Get in Touch

Course Outline

VPN Sovereignty Fundamentals

  • Understanding why commercial VPNs log metadata and comply with legal requests.
  • OpenVPN: A mature, feature-rich solution offering TAP/TUN flexibility.
  • WireGuard: A modern, minimalistic protocol delivering high-performance cryptography.
  • Selecting the appropriate protocol for your specific threat model.

OpenVPN Deployment

  • Installing OpenVPN alongside Easy-RSA PKI.
  • Configuring the server: cipher, HMAC, TLS-auth, and topology settings.
  • Generating and distributing client configurations.
  • Managing revocation and Certificate Revocation Lists (CRL).

WireGuard Deployment

  • Installing the kernel module and WireGuard-tools.
  • Generating keys and configuring peers.
  • Utilizing wg-quick and systemd unit management.
  • Implementing road warrior and site-to-site mesh topologies.

Authentication and Authorization

  • Implementing certificate-based authentication with OpenVPN.
  • Integrating LDAP and RADIUS backends.
  • Enabling two-factor authentication via TOTP plugins.
  • Managing access control lists and per-user IP allocation.

Routing and Network Design

  • Distinguishing between full tunnel and split tunnel routing strategies.
  • Configuring pushed routes, DNS, and WINS settings.
  • Setting up NAT and masquerading for egress traffic.
  • Implementing Multi-WAN and policy-based routing.

Performance and Scaling

  • Analyzing throughput benchmarks comparing WireGuard and OpenVPN.
  • Optimizing for multi-core processors and kernel bypass techniques.
  • Load balancing across multiple VPN servers.
  • Implementing DDoS protection and connection rate limiting.

Monitoring and Maintenance

  • Tracking connection logs and accounting for bandwidth usage.
  • Integrating syslog and Prometheus exporters.
  • Scheduling automated certificate renewal and setting up expiration alerts.
  • Establishing disaster recovery plans and configuration backups.

Requirements

  • Intermediate knowledge of Linux networking and firewall administration.
  • Fundamental understanding of PKI, certificates, and encryption protocols.
  • Familiarity with routing, NAT, and IP forwarding concepts.

Audience

  • Network administrators transitioning from commercial VPN services.
  • Remote work teams requiring secure, sovereign access solutions.
  • Organizations operating in regions with VPN restrictions or surveillance.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories