Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of VPN Sovereignty
- Reasons why commercial VPNs may log metadata and respond to legal inquiries.
- OpenVPN: A mature, feature-dense solution with TAP/TUN versatility.
- WireGuard: A modern, lightweight approach with high-performance cryptography.
- Selecting the appropriate protocol based on your specific threat model.
Deploying OpenVPN
- Installing OpenVPN alongside Easy-RSA PKI.
- Server-side setup: defining ciphers, HMAC, TLS-auth, and topology.
- Generating and distributing client configurations.
- Managing revocation and CRLs.
Deploying WireGuard
- Installing kernel modules and WireGuard tools.
- Generating keys and configuring peers.
- Managing wg-quick and systemd units.
- Setting up road warrior and site-to-site mesh topologies.
Authentication and Authorization
- Utilizing certificate-based authentication with OpenVPN.
- Integrating LDAP and RADIUS backends.
- Implementing two-factor authentication via TOTP plugins.
- Configuring access control lists and per-user IP assignments.
Routing and Network Architecture
- Distinguishing between full tunnel and split tunnel routing.
- Configuring push routes, DNS, and WINS.
- Applying NAT and masquerading for egress traffic.
- Implementing Multi-WAN and policy-based routing.
Performance and Scalability
- Benchmarking WireGuard versus OpenVPN throughput.
- Optimizing for multi-core performance and kernel bypass.
- Load balancing across multiple VPN servers.
- Mitigating DDoS attacks and enforcing connection rate limits.
Monitoring and Maintenance
- Logging connections and tracking bandwidth accounting.
- Integrating Syslog and Prometheus exporters.
- Automating certificate renewal and expiration alerts.
- Planning disaster recovery and configuration backups.
Requirements
- Mid-level proficiency in Linux networking and firewall management.
- Knowledge of PKI, digital certificates, and encryption protocols.
- Comfort with routing, NAT, and IP forwarding concepts.
Target Audience
- Network administrators transitioning from commercial VPN services.
- Remote teams requiring secure, sovereign access.
- Organizations operating in regions characterized by VPN blocking or surveillance.
14 Hours