Your team admins twelve VPS via permanent WireGuard VPN. VPN logs record every personal DNS query from the remote developer. Audit asks who accessed prod server March 14: impossible to isolate SSH session in noise. A bastion with auditd and MFA would leave one trace per admin connection.
The question: which access produces useful proof without opening more network than needed?
VPN: wide tunnel, comfort, extended surface
Once connected, VPN gives full private network access. Strengths: several internal services, homogeneous remote team, team familiarity. Unnecessary traces: non-prod traffic, long connections, split tunnel leaks, hard per-host correlation.
Risks: compromised VPN key = whole network; forgotten VPN patch.
Bastion: single door, targeted logs
SSH or RDP jump host; prod access only via hop. Strengths: centralized MFA, IP allowlist on bastion, session logs, least privilege per key. Limits: one more service to harden; no bulk network access without extra tunnel.
| Criterion | VPN | Bastion |
|---|---|---|
| Network surface | Wide | Narrow |
| Actionable logs | Weak | Strong |
| Small team setup | Heavy | Light |
| Multi internal service | Ideal | Complement VPN/ZT |
Zero Trust: third voice
BeyondCorp, Tailscale ACL, Cloudflare Access — auth per session and service, not flat network. Modern compromise between VPN and bastion for cloud stacks.
To harden first VPS, see Netcup: secure first VPS.
The peak: fewer traces ≠ fewer logs
Decide and move forward without blind spots
Map who accesses what — SSH only or full private network. Choose bastion if SSH admin is main case; VPN if several private subnets. Apply MFA and keys on bastion; disable password auth on prod SSH. Align admin log retention with investigation needs and GDPR minimization. See our guides and directory.
Frequently asked questions
VPN or bastion to admin a VPS?
Bastion often enough; VPN if wide private network or several internal services.
What unnecessary traces with VPN?
Personal traffic, permanent connection, misconfigured split tunnel, noisy logs.
Does bastion replace VPN?
For SSH admin often; full private network = VPN or Zero Trust.
What to log absolutely?
Who, when, key, auth failures, source IP — GDPR-aligned retention.
Ideal admin access opens one door, leaves a clear trace, and closes — not a permanent tunnel where nobody finds the faulty session.
