VPN connected, application unreachable: a layer-by-layer runbook
A successful tunnel handshake proves only that the tunnel exists. DNS, routes, return paths and firewall policy still decide whether the business app loads.
Write-ups from deployments we have actually run, organised by section. Specific problems, the reasoning behind the approach, and what it cost to get wrong. Client names are withheld under confidentiality.
Page 1 of 8
A successful tunnel handshake proves only that the tunnel exists. DNS, routes, return paths and firewall policy still decide whether the business app loads.
A gateway error is a symptom. Separate a dead upstream, a slow handler, an exhausted worker pool and a timeout mismatch before increasing limits.
A capable model earns its place when it reduces the work required to approve a result. How to assess Claude Opus 5 for technical reviews, operational analysis and controlled business workflows.
Delegating a task that lasts hours requires more than a capable model. A practical guide to using Claude Fable 5.1 with checkpoints, durable records, budgets and accountable review.
Complex business work needs reliable interfaces, not just a powerful model. Where GPT-6 Astra fits, how to constrain its tools and what a production-ready handover should contain.
A business application rarely has one kind of AI work. Design a routing policy that gives difficult requests enough capability without sending every routine task to the same model.
A model comparison is only part of an enterprise purchase. Compare Claude and GPT around the complete workload, provider route, data controls, tools, support and the cost of changing later.
Model Context Protocol can make tools easier to connect. It does not decide who may use them. Build MCP integrations around scoped identities, reviewed tools and enforceable business permissions.
A knowledge assistant can retrieve a correct answer from the wrong document. Design retrieval around identity, source permissions, freshness and deletion before expanding the document collection.
An approval button is useful only if it authorizes a specific, current action. Design AI agent handovers around clear payloads, expiry, independent checks and evidence of execution.
A cheap model call can produce an expensive workflow. Build an AI operating budget around accepted outcomes, review effort, retries, infrastructure and the work that still stays manual.
A second model is not a complete continuity plan. Decide which AI tasks should queue, degrade, move to manual work or use a tested alternative without changing data boundaries.
We typically respond within 4–8 business hours.