## TL;DR
Write the VPN runbook as a decision tree: cannot connect, connects-but-no-traffic, drops, and slow. Each branch gets 3 to 5 checks with exact commands and expected outputs, plus a clear escalation line (what to collect, who gets it). Test the doc by having a new agent follow it on a real ticket.

## The error
```text
(Documentation task; no error.)
```

## Steps
1. Split the doc into four symptom branches: will not connect, connects but nothing works, drops repeatedly, slow. Expected: four sections. Symptom-based beats component-based for tier 1.
2. For each branch, list checks in order with the exact command or click path and the expected result. Expected: an agent can follow it without guessing. "Check DNS" is not a step; "run nslookup intranet and confirm the corporate server answers" is.
3. Add the three-way isolation test (VPN on/off, alternate network) near the top. Expected: included. It routes half of all VPN tickets correctly on its own.
4. Define the escalation package: client logs, failure timestamp, public IP, what was tried. Expected: checklist. Escalations without this get bounced.
5. Have a new hire use the doc on a live ticket and fix what confuses them. Expected: doc validated. Docs written by experts skip the steps novices need.

## When to use
- Building or refreshing VPN runbooks
- Reducing VPN escalations to network engineering

## When not to use
- One-off troubleshooting (just fix it)
- Network-team deep documentation

## Compatibility
- Vendor-agnostic; adapt commands to your client

## Variants
### Multiple VPN clients in the org
One decision tree per client, with a router page at the top.
### High VPN ticket volume
Add the top 5 fixes to a user-facing FAQ to deflect before tier 1.

## Why it happens
VPN tickets are high-volume and repetitive, but each has just enough variation to confuse. A decision tree converts expert pattern-matching into a repeatable process.

## Edge cases
- Review the doc quarterly; client updates and gateway changes silently obsolete steps.
- Track which branch resolves most tickets; invest documentation effort there.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_LlKW_SMC-7CWZ27PEwSGSA
