Re: net-to-net vpn
"G.W. Haywood" <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
Hi there, On Tue, 2 Jun 2015, [email protected] wrote (twice, apparently): > ... OPENVPN rather than via IPSEC ... > > Is this something which is difficult to implement? or is there no > demand for it? I'm not sure it's necessary or indeed even desirable. I routinely use OpenVPN to implement VPNs which pass through IPCop machines, but I do not normally run OpenVPN on the IPCop machines themselves. It is more flexible to run OpenVPN on a machine or machines inside the firewalled perimeter, and the encryption can then be handled by a machine easily capable of the encryption overhead, which can be substantial. Set up machines which run OpenVPN to be able to route packets (for example on a Linux box, "/bin/echo 1 > /proc/sys/net/ipv4/ip_forward") and then simply poke appropriate holes in the firewall(s) to allow the traffic. Machines on the LAN which need access to the VPN(s) will have routing table entries (for the tunnel IPs) which point to the OpenVPN machines rather than the default gateway. > Many articles on VPN assert that OPENVPN is more robust than is IPSEC, > particularly over congested networks. In my experience OpenVPN was not so stable ten or twelve years ago as it is now. Occasionally I would have to re-start a tunnel, sometimes as often as every day or so. But it steadily improved to the point where now it's a lot like my clothing. I choose the configuration intelligently, implement it with care, and then forget all about it. -- 73, Ged. ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user