@dguido Use IKEv2 w/ Suite B algos (i.e. AES GCM) and key sizes. Disable short key lengths, some clients default to them for compat (iOS).
-
-
-
@dguido TLS (used by OpenVPN) is overkill for use between trusted peers and enables attacks that are less risk elsewhere (i.e. heartbleed). -
@dinodaizovi Oh, I've made my choice (and it agrees with yours I see)! I'm looking for more detailed info to back it up now. -
@dinodaizovi AFAICT the one thing OpenVPN has on IPSec (by a mile) is ease of config and there is really something to be said for that. -
@dguido@dinodaizovi I think@kennwhite did a big thing on IPSec config. -
@thegrugq@dguido@dinodaizovi imo best config (for both) is Streisand: https://github.com/jlund/streisand My pref is IPSec IKEv2 w/ GCM mode sans lt2p -
@thegrugq@dguido@dinodaizovi and 99.999% of VPN services are steaming piles at best, fully surveilled at worst. -
@kennwhite@thegrugq@dguido Yeah, I wouldn't recommend them for much beyond routing around streaming video country restrictions.
End of conversation
New conversation -
-
-
@dguido yes, one is easy to configure the other one drives you to near insanity every single time...you figure out which one ;-PThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@dguido yes, but unfortunately the next answer is "no" (for 3-6mo values of no)Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@dguido I wish there were better how-tos online for popular IPSec clients like osx/iOS. Getting one connected to cisco IOS should be easier!Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@dguido rfc4308 + rfc7296 + RFC7427 + RFC7670Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@dguido IKEv2 = IPv6 + IPv4 + Peer Authorization Database + EAP-IKEv2 Payloads + new of Internet Key Exchange Version 2 (IKEv2) ParametersThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.