Technical guides
Migration guides
Each guide answers one operational question about migrating a real VPN estate. None of them requires a conversation, an email address, or a decision about PQVPN. They are the same reasoning PQVPN applies in an engagement.
All guides
Guide
Building a VPN cryptographic inventory you can act on
What exactly do we need to record about our VPN estate before a post-quantum migration can be planned?
What to record per gateway and per tunnel, why device state beats documentation, and how to structure an inventory that supports migration decisions.
Last reviewed · 9 min read
Guide
Hybrid post-quantum IPsec: what changes on the wire and what it costs
What actually changes on an IPsec tunnel when we move to hybrid post-quantum key establishment?
What a hybrid post-quantum IPsec change alters on the wire, what stays the same, and the operational costs to plan for.
Last reviewed · 8 min read
Guide
Migrating tunnels whose far end belongs to someone else
How do we migrate tunnels that terminate on a peer controlled by another organisation?
How to identify, sequence and coordinate migration of VPN tunnels terminating on counterparty-controlled equipment, and what to do when they will not move.
Last reviewed · 7 min read
Guide
What to do with a gateway that cannot support post-quantum key establishment
What are our options when a VPN gateway cannot support post-quantum key establishment?
Seven options for a gateway that cannot reach the target capability, what each costs, and how to choose between them defensibly.
Last reviewed · 8 min read
Guide
Post-quantum VPN migration checklist: per wave and per tunnel
What checks should we run before, during and after each post-quantum migration wave?
A working checklist for post-quantum VPN migration waves: pre-flight, change window, verification and closure, with the reason behind each check.
Last reviewed · 7 min read
Guide
How to migrate an enterprise VPN estate to post-quantum key establishment
How do we plan and execute a post-quantum migration across an existing enterprise VPN estate?
An end-to-end method for migrating a heterogeneous enterprise VPN estate, from inventory through wave sequencing to verified handover.
Last reviewed · 12 min read
Guide
Verifying a post-quantum VPN migration: proving what was negotiated
How do we prove that a migrated tunnel actually negotiated post-quantum key establishment?
Why configuration is not evidence, what to capture from an established security association, and how to build a verification record that survives an audit.
Last reviewed · 8 min read
These guides describe the method. An assessment applies it to your estate.
If the guides are enough for your team to proceed, use them — that is what they are for. If the estate is complex enough that you would rather not find out the hard way, scope an assessment.