2. Project News
â Development
â 2.1.1
â 2.2
â At SCALE this weekend
â https://www.socallinuxexpo.org
â Next session - March 21
â Questions at the end
4. VPN Comparison - PPTP
â Insecure
â Likely to be NAT-broken
â Just donât use it!
5. VPN Comparison - OpenVPN and
IPsec
IPsec OpenVPN
NAT-friendly with NAT-T, Y Y
Widely interoperable with
other firewalls
Y N
Client for Windows Shrew Soft, others OpenVPN
Client for Android Built into most Android 4.x
versions
Two options available in
Google Play
Client for iOS Built into iOS 3.x and newer Available in App Store
Client for OS X Built-in Tunnelblick (free) and
Viscosity (commercial)
available
6. VPN Selection - Site to Site
â Interoperability with third party devices -
IPsec
â One endpoint behind NAT - OpenVPN
â NAT within VPN, both, but OpenVPN most
flexible
7. VPN Selection - Mobile Users
â OpenVPN usually easier to configure
â Depends on devices supported and personal
preferences
8. IPsec Intro - Modes
â Tunnel
â Transport
http://diecarvi.wordpress.com/2013/07/04/ipsec-tunnel-and-transport-modes-why-doesnt-transport-mode-work-between-routers/
9. IPsec and IPv6
â IPv6 inside IPv6 tunnels
â IPv4 inside IPv4 tunnels
â Mobile clients IPv4-only