OpenVLAN vs Cisco Secure Client

The incumbent VPN, honestly assessed — and where an identity-based mesh does what concentrators can't.

Side by side

OpenVLANCisco Secure Client
ArchitecturePeer-to-peer meshConcentrator/head-end (ASA, FTD, ISE)
EncryptionAmneziaWG end-to-endIPsec/TLS to head-end
Access controlPer user/device/resource ACLsGroup policies + DAP, network-scoped
Client experienceSilent, low battery drainMixed; profile updates can disrupt
Remote worker scalingNo backhaulTraffic hairpins through head-end
HardwareNoneAppliances or licensed virtual head-ends
Typical rolloutDaysWeeks (ISE, certificates, change boards)

The fair points for Cisco

Deep Cisco estate

If ISE, TrustSec, and ASA firewalls run your world, Secure Client integrates with what you already operate.

Mandated compliance stacks

Some regulated environments standardize on a single vendor's audit story. That's a real constraint.

Why teams add (or switch to) OpenVLAN

Head-end capacity planning, split-tunnel debates, and "is the VPN up?" are symptoms of the concentrator model itself. Mesh removes the head-end; identity removes the split-tunnel question — each connection is already least-privilege.

Keep the firewalls. Lose the concentrator.