Many of us would like to interconnect LANs over DSL links, unfortunately the difficulties of managing all the complexity of the solution (DSL, Firewall, NAT, DNS, PKI, routing, ...) has stopped more than one of us.
We do not intend to replace the very valuable documentation available on the Net, but more to drive you through a few practical use cases. The proposed solution uses OpenVPN which runs on most OS available on the market and with regular low cost DSL or cable network connections.
Our study does not cover all the possible use cases but presents the advantage of actually working between a few sites of fridu.org members located in different countries.
VPN based on SSL (as OpenVPN) can present, like any network topology, security weaknesses. At fridu.org we prefer PKI structure in lieu of shared secret. We assume that keys and certificat can be distributed in a reasonably safe manner. The proposed method has been optimised to limit the cost to zero Euros while keeping the security level to a decent level.