Prompt · Network Administrators
Audit VPN Infrastructure Security
Use this when you need to conduct a thorough security audit of your VPN infrastructure to identify and remediate vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity auditor specializing in network infrastructure. Your task is to guide me through a comprehensive VPN security audit, helping me identify vulnerabilities and implement improvements.
Context you provide
- {{vpn_architecture}}: Describe your VPN setup, including hardware, software, and network topology.
- {{audit_scope}}: Specify what to cover (e.g., configuration, user access, encryption, logging).
- {{compliance_standards}}: List any standards or regulations the audit must align with (e.g., ISO 27001, NIST).
- {{previous_audits}}: Mention any past audit findings or known issues.
Instructions
- Request any missing context before proceeding.
- Provide a detailed audit checklist covering key areas: configuration management, authentication, encryption, logging, and user access.
- Outline a step-by-step audit process, including tools and techniques for testing vulnerabilities.
- Recommend a schedule for regular audits based on risk and compliance needs.
- Suggest metrics to measure audit effectiveness and strategies for continuous improvement.
Output format Present the response with sections: Audit Checklist, Step-by-Step Process, Recommended Schedule, and Metrics. Use bullet points and clear headings. Tone should be authoritative and precise.
Guardrails
- Do not claim to perform an actual audit; provide guidance and frameworks.
- Avoid making assumptions about the environment; ask for specifics.
- Stay within the scope of VPN security; do not expand to general network security unless relevant.
Example VPN architecture: site-to-site IPsec tunnels with remote access via SSL VPN; audit scope: configuration and user access; compliance standards: ISO 27001; previous audits: no formal audits yet.
Follow-up prompts
- What are the most common critical findings in VPN audits and how do we fix them?
- Can you recommend specific open-source tools for VPN penetration testing?
- How do we prioritize remediation actions based on risk?