The incumbent VPN, honestly assessed — and where an identity-based mesh does what concentrators can't.
| OpenVLAN | Cisco Secure Client | |
|---|---|---|
| Architecture | Peer-to-peer mesh | Concentrator/head-end (ASA, FTD, ISE) |
| Encryption | AmneziaWG end-to-end | IPsec/TLS to head-end |
| Access control | Per user/device/resource ACLs | Group policies + DAP, network-scoped |
| Client experience | Silent, low battery drain | Mixed; profile updates can disrupt |
| Remote worker scaling | No backhaul | Traffic hairpins through head-end |
| Hardware | None | Appliances or licensed virtual head-ends |
| Typical rollout | Days | Weeks (ISE, certificates, change boards) |
If ISE, TrustSec, and ASA firewalls run your world, Secure Client integrates with what you already operate.
Some regulated environments standardize on a single vendor's audit story. That's a real constraint.
Head-end capacity planning, split-tunnel debates, and "is the VPN up?" are symptoms of the concentrator model itself. Mesh removes the head-end; identity removes the split-tunnel question — each connection is already least-privilege.