Get in Touch

Course Outline

Foundations of VPN Sovereignty

  • Reasons why commercial VPNs may log metadata and respond to legal inquiries.
  • OpenVPN: A mature, feature-dense solution with TAP/TUN versatility.
  • WireGuard: A modern, lightweight approach with high-performance cryptography.
  • Selecting the appropriate protocol based on your specific threat model.

Deploying OpenVPN

  • Installing OpenVPN alongside Easy-RSA PKI.
  • Server-side setup: defining ciphers, HMAC, TLS-auth, and topology.
  • Generating and distributing client configurations.
  • Managing revocation and CRLs.

Deploying WireGuard

  • Installing kernel modules and WireGuard tools.
  • Generating keys and configuring peers.
  • Managing wg-quick and systemd units.
  • Setting up road warrior and site-to-site mesh topologies.

Authentication and Authorization

  • Utilizing certificate-based authentication with OpenVPN.
  • Integrating LDAP and RADIUS backends.
  • Implementing two-factor authentication via TOTP plugins.
  • Configuring access control lists and per-user IP assignments.

Routing and Network Architecture

  • Distinguishing between full tunnel and split tunnel routing.
  • Configuring push routes, DNS, and WINS.
  • Applying NAT and masquerading for egress traffic.
  • Implementing Multi-WAN and policy-based routing.

Performance and Scalability

  • Benchmarking WireGuard versus OpenVPN throughput.
  • Optimizing for multi-core performance and kernel bypass.
  • Load balancing across multiple VPN servers.
  • Mitigating DDoS attacks and enforcing connection rate limits.

Monitoring and Maintenance

  • Logging connections and tracking bandwidth accounting.
  • Integrating Syslog and Prometheus exporters.
  • Automating certificate renewal and expiration alerts.
  • Planning disaster recovery and configuration backups.

Requirements

  • Mid-level proficiency in Linux networking and firewall management.
  • Knowledge of PKI, digital certificates, and encryption protocols.
  • Comfort with routing, NAT, and IP forwarding concepts.

Target Audience

  • Network administrators transitioning from commercial VPN services.
  • Remote teams requiring secure, sovereign access.
  • Organizations operating in regions characterized by VPN blocking or surveillance.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories