exploitation and known vulnerabilities

Where a gateway runs a version affected by a known flaw, we verify the exposure safely rather than assuming the version banner tells the truth. The last few years brought pre-authentication vulnerabilities in SSL VPN products from several major vendors, some enabling remote code execution on the appliance itself. We confirm whether yours is genuinely affected, with evidence, and without knocking the device over.

Post-access and segmentation

Getting a tunnel is not the end of the story. Once connected, we assess what a compromised remote user can actually reach. A flat network where the VPN drops you next to the domain controllers is a very different risk from one where remote users are boxed into a tightly segmented zone. We test split-tunnel configuration, lateral-movement paths and whether the session can be hijacked or extended.

48h
to first critical findings on exposed gateways
100%
manual verification, no scanner false positives
Free
retest once you patch and reconfigure

Vulnerability classes we find on remote-access systems

Certain weaknesses recur across the remote-access engagements we run for European clients.

Unpatched appliance vulnerabilities

SSL VPN and gateway appliances are patched far less often than the servers behind them, partly because taking the remote-access edge down disrupts everyone. That lag is exactly what attackers exploit. Pre-authentication path traversal, authentication bypass and remote code execution have all appeared in mainstream products, and unpatched boxes remain live targets long after a fix ships.

Weak or bypassable MFA

Plenty of gateways technically have MFA but implement it in a way that can be sidestepped: a legacy protocol that skips the second factor, an enrollment flow an attacker can hijack, or push notifications vulnerable to fatigue attacks. We test whether your MFA actually stops a valid password from being enough.

Over-permissive access after login

The most common configuration failure is not at the perimeter, it is inside. When the tunnel grants broad network access instead of least-privilege routing, one phished VPN credential becomes access to file servers, databases and admin interfaces. We map exactly how far a single account reaches.

Session and token weaknesses

Sessions that never re-authenticate, tokens that can be replayed from another location, and portals that leak internal details all extend an attacker’s window. We check the full lifecycle of a remote session, not just the moment of login.

Information leakage before login

Remote-access portals often reveal more than they should before anyone authenticates: internal hostnames, software build numbers, valid usernames through timing or error differences, and version banners that hand an attacker a precise target list. We flag every pre-authentication leak, because reducing that noise makes your edge meaningfully harder to profile and attack.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

You receive a report your network team can act on immediately, plus the summary leadership needs to understand the risk.

Findings with proof and CVSS

Every finding includes a clear impact statement, a CVSS score, the exact steps to reproduce it, and a prioritized fix. Where a known CVE applies, we cite it and confirm your specific exposure rather than relying on a version guess. Screenshots and request captures back up each issue.

A remediation and hardening plan

Beyond the individual fixes, we give you a hardening path for the remote-access edge: patch priorities, MFA improvements, and segmentation changes that shrink the blast radius of a stolen credential. A free retest confirms the fixes held.

Evidence for auditors

The report is written to satisfy external-testing requirements under the frameworks you work to, so the same engagement that hardens your edge also feeds your compliance file.

Compliance and standards mapping

Remote-access testing supports several obligations that European organizations carry.

ISO 27001 and PCI DSS

ISO 27001:2022 control A.8.20 addresses network security and A.8.21 the security of network services, both directly relevant to remote-access design. For anyone handling cardholder data, PCI DSS 4.0 requirement 11.4 mandates regular penetration testing of the environment, and remote access into the cardholder data environment is squarely in scope.

NIS2 and DORA

NIS2 pushes essential and important entities to secure remote access as part of network-security and access-control measures, and a documented VPN penetration test is strong evidence of that. Financial entities under DORA can use the results within their ICT risk-management and resilience testing. We map each finding to the framework you name.

Why manual testing beats a version scanner

A vulnerability scanner reads the banner on your gateway, matches it to a CVE list, and files a ticket. That approach produces false positives when a vendor back-ports a fix without changing the version string, and false negatives when the real problem is a configuration choice no scanner understands. Our engineers confirm whether an appliance is genuinely exploitable, test the MFA and session logic by hand, and, crucially, walk the path from the internet to your internal systems the way an attacker would. The difference is knowing whether your edge would actually hold, not just what version it claims to run.

Remote-access architectures we test

Remote access has moved well beyond a single VPN concentrator, and we test the range of designs European organizations now run.

Traditional and always-on VPN

Classic SSL VPN and IPsec setups, whether user-initiated or always-on, remain the backbone for most companies. We test the concentrator, the client authentication, and the routing that decides what a connected device can reach. Always-on designs deserve particular scrutiny because a compromised endpoint is effectively permanently on your network.

Cloud and vendor-hosted gateways

Cloud-delivered remote access and vendor-hosted gateways shift some risk to the provider, but not the authentication, the authorization, or the integration with your identity system. We test those layers and the trust you place in the service, since a misconfigured cloud gateway exposes the same internal systems a physical appliance would.

Zero-trust access and its gaps

Many organizations are moving from network-level VPN to zero-trust access that brokers each application individually. Done well it shrinks the blast radius considerably. Done partially, it leaves a VPN running alongside it as a soft backdoor. We test both the new broker and any legacy path that undermines it, because attackers target the weakest route in, not the one on your architecture diagram.

Pricing

Pricing depends on how many gateways and remote-access services are exposed, whether we test authenticated access with credentials you provide, and how deep the internal segmentation review goes. Testing only the external edge costs less than a full external-plus-internal assessment.

Engagement What’s included Timeline Price
Edge assessment Single VPN or gateway, external testing, version and CVE verification, authentication and MFA checks, report 3–5 working days from €1,800
Standard remote access Multiple gateways or protocols, authenticated testing, session-handling review, exec + technical report 5–8 working days €2,500–€6,000
Edge plus segmentation Remote-access testing combined with an internal segmentation review of what the tunnel can reach 8–12 working days from €3,000
Compliance add-on Mapping and attestation for PCI DSS, ISO 27001, NIS2 or DORA external-testing requirements with any tier from €800
Custom / large estate Many sites and gateways or a full remote-workforce environment, scoped to your needs on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote

FAQ

How much does remote access VPN penetration testing cost?
Testing a single exposed gateway starts from €1,800, with a typical range of €2,500 to €6,000 depending on how many gateways and protocols are in scope and whether we test authenticated access. You get a fixed quote after a free scoping call.
Will the test knock our VPN offline?
No. We verify known vulnerabilities safely rather than firing exploits that risk crashing the appliance, and we agree any intrusive checks in advance. Noisy steps can run out of hours so remote staff are not affected.
Do you check for the recent Fortinet, Ivanti and Citrix vulnerabilities?
Yes. We fingerprint each appliance and verify whether it is genuinely affected by the relevant CVEs, rather than trusting the version banner. Vendors sometimes back-port fixes, so we confirm real exposure with evidence.
Can you test whether our MFA can be bypassed?
Yes. We probe the multi-factor flow for legacy-protocol gaps, enrollment hijacking, token replay and push-fatigue weaknesses, so you know whether a stolen password alone is enough to get in.
Do you test what happens after someone connects?
Yes, and it matters. Once a tunnel is up we assess split-tunnel configuration, segmentation and lateral movement to see how far a single compromised remote user could reach inside your network.
Does this satisfy PCI DSS or NIS2 requirements?
The report is written to evidence PCI DSS 4.0 requirement 11.4 penetration testing and supports ISO 27001, NIS2 and DORA network-security and access-control measures. Tell us your framework and we align the deliverables and attestation.
How long does the engagement take?
An external edge assessment runs three to five working days, while a combined edge-and-segmentation test takes eight to twelve. If we find a critical pre-authentication issue you hear about it the same day.
What will you deliver?
An executive summary of the remote-access risk and a technical report with every finding, its CVSS score, reproduction steps and a prioritized fix, plus a hardening plan for the edge. A free retest confirms the fixes hold.

Related services

Who needs this

Any European organization with a remote or hybrid workforce reaching in through an SSL VPN, IPsec tunnel or Citrix and RDP gateway. It is especially relevant if you run an appliance from a vendor with a recent critical CVE, are preparing for PCI DSS or NIS2, or have never tested what a stolen VPN credential could actually reach. If your remote workforce grew quickly during the shift to hybrid work and the edge was stood up under pressure, this is exactly the review it needs.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Remote Access & VPN Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.