www.fridu.net

  • Increase font size
  • Default font size
  • Decrease font size
OpenVPN

1. LAN interconnection over DSL

Print

Interconnect IconMany of us would like to interconnect LANs over DSL links, unfortunately the difficulties of managing all the complexity of the solution (DSL, Firewall, NAT, DNS, PKI, routing, ...) has stopped more than one of us.

We do not intend to replace the very valuable documentation available on the Net, but more to drive you through a few practical use cases. The proposed solution uses OpenVPN  which runs on most OS available on the market and with regular low cost DSL or cable network connections.

Our study does not cover all the possible use cases but presents the advantage of actually working between a few sites of fridu.org members located in different countries.

VPN based on SSL (as OpenVPN)  can present, like any network topology, security weaknesses. At fridu.org we prefer PKI structure in lieu of shared secret. We assume that keys and certificat can be distributed in a reasonably safe manner. The proposed method has been optimised to limit the cost to zero Euros while keeping the security level to a decent level.

Read more...
 

2. LAN Interconnection use case

Print

Remote officeThe Lan  Interconnection use case covers the need of small office remote users who need to be permanently connected to a main LAN. At fridu.org we think that remote offices must stay operational even if the DSL link is down. To achieve this independence, we propose an IP interconnection and not an Ethernet bridge mode as covered in the roaming user use case.

Read more...
 

3. Roaming use case

Print

Roaming from the poolThe roaming use case represents the need of a remote user who needs to connect to a main LAN in a transparent manner. Ideally, the remote and main LAN users will see no difference between roaming and locally connected users. The IP addressing plan will be the same, non IP protocol (e.g. printer and share discovery, Novell directory, ...) and IP multicast will work.

Read more...
 

4. Security matters

Print

Security IconSSL versus IPSEC is a common discussion topic.

A sad reality shows that most of attacks come from inside any organisation while most of protection effort is done on the outside. A good practice consists to force the use of transparent proxy for all outgoing traffic beside of ssl and to block any incoming traffic and port redirect the absolute minimum (HTTP, HTTPS, SSL, SMTP, NTP, OpenVPN).

 

Read more...
 

5. OpenVPN Principle

Print

A fine TunnelOpenVPN is based on the Secured Socket Layer (SSL) which sits on top of the IP stack. With OpenVPN you can select variousauthentication methods and encryption algorithms. It can also provide data stream compression.

In most of configuration, we will have a main site which will act as the VPN Server and either fixed remote site with interconnected LAN and/or roaming mobile users.

We assume that LAN interconnection is done at IP level while Roaming users are connected via a bridged Ethernet. 

The general configuration could be as described bellow.Image 

 

Read more...
 
More Articles...
  • «
  •  Start 
  •  Prev 
  •  1 
  •  2 
  •  Next 
  •  End 
  • »


Page 1 of 2