PPTP is completely broken (MS-CHAPv2 especially), OpenVPN is hard to setup and maintain.
I've been using ssh as an impromptu VPN-like thing but I'd really, really like an actual VPN solution.
PPTP is completely broken (MS-CHAPv2 especially), OpenVPN is hard to setup and maintain.
I've been using ssh as an impromptu VPN-like thing but I'd really, really like an actual VPN solution.
That's not true. OpenVPN is the easier, most straight-forward solution when it comes to set-up[1] and configuration (routing, firewalling, client auth, etc.). Try to setup OpenSWAN and you'll see what hard to setup really means. I don't know about new software like SigmaVPN.
[1] Or maybe I am too used to it.
https://gist.github.com/arnehormann/9744964 There's a usage howto in the comments and this should be short enough to fully grasp what it does. No third party requirements, just ruby core + openssl.
It creates client and server configuration and creates and manages CA and CRL.
The VPN uses tun mode over UDP. Required changes on the server are written down in comments at the beginning of the server configuration.
If there is sufficient interest, I can make it a real repo so it can get issues and pull requests.
After this thread I'll be looking at fastd and zerotierone, though.
Do you have something else to create L2 overlays that is more secure?
Someone has to run an OpenVPN server. Everyone on the network has to trust that server.
And connections between network participants are not peer to peer.
With OpenVPN and most other VPN's, if I'm not mistaken, each person's traffic passes through a central point: some VPN server/appliance.
This is a major difference and has its own set of security implications.
I was looking them up the other day they seem very nice.