Raspberry Pi VPN Server: Build Your Own Virtual Private Network
pimylifeup.com
pimylifeup.com
Security isn't a thing that you 'buy' or 'add', it's something that you 'do' and 'know'.
Using a VPN server and a VPN client doesn't do anything other than getting traffic from A to B over a presumed hostile network. Ideally using asymmetrical encryption to make sure the keys don't have to travel the network. Then, you sure probably use that tunnel to send all traffic, not just your p2p or http traffic. Using DNS over the normal network and your 'secret' stuff over the tunnel still exposes what you are doing and actually makes you more suspicious since you now look like you are trying to hide things (and doing a bad job at it). And what about firewalls, WebRTC hacks, routing tables etc. that now expose your network setup to any software you execute (be it an application or a webpage), or applications that don't honor your VPN setup and route packets wherever they want to. What about your OS routing stuff elsewhere? What about that Pi not being setup correctly and you happily using it but still leaking a ton of traffic over the visible network? A user of an easy VPN setup will not know and be covered by a false sense of security.
Even if you have perfect instructions and set it up perfectly initially, you would still be vulnerable down the road as new problems arise and mitigations might be available but unknown due to a user not actually knowing what it is or what they are doing.
They for obvious reasons should not be used for anonymity[2] although for some this is the sole reason they use a VPN. I think, since they are a single hop proxy, that chaining VPNs together and buying subscriptions anonymously with tumbled Bitcoins/Monero is the only way you might get anonymity, but the overhead and potential for things to go wrong is massive. Things like Tor already solves many of these obstacles and provides reasonable OPSEC, providing you use it correctly.
Being a bit more serious, thank you for the link, it was enlightening. Kudos.
Fix it with technology, not with instructions.
I do have a Pi too, but after all these new laws where ISP's can sell your Internet history etc. I think it's nice to be able to hide traffic from them too.
A bit more expensive but at least 100x faster option would be https://www.amazon.com/Supermicro-A1SRi-2558F-Intel-Fanless-...
And I suppose something like https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-Bare... or maybe https://www.amazon.com/Solana-Tech-pfSense-firewall-router/d... would be an OK cheaper alternative.
After a quick look at ubnt forums looks like it'll max out around 15mbps doing openvpn https://community.ubnt.com/t5/EdgeMAX/EdgeRouter-Pro-OpenVPN...
You can do 100Mbit IPsec on the EdgeRouter I guess, but I think last I checked the cipher support was a bit lacking.
The supermicro board with QuickAssist should easily do gigabits of IPsec.
I've tested an Odroid C2 doing ~400 Mbit/s using SSH (chacha20-poly1305@openssh.com) (maxed out one of four cores). Same form factor, same GPIO pinout, similar power requirements as the Pi. Supported well-enough for virtually any application with armbian. People are gouging on price for now but even still it's only $10 more for the board and it trounces the Pi in any networking application.
Thus, here is a blog post I wrote a bit ago on how to setup a dedicated native Cisco ipsec pi:
https://blog.elasticbyte.net/setting-up-a-native-cisco-ipsec...
My VPN needs are, roughly:
- Remote access to my home network from my phone/laptop/tablet. This is mainly to check on my security cameras, but being able to access my NAS and everything else is a nice bonus. I can even turn my Philips Hue lights on and off via my VPN connection.
- Remote access to VMs running on a rented machine at Joe's Data Center. Basically the same scenario as above, but with different stuff on the other side of the tunnel.
- Seamless integration of my home network with the remote one. This is where things get fun. Basically, custom routes on my router tell it to send packets destined for the remote subnets to the VPN server, plus some custom dnsmasq configuration routes DNS requests for remote machines to the appropriate server.
Honestly, the only thing that bugs me about my setup is that I can't figure out what the secret sauce is to get Windows 10's native VPN client to connect to my servers. I'm pretty sure that my certificates are missing something that Win10 needs in order to use them, but I haven't figured out what it is yet. Fortunately, this isn't something I need right now, but it would be nice to get it working.
My servers are primarily FreeBSD, but I wouldn't recommend doing IPSec on it. FreeBSD 10 doesn't enable IPSEC by default, so you have to recompile the kernel to use it. FreeBSD 11 enables IPSEC but does not enable IPSEC_NAT_T (NAT Traversal, basically IPSec encapsulated in UDP), so you need to recompile to use it since many clients end up being behind NAT at some point.
My ideal setup would see OpenBSD gateways in front of my FreeBSD servers, but in some cases that isn't possible. I'll probably end up creating small OpenBSD VMs on the FreeBSD hosts to do the VPN work.
> FreeBSD 11 enables IPSEC but does not enable IPSEC_NAT_T
FWIW I heard that FreeBSD 11.1 (already in 11-Stable) is going to removed IPSEC_NAT_T as a tunable, and it will be effectively enabled by default.I wanted to create an openbsd vm (on bhyve) too, but there is some weird issue with openbsd 6.1 and bhyve passing through some funky cpu flags it shouldn't be that causes openbsd to panic. Apparently passing -w to bhyve works, but I haven't tried it yet.
Sweet!! I guess I'll hold off on upgrading my boxes until 11.1 lands.
> I wanted to create an openbsd vm (on bhyve) too, but there is some weird issue with openbsd 6.1 and bhyve passing through some funky cpu flags it shouldn't be that causes openbsd to panic. Apparently passing -w to bhyve works, but I haven't tried it yet.
Good to know - thanks!
I myself am not entirely happy with the way TLS works. It invites for bad configurations and in our pen testing reports, it is extremely rare to see setups that do not have some recommendation. I have yet to see one, but I'm sure someone in the office will have seen a "perfect" setup on some odd assignment (once again: given enough samples, you'll find one...). And then there's the fact that almost all TLS connections use endpoints written in memory-unsafe languages, which has caused its fair share of vulnerabilities. (Alright, maybe a lot more than its fair share.)
But the notion that OpenVPN is bad just because it relies on TLS is mildly ridiculous. The only reason I could agree with "let's move OpenVPN off of TLS" is because too much relies on one protocol. Then again, that makes it an extremely well-vetted protocol, which is one of the things that makes it so good, and it's a fairly versatile protocol. Most of the important parts can be swapped out with a configuration change.
Like 3MB/s maybe? Even that is pretty optimistic however. The older Pi wouldn't even do a MB/s
UltraHD video is about 7GB per hour, or about 2MB/s.
Mind you I'm surprised that Ofcom actually reports average UK bandwidth to be 4.5MB/s (SamKnows study; self-selected group of 2000 participants AFAIK).