LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-16-2015, 02:09 AM   #1
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Smile OpenVPN Network Topology Design


Hi all expert,

I'm need to setup vpn technology using for browsing internet securely.

AFAIK, VPN connection must operates on two endpoins.
Does this rules applies to LAN or WAN?

if LAN
OpenBSD Router(OpenVPN Server) <----------------- LAN (OpenVPN Client)

if WAN
OpenBSD Router(OpenVPN Client) ----------------------> VPS(OpenVPN Server)

Please help. Thanks.
 
Old 09-16-2015, 07:22 AM   #2
cliffordw
Member
 
Registered: Jan 2012
Location: South Africa
Posts: 509

Rep: Reputation: 203Reputation: 203Reputation: 203
Hi Peter,

I'm a little unclear on what you are trying to do. Could you elaborate? What exactly do you mean by "browsing internet securely"?

While using a VPN for browsing the internet can solve some problems (like preventing someone on the coffee shop wifi network from spying on you, and hiding your location), it doesn't necessarily "secure" your browsing completely, as the traffic has to leave the VPN at some point to reach the web server (i.e. the connection from the VPN server to the web server).

Assuming this is your network, you control the router, and trust other users on the LAN, there is probably no real benefit in a VPN between the client and the router. You can probably just create a VPN connection from the router to some external VPN server.

If you want to encrypt the LAN traffic too, you can either create two separate VPN connections as you suggested (from client to router, and from router to external VPN server), or just create an end to end VPN connection directly from the client to the VPN server (assuming the firewall rules on the router are set up to allow this).

I hope this helps.
 
Old 09-16-2015, 07:43 AM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940
The essential purpose of VPN is to create a tunnel which encompasses a range of IP-addresses and ports. All information passes securely through this tunnel, and the presence of the encryption is concealed from the users thereof. I think it's a good strategy to do this, when possible, at the router level.

If this is done, the router can usually act as a "trusted insider," in that you don't need to further secure the inside connections made to it. The router communicates securely with its counterparts to create, as the name implies, a "virtual private network."

In all cases, digital certificates, not "PSKs == passwords," should be used to secure the connection, and to uniquely identify every participating device. Every party knows that it is communicating with a bearer of a certificate that it has been told to recognize, and every one of these certificates is one-of-a-kind, issued by a trusted authority (you).

Last edited by sundialsvcs; 09-16-2015 at 07:45 AM.
 
Old 09-16-2015, 08:43 PM   #4
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Original Poster
Rep: Reputation: 31
Let me state the question clearly.

I don't want to secure the LAN connection at all.
From usual case, OpenVPN client connects to remote OpenVPN server but this setup is very slow. I cann't even browse google search with 2MBps connection.

Therefore, I'm plan to roll out OpenVPN Server on my own OpenBSD router and LAN clients connect to it and tunnel out the connection.
I wonder is this setup possbiel?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Looking for a Network Topology design software angel115 Linux - Software 4 05-06-2010 10:16 AM
Help with Network Topology and Firewall lrt Linux - Networking 10 02-07-2009 01:56 AM
Is this network topology available? bambeklis Linux - Networking 6 03-25-2008 03:43 PM
network topology visualization grimse Linux - Software 9 06-19-2005 04:24 PM
Network Topology chaste Linux - Networking 6 08-06-2002 09:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration